The U.S. is bringing private business into the cyber war: a new strategy against international hackers

On August 12, U.S. President Donald Trump signed a memorandum that dramatically expands the role of the private sector in combating cybercrime. This is not just about cooperation, but about the direct participation of certified commercial companies in offensive cyber operations against foreign criminal groups—under strict federal oversight.
The program targets transnational syndicates engaged in ransomware, financial fraud, and other digital crimes. Contractors will be allowed not only to gather intelligence on attackers' infrastructure but also to conduct active operations: blocking, disrupting, or destroying servers and data.
Mechanics and oversight
Coordination is assigned to the National Coordination Center under the Department of Homeland Security, with oversight by the Department of Justice. Companies will operate exclusively "under the direction, control, and authority of the U.S. government"—independent target selection is prohibited. To gain clearance, a contractor must pass strict certification: confirming technical competence, experience in similar operations, and the security of its own infrastructure. A bond or escrow deposit of at least $1 million is also required—this amount may be confiscated in case of violations.
An important nuance: targets are strictly limited to foreign criminal structures that are not part of any state or under its direct control. This eliminates the risk of diplomatic incidents with sovereign governments.
Preparation for this initiative has been underway since spring. In a March 6 executive order, Trump directed the development of a plan to counter foreign scam centers, providing for the creation of an operational cell and the involvement of the private sector. The new memorandum moves these intentions into the practical realm.
Precedents and early results
Cooperation with tech giants is already bearing fruit. In May, the Scam Center Strike Force task force conducted its first large-scale Disruption Week with participation from Apple, Coinbase, Google, Meta, Microsoft, SpaceX, and TRM Labs. Law enforcement shared data on fraudulent networks in Southeast Asia with partners, and companies independently identified accounts and infrastructure violating their policies.
The results are impressive: over 1.4 million accounts were blocked, malicious traffic was disrupted, and servers and hosting services were taken down. Participants froze over $3.8 million in cryptocurrency used for money laundering, and seven suspects were detained in Thailand.
However, involving the private sector in offensive actions is a double-edged sword. Key risks include retaliatory aggression from hackers, collateral damage to innocent parties, and coordination difficulties between agencies. Notably, losses from scam operations in Asia and Oceania reached $114.1 billion in 2025—this underscores the scale of the threat and explains such radical measures.
My verdict: this step is a logical evolution, but it opens Pandora's box. Private companies gain tools comparable to those of the state, and the only question is how effectively Washington can control the "gray cardinals" of cyberwarfare. In the long term, this could lead to a new arms race in the digital space.