The United States government has announced a significant policy shift that will allow carefully selected private companies to take part in offensive cyber operations aimed at foreign criminal organizations. A presidential memorandum released this week establishes a formal program under which vetted American firms can conduct surveillance and disruptive actions against groups responsible for ransomware attacks, financial fraud, phishing campaigns, and other cyber enabled crimes that harm Americans.
For years, private companies have been barred by federal law from launching attacks on the systems of others, even when those systems belong to known criminal networks. Law enforcement and intelligence agencies alone handled offensive work. The new approach recognizes that the private sector holds unmatched technical talent, speed, and resources that government agencies often struggle to match.
Officials argue these strengths have been underused in the fight against transnational criminal organizations that operate across borders and frequently from countries where traditional legal tools prove slow or ineffective. The program will be managed by the National Coordination Center. Participating companies must first pass rigorous vetting that examines technical skill, past performance, security practices, and personnel reliability. Once approved, they enter contracts with either the Department of Justice or the Department of Homeland Security.
A key requirement is a one million dollar escrow deposit that the company forfeits if it violates the rules. Operations remain under continuous federal oversight. Every proposed action needs written approval from designated officials in both departments before it can proceed. Two main types of activity are authorized.
Cyber surveillance operations allow access to foreign systems for intelligence gathering. Cyber effects operations go further and permit actions that manipulate, disrupt, degrade, or destroy the information systems and networks used by the targeted groups. The memorandum makes clear that these steps form part of lawful law enforcement efforts. Companies cannot act on their own initiative.
They operate only under government direction and control. Targets are limited to foreign cyber enabled transnational criminal organizations. These are defined as groups that commit cyber crimes against the United States, its people, or its interests, but that are not institutional parts of a foreign government or fully directed by one. Safeguards prevent any operation from affecting Americans or systems located inside the United States.
The program also requires participating firms to alert authorities immediately if they uncover an imminent threat to critical infrastructure such as power grids or water systems. White House statements highlight the scale of the problem. Americans reported more than twenty billion dollars in losses from cyber enabled crime in the previous year. Ransomware groups and fraud networks have extracted huge sums while remaining largely out of reach.
By bringing private sector capabilities into the effort, the government hopes to increase the pace and volume of disruptions against these networks. Critics have long warned that allowing private firms into offensive cyber work could create risks of misattribution, unintended escalation, or legal complications abroad. The memorandum seeks to address those concerns through layered approvals, strict targeting rules, and ongoing supervision. Whether the approach succeeds will depend heavily on how the still developing guidance is written and enforced.
Officials have sixty days to issue detailed participation criteria that will apply to companies of various sizes. This policy represents a clear departure from decades of practice that kept offensive cyber tools almost exclusively in government hands. If implemented carefully, it could give law enforcement a powerful new set of tools against criminal gangs that have thrived in the digital shadows. The coming months will reveal how many firms step forward and how effectively the oversight mechanisms function in practice.



