The U.S. is bringing private business into offensive cyber operations: Trump's new memorandum

On August 12, U.S. President Donald Trump signed a memorandum that radically expands the role of the private sector in combating transnational cybercrime. Now, certified commercial companies will be allowed to participate in offensive operations against foreign criminal groups—but only under strict federal oversight. This is not just a declaration, but a working mechanism that elevates state-business cooperation to a fundamentally new level.
The essence of the new initiative
The program targets criminal syndicates engaged in ransomware, financial fraud, and other digital crimes. Contractors will be permitted not only to gather intelligence on their infrastructure but also to conduct targeted actions—up to blocking, destabilizing, or completely destroying servers and data. Coordination of operations is assigned to the National Coordination Center under the Department of Homeland Security, while oversight is provided by the Department of Justice. Private companies will operate exclusively "under the direction, control, and authority of the U.S. government"—independent target selection is strictly prohibited.
Conditions for contractors
Admission to the program requires serious certification: technical competence, proven experience in similar operations, and the security of their own infrastructure. Additionally, participants must post a bond or place at least $1 million in an escrow account—these funds may be confiscated in case of violations. The range of permissible targets is strictly limited: only foreign criminal structures that are not part of another state's government and not under its direct control.
Preparation for such a step has been underway since spring. In a decree dated March 6, Trump ordered the development of a plan to counter foreign scam centers, explicitly providing for the creation of an operational cell and the involvement of the private sector. Now this directive has taken the form of a separate program.
First results and risks
Cooperation with tech giants is already bearing fruit. In May, the Scam Center Strike Force task force, with participation from Apple, Coinbase, Google, Meta, Microsoft, SpaceX, and TRM Labs, conducted its first large-scale Disruption Week. Law enforcement shared data on fraudulent networks in Southeast Asia with partners, and the companies independently identified and blocked over 1.4 million accounts, halted malicious traffic, and took down servers. Participants also froze over $3.8 million in cryptocurrency used for money laundering, and seven suspects were detained in Thailand.
However, involving businesses in offensive actions is a double-edged sword. Among the key risks are retaliatory aggression from hackers, collateral damage to innocent parties, and coordination difficulties between agencies. Recall that in July, the UN Office on Drugs and Crime estimated damages from scam operations in East and Southeast Asia, Australia, and New Zealand at $114.1 billion for 2025.
My analysis: This initiative is a landmark precedent that could change the rules of the game in cybersecurity. But the program's effectiveness will depend on how clearly authorities can control the actions of private contractors. Otherwise, we risk uncontrolled chaos in the digital space, where the line between a legitimate operation and cyberwarfare becomes even more blurred.