Crypto news

14.08.2026
09:45

The U.S. is bringing the private sector into offensive cyber operations: a new phase in the fight against transnational crime.

USA США

Washington is betting on consolidating the efforts of the state and business in countering digital threats. On August 12, the U.S. President approved a memorandum that radically expands the powers of certified private companies in the field of cybersecurity. Now they will be able not only to collect intelligence but also to directly participate in offensive operations against foreign hacker groups, operating under the auspices of the federal government.

The program is aimed at eliminating transnational syndicates engaged in ransomware, financial fraud, and other cybercrimes. The key innovation is the permission for "kinetic impact": from blocking and disrupting operations to the complete destruction of attackers' infrastructure, including equipment and data.

Mechanics and oversight

Coordination is assigned to the National Coordination Center under the Department of Homeland Security, while oversight is provided by the Department of Justice. Private contractors act exclusively "under the direction, control, and authority of the U.S. government," which precludes freelance target selection. Access to the program requires strict certification: confirmed technical competence, relevant experience, and reliable protection of their own systems. The financial barrier is a bond or escrow account of at least $1 million, which may be confiscated for violating the terms.

It is important to emphasize: targets are strictly limited to foreign criminal structures that are not part of another country's state apparatus. This excludes politically motivated operations and keeps the focus on purely criminal elements.

Prelude to decisive action

Preparation for such a scenario has been underway since spring. A decree from March 6 already mandated the creation of an operational cell and the involvement of commercial infosec companies to identify malicious actors and disrupt their operations. The current memorandum formalizes these developments into a full-fledged program with the right to conduct offensive actions.

Indicative is the May experience of the Scam Center Strike Force task force, within which Apple, Coinbase, Google, Meta, Microsoft, SpaceX, and TRM Labs already interacted with authorities. Then, relying on transmitted data about fraudulent networks in Southeast Asia, the companies blocked more than 1.4 million accounts, disabled servers, and froze over $3.8 million in cryptocurrency. In Thailand, seven suspects were detained as a result of the operation.

However, the new initiative also raises legitimate risks: retaliatory aggression from hackers, collateral damage to innocent parties, and coordination difficulties between agencies. It is also important to remember the scale of the threat: according to UN estimates, damage from scam operations in Asia and Oceania in 2025 reached $114.1 billion.

My analysis: This is a landmark precedent that legalizes business participation in cyber warfare. However, the program's effectiveness will depend on the clarity of oversight and the minimization of collateral damage. In the long term, such measures could become a standard for other jurisdictions, but for now, this is a risky experiment requiring impeccable execution discipline.