Trump signed memorandum authorizing private companies to conduct offensive cyber operations against foreign criminal groups

President Trump signed a National Security Presidential Memorandum on August 12, 2026 directing the Department of Homeland Security and Department of Justice to create a program authorizing vetted private companies to conduct offensive "cyber surveillance" and "cyber effects" operations against foreign transnational criminal organizations, under federal government direction and oversight. It is the first time the U.S. government has authorized private firms to conduct offensive hacking operations, a role historically reserved for government agencies; participating companies must maintain a bond or escrow of at least $1 million.

On August 12, 2026, President Trump signed a National Security Presidential Memorandum, "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," directing the Homeland Security Task Force's National Coordination Center to create a program authorizing vetted private companies to conduct offensive cyber operations against foreign transnational criminal organizations (TCOs). The program is to be overseen by co-Executive Directors from the Department of Justice and the Department of Homeland Security, who must approve individual operations; it does not grant participating companies unlimited hacking authority, but authorizes "limited cyber operations at the direction of the US government" following vetting. Participating companies must maintain a bond or escrow of at least $1 million and are encouraged to enter agreements with other private entities and with federal, state, local, tribal, and territorial agencies to gather threat information and propose operations against specified targets.

The memorandum extends Executive Order 14390 of March 6, 2026, which directed federal agencies to combat cyber-enabled crime, by adding a private-sector operational role that has traditionally been reserved for government agencies. Legal experts have raised questions about the risks companies could face as they become directly involved in offensive international cyber operations, including potential tension with the Computer Fraud and Abuse Act's restrictions on unauthorized computer access; notably, the memo does not amend the CFAA the way earlier proposals to open private-sector hacking would have, relying instead on an interpretation of an existing exemption. The program echoes a distinct proposal that has circulated in conservative policy circles in recent years: authorizing "letters of marque" for private-sector cyber firms, modeled on the letters historically granted to sea privateers -- an Article I power the Constitution assigns to Congress, not the President, to authorize.

This memorandum authorizes private companies to conduct offensive cyber operations against foreign targets under federal direction -- a role historically reserved to government agencies and adjacent to conduct the Computer Fraud and Abuse Act otherwise criminalizes. Authorizing private parties to conduct hostile operations against foreign targets is the kind of act the Constitution assigns to Congress, not the President, to authorize; doing it through a presidential memorandum rather than legislation extends executive cyber authority into a domain Congress has not specifically authorized private actors to occupy.

  1. Expanding Capabilities to Combat Transnational Cyber-Enabled CrimeThe White House primary accessed August 14, 2026
  2. Fact Sheet: President Donald J. Trump Expands Capabilities to Combat Transnational Cyber-Enabled CrimeThe White House primary accessed August 14, 2026
  3. Donald Trump empowers US private companies to conduct cyber-attacksThe Guardian investigative accessed August 14, 2026
  4. Trump turns to private sector in offensive hacking operations memoCyberScoop investigative accessed August 15, 2026