August 31, 2026ADMIN

White House plans private-sector cyber operations against overseas criminal groups

The White House has directed officials to develop a program allowing private security firms to join authorized cyber operations against overseas criminal groups.

White House plans private-sector cyber operations against overseas criminal groups

The Trump administration is moving to involve private security companies in federally authorized cyber operations against criminal organizations based overseas. The initiative focuses on groups that use hacking and other cyber-enabled crimes to target US individuals, organizations, government entities, or broader US interests.

A National Security Presidential Memorandum issued by President Donald Trump directs the National Coordination Center to create the program. The center operates under the Homeland Security Task Force, while the Departments of Justice and Homeland Security are expected to oversee the effort.

A new role for private security firms

Private-sector participation is central to the planned program. Under the memorandum, selected companies could take part in specific operations authorized by the federal government rather than acting independently.

The memorandum says participating firms may conduct two categories of activity:

  • Cyber Surveillance Operations, which would involve monitoring or gathering information related to eligible criminal organizations.
  • Cyber Effects Operations, a term covering operations intended to produce an effect against targeted cybercriminal groups or their capabilities.

The source material does not provide further operational definitions for those categories. It also does not describe the process for selecting companies or spell out how individual operations would be approved. Instead, the memorandum directs the National Coordination Center to develop the program, leaving those implementation details to be established.

Which cybercrimes could be targeted

A White House fact sheet released with the memorandum identifies several types of criminal activity that may fall within the initiative’s scope. They include:

  • Ransomware attacks
  • Sextortion schemes
  • Phishing campaigns
  • Financial fraud
  • Impersonation scams

These activities would be eligible targets when conducted by qualifying foreign transnational criminal organizations. The program is therefore not framed as a general authorization for companies to retaliate against any suspected hacker. It is intended to support specific, government-authorized operations against organizations that meet the memorandum’s definition.

That distinction is important because private companies participating in the program would be operating as part of a federal initiative with oversight from the Justice and Homeland Security departments.

How the memorandum defines eligible groups

The policy applies to foreign groups engaged in cyber-enabled crime against the US government, a US person, or US interests. The memorandum describes these groups as cyber-enabled transnational criminal organizations, or TCOs.

Its definition excludes organizations that are an institutional part of a foreign government or operate wholly under a foreign government’s direction. As a result, the program described in the memorandum is aimed at overseas criminal organizations rather than foreign government bodies themselves.

The definition establishes several basic conditions for a potential target:

  • It must be a foreign group.
  • It must conduct cyber-enabled crime affecting US targets or interests.
  • It cannot be an institutional part of a foreign government.
  • It cannot operate entirely under a foreign government’s direction.

The memorandum’s language draws a boundary between transnational cybercrime and state-directed activity, at least for the purposes of this program.

Federal oversight and authorization

The National Coordination Center has been tasked with developing the operational framework. The Departments of Justice and Homeland Security will oversee the program, according to the memorandum.

That structure indicates that private firms will not receive an unrestricted ability to conduct offensive cyber activity. Their participation will be tied to particular operations authorized through the federal program. The available information does not explain how responsibilities will be divided among the National Coordination Center, the two oversight departments, and participating companies.

The memorandum also marks a broader change in how the administration plans to confront overseas cybercrime. Rather than relying only on government personnel and capabilities, the initiative seeks to add expertise and resources from private security businesses. The exact reach of that private-sector role will depend on the rules and procedures created as the program is developed.

Important details remain to be defined

The announcement establishes the program’s purpose, oversight structure, target categories, and intended use of private companies. It does not provide a complete operational rulebook.

Among the elements not detailed in the source material are the standards companies must meet to participate, the approval process for particular operations, and the practical limits placed on surveillance or effects activities. Those questions will shape how the initiative functions and how tightly private-sector actions remain connected to federal decision-making.

For now, the policy represents a directive to build the program rather than a full description of how every operation will be carried out.

Conclusion

The White House initiative would give private security firms a formal role in government-authorized operations against overseas criminal groups that target US people, institutions, and interests through cyber-enabled crime. Ransomware, phishing, sextortion, financial fraud, and impersonation scams are among the listed activities. Justice and Homeland Security oversight is planned, but key operational details still depend on the framework developed by the National Coordination Center.

Original reporting: Ars.


Originally reported by Ars.