DEALSTreasury's $6bn buyback fails to halt 30-year yield at 5.2%Sep 10, 2026
WORLDChina regulators warn banks against flooding IPO market with low-quality listingsSep 10, 2026
EARNINGSJ.J. McCarthy demoted to third string as Vikings name Wentz backup ahead of Green Bay openerSep 10, 2026
KALAKALA BIO sets November 3 annual meeting; stockholder nomination window closes September 19Sep 9, 2026
MACROTwenty-nine health systems plan to exit Medicare AdvantageSep 9, 2026
MACROCopper hits record $14,858.50 a ton as tariff stockpiling and global supply crunch convergeSep 9, 2026
CRYPTOIran relaxes foreign currency controls in quiet pivot toward cryptoSep 9, 2026
AMZNAmazon routes 360,000 annual scam inquiries through a new Alexa verification toolSep 9, 2026
DEALSTreasury's $6bn buyback fails to halt 30-year yield at 5.2%Sep 10, 2026
WORLDChina regulators warn banks against flooding IPO market with low-quality listingsSep 10, 2026
EARNINGSJ.J. McCarthy demoted to third string as Vikings name Wentz backup ahead of Green Bay openerSep 10, 2026
KALAKALA BIO sets November 3 annual meeting; stockholder nomination window closes September 19Sep 9, 2026
MACROTwenty-nine health systems plan to exit Medicare AdvantageSep 9, 2026
MACROCopper hits record $14,858.50 a ton as tariff stockpiling and global supply crunch convergeSep 9, 2026
CRYPTOIran relaxes foreign currency controls in quiet pivot toward cryptoSep 9, 2026
AMZNAmazon routes 360,000 annual scam inquiries through a new Alexa verification toolSep 9, 2026

Trump memorandum authorizes private firms to hack foreign cybercriminal networks

$20.877 billion in losses reported to the FBI's Internet Crime Complaint Center in 2025, across 1,008,597 complaints and running 26% above the 2024 figure, is the aggregate the White House put behind President Donald Trump's decision to…

By Kwame Asante·Aug 23, 2026·2 min read·world

Key takeaways

  • President Donald Trump signed a National Security Presidential Memorandum authorizing vetted private U.S. companies to conduct offensive cyber operations against certain foreign criminal organizations.
  • The White House cited $20.877 billion in losses reported to the FBI's Internet Crime Complaint Center in 2025 across 1,008,597 complaints, running 26% above the 2024 figure, as justification.
  • The Department of Justice and Department of Homeland Security will jointly oversee the operations, which fall into two classes: Cyber Surveillance Operations and Cyber Effects Operations.
  • Every participating company must be accepted into the program, sign a contract with DOJ or DHS, and obtain written approval from executive directors before any operation, with a possible bond or escrow of at least $1 million.
  • Program leaders have 60 days from August 12 to draft procedural rules, and no companies have been named as participants.

$20.877 billion in losses reported to the FBI's Internet Crime Complaint Center in 2025, across 1,008,597 complaints and running 26% above the 2024 figure, is the aggregate the White House put behind President Donald Trump's decision to sign a National Security Presidential Memorandum authorizing vetted private U.S. companies to conduct offensive cyber operations against certain foreign criminal organizations. The Department of Justice and Department of Homeland Security will jointly oversee those operations. Program leaders have 60 days from August 12 to write the procedural rules that will make the framework executable.

Two operation classes, one written approval gate

The memorandum establishes two categories of activity. Cyber Surveillance Operations allow covert access to targeted computer systems for intelligence collection, with participants expected to remain undetected. The memo acknowledges that access may occur without authorization from system owners.

Cyber Effects Operations go further. Participants can manipulate, disrupt, deny access to, degrade, or destroy systems and digital infrastructure that the targeted organizations control.

Neither class is self-directing. Every company must be accepted into the program and execute a contractual agreement with DOJ or DHS. Before any operation proceeds, the program's executive directors must review the operation package and issue written approval. DOJ or DHS may also require a bond or escrow account of at least $1 million, forfeitable on contract violation.

Targets, guardrails, and the line the program cannot cross

The authorized targets are defined as Cyber-Enabled Transnational Criminal Organizations (CE-TCOs): foreign groups that conduct cyber-enabled crimes against the U.S. government, Americans, or U.S. interests. Organizations that form an institutional part of a foreign government, or operate wholly under foreign government direction, are excluded.

If an operation strays onto a U.S. person or a system located in the United States, the company must stop immediately, apply minimization procedures, and notify the National Coordination Center, which then routes disclosure to the Justice Department.

The memorandum defines a Critical Outcome category: any operation likely to result in loss of life, serious injury, or rising to the level of a use of force or armed attack under international law. Program directors at DOJ and DHS are not permitted to approve those. What happens above that threshold is not spelled out in the public version of the memo.

No companies have been named as participants. The operational procedures governing eligibility, targeting, legal review, and oversight are still being drafted. Annual evaluations of participating companies are required once the program is running, and a first status report to the White House homeland security adviser and the National Cyber Director is due within 180 days of August 12.

Related reading

Share
Source: foxnews.com
© 2026 NewsMeter

Frequently asked

What are the two categories of operations authorized by the memorandum?

Cyber Surveillance Operations allow covert access to targeted systems for intelligence collection while remaining undetected, and Cyber Effects Operations allow participants to manipulate, disrupt, deny access to, degrade, or destroy systems controlled by targeted organizations.

Who can be targeted under the program?

The authorized targets are Cyber-Enabled Transnational Criminal Organizations (CE-TCOs), foreign groups conducting cyber-enabled crimes against the U.S. government, Americans, or U.S. interests; groups that are part of or operate wholly under a foreign government's direction are excluded.

What happens if an operation affects a U.S. person or a system in the United States?

The company must stop immediately, apply minimization procedures, and notify the National Coordination Center, which routes disclosure to the Justice Department.

What operations are program directors forbidden from approving?

Directors at DOJ and DHS cannot approve operations in the Critical Outcome category—those likely to result in loss of life, serious injury, or rising to the level of a use of force or armed attack under international law.

When is the first status report to the White House due?

A first status report to the White House homeland security adviser and the National Cyber Director is due within 180 days of August 12.