$20.877 billion in losses reported to the FBI's Internet Crime Complaint Center in 2025, across 1,008,597 complaints and running 26% above the 2024 figure, is the aggregate the White House put behind President Donald Trump's decision to sign a National Security Presidential Memorandum authorizing vetted private U.S. companies to conduct offensive cyber operations against certain foreign criminal organizations. The Department of Justice and Department of Homeland Security will jointly oversee those operations. Program leaders have 60 days from August 12 to write the procedural rules that will make the framework executable.
Two operation classes, one written approval gate
The memorandum establishes two categories of activity. Cyber Surveillance Operations allow covert access to targeted computer systems for intelligence collection, with participants expected to remain undetected. The memo acknowledges that access may occur without authorization from system owners.
Cyber Effects Operations go further. Participants can manipulate, disrupt, deny access to, degrade, or destroy systems and digital infrastructure that the targeted organizations control.
Neither class is self-directing. Every company must be accepted into the program and execute a contractual agreement with DOJ or DHS. Before any operation proceeds, the program's executive directors must review the operation package and issue written approval. DOJ or DHS may also require a bond or escrow account of at least $1 million, forfeitable on contract violation.
Targets, guardrails, and the line the program cannot cross
The authorized targets are defined as Cyber-Enabled Transnational Criminal Organizations (CE-TCOs): foreign groups that conduct cyber-enabled crimes against the U.S. government, Americans, or U.S. interests. Organizations that form an institutional part of a foreign government, or operate wholly under foreign government direction, are excluded.
If an operation strays onto a U.S. person or a system located in the United States, the company must stop immediately, apply minimization procedures, and notify the National Coordination Center, which then routes disclosure to the Justice Department.
The memorandum defines a Critical Outcome category: any operation likely to result in loss of life, serious injury, or rising to the level of a use of force or armed attack under international law. Program directors at DOJ and DHS are not permitted to approve those. What happens above that threshold is not spelled out in the public version of the memo.
No companies have been named as participants. The operational procedures governing eligibility, targeting, legal review, and oversight are still being drafted. Annual evaluations of participating companies are required once the program is running, and a first status report to the White House homeland security adviser and the National Cyber Director is due within 180 days of August 12.