Published Build3 min read
The Offensive Cyber Contract Now Has a Purchase Order and a Two-Key Lock
An August 12 presidential memorandum lets vetted US companies be hired to break into and disrupt foreign criminal infrastructure. The interesting part for vendors is not the hacking.
Written for builders.See today for builders

What happened
- President Donald Trump signed an August 12 memorandum creating a government-controlled program under which vetted US companies can be contracted to penetrate, surveil and disrupt computer systems used by foreign cybercrime groups.
- The program opens a federal market for offensive security founders who have historically sold tools, threat intelligence or technical expertise while leaving the government to execute intrusions.
- The program will be managed by the National Coordination Center, an interagency body that Trump assigned a cybercrime role through a March 6 executive order.
- DOJ and DHS will each appoint an executive director to oversee the program.
- Companies will operate through contracts with DOJ or DHS, and their actions must be conducted on behalf of the federal government under its legal authorities.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
President Donald Trump signed an August 12 memorandum allowing vetted US companies to be contracted to penetrate, surveil and disrupt the computer systems used by foreign cybercrime groups [1]. For vendors that have sold tools, threat intelligence and technical expertise while leaving the actual intrusions to the government, that converts a product line into a contracted operational service with a federal approval queue in front of it [2].
The approval path is the part that will rearrange org charts. The program sits with the National Coordination Center, an interagency body that a March 6 executive order gave a cybercrime role [3]. DOJ and DHS each appoint an executive director [4], companies hold contracts with DOJ or DHS [5], and every proposed operation requires written approval and instructions from both directors [6]. That is a floor of two separate federal sign-offs per mission [1], plus coordination with other national security agencies before the activity begins [7]. Contractors cannot pick a target and strike on their own [8].
The permitted work is not defensive. Participants can conduct covert surveillance and what the memorandum calls "cyber effects operations", which can include manipulating, disrupting, denying, degrading or destroying information systems, networks and infrastructure [9]. Surveillance can include accessing systems without the owner's authorization, remaining undetected and gathering intelligence for future disruption missions [10].
On liability, according to runtimewire.com's account, the design runs opposite to the deniable proxy arrangement often associated with Russian operations [11]. Agency contracts, written approvals and government-issued instructions are meant to make US direction explicit [12], and the reason for pulling contractors inside the federal chain of authority is so they can claim lawful authorization [13]. Execution and some operational risk still move to the contractor [14]. There is a cash stake as well: DOJ and DHS may require each participant to maintain a bond or escrow account of at least $1 million, which can be forfeited for violating its contract [15].
Staffing and real estate are gating items here, not paperwork. Eligibility will turn on technical proficiency, operational experience, secure facilities, vetted personnel, and reliability and competence [16], with rules written to accommodate both large contractors and smaller companies suited to specialized assignments [17].
The intake side is where this stops looking like a conventional federal services contract, which the source describes as the point [26]. Participants may sign commercial agreements with businesses that collect threat data through ordinary operations [18], and state, local, tribal and territorial agencies can identify criminal groups and pass that information to contractors, which can then propose operations to the coordination center [19]. All of those relationships must be disclosed to the government [20]. In practice a vendor could take intelligence from a bank, cloud provider or telecommunications company, prepare an operation, and seek authorization to run it [21].
Targeting is bounded to foreign cyber-enabled transnational criminal organizations, excluding groups that are institutional parts of foreign governments or that operate wholly under a government's direction [22], with a presumption that a group is independent unless clear intelligence establishes a state connection [23].
Watch the 60-day procedures, which will decide how contractors are paid, how information is handled and which companies can meet the security requirements [24]. If that clock runs from signing, it lands around October 11 [2]. The first program report is due within 180 days, or roughly early February [3], followed by annual reports to the White House homeland security adviser and the national cyber director [25].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
President Donald Trump signed an August 12 memorandum creating a government-controlled program under which vetted US companies can be contracted to penetrate, surveil and disrupt computer systems used by foreign cybercrime groups.
- [2]
The program opens a federal market for offensive security founders who have historically sold tools, threat intelligence or technical expertise while leaving the government to execute intrusions.
- [3]
The program will be managed by the National Coordination Center, an interagency body that Trump assigned a cybercrime role through a March 6 executive order.
- [4]
DOJ and DHS will each appoint an executive director to oversee the program.
- [5]
Companies will operate through contracts with DOJ or DHS, and their actions must be conducted on behalf of the federal government under its legal authorities.
- [6]
Every proposed operation will require written approval and instructions from both executive directors.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- runtimewire.comRuntimeWire StaffAug 12Trump enlists private cyber contractors to hack foreign crime groups
Cited in this coverage: runtimewire.com

