Trump taps cyber firms to go on offensive against criminals
Editor's note: This article was updated at 12:15 p.m. EST with comment from Congressman Bennie Thompson (D-MS).
The Trump administration will allow private companies to launch attacks on cybercrime organizations, according to a presidential memorandum released late on Wednesday.
The firms will partner with the Justice and Homeland Security departments on offensive operations and surveillance targeting “transnational cybercrime, fraud, and other predatory schemes against American citizens.”
“By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter [Transnational Criminal Organizations] threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens,” the memorandum said.
The cyber operations would need to be approved in advance by DOJ and DHS officials. The document makes clear that officials will not sanction any operation that results in either the loss of life or “rise to the level of use of force or armed attack under international law.”
The officials will “review every cyber operations package and provide written approval and direction to the Participating Company before action may be taken.”
The memorandum builds on an executive order from March that ordered federal agencies to take a more robust stance against cybercrime, which continues to siphon billions each year from Americans through scams, ransomware attacks and cyberattacks.
A fact sheet released by the White House alongside the memorandum said American consumers reported $20.8 billion in cyber-related losses last year.
The goal of the latest effort, according to the memorandum, is to incorporate the “ingenuity of the private sector” — arguing that American businesses “have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace.”
Since taking office last year, Trump administration officials have repeatedly stated a desire to focus on offensive cyber operations. National Cyber Director Sean Cairncross hinted at private sector offensive cyber operations in March.
“Thus, it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime,” the memorandum says.
The memorandum is light on details about what will happen in thorny situations where cybercriminal organizations are tied to nation-state hacking groups or government entities. Earlier this year, State Department officials said there is evidence tying many of the Chinese gangs that run Southeast Asian scam centers to Chinese government projects.
The DOJ recently implicated several government and military officials in Cambodia and Myanmar in indictments targeting the transnational criminal organizations that run lucrative romance and financial scams through compounds in both countries.
Several cybersecurity experts questioned the lack of legal protections in the memorandum and expressed concerns about the potential for foreign governments to directly target cybersecurity employees involved in the program. What would be the protocol if mistakes were made or targets misidentified, some asked.
Others worried about U.S. employees facing situations similar to the experience of a Chinese citizen on vacation in Italy who was recently arrested and extradited to the U.S. on accusations of working for a cybersecurity company that launched attacks against American companies on behalf of the Chinese government.
Bennie Thompson (D-MS), ranking member of the Committee on Homeland Security, said he has serious concerns about the legal implications for the participating companies and other potential unintended impacts, noting that the oversight procedures are unclear.
“We all recognize the need to protect Americans from cyber-enabled crimes, but the proper venue to address this challenge is through the Administration working with Congress to ensure the necessary authorities, legal procedures, and resources are in place rather than a presidential memorandum that raises as many questions as it answers,” he said.
$1 million penalty
Participating companies would sign contracts with DOJ or DHS and “undergo rigorous vetting” so that their “performance adheres to the strict operational procedures outlined in the implementation guidance.”
The companies would get access to threat information that may help their cyber operations and work alongside federal, state and local officials to disrupt cybercrime operations
Federal agencies have two months to develop operating procedures and minimum standards companies must meet in order to participate. The standards will include “technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence, reliability, and other factors.”
DHS and the DOJ will create a framework for how targets will be identified and companies will need to report their activities to the federal government on a routine basis.
The White House did not respond to requests for comment about whether companies have already agreed to participate but the memorandum says they are seeking both large and small firms for different aspects of the scheme.
Participating companies will have to disclose all of their contractual relationships to the federal government and will face a penalty of at least $1 million if any aspect of the deal is violated. They will be evaluated annually in order to continue participating in the program.
The memorandum notes that procedures will need to be created governing what happens when a company “discovers operational activity exceeding the parameters and restrictions of the cyber operation … such as unintentional targeting of (1) a United States person, (2) an information system residing in the United States, or (3) an information system under the control of a United States person.”
If any of those are caught up in an operation, the companies must “cease such operation, conduct minimization procedures, and immediately notify the NCC, which shall notify the Department of Justice.”
Companies will also be forced to notify the federal government if they discover an imminent cyberattack against U.S. critical infrastructure or uncover a plot that may result in loss of life.
Martin Matishak
is the senior cybersecurity reporter for The Record. Prior to joining Recorded Future News in 2021, he spent more than five years at Politico, where he covered digital and national security developments across Capitol Hill, the Pentagon and the U.S. intelligence community. He previously was a reporter at The Hill, National Journal Group and Inside Washington Publishers.
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.




