President Donald Trump has signed a memorandum allowing U.S. agencies to conduct hacking operations against transnational crime organizations overseas.
President Donald Trump has approved a National Security Presidential Memorandum that allows US federal law enforcement to carry out offensive cyber operations against transnational criminal organizations operating internationally. In essence, the US is formally permitting itself to combat hackers, which is as significant as it appears.
The memorandum targets foreign criminal entities that harm Americans through ransomware, phishing, financial fraud, sextortion, and the surge of AI-assisted impersonation scams observed in the past year. The goal is to disrupt these activities at their source instead of waiting for the financial and personal damage to affect Americans.
The statistics associated with this initiative are quite alarming. The White House reports $20.8 billion in cybercrime losses projected for 2025 and states that 73% of US adults have encountered online scams. More disturbingly, it highlights that one in seven young individuals victimized by sextortion have reported self-harm, underscoring that the impact of these networks cannot be measured solely in monetary terms.
On paper, the program includes a structured framework. A new National Coordination Center will operate under a Homeland Security Task Force and will be co-directed by the Department of Justice and the Department of Homeland Security to oversee these operations. The Homeland Security Council is responsible for establishing procedures, and the memorandum requires “rigorous procedures” to ensure compliance with the Constitution, US law, and international treaties.
One particularly striking provision concerns the private sector. The coordination center is instructed to “leverage the capability and innovation of the private sector” to execute operations under government oversight. This implies that private companies may be brought in to assist the government in infiltrating criminal networks abroad, a boundary that many governments have been cautious not to openly cross.
This aspect raises significant concerns, especially for European readers. State-sanctioned offensive hacking, even against unequivocally malicious targets, is a capability that does not easily revert once activated. A major concern is escalation since criminal organizations often share infrastructure with legitimate services, and targeting one may inadvertently disrupt the other.
Attribution presents a second challenge. Cyber operations are notoriously difficult to trace, which is why they appeal to criminals, and this ambiguity complicates matters when it’s the government wielding the exploit. A failed operation, or one that mistakenly targets the wrong server in an unintended country, is not easily retracted or defensibly denied.
Additionally, there is the issue of collateral damage. The individuals managing these networks excel at masking themselves among regular users, meaning that operations aimed at a specific scam site or ransomware group could unintentionally affect innocent bystanders, foreign businesses, or even allied infrastructures, as shown by previous botnet takedowns.
The involvement of private contractors adds another layer to this complexity. Providing offensive tools to commercial entities, regardless of how much the memorandum emphasizes “direction and control,” blurs the line between public accountability and private interests. Europe has spent years attempting to regulate the commercial spyware market for precisely this reason, and watching Washington incorporate contractors into governmental cyber offensives will undoubtedly draw attention in Brussels.
To be fair, the threat is genuine, and the existing strategies are evidently insufficient. Ransomware gangs and scam networks have thrived on the disconnect between where they operate and where their victims reside, making it challenging for traditional law enforcement, constrained by borders, to address the escalating deepfake-driven fraud and overall fraud economy.
The central question remains whether the safeguards will be effective. While “rigorous procedures” and constitutional adherence sound reassuring in theory, the true test will arise the first time an operation goes awry, the first instance of a contractor overstepping boundaries, or the first time an allied nation inquiries about the authorization behind the code executing on a server within its territory.
Other articles
President Donald Trump has signed a memorandum allowing U.S. agencies to conduct hacking operations against transnational crime organizations overseas.
A recent presidential memo permits U.S. law enforcement to conduct offensive cyber activities against international criminal organizations and to engage private contractors for assistance.
