Private US companies are now permitted to conduct cyber operations outside the country. However, state-sponsored hackers are not included in this allowance.
Donald Trump issued the memorandum on August 12, which the White House made public that night. The document consists of five sections. It establishes a National Coordination Center to oversee the program, managed by two Program Executive Directors – one designated by the Attorney General and the other by the Secretary of Homeland Security.
**Purpose as stated by the White House**
Section 1 outlines the rationale behind the memorandum, indicating that transnational criminal organizations “pose a growing threat to American citizens, businesses, and national security.” The memorandum emphasizes a policy of utilizing all instruments of national power, including “the innovative capabilities of the private sector,” and notes that American businesses have historically been “underutilized” in the fight against criminal networks. According to the accompanying fact sheet, American consumers lost $20.8 billion to cyber-enabled crime in 2025. It reveals that 73% of US adults have experienced online scams or attacks, and 98% believe scams are a threat to the nation. One in seven young victims of sextortion reported self-harm. The administration claims that these campaigns primarily target seniors, children, and low-income families through various methods like ransomware, phishing, fraud, and sextortion.
**Authorization details**
Section 4 distinguishes between two types of operations: a Cyber Surveillance Operation, which gathers information or intelligence while attempting to remain undetected, and a Cyber Effects Operation, which involves the manipulation, disruption, denial, degradation, or destruction of information systems, networks, and infrastructure. TechCrunch mentions that surveillance could involve spyware.
**Targeting criteria**
The memorandum specifies that the target is a cyber-enabled transnational criminal organization, defined as “any foreign group conducting cyber-enabled crime” against the US government, US individuals, or US interests. It excludes groups that are institutional components of a foreign government or operate entirely under a foreign government’s direction. Various sources highlight the implications of this definition; for example, North Korean hackers act under state direction, and many Eastern European gangs are believed to operate with some level of agreement from the Russian government, while Chinese and Iranian state hackers sometimes engage in criminal activities.
**Clarifications on hacking back**
Some reports characterized the memorandum as permitting hacking back, which refers to victims retaliating against their attackers on their own initiative. However, according to TechCrunch, the memorandum does not endorse this practice. Instead, under this program, companies must operate under government contracts, targeting approved entities with federal oversight. This reaffirms the longstanding US stance that private companies can defend against cyberattacks but cannot launch counterattacks.
**Requirements for companies**
Section 3 mandates that the Program Executive Directors have 60 days to create operational procedures, with an initial report due within 180 days. Minimum standards will include technical capability, experience in cyber operations, facility security, personnel vetting, and reliability, accommodating both large and smaller "more agile companies." Firms must disclose all contractual relations to the National Coordination Center and maintain a bond or escrow of at least $1 million for non-compliance. Each company's participation will be reviewed at least annually, with the Program Executive Directors required to evaluate and approve every cyber operations package in writing.
**Limits established by the memorandum**
Operations must not result in what the memorandum describes as Critical Outcomes, which encompass actions likely to cause loss of life or serious injury, or actions qualifying as the use of force under international law. Any activities targeting a US person must receive the necessary authorization before approval. One specific clause addresses accidental targeting, stating that if a company inadvertently targets a US individual or entity, it must cease operations, minimize the impact, and notify the relevant authorities immediately. Companies are also required to warn the government of imminent threats to US critical infrastructure. Section 5 clarifies that the memorandum does not create any legal rights or benefits enforceable in law.
**Reactions from supporters**
Industry leaders have expressed approval. Joe Lin, CEO of Twenty, which develops offensive tools for the government, stated, “For years we’ve called the American technology industry a strategic asset but left it on the cyber sidelines.” Mike Centrella from SecurityScorecard remarked to Nextgov that the memorandum signifies a crucial change in the US approach to cyber threats from abroad, shifting from merely sharing threat information to leveraging government authority and private resources to disrupt criminal networks.
**Criticism from opponents**
Jake Williams, vice president of research and development at Hunter Strategy, warned of potential risks to individuals, suggesting that Americans involved in these operations might be classified as non-uniformed combatants while abroad. He pointed out that allegations of American participation need not be true and described the policy as underdeveloped, expressing skepticism about its resilience against misuse. Williams also noted a classified addendum, which he believes covers aspects of target selection. TechCrunch reported that the policy may face legal challenges and questioned the White House on the involvement of any companies, but did not receive a response.
**Legal considerations**
The Computer Fraud and Abuse Act
Other articles
Private US companies are now permitted to conduct cyber operations outside the country. However, state-sponsored hackers are not included in this allowance.
A memo from the White House permits approved US companies to conduct offensive cyber operations targeting foreign criminal organizations. However, state-sponsored hackers are not included.
