The U.S. is bringing the private sector into offensive cyber operations: a new era of hybrid warfare with cybercrime.

The U.S. administration has taken a radical step in the fight against transnational cybercrime. On August 12, President Donald Trump signed a memorandum that legalizes the participation of certified private companies in offensive cyber operations against foreign criminal groups. This is not just an expansion of authority—it is a fundamental transformation of the model of interaction between the state and business in digital warfare.
The new program focuses on combating groups specializing in ransomware, financial fraud, and other illegal activities online. Contractors will gain the right not only to collect intelligence on attackers' infrastructure but also to conduct "kinetic effects"—up to blocking, disrupting, or completely destroying servers and data.
Program Mechanics and Oversight
Operational management is assigned to the National Coordination Center under the Department of Homeland Security, with oversight provided by the Department of Justice. The key principle is that companies operate exclusively "under the direction, control, and authority of the U.S. government." Independent target selection is strictly prohibited.
Participation requires rigorous certification: technical competence, proven experience, and the security of one's own infrastructure. The financial barrier is also high—applicants must post a bond or place at least $1 million in an escrow account, which may be confiscated in case of violations. Targets are strictly limited: only foreign criminal structures that are not part of another state's government.
From Intelligence to Action
Preparation for this step has been underway since spring. The executive order of March 6 tasked developing a plan to counter foreign scam centers, explicitly providing for the creation of an operational cell and the involvement of the private sector. Now this plan is taking concrete form—private contractors are becoming full-fledged participants in state-sanctioned offensive actions.
It is worth noting that cooperation with the technology sector is not new. In May, the Scam Center Strike Force task force conducted its first large-scale "Disruption Week" with the participation of Apple, Coinbase, Google, Meta, Microsoft, SpaceX, and TRM Labs. At that time, companies, having received data on fraudulent networks from Southeast Asia, independently blocked accounts and infrastructure within their platforms. The results are impressive: more than 1.4 million blocked accounts, over $3.8 million in cryptocurrency frozen, and seven suspects detained in Thailand.
However, the new memorandum elevates this cooperation to a fundamentally different level. Private companies gain the right to conduct direct offensive actions, which inevitably generates serious risks: possible retaliatory aggression from hackers, collateral damage to innocent parties, and difficulties in coordination between agencies.
My analysis: This is a historic precedent that could change the rules of the game in global cybersecurity. On the one hand, leveraging the resources and expertise of the private sector is a logical step against well-funded criminal syndicates causing $114 billion in damage in the Asia-Pacific region alone. On the other hand, blurring the line between the state's monopoly on violence and corporate interests creates a dangerous precedent. The question is not whether companies can act effectively, but who will bear responsibility for the inevitable mistakes and collateral damage in cyberspace.