The White House published a presidential memorandum that creates a legal framework for engaging private cybersecurity companies to conduct offensive operations against foreign criminal groups. The operations will be carried out under government contracts, overseen by the Department of Justice and the Department of Homeland Security, with mandatory approval of targets and methods of impact. The initiative affects both the US cybersecurity industry, which is receiving a fundamentally new class of government contracts, and the international cybercriminal ecosystem, against which the resources of the private sector can for the first time be directed with the official sanction of the state.
Key parameters of the program
According to the memorandum, the National Coordination Center (NCC) will be responsible for preparing the program, and the rules for conducting operations must be presented within 60 days. The program provides for two types of activities: covert intelligence within the infrastructure of foreign criminals and so‑called Cyber Effects Operations — interference with system operation, disruption or blocking of their functioning, and destruction of data and infrastructure.
According to a White House fact sheet, operations may target groups engaged in:
- extortion using ransomware;
- phishing and financial fraud;
- identity theft schemes;
- sexual extortion (sextortion).
The justification for creating the program is the losses suffered by American users from cybercrime, which, according to the White House, exceeded $20.8 billion in 2025 alone.
Oversight mechanisms and limitations
The memorandum establishes a multi‑layer system of restrictions. Only companies that have passed a special assessment against four criteria will be allowed to participate in the program: technical capabilities, experience in conducting cyber operations, the security of their own infrastructure, and personnel reliability. Compliance with these requirements must be confirmed annually.
Financial safeguards include a mandatory bond or escrow of at least $1 million for each contractor company. These funds may be confiscated if the terms of the contract are violated.
Operational constraints include several fundamental prohibitions:
- prohibited are attacks on organizations that are part of foreign governments or fully controlled by them;
- prohibited are operations that could lead to death or serious injury of people;
- prohibited are actions that international law could qualify as the use of force or an armed attack;
- in the event of accidental impact on US citizens or American systems, the contractor is obliged to immediately halt the operation and notify the NCC.
Legal uncertainty
The legal basis of the initiative remains a matter of debate. Previously, US companies were prohibited from independently conducting retaliatory cyberattacks (so‑called hack‑back operations) without a court order. According to lawyers cited in the original source, legislative changes may be required for the program to operate fully. At the same time, it is noted that the Computer Fraud and Abuse Act (CFAA) contains an exception for government‑sanctioned investigative, defensive, and intelligence operations — and this exception could potentially be extended to private contractors acting under the direct instruction of the authorities. However, this interpretation has not yet been supported by case law or an official legal opinion.
Industry reaction and strategic implications
Veracode co‑founder Chris Wysopal described the memorandum as a serious shift in US cyber policy and a significant expansion of the role of the private sector in offensive operations.
Researcher Kevin Beaumont acknowledged that the idea of attacking ransomware operators’ infrastructure makes sense, but expressed doubt about the interest of the cybersecurity companies themselves: many of them have for years earned money by countering precisely the threats that are now proposed to be eliminated through offensive means. This conflict of interest is one of the key issues that will have to be resolved when forming the pool of contractors.
Strategically, the memorandum creates a new class of relationship between the state and the private sector in cyberspace. Until now, offensive cyber operations have remained the exclusive prerogative of the military and intelligence services. Bringing in commercial companies potentially increases operational capabilities but at the same time creates risks: from the leakage of offensive tools to the escalation of conflicts with states under whose jurisdiction the criminal groups operate. The ban on attacks against state entities is intended to minimize this risk, but in practice the line between “state” and “non‑state” cybercrime is often blurred.
Companies operating in the cybersecurity field in the US market should monitor the publication of the rules of engagement — which are due to appear within 60 days — and assess whether their technical capabilities and organizational structure meet the admission criteria for the program. For organizations outside the United States, especially those whose infrastructure may overlap with that of criminal groups, this is a signal to strengthen network segmentation and to document the legitimacy of their operations — so as to avoid inadvertently falling within the scope of contractors’ activities.