A presidential memorandum lets vetted US firms run surveillance and disruptive operations against foreign criminal groups. DOJ and DHS must approve each one, and a $1 million bond is forfeitable on violations.
A presidential memorandum signed Wednesday lets vetted US private companies run offensive cyber operations against foreign criminal groups for the first time, breaking a decades-long federal position that confined the private sector to defense. The change is narrow on paper, dense in detail, and almost certain to be challenged in court.
The White House's expanding-capabilities memorandum and accompanying fact sheet authorize two kinds of operations against transnational criminal groups: surveillance, including spyware-style intelligence collection, and disruptive attacks that destroy criminals' data or systems. The named targets are ransomware operators, financial-scam networks, sextortion rings, and broader transnational cybercrime aimed at Americans. The stated rationale is to harness "the innovative capabilities of the private sector" against crime that crosses borders faster than federal investigators can follow it.
The program is real but not yet operational. The administration will issue implementation guidance within roughly two months. The Department of Justice and the Department of Homeland Security must co-sign every operation before any approved company can act, and the procedures must bar any targeting of Americans or US-based systems. Any participating firm must post a $1 million escrow deposit that is forfeited on rule violations, a structure that signals financial liability but leaves the size of a punitive haircut for the implementing rules. Eligibility extends to companies of any size, including smaller specialized firms, not just the largest defense contractors.
The federal computer-hacking statutes, including the Computer Fraud and Abuse Act, remain on the books; the memorandum is creating a narrow permitted lane rather than amending those laws. The US position for decades, across administrations, was that private companies can defend themselves against incoming attacks but cannot launch or operate them. The memorandum does not require court authorization for any individual operation. A private company that has been approved by DOJ and DHS can conduct surveillance or run a disruptive attack without a judge's sign-off, provided the target is foreign and the operation is limited to non-US systems.
That structure, executive-branch sign-off in place of a warrant, the same underlying statutes that criminalize the activity, and no public reporting requirement, is the part civil-liberties lawyers have already flagged as the most likely fault line. The doctrinal argument runs through the CFAA itself: the statutes were written to prohibit exactly the kind of computer intrusion the program now permits, and the program depends on executive-branch discretion to draw the line. Critics have also pointed to the absence of disclosed escalation rules, the breadth of the named target list, and the speed at which the program is moving from announcement to implementation, roughly two months, with no statutory hearing or notice-and-comment on the underlying scope.
The White House is not pitching the program as a substitute for federal law enforcement. SecurityWeek's coverage frames the move as a mobilization of private security firms for offensive operations against foreign cybercrime gangs, a posture the administration has also used for adjacent cyber defense work. TechCrunch's original report walks through the operational mechanics: vetting, escrow, sign-off, and the prohibition on US targets. The legal scholars who will be litigating the program within a year have not yet been named in published reporting, but the doctrinal hooks are already public.
The first 60 days will set the shape. The implementation guidance will define the vetting standard, the operational review process at DOJ and DHS, the data-handling rules for any intelligence a private company collects under the program, and the public reporting, if any, on approved operations. A narrow rule and a small number of tightly controlled operations would let the program settle into a contained new instrument. A loose vetting standard, a high volume of approved operations, or a single approved company hitting a target the public finds indefensible would give the CFAA-based objections a concrete case to chew on.
For now, no company has been approved, no operation has been authorized, and the criminal groups named as targets are the same ones the FBI and Cyber Command have been pursuing for years. The first approved operation, and the first civil-liberties lawsuit it draws, will define the program.