President Trump signed a memorandum allowing vetted U.S. companies to carry out cyberattack campaigns targeting transnational criminal organizations.

President Donald Trump on Tuesday signed a memorandum directing the federal government to mobilize vetted U.S. companies to take part in cyberattack campaigns targeting foreign criminal networks. The President’s National Security Memorandum, dated August 12, establishes a program under the National Coordination Center of the Department of Homeland Security’s special operations forces.

According to the White House, this document expands the fight against cybercrime carried out by transnational criminal organizations by tapping the creative capabilities of the private sector, through cooperation with companies operating under the direction and oversight of the Federal Government, to enhance the ability to respond to threats from transnational crime, fraud, and other profit-seeking schemes targeting U.S. citizens.

The program will be overseen by two executive directors, one from the Department of Justice and one from the Department of Homeland Security. Private companies that contract with one of these two agencies may propose and carry out operations to access, monitor, disrupt, or destroy systems related to criminal networks operating abroad.

The review mechanism and the scope of permitted activities

The real-world implementation process requires a company to submit an application, pass the review process, and provide a bond or at least a $1 million escrow; this money will be forfeited if the company violates the regulations. The company gathers information about threats from other businesses or from state and local authorities, and then proposes an operational plan to the coordinating office within the Department of Homeland Security.

No operation may be carried out until the program’s executive directors have fully reviewed the dossiers and issued approval along with written direction, while the Government retains oversight and the company may take action only when directed by the Government.

The memorandum allows network monitoring activities, including accessing systems without authorization from the owner or beyond the access scope granted, as well as broader attacks targeting the networks behind ransomware campaigns, phishing, financial fraud, and sex extortion.

However, campaigns that could cause serious consequences will be prohibited, and if a campaign affects U.S. citizens or a system located in the U.S., the activity must be halted immediately and impact-mitigation procedures applied.

The White House cites the scale of the threat as the basis for this policy, noting that the U.S. policy is to use every tool of national power, including the private sector’s innovation capabilities, to combat cybercrime.

Separately, fraud cases related to crypto assets are estimated to have caused $80.7 billion in losses to Americans in 2025, while North Korean hackers are currently using increasingly sophisticated methods to launder stolen crypto assets, and the U.S. government has seized more than $25 million in crypto assets linked to investment scams and romance scams.

The rules for determining the program’s specific targets are set out in a classified annex; therefore, the limits that are publicly disclosed still contain relatively little detail, while the memorandum sets a 60-day timeframe for issuing implementation guidance.