WASHINGTON, UNITED STATES — 12 August 2026

The United States is preparing to fight international criminal networks with a new kind of task force—one that may include private cybersecurity companies operating alongside federal law-enforcement agencies.

President Donald Trump signed a National Security Presidential Memorandum on Wednesday authorising the creation of a government-controlled programme targeting foreign organisations accused of attacking American citizens, businesses and institutions through cyberspace.

Unlike traditional cybercrime investigations, which usually concentrate on identifying suspects, freezing money and bringing criminal charges, the new programme could permit approved companies to enter criminal digital infrastructure, collect intelligence and disrupt the systems used to conduct attacks.

The memorandum was officially issued on 12 August 2026, making this a fresh political and national-security development announced today. Read the presidential memorandum.

Private expertise under government command

The programme will be managed by the Homeland Security Task Force’s National Coordination Center. Leadership will be shared by officials appointed by the Department of Justice and the Department of Homeland Security.

Private companies will not receive unrestricted permission to launch digital attacks. Each participating business must be vetted, enter a formal contract with the government and obtain written approval before beginning an operation.

The memorandum permits two main categories of activity.

The first is cyber surveillance: secretly entering or monitoring a criminal network’s systems to collect intelligence. The second is a cyber-effects operation, which could manipulate, interrupt, disable or destroy digital infrastructure controlled by a targeted criminal organisation.

Companies may also be required to maintain a bond or escrow deposit of at least $1 million. That money could be forfeited if a participant violates the conditions of its government contract.

Detailed operating rules must be developed within 60 days. According to the memorandum, both large technology companies and smaller specialist cybersecurity firms should be eligible to participate if they meet the required technical, security and personnel standards.

The criminals in Washington’s sights

The initiative is aimed at cyber-enabled transnational criminal organisations rather than foreign governments.

Possible targets include networks connected to ransomware, phishing operations, impersonation scams, financial fraud and sextortion. Many such groups operate across national borders, making arrests and prosecutions difficult when suspects are located in countries that cannot—or will not—cooperate with American authorities.

The White House says American consumers reported losing more than $20.8 billion to cyber-enabled crime in 2025. It argues that conventional enforcement has struggled to keep pace with criminal groups capable of moving their servers, money and personnel between jurisdictions. White House fact sheet

The new strategy seeks to attack the infrastructure supporting those operations rather than waiting for individual perpetrators to be extradited.

Not a licence for companies to “hack back”

The distinction between government control and private participation will be crucial.

American businesses are generally prohibited from breaking into external computer systems, even when pursuing hackers who have attacked them. Wednesday’s memorandum does not remove that general restriction or allow ordinary companies to retaliate on their own.

Instead, selected firms would become operational partners acting under the authority and supervision of the US government. Every proposed mission must pass through an approval process involving Justice and Homeland Security officials.

Companies must stop an operation immediately if it unintentionally reaches an American citizen, a US-based information system or infrastructure controlled by an American entity. Operations that could cause death, serious injury or consequences equivalent to an armed attack cannot be approved through the programme’s ordinary process.

Reuters reported that companies would be able to gather threat information from other businesses and government bodies before proposing specific operations against identified networks. Reuters report

Why this matters internationally

The policy could reshape the debate over who is permitted to conduct offensive activity in cyberspace.

Governments have traditionally kept such operations within military, intelligence and law-enforcement agencies. Giving private companies a controlled operational role could provide access to highly specialised talent and technology but it may also create diplomatic and legal complications.

A criminal server located in another country could share infrastructure with innocent businesses or government services. Disabling it without the host country’s cooperation might generate accusations that the United States has violated national sovereignty.

Cyber attribution presents another risk. Criminal organisations sometimes use infrastructure belonging to unrelated victims or operate with hidden assistance from state agencies. An error could disrupt legitimate systems or increase tensions between governments.

The White House says operations must comply with the US Constitution, domestic law and applicable international agreements. However, part of the programme’s operational framework is contained in a classified annex, meaning significant details will remain outside public view.

What happens next

The programme is not expected to begin launching operations immediately.

Justice and Homeland Security officials must first establish participation standards, approval procedures, reporting requirements and safeguards. The first progress report is due within 180 days, with additional reports required annually.

The identities of participating companies and the first criminal networks considered for action have not been disclosed.

What is already clear is that Washington no longer wants to treat major cybercrime only as something to investigate after money or information has been stolen. Under the new policy, the United States intends to pursue the machinery behind the crimes quietly, digitally and, when authorised, beyond its own borders.