
On August 12, U.S. President Donald Trump signed a memorandum allowing vetted private companies to participate in cyber operations against foreign criminal groups under federal oversight.
The new program targets transnational criminal organizations involved in ransomware, financial fraud, and other illegal activities in the digital realm. Contractors will be able to gather intelligence on their infrastructure and suggest targets for precise interventions to authorities.
In addition to gathering intelligence, certified firms will be permitted to carry out disruptive actions on information systems, including blocking, disrupting operations, or destroying equipment and stored data.
How the Program Will Work
The operations will be managed by the National Coordination Center under the U.S. Department of Homeland Security. Oversight is also provided by the Department of Justice. Private companies will operate “under the direction, control, and authority of the U.S. government”—they are not allowed to select targets independently.
To participate in the program, contractors must undergo certification. Requirements include technical competence, proven experience in such operations, and the security of their own infrastructure. They must also post a bond or place funds in escrow of at least $1 million, which may be forfeited if conditions are violated.
The range of permissible targets is strictly limited. Companies can only act against foreign criminal entities that are not part of another state’s government or under its direct control.
The White House began laying the groundwork for this new approach in the spring. In a March 6 directive, Trump ordered the development of a plan to counter foreign scam centers and other transnational organizations. The document explicitly provided for the creation of an operational cell within the National Coordination Center and the involvement of the private sector in combating illegal online activities.
The Department of Justice and the Department of Homeland Security were also tasked with leveraging the technical developments, intelligence, and practical experience of commercial cybersecurity companies to identify perpetrators, track their movements, and disrupt their infrastructure.
The new memorandum will formalize this initiative into a distinct program, allowing private contractors to directly participate in state-sanctioned offensive actions.
Authorities Have Already Engaged Apple, Coinbase, and Google
The U.S. authorities’ collaboration with the tech sector began earlier. However, until now, business actions were confined to their own services.
In May, the Scam Center Strike Force conducted its first large-scale Disruption Week. Participants included Apple, Coinbase, Google, Meta, Microsoft, SpaceX, TRM Labs, and others, reported the Department of Justice.
Law enforcement provided partners with data on specific fraudulent networks from Southeast Asia. Based on this information, companies independently identified accounts and infrastructure elements that violated their platform rules.
The operation resulted in the blocking of over 1.4 million social media and email accounts, the disruption of malicious traffic, and the shutdown of fraudsters’ servers and hosting services.
Thanks to data received from authorities, participants froze more than $3.8 million in cryptocurrency used for money laundering. In Thailand, seven cybercrime suspects were arrested following the joint operation.
However, involving the private sector in offensive online actions remains a controversial practice. Reuters journalists highlighted potential risks such as retaliatory aggression, accidental harm to innocents, and coordination issues between agencies.
Earlier, in July, the UN Office on Drugs and Crime published a report stating that in 2025, scam operations in East and Southeast Asia, Australia, and New Zealand caused damages of up to $114.1 billion.
