Published Security3 min read
Washington puts offensive cyber on contract, and the liability questions start now
An August 13 memorandum lets vetted US firms run surveillance and disruption operations against criminal networks. The controls are written around US persons, not bystanders.
Not a builder's beat, but builders have a standing stake in it.See today for builders

What happened
- President Trump signed a national security memorandum on August 13 establishing a formal program allowing vetted private US cybersecurity companies to conduct offensive cyber operations against transnational criminal organizations under government direction and oversight.
- The program is managed by the National Coordination Center.
- The program covers both intelligence collection, described as Cyber Surveillance Operations, and active disruption of criminal infrastructure, described as Cyber Effects Operations.
- The memorandum states that the American private sector's "scale, speed, and capacity secure a critical offensive cyber advantage for the United States" and that American businesses' innovative capabilities "have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace."
- The memorandum states: "By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens."
Compiled by The WatchSomething wrong?How this is made
Why it matters
President Trump signed a national security memorandum on August 13 establishing a program under which vetted private US cybersecurity companies may conduct offensive cyber operations against transnational criminal organizations, under government direction and oversight [1]. The program, managed by the National Coordination Center, covers both intelligence collection, termed Cyber Surveillance Operations, and active disruption of criminal infrastructure, termed Cyber Effects Operations [2][3], which means intrusion and takedown work now has a buyer, a contract, and a compliance regime.
The memorandum's stated rationale is capacity. It asserts that the American private sector's "scale, speed, and capacity secure a critical offensive cyber advantage for the United States" and that those capabilities have "historically been underutilized" against criminal networks in cyberspace [4]. The document frames the arrangement as partnering with vetted United States companies subject to federal direction and oversight [5]. It is the formal implementation of what the White House's Cyber Strategy for America promised in March [6].
Scope is where attribution risk enters. Targets are defined as Cyber-Enabled Transnational Criminal Organizations: any foreign group conducting cyber-enabled crime against US interests, explicitly excluding institutional parts of foreign governments or entities wholly operated under foreign government direction [7]. According to the reported text, the memo presumes a group is not government-directed unless clear intelligence says otherwise [8]. That presumption resolves ambiguity in favor of acting, and the classification decision is made before the operation, not after.
The effects definition is broad. A Cyber Effects Operation covers manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident on them [9]. Anything reaching "physical or virtual infrastructure controlled by information systems" extends past a target's own servers by construction [10].
The controls are real but narrow. Program executive directors from the Department of Justice and the Department of Homeland Security must co-approve every operation in writing before any action [11]. Operations that could produce Critical Outcomes require authorization beyond those directors, which the source describes as an acknowledgment that some cyber actions cross into territory governed by the laws of armed conflict [12]. The Justice Department will review any operation that touches a US person or raises domestic constitutional questions [13], and unintended contact with a US person or system must trigger an immediate stop and notification [14]. Note what the tripwire is keyed to: US persons and US systems. The described protection is not keyed to foreign third parties whose infrastructure sits next to a target [15].
Entry terms are commercial. Firms must clear rigorous vetting, demonstrate technical capability, submit to annual evaluations, and maintain a bond or escrow of at least $1 million that is forfeited on breach of contract terms [16]. As reported, that bond runs to the government for contract violations; no mechanism for compensating affected third parties is described [17].
The unresolved legal question is whether the Computer Fraud and Abuse Act exemption for lawfully authorized government investigative activity extends to private companies acting under government contract, which no US court has answered [18]. Jenner & Block lawyers cited in the report say the exemption likely applies under direct government direction but would not cover independent offensive operations [19].
Operational procedures are due within 60 days of signing, which by the calendar lands around October 12 [20][21]. Watch whether those procedures define Critical Outcomes, whether participating firms are named, and whether contracts carry indemnification for collateral damage.
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
President Trump signed a national security memorandum on August 13 establishing a formal program allowing vetted private US cybersecurity companies to conduct offensive cyber operations against transnational criminal organizations under government direction and oversight.
- [3]
The program covers both intelligence collection, described as Cyber Surveillance Operations, and active disruption of criminal infrastructure, described as Cyber Effects Operations.
ReportedView cited source - [4]
The memorandum states that the American private sector's "scale, speed, and capacity secure a critical offensive cyber advantage for the United States" and that American businesses' innovative capabilities "have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace."
- [5]
The memorandum states: "By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens."
- [6]
The program is the formal implementation of what the White House's Cyber Strategy for America promised in March: unleashing the private sector as an offensive cyber instrument.
ReportedView cited source
Sources & coverage · 1 publisher
The reporting this story was synthesized from, earliest first. Every link goes to the original.
- securityaffairs.comPierluigi PaganiniAug 14US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks
Additional citations
- SecurityAffairs
- national security memorandum, as quoted by SecurityAffairs
- SecurityAffairs characterization of the memorandum
- Jenner & Block lawyers, cited by SecurityAffairs



