Crypto news

14.08.2026
11:09

The U.S. is bringing private business into offensive cyber operations: Trump's new memorandum

USA США

On August 12, U.S. President Donald Trump signed a memorandum that dramatically expands the role of the private sector in combating international cybercrime. The document legalizes the participation of certified commercial entities in offensive operations against foreign hacker groups—but under strict federal oversight.

The focus is on transnational criminal networks specializing in ransomware, financial fraud, and other digital offenses. Contractors will gain access to intelligence about attackers' infrastructure and can propose targets for precision strikes. Moreover, certified firms will be permitted to conduct disabling actions—from blocking and disrupting systems to the complete destruction of equipment and data.

Mechanics and Oversight

Coordination of the program is assigned to the National Coordination Center under the Department of Homeland Security, with oversight provided by the Department of Justice. The key principle is that companies operate exclusively "under the direction, control, and authority of the U.S. government." Independent target selection is strictly prohibited.

Participation requires certification: technical competence, proven experience in similar operations, and the security of one's own infrastructure. Additionally, the contractor must post a bond or place at least $1 million in an escrow account—these funds may be confiscated in case of violations. The range of permissible targets is limited: only foreign criminal structures that are not part of another state's government.

Preparation for this initiative began back in the spring. A decree from March 6 tasked developing a plan to counter foreign scam centers, including the creation of an operational cell and the involvement of the private sector. Now the memorandum translates these intentions into practical action.

Precedents of Cooperation

U.S. authorities have already interacted with tech giants on multiple occasions. In May, the Scam Center Strike Force task force conducted its first large-scale Disruption Week with participation from Apple, Coinbase, Google, Meta, Microsoft, SpaceX, and TRM Labs. Law enforcement shared data on fraudulent networks in Southeast Asia with partners, and companies independently identified accounts and infrastructure of violators.

The results are impressive: over 1.4 million accounts on social media and email services were blocked, malicious traffic was disrupted, and scam servers were taken offline. More than $3.8 million in cryptocurrency used for money laundering was frozen, and seven suspects were detained in Thailand.

However, involving businesses in offensive actions remains controversial. Among the key risks are retaliatory aggression, collateral damage to innocent parties, and coordination difficulties between agencies. It's worth recalling that, according to estimates from the UN Office on Drugs and Crime, losses from scam operations in Asia and Oceania reached $114.1 billion in 2025.

My analysis: This step is a logical evolution of public-private partnership in cybersecurity, but it opens a Pandora's box. Legal liability for potential collateral damage will fall on businesses, which could deter many players. However, in conditions where losses from cybercrime are measured in hundreds of billions, the stakes justify an experimental approach.