Trump administration authorises private firms to conduct cyber attacks on overseas criminals
The White House has directed the National Coordination Center to develop a program allowing vetted security companies to hack transnational criminal organisations targeting US interests, subject to strict oversight and financial penalties.

The Trump administration has issued a National Security Presidential Memorandum directing the National Coordination Center to develop a program allowing private security firms to conduct authorised cyber operations against overseas transnational criminal organisations. This marks the first time the federal government has permitted the private sector to perform offensive cyber attacks, including the use of spyware or data destruction, against groups targeting US persons or entities.
The Departments of Justice and Homeland Security will oversee the program, which requires participating companies to undergo vetting, meet technical standards, and deposit $1 million in an escrow account. Operations are prohibited from resulting in loss of life or rising to the level of armed attack under international law.
The memorandum defines eligible targets as foreign groups conducting cyber-enabled crime against the US government, US persons, or US interests, provided they are not institutional parts of a foreign government. Eligible activities for private firms include combating ransomware, sextortion, phishing, financial fraud, and impersonation scams.
Private companies must undergo vetting by the Departments of Justice and Homeland Security and meet minimum standards for technical proficiency, security, and reliability. The memo also notes that the Computer Fraud and Abuse Act, which typically criminalises unauthorised computer access, will not apply to participating firms for these authorised actions.
Independent security researcher Kevin Beamont noted that while hacking ransomware groups has merit, private cyber companies have historically lobbied against regulatory changes that might reduce their profitability. He stated that putting them in charge of stopping cybercrime seems optimistic without correct incentives.
The Departments of Justice and Homeland Security have 60 days to deliver specific operational particulars and standards for the programme. The deposit of $1 million will be forfeited should a participating company enter non-compliance with its contractual agreement.
The programme is distinct from other recent Trump administration controversies, such as the lawsuit challenging the Truth Social API subscription model. This directive represents a substantial expansion from a 2022 Department of Justice announcement that declined to prosecute white-hat hackers conducting security research.


