White House Creates Program Allowing Vetted U.S. Companies To Conduct Cyber Operations Against Foreign Criminal Groups

The White House has directed the federal government to establish a new program that can authorize vetted U.S. private companies to conduct cyber surveillance and cyber effects operations against foreign cyber-enabled transnational criminal organizations under federal control and oversight.

The August 12 presidential memorandum expands the administration’s efforts against transnational cybercrime by bringing private-sector cybersecurity capabilities directly into certain government-authorized operations. The initiative builds on a March 2026 executive order targeting cybercrime, fraud, and predatory schemes against Americans.

Under the memorandum, the National Coordination Center will establish and manage the program. Participating companies may be authorized to conduct cyber operations targeting qualifying foreign criminal organizations, but those activities must be carried out on behalf of, under the supervision of, and pursuant to the legal authorities of the federal government.

The program will be jointly overseen by executive directors designated by the Attorney General and the Secretary of Homeland Security. Companies seeking to participate will have to enter contracts with either the Department of Justice or the Department of Homeland Security and undergo government vetting.

The memorandum requires operating procedures to be developed within 60 days. Those standards will evaluate participating companies on factors including technical proficiency, prior cyber operations experience, facility security, personnel vetting, reliability, and competence. Eligibility is intended to include both large companies with significant resources and smaller companies suited to specialized missions.

DOJ and DHS may also require participating companies to maintain a bond or escrow account of at least $1 million, which could be forfeited for contractual noncompliance. Every proposed cyber operations package must receive written government approval and direction before a company can act.

The framework distinguishes between cyber surveillance and cyber effects operations. Surveillance operations can involve unauthorized access to foreign criminal information systems for intelligence collection, while cyber effects operations can involve manipulation, disruption, denial, degradation, or destruction of targeted systems or information.

The memorandum places additional restrictions around operations that could affect U.S. persons, systems located in the U.S., or American-controlled infrastructure. Participating companies would have to stop operations and notify the government if their activities move beyond approved parameters.

Actions likely to result in loss of life, serious injury, or activity rising to the level of a use of force or armed attack under international law are defined as “Critical Outcomes” and are subject to heightened restrictions.

The program represents a significant expansion in how the U.S. government could incorporate private cybersecurity companies into offensive and intelligence-oriented operations against overseas criminal networks, while formally keeping those activities under government legal authority and operational control.