By Interestana AI Editorial — AI-drafted, human-overseen. How we report
US Authorizes Private Firms for Overseas Cyber Attacks

The Trump administration is initiating a program to authorize private security firms to conduct federal government-sanctioned cyber operations against overseas criminal organizations. This initiative, detailed in a National Security Presidential Memorandum issued on Thursday, aims to combat foreign transnational criminal organizations (TCOs) that engage in cybercrimes targeting US persons, organizations, or government entities. The National Coordination Center (NCC), operating under the Homeland Security Task Force, has been directed by President Donald Trump to develop this program, with oversight provided by the Departments of Justice and Homeland Security. A key component of this strategy involves the participation of private sector companies.
The memo specifies that these private firms will be authorized to conduct "Cyber Surveillance Operations and Cyber Effects Operations." The targets are defined as "cyber-enabled" TCOs, which are characterized as any foreign group conducting cybercrime against the United States Government, a US person, or US interests, provided they are not an institutional part of a foreign government or wholly operated under its direction. The types of criminal activities eligible for targeting by these private security firms include ransomware attacks, sextortion schemes, phishing campaigns, financial fraud, and impersonation scams. This represents a significant shift in US cyber defense strategy, moving towards leveraging private sector capabilities for offensive cyber operations abroad.
While the memorandum outlines the intent and scope of the program, many of the operational details remain undefined. The fact sheet accompanying the memo provided a list of targeted criminal activities, but the precise methods, legal frameworks, and accountability mechanisms for these private sector operations are still under development. The involvement of private entities in conducting offensive cyber operations raises complex legal and ethical questions, particularly concerning jurisdiction, attribution, and the potential for unintended consequences or escalation. The Departments of Justice and Homeland Security will be responsible for establishing the necessary guidelines and ensuring compliance.
This new policy marks a departure from traditional government-led cyber operations, acknowledging the growing sophistication and reach of foreign cybercriminal groups. By engaging private security firms, the US government seeks to augment its capabilities and potentially accelerate response times to cyber threats originating from outside its borders. The success of this program will likely depend on the careful definition of operational parameters, robust oversight, and the establishment of clear lines of responsibility between government agencies and private contractors. The memo's directive to the NCC signifies the urgency with which the administration views the threat posed by these overseas cybercriminal organizations.
Original source — read the full reporting at the publisher:
Read on Ars TechnicaGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.