Private companies in the US are now permitted to conduct cyber operations internationally, while state-sponsored hackers are not included.

Private companies in the US are now permitted to conduct cyber operations internationally, while state-sponsored hackers are not included.

      Donald Trump signed the memorandum on August 12, and the White House released it that same evening. The memorandum consists of five sections. A National Coordination Center is established to create and oversee the program, managed by two Program Executive Directors. One is appointed by the Attorney General, and the other is designated by the Secretary of Homeland Security.

      What the White House states the purpose is:

      Section 1 outlines the rationale. According to the memorandum, transnational criminal organizations represent an increasing threat to American citizens, businesses, and national security. It advocates for the use of all available national power tools, “including the innovative capabilities of the private sector,” while noting that American businesses' abilities “have historically been underutilized” in combating criminal networks. The associated fact sheet provides statistics, indicating that American consumers suffered losses of $20.8 billion due to cyber-enabled crime in 2025. It notes that 73% of US adults have encountered online scams or attacks, and that 98% perceive scams as a threat to the nation. Additionally, one in seven young victims of sextortion reported self-harm. The administration claims these campaigns primarily target seniors, children, and low-income families through methods such as ransomware, phishing, fraud, and sextortion.

      What the memorandum permits:

      Section 4 differentiates two types of operations. A Cyber Surveillance Operation involves collecting information or intelligence, which may entail accessing systems without authorization while aiming to stay undetected. A Cyber Effects Operation refers to activities that lead to “the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure.” TechCrunch mentions that surveillance activities might incorporate the use of spyware.

      Who can be targeted, and who cannot:

      The memorandum specifies its target as a cyber-enabled transnational criminal organization, defining this as “any foreign group that conducts cyber-enabled crime” against the US government, a US person, or US interests. It excludes groups that are institutional parts of foreign governments or are entirely operated under a foreign government’s direction. Several reports highlight omissions from this definition, noting, for example, that North Korean hackers operate on behalf of the state, and that many Eastern European gangs are believed to work with tacit Russian government approval. There are also instances where Chinese and Iranian state hackers may engage in criminal activities.

      It is not a hack-back initiative:

      Various sources have characterized the memorandum as permission to hack back. However, TechCrunch clarifies, based on its security editor's analysis, that it does not endorse such actions. Hacking back refers to a victim retaliating against an attacker independently, while under this program, companies will act under a contract against approved targets and under federal supervision. TechCrunch also reflects the longstanding US position, maintained across administrations, that private companies are permitted to defend against attacks but not to initiate them.

      What is required of companies:

      Section 3 allows 60 days for the Program Executive Directors to establish operating procedures, with an initial report expected within 180 days. Minimum standards will include technical proficiency, cybersecurity experience, facility security, personnel vetting, and reliability. These standards will cater to both large corporations and “smaller, more agile companies.” Companies will need to disclose all contractual relationships to the National Coordination Center and must maintain a bond or escrow of “not less than $1 million” to ensure compliance. Each company will undergo an annual review of its participation, and Program Executive Directors must review and approve every cyber operations proposal in writing prior to execution.

      Limits imposed by the memorandum:

      Operations must not result in what the document labels Critical Outcomes, which are actions likely to cause loss of life or serious injury, or anything that constitutes the use of force or armed attack under international law. Activities aimed at a US person must obtain “any necessary authorization, judicial or otherwise, prior to approval.” There is a clause addressing errors regarding unintended targeting of a US person, a system based in the US, or one overseen by a US individual, requiring cessation of the operation, minimization of conduct, and immediate notification. Moreover, companies are obligated to inform the government about imminent threats to US critical infrastructure. Section 5 indicates that the memorandum does not create any enforceable legal rights or benefits.

      What proponents say:

      Industry leaders have expressed their support. Joe Lin, CEO of Twenty, which develops offensive tools for the government, remarked, “For years, we’ve termed the American technology industry a strategic asset, yet left it sidelined in cyberspace.” Mike Centrella, head of public policy at SecurityScorecard, shared with Nextgov that the memorandum signifies a crucial change in how the US addresses cyber threats originating from abroad. He described a shift in approach, with public-private collaboration evolving from mere threat information sharing to leveraging governmental powers and private capabilities to dismantle criminal networks.

      What critics argue:

      Jake Williams, VP of research and development at Hunter Strategy, raised concerns about risks to individuals, stating that “Americans involved in these operations could easily be classified as

Other articles

Apple aims to compensate publishers based on usage instead of an annual fee for providing news to Siri. Apple aims to compensate publishers based on usage instead of an annual fee for providing news to Siri. According to the Wall Street Journal, Apple’s deals with publishers for Siri would compensate news organizations every time their articles are utilized, backed by a potential budget in the nine-figure range. Google Meet can now take notes for your in-person meetings. Google Meet can now take notes for your in-person meetings. Google Meet's meeting notes function is broadening its scope beyond video calls, allowing Gemini to record notes during your in-person meetings and convert them into a document that includes action items and a complete transcript. Apple aims to compensate publishers based on usage rather than on an annual basis for providing news to Siri. Apple aims to compensate publishers based on usage rather than on an annual basis for providing news to Siri. According to the Wall Street Journal, Apple’s agreements with publishers for Siri would compensate news organizations every time their articles are utilized, with a potential budget reaching nine figures. AI agents are attending students' online courses, and universities are finding it difficult to prevent this. AI agents are attending students' online courses, and universities are finding it difficult to prevent this. AI agents are elevating AI-assisted cheating by successfully completing entire online college courses, which includes watching lectures, taking quizzes, writing papers, and participating in discussions. The CEO of Airbnb states that AI is not being developed for everyday users. He serves on the board of Y Combinator. The CEO of Airbnb states that AI is not being developed for everyday users. He serves on the board of Y Combinator. Brian Chesky states that the divide in consumer AI is the reason for Americans' negative feelings towards AI. According to his figures, 159 out of 175 Y Combinator startups were focused on enterprise. Flock Safety reduces data retention to seven days following numerous instances of police misconduct. Flock Safety reduces data retention to seven days following numerous instances of police misconduct. Flock Safety's updates to privacy policies have reduced data retention from 30 days to seven and mandated search audits, following multiple incidents of police misconduct.

Private companies in the US are now permitted to conduct cyber operations internationally, while state-sponsored hackers are not included.

A memo from the White House permits approved US companies to conduct offensive cyber operations against overseas criminal organizations. Hackers operating under state direction are not included in this authorization.