Get all your news in one place.
100's of premium titles.
One app.
Start reading
International Business Times UK
International Business Times UK
World
Bernadette B. Tixon

Trump Authorises Private Cyber Firms To Hack Foreign Scammers After Americans Lost $20.8bn to Fraud

Cyber shift: Trump authorises vetted private firms to launch offensive cyber operations against foreign criminal networks — a first in US history (Credit: The Trump White House/WikiMedia Commons)

President Donald Trump has signed a memorandum authorising vetted private American companies to carry out offensive cyber operations against foreign criminal networks for the first time in US history. The move marks a significant shift in Washington's approach to tackling cybercrime, positioning private firms as active participants rather than bystanders.

The memorandum, signed on 12 August and titled 'Expanding Capabilities to Combat Transnational Cyber-Enabled Crime', comes after the White House said American consumers reported losing more than $20.8 billion (£16.3bn) to cyber-enabled crime in 2025.

What The Programme Allows

Under the new framework, the Homeland Security Task Force's National Coordination Center (NCC) will run a programme allowing 'Participating Companies' to conduct what the memorandum calls Cyber Surveillance Operations and Cyber Effects Operations. Cyber Effects Operations — meaning active hacking, disruption, or damage to foreign networks — are a significant departure from the private sector's traditional defensive role.

These operations are directed at foreign Cyber-Enabled Transnational Criminal Organisations, or CE-TCOs. The memorandum states any resulting operational action will be 'exclusively conducted on behalf of and under the supervision of the Federal Government'.

Companies accepted into the scheme must sign contracts with either the Department of Justice or the Department of Homeland Security and undergo what the document calls 'rigorous vetting'. Firms must also maintain a bond or escrow of at least $1 million, forfeited if they breach their contractual agreement. Every operation requires written approval from programme executive directors at the two departments before any action can be taken.

Cybersecurity Industry Split Over 'Billable Threats' Concerns

The announcement has divided cybersecurity professionals. Veracode co-founder Chris Wysopal described the policy on X as 'a pretty big shift in US cyber policy', adding it was 'not exactly 'hack back', but definitely a major expansion of the private sector's role in offensive cyber operations'.

Not everyone shares that enthusiasm. Former US Cyber Command official Jason Kitka criticised the plan in a Bluesky post, calling it 'a perpetual motion machine for billable threats'. Josh Steinman, a former White House cyber official during Trump's first term and now co-founder of Galvanick, welcomed the development. The split reflects a long-running industry debate over whether private firms should ever be authorised to strike back at attackers.

The Collateral Damage Problem

Security analysts have raised concerns about how the programme will handle misidentified targets. Pareekh Jain, chief executive of Pareekh Consulting, said that government control may limit what companies can do, but does not remove the operational risk.

'Avoiding collateral damage is extremely hard,' Jain said, noting that criminals often hide inside legitimate company networks or use hacked smart home devices and stolen credit cards to rent cloud servers. The memorandum includes safeguards. Companies must halt an operation and immediately notify the NCC if they unintentionally target a US person or a system located in the United States, triggering a Justice Department review.

Analysts have also questioned the commercial case for participation. Jonathan Ong, senior analyst for managed security services at Omdia, said he does not 'see the financial incentive for a mega-cap cyber company to undertake the risks'.

Ong also noted that participating firms lack clear legal protection. He said the memorandum offers 'neither immunity nor indemnity that we can see', and that companies would not have 'the protection from nation-state capabilities that a government agency does'. A company that misidentifies a target could face civil lawsuits, reputational damage, or criminal liability — without government indemnity to fall back on.

Earlier proposals to let private companies strike back at hackers would have required amending the Computer Fraud and Abuse Act, the main US anti-hacking statute. This memorandum does not amend that law. Instead, it keeps companies operating inside existing legal authority, with every operation requiring government approval rather than independent action. That distinction is what separates this programme from the more sweeping 'hack back' bills the cybersecurity industry has resisted in the past.

For ordinary consumers, the practical effect will depend on how quickly the programme becomes operational. The memorandum gives officials 60 days to draw up procedures, and the first public report on the scheme's progress is not due for 180 days, meaning most of its real-world impact remains untested for now.

For UK readers, the programme's implications may extend beyond US borders — British companies with US operations or cloud infrastructure could find themselves caught in the crossfire of private-sector cyber operations. The 180-day review period means the full scope of the policy will not be clear until 2026.

Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.