Cybersecurity & Protection

US Allows Vetted Companies to Conduct Offensive Cyber Operations Against Criminals

Aug 14, 2026 3 min read
All articles

US President Donald Trump has signed a national security memorandum allowing vetted companies to conduct limited offensive cyber operations against foreign criminal groups. The new powers come with strict requirements and remain under the direct oversight of the US government.

Government control as a prerequisite

The memorandum tasks the Homeland Security Task Force's National Coordination Center with building the corresponding program, jointly led by the Department of Homeland Security (DHS) and the Department of Justice (DOJ). Before a company can take part, it must go through a vetting process and sign contracts with the agencies. Those contracts can additionally require the companies to post a bond or escrow amount of at least one million US dollars.

Once approved, companies can propose attacks on foreign networks and collect cybersecurity data. The authorization covers both cyber surveillance and cyber effects operations. According to the document, the latter include manipulating, disrupting, denying, degrading, or destroying information systems, networks, and physical or virtual infrastructure controlled by such systems.

Targeted against criminal organizations

The program targets criminal organizations abroad that use ransomware, financial fraud, or attacks on critical infrastructure. Just at the end of July 2026, a coordinated attack on more than 30 water utilities in Minnesota and at least six other US states caused disruptions. Still, the contracts don't give companies unlimited freedom of action: program leaders may not approve operations that are likely to injure or kill people or that would qualify as a use of force under international law. Actions against US citizens or domestic systems require additional, potentially judicial, approval. If such targets are unintentionally affected, the companies must halt the operation, take mitigation steps, and report it immediately.

Criticism from experts

The security industry has voiced concerns about legal risk, possible unintended consequences, and an escalation of digital conflicts. Jake Williams, vice president at Hunter Strategy, sees a danger that Americans involved abroad could be classified as unlawful combatants, regardless of whether such a classification would actually hold up. Former Cyber Command officer Jason Kitka called the program a "perpetual threat-billing machine," meaning an incentive for companies to keep proposing new operations. Security veteran Chris Wysopal described the memorandum as a "major shift in US cyber policy," though one that falls short of earlier hackback proposals. How targets are identified and mistakes corrected is governed by a classified annex to the memorandum that isn't publicly available.