New Approach to Cybercrime: U.S. Government Enlists Private Companies
Typically, when discussing cybercriminals, the focus is on thwarting their attempts to breach your accounts or steal your money. Recently, however, the U.S. government is shifting its strategy to tackle foreign criminal organizations linked to cyber-enabled crimes. Earlier this month, President Donald Trump signed a National Security Presidential Memorandum that outlines a framework for specialized private U.S. companies to conduct cyber operations against specific foreign criminal groups. The operations would be directed and supervised by the federal government.
The memorandum outlines two main categories of activities. One allows companies to secretly gather intelligence from targeted computer systems. Additionally, with federal authorization, they can interfere with, disrupt, deny access to, or even dismantle systems and digital infrastructures managed by these criminal entities. But what does that actually mean for the companies involved, and for individuals like you?
Why the Government Seeks Private Sector Assistance
Cybercrime continues to exact a heavy toll on Americans. The FBI’s Internet Crime Complaint Center reported receiving over a million complaints in 2025, with losses amounting to a staggering $20.877 billion—a rise of 26% from the previous year. The White House attributes these incidents to sophisticated foreign criminal organizations engaging in ransomware, phishing, financial fraud, and impersonation scams targeting both Americans and U.S. interests.
Technology is aiding these criminals in crafting increasingly deceptive attacks. As I’ve noted in earlier discussions, the rise of AI has enabled them to develop more persuasive impersonation scams. Moreover, once personal information is compromised, it tends to circulate in dark corners, making identity theft victims vulnerable all over again. This new initiative is intended to equip the federal government with additional tools to combat these foreign criminal organizations involved in cybercrime.
What Actions Private Companies Might Undertake
Under the memorandum, participating companies can engage in two primary operations sanctioned by the federal government. The first is termed a Cyber Surveillance Operation, where companies may covertly access targeted systems to gather information or intelligence. This kind of operation aims to remain under the radar, which might involve accessing systems without explicit permission from the owners.
The second category, Cyber Effects Operation, involves manipulating or disrupting information systems. This could mean denying access, degrading systems, or even destroying data and infrastructure controlled by these criminal groups. However, it’s important to clarify that these private companies won’t just be able to take matters into their own hands and hack suspected criminals independently.
Limits on Cyber Operations
To participate in the program, companies must be vetted by the government and establish contractual relationships with the Department of Justice or the Department of Homeland Security. Any operations must occur under federal oversight. Every proposed operation will be reviewed by executives at the DOJ or DHS, who must give written approval before any action can be taken. These companies will also face strict vetting criteria based on their technical abilities, past experiences in cyber operations, and the dependability of their personnel.
Additionally, the DOJ or DHS may require companies to maintain a bond or escrow account amounting to at least $1 million, which could be forfeited in case of any contractual violations. Notably, the memorandum does not specify which companies will be included in this initiative.
Defining Target Organizations
It’s crucial to note that this program doesn’t target just anyone allegedly involved in cybercrime. The targets are defined as Cyber-Enabled Transnational Criminal Organizations, or CE-TCOs, which includes foreign groups conducting cyber-enabled crimes against U.S. entities. The memorandum distinctly clarifies that organizations recognized as part of a foreign government or operating under government direction are excluded from this framework, as the authorized operations could be deeply invasive.
What Happens If Boundaries Are Crossed?
There are safeguards outlined in the memorandum for operations that inadvertently cross established boundaries. If a company finds that its operation has accidentally targeted a U.S. person or a system within the U.S., it must immediately halt the operation, follow specified procedures, and inform the National Coordination Center, which in turn must notify the Justice Department.
Furthermore, when operations involve U.S. individuals or touch upon constitutional, federal, or international law issues, they will necessitate a review and proper authorization from the Justice Department. There’s also a significant restriction regarding what the memorandum terms a Critical Outcome—an operation likely to lead to loss of life or serious injury cannot receive approval.
Unwritten Rules of Engagement
The memorandum lays down a framework, yet many operational protocols still need to be crafted. From the date of the memorandum’s initiation, program leaders have 60 days to establish rules governing eligibility, targeting practices, and federal oversight. Companies involved must also be reassessed each year to ensure they still meet participation criteria.
Within 180 days, program leaders are expected to provide a status update to the White House’s homeland security advisor and the National Cyber Director, with additional reports required annually. So, while the overarching framework is in place, the nitty-gritty rules on how operations will unfold are still underway.
Implications for the Public
There’s no need for you to alter any settings or sign up for anything because of this new directive. The potential impacts will largely operate in the background. The program would allow the federal government to pursue particular foreign cybercriminals more effectively, gathering intelligence or disrupting their operational frameworks.
Meanwhile, private companies participating in this initiative will wield considerable cyber capabilities under federal guidance. How these activities will be governed depends strongly on the procedures currently being drafted. Importantly, maintaining good cybersecurity practices on your end is as crucial as ever. If you suspect a breach, it’s wise to follow established steps to secure your device.
Final Thoughts
For years, I’ve highlighted ways to guard against potential attacks from cybercriminals. I find it interesting that the government is looking to intensify its efforts against certain foreign entities responsible for these crimes. If these federal-approved operations can disrupt criminal networks or yield valuable intelligence, it could bolster existing protections for Americans. However, there’s a need to carefully monitor how this process unfolds, especially when considering the potential for misdirected operations. The memorandum’s insistence on federal oversight and legal reviews is reassuring, but I’m curious to see the finalized rules and the level of supervision federal officials will enforce once operations commence.
Do you feel safer knowing that vetted U.S. companies might assist the government in countering foreign cybercriminals, or does involving private companies in this way raise concerns for you? Share your thoughts.

