White House Memorandum Enlists Private Firms to Hack Foreign Cybercriminal Networks—At Their Own Legal Risk
Key Takeaways
- •The memorandum creates a program inside the National Coordination Center of the Homeland Security Task Force through which vetted U.S. companies can access, surveil, disrupt, or destroy systems tied to foreign criminal networks under federal direction.
- •Participating firms must clear a vetting process, post a bond or escrow of at least $1 million that is forfeited for rule violations, receive written approval from the program's executive directors before acting, and undergo annual review.
- •The policy departs from long-standing U.S. practice, since unauthorized computer access remains a federal crime under the Computer Fraud and Abuse Act and a 2017 bill that would have exempted limited defensive hacking never became law.
- •The White House justified the program by citing more than $20.8 billion in reported cyber-enabled crime losses in 2025, alongside FBI figures of $16.6 billion in reported losses for 2024, a 33 percent rise from 2023.
- •Operations that would cause Critical Outcomes are barred and any touching a U.S. person or U.S.-based system must stop immediately, but the targeting rules sit in a classified annex and the public text offers no liability shield for contractors.

President Donald Trump signed a memorandum on Tuesday directing the federal government to enlist vetted U.S. companies in offensive cyber operations against foreign criminal networks. The National Security Presidential Memorandum, dated Aug. 12, establishes a program inside the National Coordination Center (NCC) of the Homeland Security Task Force through which private firms can disrupt foreign cybercriminal networks—under government direction and at their own legal and financial risk.
The policy departs from long-standing U.S. practice against private "hacking back": unauthorized access to computers is a federal crime under the Computer Fraud and Abuse Act, Justice Department officials have long discouraged victims from retaliating on their own, and a 2017 bill that would have exempted limited defensive hacking from the CFAA—the Active Cyber Defense Certainty Act—never became law.
"This memorandum expands the fight against TCO-perpetrated cybercrime by incorporating the ingenuity of the private sector," the White House wrote in the order's purpose section, referring to transnational criminal organizations. "By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens."
Per the memorandum, "it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime."
How the program works
Two executive directors—one each from the Department of Justice and the Department of Homeland Security—would run the program. Private firms that contract with either agency could propose and carry out operations to access, surveil, disrupt, or destroy systems tied to those criminal networks operating abroad. The DOJ-DHS pairing mirrors the existing division of labor in cyber enforcement: the FBI sits inside Justice, while DHS houses the Secret Service, which investigates cybercrime, and the Cybersecurity and Infrastructure Security Agency, which handles defense of civilian networks.
A participating company applies, clears a vetting process, and posts a bond or escrow of at least $1 million, which is forfeited if the company breaks the rules. It then gathers threat information from other businesses or from state and local agencies and proposes operations to the NCC at Homeland Security. Nothing moves until the program's executive directors review the package and give written approval and direction. The government keeps operational control: the company pulls the trigger only on the government's say-so. Participating companies also face annual review.
What the companies can do
The memo authorizes "Cyber Surveillance Operations"—accessing systems without the owner's permission or by exceeding authorized access—as well as broader offensive action against the networks behind ransomware, phishing, financial fraud, and sextortion schemes. Operations that would cause "Critical Outcomes" are barred, and any operation touching a U.S. person or a U.S.-based system must stop immediately under minimization procedures.
U.S. agencies have disrupted criminal infrastructure before—botnet takedowns and server seizures carried out by government personnel under court orders—but the memo extends operational roles to vetted contractors.
The stated justification: scale
The scale of the threat is the White House's stated rationale. Americans reported more than $20.8 billion in losses to cyber-enabled crime in 2025, the White House said. Crypto scams alone cost Americans an estimated $80.7 billion in 2025. North Korean hackers now have more sophisticated and complex ways to launder stolen crypto, and the government has already seized more than $25 million in crypto tied to investment and romance scams. The program would scale that enforcement model with private hands. The trajectory has been rising for years: the FBI's Internet Crime Complaint Center logged $16.6 billion in reported losses for 2024, up 33% from 2023.
Guardrails and open questions
The program's targeting rules sit in a classified annex, so the public guardrails are thin on detail. Because a presidential memorandum cannot amend federal law, the public text describes no liability shield for contractors—and intrusions into systems located abroad can also violate the laws of the countries where those systems sit, a risk long cited in hacking-back debates. The memo gives companies 60 days before implementation guidance is due; the first vetted firms and the program's annual review cycle are the next visible checkpoints.
The full memorandum is available on the White House website.