The U.S. is bringing the private sector into cyber warfare: a new era in the fight against digital crime.

The American administration has taken an unprecedented step by officially legalizing the participation of private companies in offensive cyber operations against foreign criminal structures. On August 12, the U.S. President approved a memorandum that radically changes the rules of the game in the field of digital security.
The essence of the new initiative
This involves the creation of a formalized program under which certified contractors will gain the right not only to collect intelligence but also to conduct active actions against the infrastructure of transnational criminal groups—from blocking servers to the complete destruction of equipment and data.
A key point: companies do not receive a blank check. All operations will be conducted under the strict control of the National Coordination Center under the Department of Homeland Security, with oversight provided by the Department of Justice. The private sector acts exclusively "under the direction and authority of the U.S. government," without the right to independently select targets.
Requirements for participants
Access to the program is not a formality. Contractors will need to undergo rigorous certification, confirming technical competence and experience in similar operations. Special attention is paid to the security of their own infrastructure. Financial backing—a bond or escrow account of at least $1 million—may be confiscated in case of violations of the terms.
An important restriction: only those structures that are not part of a foreign government and are not directly controlled by it can be attacked. This eliminates the risk of international diplomatic scandals.
From intelligence to action
Preparation for this scheme has been underway since spring. In a decree dated March 6, Trump ordered the development of a mechanism to counter foreign scam centers, providing for the creation of an operational cell within the coordination center. At the same time, the Department of Justice and DHS were tasked with leveraging the technical developments of commercial cybersecurity companies.
Notable is the recent experience of the Scam Center Strike Force operation, which involved Apple, Coinbase, Google, Meta, Microsoft, and TRM Labs. The results are impressive: over 1.4 million blocked accounts, $3.8 million in frozen cryptocurrency, and arrests in Thailand. However, that format was limited to the companies' own platforms. The new memorandum removes these restrictions, elevating cooperation to a qualitatively different level.
Risks and prospects
It is obvious that involving the private sector in offensive operations is a double-edged sword. Among the main threats are possible retaliatory aggression from hackers, unintended harm to innocent parties, and coordination problems between agencies. Given that losses from scam operations in Asia reached $114 billion in 2025, the stakes are higher than ever.
My analysis: This step is a logical recognition that the state alone cannot effectively counter transnational cybercrime. However, transferring offensive cyber capabilities to private companies creates a dangerous precedent that could be exploited for selfish purposes. The question is not whether such a program is needed, but how strict the control mechanisms will be and how quickly they will turn into a tool of political pressure.