Trump Admin Authorizes Private Firms to Hack Overseas Cybercriminals
Original: Private security firms will soon be allowed to hack overseas cybercriminals
Why This Matters
First-ever US government authorization for private sector offensive cyber ops sets a major policy precedent.
The Trump administration issued a National Security Presidential Memorandum on August 13, 2026, authorizing vetted private security firms to conduct offensive cyber operations, including attacks and surveillance, against foreign transnational criminal organizations targeting the US.
President Trump signed a National Security Presidential Memorandum directing the National Coordination Center (NCC), under the Homeland Security Task Force, to develop a program allowing private security companies to perform offensive cyber operations against overseas criminal organizations. The Departments of Justice and Homeland Security will oversee the program and vet participating firms.
Eligible targets include groups conducting ransomware attacks, sextortion, phishing, financial fraud, and impersonation scams against US persons, organizations, or government entities. Authorized operations include 'Cyber Surveillance Operations' and 'Cyber Effects Operations,' potentially including spyware deployment and destructive attacks on TCO data or systems.
This marks the first time the US federal government has formally authorized private companies to conduct offensive cyber operations. Previously, such actions required court approval. Key restrictions include a ban on operations resulting in loss of life, serious injury, or actions rising to the level of 'use of force' under international law.
Independent security researcher Kevin Beaumont acknowledged the idea has merit but cautioned: 'The biggest problem I've had with fighting ransomware over the past 5 years is private cyber companies basically lobbying for nothing to change. A lot of companies have made a lot of money, so putting them in charge of stopping it seems optimistic.'