The Trump administration is launching a program allowing private firms to conduct international cyberattacks against foreign criminal networks under federal oversight, raising concerns about legal risks and collateral damage.
<figure>
<img alt="A matrix of green binary code flows down in the background of a laptop computer with a green-hued image of the US Capitol building" data-caption="" data-portal-copyright="Illustration by Amelia Holowaty Krales / The Verge" data-has-syndication-rights="1" src="https://platform.theverge.com/wp-content/uploads/sites/2/chorus/uploads/chorus_asset/file/23318432/akrales_220309_4977_0079.jpg?quality=90&strip=all&crop=0,0,100,100" />
<figcaption>
</figcaption>
</figure>
<p class="wp-block-paragraph">The Trump administration is launching a new program that will allow private firms to perform cyberattacks against foreign criminals, <a href="https://www.bloomberg.com/news/articles/2026-08-13/trump-enlists-private-sector-to-boost-cyber-offensive-arsenal">as reported earlier by <em>Bloomberg</em></a>. The private firms would operate "under the control and oversight" of the federal government, giving them permission to surveil and disrupt criminal networks, according to <a href="https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/">a presidential memorandum published</a> on Wednesday.</p>
<p class="wp-block-paragraph">The Department of Justice and Department of Homeland Security will oversee the private firms, which must meet requirements in "technical proficiency, proven performance of cyber operations, facility security," and more. Companies in the program must hold a bon …</p>
<p><a href="https://www.theverge.com/policy/979734/trump-administration-cybercrime-private-firms">Read the full story at The Verge.</a></p>
# The Trump admin will start letting private firms launch international cyberattacks
Source: [https://www.theverge.com/policy/979734/trump-administration-cybercrime-private-firms](https://www.theverge.com/policy/979734/trump-administration-cybercrime-private-firms)
The Trump administration is launching a new program that will allow private firms to perform cyberattacks against foreign criminals,[as reported earlier by*Bloomberg*](https://www.bloomberg.com/news/articles/2026-08-13/trump-enlists-private-sector-to-boost-cyber-offensive-arsenal)\. The private firms would operate “under the control and oversight” of the federal government, giving them permission to surveil and disrupt criminal networks, according to[a presidential memorandum published](https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/)on Wednesday\.
The Department of Justice and Department of Homeland Security will oversee the private firms, which must meet requirements in “technical proficiency, proven performance of cyber operations, facility security,” and more\. Companies in the program must hold a bond or escrow of at least $1 million that they’ll forfeit if they don’t comply with their contractual agreement\. The memorandum also says private firms will only hack groups that are “not an institutional part of a foreign government or wholly operated under a foreign government’s direction\.”
The memo describes private businesses as “underutilized” forces for fighting criminal networks\. “It is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime,” it says\.
But as[pointed out by*Cybersecurity Dive*](https://www.cybersecuritydive.com/news/us-private-companies-gangs-cyberattacks-offensive-operations/827805/), it can be difficult to identify which criminal groups are affiliated with foreign governments, which could put cybersecurity firms at risk of stoking geopolitical or legal conflicts\. Jason Healey, a senior cyber conflict researcher at Columbia University, tells*Cybersecurity Dive*that “Anyone conducting these operations is doing so at substantial personal legal risk\.” Jake Williams, the vice president of research and development at Hunter Strategy, similarly[tells*TechCrunch*](https://techcrunch.com/2026/08/13/in-a-first-us-will-allow-some-private-firms-to-carry-out-cyberattacks/?utm_medium=organic_social&utm_source=TWITTER)that “Americans participating in these operations could easily be classified as non\-uniformed combatants while traveling overseas\.”
Ben Bernstein, a manager for the cybersecurity advisers team at Huntress, also raises concerns about how this program will play out\. “Threat actors don’t launch attacks from labeled servers in Moscow; they route traffic through compromised, innocent infrastructure, like a vulnerable router at an Ohio dental office or a hospital network,” Bernstein says\. “That makes it practically impossible to ‘strike back’ without taking out innocent bystanders\.”
The US government previously carried out its own cyber operations, rather than relying on third parties\. President Donald Trump began making plans to get private cybersecurity companies involved last year,[*Bloomberg*reported](https://www.bloomberg.com/news/articles/2025-12-12/trump-administration-turning-to-private-firms-in-cyber-offensive)\.
**Follow topics and authors**from this story to see more like this in your personalized homepage feed and to receive email updates\.
- Emma Roth
The Trump administration is authorizing private security firms to conduct offensive cyber operations against overseas cybercriminals, marking a significant shift in US policy that expands the role of the private sector in national security.
The White House issued a memorandum directing federal agencies to create a program authorizing vetted private U.S. companies to conduct government-overseen cyber surveillance and effects operations against transnational criminal organizations engaged in cybercrime.
The Trump administration plans to request US AI companies to voluntarily submit their AI models for cybersecurity testing, aiming to enhance national security.
President Trump signed an executive order creating a voluntary framework for AI companies to share frontier models with the federal government before public release to assess their advanced cyber capabilities and strengthen critical infrastructure security.