
A national security presidential memorandum signed on August 12, 2026, directs the National Coordination Center (NCC) to create a program under which vetted U.S. private companies could conduct approved cyber operations against foreign cyber-enabled transnational criminal organizations. The operations would remain under federal government control and supervision, with the Justice Department and Homeland Security Department overseeing the program through two executive directors.
What does the program authorize?
The framework covers two categories of activity. Cyber surveillance operations involve observing or gathering information about qualifying criminal organizations, while cyber effects operations are actions intended to affect their systems or operations. The memorandum limits the program to foreign cyber-enabled transnational criminal organizations, or CE-TCOs, as defined by the order.
Approved actions would be carried out as part of lawful federal law-enforcement, protective, or intelligence operations. They would be conducted on behalf of, and under the supervision of, the federal government pursuant to its legal authorities.
The program does not create unrestricted authority for companies to pursue attackers on their own. Participating companies must contract with either the Justice Department or the Homeland Security Department, undergo rigorous vetting, and follow strict operational procedures established through implementation guidance.
How would companies participate?
Private companies could enter into commercial agreements with other private entities and with federal, state, local, tribal, and territorial agencies. Those relationships would allow participating companies to receive threat information gathered during normal business activities and to propose cyber operations addressing identified CE-TCO threats to the NCC.
The program requires coordination between the two designated executive directors before cyber operations are approved. The executive director from the Justice Department is designated by the attorney general, and the executive director from the Homeland Security Department is designated by the secretary of Homeland Security. Neither executive director may approve an operation that would result in a “critical outcome,” as defined by the memorandum.
Participating companies would also have to maintain a bond or escrow account of at least $1 million. The funds would be forfeited if a company fails to comply with its contractual agreements. If a company discovers activity outside the approved limits, including unintended targeting of U.S. citizens or systems based in the United States, it must immediately stop the operation and notify the NCC.
What safeguards and limits apply?
The memorandum requires procedures for reviewing and conducting operations in accordance with the U.S. Constitution, federal law, and applicable international agreements. The Homeland Security Council and the program’s executive directors are responsible for creating the detailed procedures.
The framework is aimed at specific criminal activity conducted by foreign organizations. Listed targets include ransomware attacks, phishing campaigns, financial fraud, sextortion schemes, and impersonation scams. These campaigns are described as coordinated operations by sophisticated transnational criminal organizations based outside the United States.
The policy follows Executive Order 14390, signed on March 6, 2026, which directed the federal government to take action against cyber-enabled crime harming U.S. citizens. The new memorandum adds vetted private-sector capabilities to the government’s efforts to identify and disrupt criminal networks operating in cyberspace.
What is the scale of the cyber-enabled crime problem?
The White House fact sheet reports that U.S. consumers reported losing more than $20.8 billion to cyber-enabled crime in 2025. It also says 73% of U.S. adults have experienced some form of online scam or attack, while 98% of Americans believe scams pose a threat to individuals in the United States. Two-thirds of those surveyed described scams as a “major” threat.
The fact sheet says seniors, children, and low-income families are disproportionately targeted by scammers. It also reports that one in seven young people who experienced sextortion as a minor harmed themselves in response to the abuse.
What does the memorandum change?
The new framework expands the role of private security companies in offensive cyber operations by placing vetted companies under federal contracts, direction, and oversight. The NCC will create, manage, and maintain the program, while the two executive directors and the Homeland Security Council establish the procedures for reviewing and conducting limited operations.
The program’s stated purpose is to use the private sector’s technical capabilities alongside federal authority against foreign criminal organizations. Its contractual, financial, reporting, and legal requirements are designed to define how that participation is authorized and constrained.
FAQ
What is the White House’s private-sector hack-back program?
It is a program to be created and managed by the National Coordination Center that allows vetted U.S. companies to conduct approved cyber surveillance or cyber effects operations against foreign cyber-enabled transnational criminal organizations under federal control and supervision.
Which government departments will oversee the program?
The Justice Department and the Homeland Security Department will each designate a program executive director. The executive directors must coordinate approvals, and neither may approve operations resulting in a critical outcome as defined by the memorandum.
What financial security must participating companies provide?
Participating companies must maintain a bond or escrow account of at least $1 million. The funds may be forfeited if the company does not comply with its contractual agreements.
What must companies do if an operation exceeds its approved limits?
Companies must immediately stop the operation and notify the National Coordination Center. The limits include avoiding unintended targeting of U.S. citizens or systems based in the United States.
Related coverage
- White House taps security firms for offensive hack-back operations
- White House to meet with AI companies over voluntary frontier model cybersecurity framework
This article summarizes reporting from bleepingcomputer.com. See our editorial disclaimer for how our articles are produced.
Run a free scan to see your AI Visibility Score, SEO rating, and local citation accuracy.