The U.S. is bringing private business into offensive cyber operations: a new era or a zone of risk?

The American administration has made a radical move in the field of cybersecurity, officially allowing certified private companies to participate in offensive operations against transnational cybercriminal groups. The corresponding memorandum, signed by the president on August 12, marks a transition from passive cooperation to active action under the auspices of the state.
This is not just about intelligence gathering. According to the new document, contractors gain the right to direct "kinetic impact" on attackers' information systems—from blocking and disrupting operations to the complete destruction of equipment and data. The primary goal is to combat ransomware, financial fraud, and other digital crime originating from abroad.
Mechanics and control
The key point is a strict chain of command. Operations will be led by the National Coordination Center under the Department of Homeland Security, with oversight handled by the Department of Justice. Private companies will not be able to act at their own discretion: the government will determine targets for them, and independent selection is strictly prohibited.
Access to the program is not for the faint of heart. In addition to verified technical competence and experience, a contractor must post a bond or place at least $1 million in an escrow account. These funds may be confiscated in the event of contract violations. There is also an important restriction on targets: attacks are permitted only against foreign criminal structures that are not part of or a direct instrument of any state.
Preparation for such a turn has been underway for a long time. As early as March, a presidential decree ordered the development of a plan to counter foreign scam centers, and even then the idea of involving the private sector was being laid out. Now that idea has taken on concrete legal form as a separate program.
Precedents and first results
It is important to understand that cooperation between authorities and tech giants is not new. Suffice it to recall the May operation Scam Center Strike Force, in which Apple, Coinbase, Google, Meta, Microsoft, and SpaceX participated. At that time, using government data on fraudulent networks in Southeast Asia, companies blocked more than 1.4 million accounts, disabled servers, and froze over $3.8 million in cryptocurrency. In Thailand, seven suspects were detained as a result of the operation.
However, previous business actions were limited to the confines of their own platforms. The new memorandum removes these restrictions, elevating cooperation to a fundamentally different level—the level of direct attacks.
This is where the main stumbling block lies. Involving the private sector in offensive actions is a double-edged sword. There are serious risks of retaliatory aggression from hackers, the likelihood of collateral damage to innocent parties, and inevitable difficulties in coordination among numerous agencies and companies. This is not just a technical challenge but a legal and ethical minefield.
My view: This step is an acknowledgment that the state alone can no longer effectively combat transnational cybercrime, especially given the damage that, according to UN estimates, reached $114 billion in the Asia-Pacific region alone. But transferring offensive cyber capabilities into the hands of private contractors sets a dangerous precedent. The question is not whether they can do it technically, but who will bear responsibility for the inevitable "collateral effects" in the global network.