Ask Finn← Discover
Trending

Trump Gives Private Cybersecurity Firms Unprecedented Authority to Strike Back Against Foreign Criminal Networks

By Jamie Sullivan · Tuesday, August 18, 2026
Finn's Take· TL;DR
  • Trump authorizes vetted private cybersecurity firms to conduct offensive cyber operations against foreign criminal networks under strict federal oversight and approval.
  • Americans lost $20.8 billion to cyber-enabled crime in 2025; the NSPM aims to disrupt foreign criminal organizations that have operated with impunity.
  • New policy carves exception to Computer Fraud and Abuse Act, but legal foundation remains untested under international law with residual risks for firms.
See this from any side — with sources:
Left takeNeutralRight take

A Historic Shift in How America Fights Cybercrime

On August 12, 2026, the White House released a National Security Presidential Memorandum (NSPM), marking a seismic shift in U.S. cybersecurity policy and establishing a framework to authorize private-sector companies to conduct offensive cyber operations — historically strictly prohibited by federal law — against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs). It is a bold and unprecedented move, one that essentially deputizes American tech companies as government-sanctioned cyber operatives.

The NSPM is built on a blunt premise: Americans lost more than $20.8 billion to cyber-enabled crime in 2025, and the foreign criminal organizations behind it have largely operated with impunity. Transnational Criminal Organizations pose a growing threat to American citizens, businesses, and national security, conducting sustained cyber campaigns to perpetrate frauds that undermine American prosperity, security, and freedom.

What the Memorandum Actually Does

The NSPM directs the creation of a program under which vetted private United States contractors will be authorized to conduct cyber surveillance and cyber effects operations against foreign cyber-enabled transnational criminal organizations, under the direction, control, and oversight of the federal government. In plain terms, approved companies can now legally hack the hackers — but only with Washington's blessing on every move they make.

The President directed the National Coordination Center (NCC) to create a federal program that will allow vetted U.S. cybersecurity companies to conduct government-supervised cyber surveillance and cyber disruption operations against CE-TCOs, while operating under Department of Justice and Department of Homeland Security approval and oversight. Participating firms must receive written approval for every operation, work under government contracts, and operate under strict federal supervision.

Accompanied by a White House fact sheet and a classified annex, the NSPM is the most significant step to date implementing the first pillar of the President's national cyber strategy, Shaping Adversary Behavior, which promised to "unleash the private-sector" to "disrupt adversary networks." The NCC has 60 days from the signing to establish operating procedures, in coordination with the Homeland Security Council.

Breaking a Long-Standing Legal Barrier

Traditionally, the Computer Fraud and Abuse Act (CFAA) and the Cybersecurity Information Sharing Act of 2015 drew a hard line against offensive operations by private sector entities — such as executing DDoS attacks against attacker infrastructure, deploying retaliatory malware, or conducting surreptitious access against threat actors. This NSPM effectively carves out a new, government-supervised exception to those restrictions.

The signing resolves a legal barrier that has blocked private-sector cyber action for decades, but it does so by creating a new category of authorized private operator that sits in uncharted territory under international law. No federal appellate court has ruled on whether this extension to private delegatees is valid — meaning the legal foundation is an interpretation, not a settled precedent, and firms that rely on it do so with some residual legal risk.

What's Next for Companies and Cybersecurity Policy

Participating companies can expect rigorous vetting, extensive government oversight, approval requirements for operational activities, compliance obligations, and continuing review of program participation. Companies considering participation should begin evaluating government contracts and risk allocation issues now, as any contracts will likely require careful consideration of liability allocation, indemnification, litigation support, and compliance risks.

One looming concern involves artificial intelligence: AI-driven autonomous cyber tools will quickly outpace human oversight. While the NSPM encourages automation, deploying agentic AI in offensive operations raises the likelihood of actions exceeding approved parameters — triggering bond forfeiture or civil exposure at machine speed. That tension between speed and accountability will be one of the central challenges as the program takes shape.

The memorandum represents the culmination of a deliberate, multi-step policy build. In March 2026, Trump signed Executive Order 14390, directing federal agencies to coordinate responses to cybercrime and other cyber-enabled fraud targeting Americans. That order was accompanied by the release of the Trump administration's National Cybersecurity Strategy, which explicitly envisioned private-sector firms taking an expanded role in offensive operations — but stopped short of formal authorization. The August NSPM delivers what that strategy promised. Whether the courts, international partners, and the cybersecurity industry itself will embrace this new frontier remains to be seen.

Have a question about this story?
Ask Finn — answers grounded in this article, from any viewpoint.