Published Security3 min read
Hack Back Becomes a Contract: White House Deputizes Vetted Firms Against Foreign Cybercrime
A presidential memorandum signed Wednesday lets vetted US companies run cyber surveillance and cyber effects operations against foreign criminal groups, with DOJ or DHS contracts, a $1 million bond, and written federal...
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- President Donald Trump signed a national security presidential memorandum on Wednesday that lays the groundwork for private sector companies to take a larger role in offensive hacking operations against transnational criminal organizations.
- The memorandum instructs the National Coordination Center (NCC), part of the Homeland Security Task Force, to establish and manage a program authorizing participating companies to conduct cyber operations against transnational criminal organizations under the control and authority of the US government.
- The program authorizes participating companies to execute 'cyber surveillance operations' and 'cyber effects operations' targeting foreign cyber-enabled transnational criminal organizations (CE-TCOs) as part of lawful investigatory, protective, or intelligence operations carried out by federal law enforcement.
- To participate, US companies must undergo rigorous vetting and sign formal contracts with the Department of Justice or the Department of Homeland Security.
- The initiative operates under co-executive directors designated by the Attorney General and the Secretary of Homeland Security, keeping operational actions under direct federal supervision.
Compiled by The WatchSomething wrong?How this is made
Why it matters
President Donald Trump signed a national security presidential memorandum on Wednesday directing the National Coordination Center to build a program under which vetted private US companies can conduct cyber surveillance operations and cyber effects operations against foreign cyber-enabled transnational criminal organizations, under federal control and oversight [1][2][3]. What has failed repeatedly as legislation is now arriving as procurement: signed contracts, a forfeitable bond, and a government sign-off requirement on each operation [4][6][8].
The mechanics are specific. The program sits with the NCC, part of the Homeland Security Task Force, and is run by co-executive directors designated by the Attorney General and the Secretary of Homeland Security [2][5]. Firms must pass what the memorandum calls rigorous vetting and contract with either DOJ or DHS [4]. Those contracts may require a bond or escrow of at least $1 million, forfeited if a company fails to meet operational requirements [6]. Before a company acts on a cyber operations package, the executive directors must review it and issue written approval and direction [8], and proposed operations go through multi-agency deconfliction involving law enforcement, the State Department, Treasury, the Department of War, DOJ, and the Intelligence Community [9].
The boundaries are drawn where you would expect. Surveillance operations mean covert access to collect intelligence; effects operations mean disrupting, degrading, or destroying adversary systems and infrastructure [10]. The memorandum bars "critical outcomes," defined as actions likely to cause loss of life or serious injury, or to rise to the level of a use of force or armed attack under international law [11]. Targets are limited to non-state criminal groups, but foreign entities are presumed independent of foreign governments unless clear intelligence says otherwise [12]. If a contractor discovers it has hit a US person or a domestic system, it must stop immediately and notify the government [13]. According to CyberScoop, the program must operate inside existing law, including the Computer Fraud and Abuse Act that earlier hack-back proposals sought to amend [14].
The stated justification is loss volume. A White House fact sheet said US consumers reported more than $20.8 billion in cyber-enabled crime losses in 2025 [15], with the program aimed at ransomware, phishing, financial fraud, sextortion, and impersonation schemes [16]. The memorandum argues American businesses "have historically been underutilized" in disrupting criminal networks in cyberspace [17], and builds on a March executive order on fraud and cybercrime [18]. For scale, the minimum bond is roughly 0.005 percent of the loss figure the White House cited [19].
Practitioners are split. Veracode co-founder Chris Wysopal called it "a pretty big shift in US cyber policy" and a major expansion of the private sector's offensive role, while noting it stops short of earlier hack-back proposals [20]. Former Cyber National Mission Force leader and Automox CTO Jason Kikta called it "a perpetual motion machine for billable threats" [21]. Josh Steinman, a former top White House cyber official in Trump's first term, welcomed it [22]. The Record reports that experts questioned the absence of legal protections for participating employees and the risk of foreign retaliation against them, citing the recent arrest in Italy and extradition to the US of a Chinese national accused of working for a firm that attacked American companies for Beijing [23][24]. The same report notes the memorandum says little about criminal groups entangled with states, even as State Department officials have tied many Chinese-run Southeast Asian scam compounds to government projects and DOJ indictments have implicated Cambodian and Myanmar officials [25][26][27].
Watch the two-month clock: agencies must produce operating procedures and minimum participation standards covering technical proficiency, proven operational performance, facility security, and personnel vetting [28], plus a DOJ and DHS framework for how targets get identified and how firms report activity [29]. The White House did not say whether any company has signed up [30].
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
President Donald Trump signed a national security presidential memorandum on Wednesday that lays the groundwork for private sector companies to take a larger role in offensive hacking operations against transnational criminal organizations.
- [2]
The memorandum instructs the National Coordination Center (NCC), part of the Homeland Security Task Force, to establish and manage a program authorizing participating companies to conduct cyber operations against transnational criminal organizations under the control and authority of the US government.
- [3]
The program authorizes participating companies to execute 'cyber surveillance operations' and 'cyber effects operations' targeting foreign cyber-enabled transnational criminal organizations (CE-TCOs) as part of lawful investigatory, protective, or intelligence operations carried out by federal law enforcement.
- [4]
To participate, US companies must undergo rigorous vetting and sign formal contracts with the Department of Justice or the Department of Homeland Security.
- [5]
The initiative operates under co-executive directors designated by the Attorney General and the Secretary of Homeland Security, keeping operational actions under direct federal supervision.
- [6]
Contracts may require a bond or escrow of at least $1 million, which is forfeited if a company fails to comply with operational requirements or contractual agreements.
Sources & coverage · 4 publishers
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- securityweek.comEduard KovacsAug 13White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs
- cyberscoop.comGreg OttoAug 13Trump turns to private sector in offensive hacking operations memo
- therecord.mediaAug 13Trump taps cyber firms to go on offensive against criminals



