The Trump administration has quietly authorized private U.S. security firms to conduct offensive cyber operations—including surveillance and cyberattacks—against foreign criminal groups that target American individuals, companies, and government agencies. The directive, delivered via a National Security Presidential Memorandum on Thursday, marks a significant shift in how the United States fights transnational cybercrime: for the first time, the private sector is being formally recruited to act as the government's cyber militia.

What the order does

The memorandum directs the National Coordination Center (NCC), which operates under the Homeland Security Task Force, to design a program within 60 days that will enable private-sector companies to carry out “Cyber Surveillance Operations and Cyber Effects Operations” against foreign transnational criminal organizations (TCOs). Oversight will rest with the Departments of Justice and Homeland Security. The action specifically targets ransomware gangs, sextortion schemes, phishing campaigns, financial fraud networks, and impersonation scams—crimes that have surged in recent years and cost Americans billions.

According to a fact sheet accompanying the memo, eligible targets are “any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests, and that is not an institutional part of a foreign government or wholly operated under a foreign government’s direction.” This definition leaves room for private firms to go after criminal syndicates that operate with tacit state tolerance, but not state-sponsored military or intelligence units.

The White House has framed the move as a necessary escalation against an enemy that has long enjoyed safe havens overseas. “The devil will be in the details,” said one cybersecurity policy analyst, noting that the still-undefined rules of engagement will determine whether the program empowers defenders or creates a legal gray zone.

Legal and accountability concerns

At the heart of the debate is the legal risk borne by participating companies. Unlike government-conducted operations, which are shielded by sovereign immunity, private firms that hack foreign systems could face criminal or civil liability under the Computer Fraud and Abuse Act and similar laws—both at home and abroad. The memorandum reportedly does not grant immunity, leaving companies to operate “at their own legal risk,” as one report put it. Legal scholars have warned that this could lead to a Wild West environment, where profit-driven firms might overstep their mandates or be drawn into dangerous confrontations.

Critics also question the accountability structure. While DOJ and DHS will provide oversight, the actual operations will be conducted by non-state actors who are not subject to the same training, rules of engagement, or public transparency as federal agents. “America wants to hack the planet,” quipped one Lawfare analysis, highlighting the breadth of the program's ambitions. Others have pointed to a more practical concern: if a private company conducts a botched operation that harms innocent parties or escalates international tensions, who is responsible? The memorandum's silence on these questions has drawn sharp criticism from civil liberties groups and international law experts.

A shifting role for the private sector

The order is part of a broader trend of drawing private cybersecurity firms into what was once the exclusive domain of intelligence agencies and the military. U.S. intelligence and defense agencies have increasingly turned to private-sector cyber specialists for everything from threat intelligence to active defense. The new program formalizes that relationship, effectively creating what some are calling "cyber privateers"—a nod to the historic practice of governments commissioning private ships to attack enemy vessels.

Supporters argue that the private sector already possesses much of the expertise and threat intelligence needed to combat cybercrime, and that government bureaucracy often moves too slowly. "The private sector is already on the front lines," said one industry executive. "This gives them legal cover to fight back." But others worry about the consequences of outsourcing the use of force. "This is a fundamental change in how cyber warfare is waged," said a former State Department official. "It blurs the line between public and private, and between self-defense and vigilantism."

The escalating threat landscape

The move comes as cybercrime continues to inflict staggering economic damage. According to the 2025 Cybersecurity Almanac, global cybercrime costs are projected to exceed $10.5 trillion annually by 2025, up from $3 trillion in 2015. The financial toll on Americans alone is enormous: reports indicate that U.S. residents lost $20.8 billion to fraud and cyber-enabled crime in a single year. Ransomware attacks have disrupted hospitals, schools, and critical infrastructure, with some analysts warning that the next major attack could cripple an entire country, not just a company.

Recent incidents underscore the urgency: a nursery chain in the UK had children's names, pictures, and addresses stolen; offshore banking platforms in Seychelles were hit by sophisticated attacks; and the FBI charged Iranian nationals in connection with cybercrime. These examples illustrate the diversity and global reach of the threat.

Implications and outlook

The memo's implementation will be watched closely by cybersecurity firms, international allies, and adversaries alike. If successful, it could serve as a model for other nations grappling with the cross-border nature of cybercrime. But if poorly managed, it could lead to unintended consequences, including diplomatic incidents, legal chaos, or even more aggressive retaliation from criminal organizations.

Some experts suggest that privatizing offensive operations is not the only answer. Lawfare has explored alternative approaches, such as using civil litigation to fight foreign hackers—a less violent but potentially effective tool. Others have noted that the "cyber apocalypse" often feared by doomsayers has not yet materialized, and that the real challenge lies in coordination, information sharing, and building resilience, rather than in going on the offensive.

For now, the program's first concrete steps will be the drafting of rules and the selection of qualified firms. Reports indicate that companies may face eligibility requirements, including a $1 million insurance rule, though these details remain unconfirmed. The 60-day road map suggests the first operations could begin before the end of the year. As the memos become reality, the world will be watching to see whether these "cyber privateers" become effective defenders—or rogue agents in an already chaotic digital battlefield.