Private companies in the US are now permitted to conduct cyber operations internationally, while state-sponsored hackers are not included.
Donald Trump signed the memorandum on August 12, and the White House released it that same evening. The memorandum consists of five sections. A National Coordination Center is established to create and oversee the program, managed by two Program Executive Directors. One is appointed by the Attorney General, and the other is designated by the Secretary of Homeland Security.
What the White House states the purpose is:
Section 1 outlines the rationale. According to the memorandum, transnational criminal organizations represent an increasing threat to American citizens, businesses, and national security. It advocates for the use of all available national power tools, “including the innovative capabilities of the private sector,” while noting that American businesses' abilities “have historically been underutilized” in combating criminal networks. The associated fact sheet provides statistics, indicating that American consumers suffered losses of $20.8 billion due to cyber-enabled crime in 2025. It notes that 73% of US adults have encountered online scams or attacks, and that 98% perceive scams as a threat to the nation. Additionally, one in seven young victims of sextortion reported self-harm. The administration claims these campaigns primarily target seniors, children, and low-income families through methods such as ransomware, phishing, fraud, and sextortion.
What the memorandum permits:
Section 4 differentiates two types of operations. A Cyber Surveillance Operation involves collecting information or intelligence, which may entail accessing systems without authorization while aiming to stay undetected. A Cyber Effects Operation refers to activities that lead to “the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure.” TechCrunch mentions that surveillance activities might incorporate the use of spyware.
Who can be targeted, and who cannot:
The memorandum specifies its target as a cyber-enabled transnational criminal organization, defining this as “any foreign group that conducts cyber-enabled crime” against the US government, a US person, or US interests. It excludes groups that are institutional parts of foreign governments or are entirely operated under a foreign government’s direction. Several reports highlight omissions from this definition, noting, for example, that North Korean hackers operate on behalf of the state, and that many Eastern European gangs are believed to work with tacit Russian government approval. There are also instances where Chinese and Iranian state hackers may engage in criminal activities.
It is not a hack-back initiative:
Various sources have characterized the memorandum as permission to hack back. However, TechCrunch clarifies, based on its security editor's analysis, that it does not endorse such actions. Hacking back refers to a victim retaliating against an attacker independently, while under this program, companies will act under a contract against approved targets and under federal supervision. TechCrunch also reflects the longstanding US position, maintained across administrations, that private companies are permitted to defend against attacks but not to initiate them.
What is required of companies:
Section 3 allows 60 days for the Program Executive Directors to establish operating procedures, with an initial report expected within 180 days. Minimum standards will include technical proficiency, cybersecurity experience, facility security, personnel vetting, and reliability. These standards will cater to both large corporations and “smaller, more agile companies.” Companies will need to disclose all contractual relationships to the National Coordination Center and must maintain a bond or escrow of “not less than $1 million” to ensure compliance. Each company will undergo an annual review of its participation, and Program Executive Directors must review and approve every cyber operations proposal in writing prior to execution.
Limits imposed by the memorandum:
Operations must not result in what the document labels Critical Outcomes, which are actions likely to cause loss of life or serious injury, or anything that constitutes the use of force or armed attack under international law. Activities aimed at a US person must obtain “any necessary authorization, judicial or otherwise, prior to approval.” There is a clause addressing errors regarding unintended targeting of a US person, a system based in the US, or one overseen by a US individual, requiring cessation of the operation, minimization of conduct, and immediate notification. Moreover, companies are obligated to inform the government about imminent threats to US critical infrastructure. Section 5 indicates that the memorandum does not create any enforceable legal rights or benefits.
What proponents say:
Industry leaders have expressed their support. Joe Lin, CEO of Twenty, which develops offensive tools for the government, remarked, “For years, we’ve termed the American technology industry a strategic asset, yet left it sidelined in cyberspace.” Mike Centrella, head of public policy at SecurityScorecard, shared with Nextgov that the memorandum signifies a crucial change in how the US addresses cyber threats originating from abroad. He described a shift in approach, with public-private collaboration evolving from mere threat information sharing to leveraging governmental powers and private capabilities to dismantle criminal networks.
What critics argue:
Jake Williams, VP of research and development at Hunter Strategy, raised concerns about risks to individuals, stating that “Americans involved in these operations could easily be classified as
Other articles
Private companies in the US are now permitted to conduct cyber operations internationally, while state-sponsored hackers are not included.
A memo from the White House permits approved US companies to conduct offensive cyber operations against overseas criminal organizations. Hackers operating under state direction are not included in this authorization.
