White House Memo Lets Vetted Security Firms Run Offensive Cyber Operations Against Foreign Crime Groups

A national security presidential memorandum signed on August 12, 2026 directs the National Coordination Center (NCC) to build a program that lets vetted U.S. private security companies conduct offensive cyber operations against foreign transnational criminal organizations, under the control of the Department of Justice and the Department of Homeland Security. The framework requires participating firms to post a bond of at least $1 million, halt any operation that crosses approved limits, and report unintended targeting of U.S. persons or systems.
What the memorandum does
The NSPM, published on the White House website on August 12, 2026, tasks the NCC, part of the Homeland Security Task Force, with creating and managing a program that authorizes “Participating Companies” to run Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs). All activity must take place within lawful federal investigatory, protective, or intelligence operations and remain under federal direction.
Two co-Executive Directors, one designated by the Attorney General and one by the Secretary of Homeland Security, will oversee the program. They have authority to approve operations proposed by personnel of their own departments after coordinating with each other, but they may not approve any operation that would cause a “Critical Outcome” as defined in the memo.
How private companies participate
Vetted firms must enter contractual agreements with either the Justice Department or the Homeland Security Department. The contracts enforce rigorous vetting and bind companies to the operational procedures laid out in implementation guidance developed by the Executive Directors and the Homeland Security Council.
Participating companies can also sign commercial agreements with other private entities to receive threat information collected during normal business, and with federal, state, local, tribal, and territorial agencies, which can flag CE-TCO threats for the companies to propose operations against.
Companies must maintain a bond or escrow of at least $1 million that is forfeited for non-compliance. They are required to stop an operation immediately if it exceeds approved scope, including any unintended targeting of U.S. citizens or U.S.-based systems, and to notify the NCC.
What the program is meant to disrupt
According to the accompanying White House fact sheet, the program targets foreign-based criminal organizations running ransomware attacks, phishing campaigns, financial frauds, sextortion schemes, and impersonation scams. The fact sheet frames the NSPM as part of a broader push that includes Executive Order 14390, signed March 6, 2026, on combating cybercrime, fraud, and predatory schemes against American citizens.
The fact sheet cites several figures on the scale of the problem: in 2025, American consumers reported losing more than $20.8 billion to cyber-enabled crime; 73% of U.S. adults have experienced some kind of online scam or attack; 98% of Americans believe scams pose a threat to individuals in the U.S., with two-thirds calling it a “major” threat; and one in seven young people who experienced sextortion as a minor reported harming themselves in response.
Limits and oversight built into the memo
Section 2 of the NSPM requires that all program activity be conducted in accordance with the Constitution and applicable law. The fact sheet stresses that operations must comply with the U.S. Constitution, federal law, and U.S. international obligations, and that the Executive Directors and the Homeland Security Council are responsible for creating “rigorous procedures for the review and conduct” of approved operations.
Companies cannot self-authorize. Any cyber operation a participating firm wants to run must be proposed to the NCC, reviewed by the co-Executive Directors, and conducted “on behalf of and under the supervision of the Federal Government.” The memo also restricts who can approve operations producing Critical Outcomes, reserving those for higher-level authority outside the Executive Directors.
Why industry figures are watching closely
Security leaders have called the policy a notable departure from past practice. Veracode co-founder Chris Wysopal described the memo as a “pretty big shift in US cyber policy” and “a major expansion of the private sector’s role in offensive cyber operations.” Jason Kikta, former leader of the Cyber National Mission Force and CTO at Automox, framed it as “a perpetual motion machine for billable threats.”
Their reactions capture the two sides of the debate: supporters see a long-overdue use of private offensive capability against foreign crime groups that have exploited the gap between federal authority and the speed of private operators; critics see a procurement and legal risk model that could pull U.S. firms into active cyber conflicts without a clear end state.
What changes for victims and defenders
For U.S. consumers and businesses, the practical effect will depend on which companies get vetted, what kinds of operations get approved, and how quickly takedowns can be executed against the infrastructure that hosts ransomware payloads, phishing kits, and scam call centers. The memo does not create a private right of action for victims, and operations remain federal actions even when a private firm carries them out.
The $1 million bond is one of the clearest accountability mechanisms in the text. It ties a participating firm’s financial exposure directly to its compliance with the contract, and it is forfeitable on breach, which gives the Justice Department and Homeland Security a concrete enforcement lever beyond simply ending the contract.
Open questions
Key implementation details have not been published. The NSPM directs the Executive Directors and the Homeland Security Council to write the implementation guidance, which will determine the vetting standard, the approval workflow, the definition of Critical Outcomes, and the rules for handling threat intelligence shared by federal, state, local, tribal, and territorial agencies.
Until that guidance lands, the practical scope of the program, how fast companies can be onboarded, and how operations will be coordinated with existing federal cyber missions, including the Cyber National Mission Force, remain to be set.
FAQ
What does the new White House memo on cyber operations do?
It directs the National Coordination Center to build a program that authorizes vetted U.S. private security companies to run Cyber Surveillance Operations and Cyber Effects Operations against foreign transnational criminal organizations, under the oversight of co-Executive Directors from the Department of Justice and the Department of Homeland Security.
How much bond must participating security firms post?
Companies participating in the program must maintain a bond or escrow of at least $1 million, which is forfeited if they fail to comply with their contractual agreements.
Which criminal activities is the program meant to disrupt?
The program targets foreign-based transnational criminal organizations behind ransomware attacks, phishing campaigns, financial frauds, sextortion schemes, and impersonation scams. The White House fact sheet reports that U.S. consumers reported losing more than $20.8 billion to cyber-enabled crime in 2025.
Related coverage
- White House taps security firms for offensive hack-back operations
- White House to meet with AI companies on new voluntary framework for testing frontier model cybersecurity capabilities
This article summarizes reporting from bleepingcomputer.com.