Published Security3 min read
Washington outsources offensive cyber, with a $1 million bond as the liability layer
A National Security Presidential Memorandum signed August 12 lets vetted private firms hack foreign criminal networks. The only stated financial safeguard is a bond of at least $1 million.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- President Trump signed a National Security Presidential Memorandum on August 12 allowing vetted private companies to run offensive cyber operations against foreign threat actors, under the control and oversight of the US government.
- The White House said: "The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States," adding that American businesses' innovative capabilities have "historically been underutilized" in efforts to identify and disrupt criminal networks in cyberspace.
- The White House stated it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime.
- The memorandum builds on an earlier executive order Trump signed in March 2026 addressing cybercrime and fraud targeting American citizens.
- According to the White House, American consumers reported losing more than $20.8 billion to cyber-enabled crime in 2025.
Compiled by The WatchSomething wrong?How this is made
Why it matters
President Trump signed a National Security Presidential Memorandum on August 12 making it United States policy for vetted private companies to run offensive cyber operations against foreign threat actors under government control and oversight [1]. The new job description includes gaining unauthorized access to a target's systems with the intent of remaining undetected, and manipulating, disrupting, degrading or destroying networks outright, which moves a stack of legal, contractual and insurance questions out of the seminar room and into procurement [8][9].
The stated rationale is capacity. The White House said the private sector's "scale, speed, and capacity secure a critical offensive cyber advantage for the United States" and that those capabilities have been "historically underutilized" against criminal networks [2], with the declared policy being to use all instruments of national power, including private capability, to combat cybercrime [3]. The supporting number is $20.8 billion in consumer-reported losses to cyber-enabled crime in 2025, according to the White House [5]. The memorandum builds on a March 2026 executive order on cybercrime and fraud targeting Americans [4], roughly five months earlier [2], and names transnational criminal organizations running ransomware, phishing and sextortion campaigns against Americans from abroad as the targets [17].
The machinery sits inside the Homeland Security Task Force's National Coordination Center, run by two Executive Directors, one designated by the Attorney General from the Justice Department and one by the Secretary of Homeland Security [6]. Companies that opt in are encouraged to form agreements with other private entities and with federal, state, local, tribal and territorial agencies to collect intelligence and propose operations [7]. Both surveillance and effects operations require written approval and direction from the Executive Directors before a company acts [10]. The Directors may approve after coordinating with each other, but cannot approve anything likely to cause loss of life or serious injury, or to rise to the level of use of force or armed attack under international law [11].
That is the part that will occupy counsel. The disclosed financial architecture is a bond or escrow of at least $1 million as a condition of participation, forfeited if a company falls into non-compliance with its contract [12], plus review at least annually to stay in the program [13]. The bond is roughly one twenty-thousandth of the annual loss figure the program cites as its justification [1]. The forfeiture trigger is written against the contract rather than against harm caused to a third party [3], and the ban on "Critical Outcomes" constrains what the Executive Directors may authorize, which is not the same thing as constraining what an operation does after it is launched [4]. The published account of the memorandum lists no indemnification, immunity or insurance requirement among the participation terms [5].
Domestic spillover has a defined procedure. A company that discovers it has unintentionally hit a US person, a system in the US, or a system controlled by a US person must stop, run minimization, and immediately notify the National Coordination Center, which notifies the Justice Department [14]. Any activity directed at a US person needs prior authorization before an operation can be approved [15]. The whole thing is qualified as subject to applicable law and the availability of appropriations [16].
Watch for the first contract language to surface, specifically whether participants get indemnity or only a bond they can lose. Watch whether cyber insurers write program participation as an exclusion before the first Cyber Effects Operation is approved. Watch what "non-compliance" is defined to mean at the annual review, and whether the $1 million floor survives contact with a collateral outage abroad.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
President Trump signed a National Security Presidential Memorandum on August 12 allowing vetted private companies to run offensive cyber operations against foreign threat actors, under the control and oversight of the US government.
- [2]
The White House said: "The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States," adding that American businesses' innovative capabilities have "historically been underutilized" in efforts to identify and disrupt criminal networks in cyberspace.
- [3]
The White House stated it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime.
- [4]
The memorandum builds on an earlier executive order Trump signed in March 2026 addressing cybercrime and fraud targeting American citizens.
- [5]
According to the White House, American consumers reported losing more than $20.8 billion to cyber-enabled crime in 2025.
- [6]
The Homeland Security Task Force's National Coordination Center will run the program, led by two Executive Directors, one designated by the Attorney General from the Department of Justice and one designated by the Secretary of Homeland Security.
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- helpnetsecurity.comSinisa MarkovicAug 13White House authorizes private US companies to hack foreign criminal networks
Additional citations
- Help Net Security
- White House, via Help Net Security



