
National Security Presidential Memorandum authorizes private sector participation in cyberattacks against foreign transnational criminal organizations
The Trump administration is enlisting private security firms to conduct US-government authorized cyber operations, including attacks, against foreign criminal groups committing hacks on US targets, under a new National Security Presidential Memorandum.
AI-generated summary
The US faces increasing cyber threats from foreign transnational criminal organizations.
The Trump administration is recruiting private security firms to conduct federal government-authorized operations, including cyberattacks, against overseas-based criminal organizations that commit hacks on US persons, organizations, or government entities.
In a National Security Presidential Memorandum issued Thursday, US President Donald Trump directed the National Coordination Center (NCC), which operates under the Homeland Security Task Force, to develop a program for conducting specific cyber operations that combat foreign transnational criminal organizations (TCOs). The Departments of Justice and Homeland Security will provide oversight. The lynchpin of that program is bringing in private sector companies to participate.
Devil will be in the still-undefined details
A fact sheet that accompanied Thursday’s memo listed ransomware, sextortion schemes, phishing campaigns, financial fraud, and impersonation scams as activities eligible for private-sector security firms to target. The memo said such firms could “conduct Cyber Surveillance Operations and Cyber Effects Operations” against “cyber-enabled” TCOs. Such groups are defined as “any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests, and that is not an institutional part of a foreign government or wholly operated under a foreign government’s direction.”
The new program is the first time the federal government will authorize private companies to conduct offensive cyber operations against overseas hackers. The memo appears to permit companies participating in the program to use spyware or launch offensive attacks intended to destroy TCO data or systems. The memo doesn’t rule out certain types of offensive attacks, such as those that use encryption to lock targets out of their networks or performing distributed denial-of-service attacks. Up until now, the government has prohibited the private sector from taking such actions without court-authorized approval.
“There’s definitely merit in the idea of hacking ransomware groups and it does already in fact happen (don’t ask me how I know),” independent security researcher Kevin Beamont said in response to the memo. “But the correct incentives have gotta be there.” He added: “The biggest problem I’ve had with fighting ransomware over the past 5 years is private cyber companies basically lobbying for nothing to change. A lot of companies have made a lot of money, so putting them in charge of stopping it seems optimistic.”
The memo placed specific limits on the scope of the new program. Private companies must first be approved after vetting by the Departments of Justice and Homeland Security. Cyber Effects Operations and Cyber Surveillance Operations may not result in “Critical Outcomes,” meaning those that result in the loss of life or serious injury or “rise to the level of use of force or armed attack under international law.” The memo also notes:
[M]inimum standards that Participating Companies must meet in order to take part in the Program, which shall include appropriate levels of technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence, reliability, and other factors that the Program Executive Directors, in coordination with the Homeland Security Council, determine are relevant or necessary for guaranteeing high confidence in a Participating Company’s ability to perform successfully.
Participating companies must also deposit $1 million in an escrow account. The deposit will be forfeited “should the Participating Company enter non‑compliance with its contractual agreement described” in the memo.
Many of the specifics of the policy remain undefined. These details will be crucial to determining how effective and judicious the program will be. The memo directs the Justice and Homeland Security departments to deliver the particulars in the next 60 days.
AI outlook — possibilities, not facts
Increased private sector involvement in US cyber operations
Likely · Within weeks

Romania intercepted and destroyed an explosive-laden drone boat near the Neptun Deep gas platform in the Black Sea. Officials blamed Russia for the incident, marking the second such threat to the critical energy infrastructure this month.

President Donald Trump signed a national space transportation policy aiming for over 1,000 annual launches by 2030. The directive mandates infrastructure upgrades at federal spaceports, improved scheduling transparency, and the identification of new launch sites for geographic resiliency.

A new Pentagon report shows that more U.S. service members are reporting unwanted sexual contact, with reporting rates rising to 33% in fiscal year 2025. Meanwhile, the overall prevalence of sexual assault and harassment incidents decreased among active duty personnel.

The USS Abraham Lincoln is returning after a nine-month deployment. Reports of deteriorating mental health and potential suicide attempts among the 5,000-person crew have surfaced, with experts citing extended isolation and inconsistent leadership messaging as key stressors.

The US and South Korea concluded their military drills six days early in a gesture to North Korea, but Pyongyang dismissed the move and test-fired about 10 short-range ballistic missiles.

The U.S. Army has directed a specialized drone warfare battalion within the 173rd Airborne Brigade to end its unmanned technology efforts and return to traditional infantry duties under acting chief of staff Gen. Christopher LaNeve.