The U.S. is bringing private business into offensive cyber operations: a new era of public-private partnership.

The U.S. administration has taken a radical step in the fight against transnational cybercrime. On August 12, President Donald Trump signed a memorandum that, for the first time, officially authorizes certified private companies to participate in offensive cyber operations against foreign criminal organizations. This decision fundamentally changes the rules of the game: businesses cease to be passive observers and become an active tool of state policy in the digital space.
The program targets groups specializing in ransomware, financial fraud, and other forms of digital scams. Contractors will gain the right not only to gather intelligence on criminals' infrastructure but also to conduct disruptive actions—from blocking to the complete destruction of servers and data. However, a key nuance: companies will not be able to act independently. All operations will be conducted under strict federal oversight, with targets approved exclusively by the government.
Mechanics and participant requirements
Coordination is assigned to the National Coordination Center under the Department of Homeland Security, with oversight provided by the Department of Justice. Private firms must undergo rigorous certification, confirming technical competence and the security of their own infrastructure. The financial barrier is also high: a bond or escrow account of at least $1 million, which may be confiscated in case of violations.
It is important to emphasize the limitations: targets must be exclusively foreign criminal organizations not affiliated with government agencies. This eliminates the risk of diplomatic incidents but leaves a gray area for interpretation.
Precedents and initial results
The new memorandum is a logical continuation of the course initiated back in March, when Trump ordered the development of a plan to counter scam centers. Already in May, the Scam Center Strike Force task force conducted its first large-scale operation involving Apple, Coinbase, Google, Meta, Microsoft, and SpaceX. The results are impressive: over 1.4 million blocked accounts, the freezing of more than $3.8 million in cryptocurrency, and arrests in Thailand.
Nevertheless, involving businesses in offensive actions raises questions. Risks include retaliatory hacker attacks on companies, collateral damage to innocent parties, and coordination difficulties between agencies. Given that losses from scam operations in Asia reached $114.1 billion in 2025, the stakes are high, but the cost of mistakes could also be significant.
My assessment: this is a bold but risky experiment. Its effectiveness will depend on how clearly the government can control private contractors and prevent abuses. In the crypto industry, where anonymity often plays into criminals' hands, such measures could become a powerful deterrent—but only under conditions of transparency and strict adherence to legal frameworks.