Skip to content

Invest1 publisher3 min readPublished Updated

Washington licenses private hacking, and hands the contractor the liability

A memorandum signed on August 12 lets vetted US firms run offensive cyber operations against foreign criminal networks. The unpriced term is who absorbs the downside.

The Investor · Invest desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying Washington licenses private hacking, and hands the contractor the liability
Generated illustration

What happened

  • Trump signed a memorandum on August 12 letting vetted US firms run Cyber Surveillance Operations and Cyber Effects Operations against foreign criminal networks, including crypto scam operations that took billions from Americans last year.
  • The memorandum directs the work through the National Coordination Center, which is part of the Homeland Security Task Force.
  • The Center must create a program for approved firms, which the memo calls "Participating Companies", to carry out Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations.
  • The attorney general and the homeland security secretary will lead the effort; companies must enter into contracts with the Justice Department or DHS, undergo vetting, and work only as directed by the government.
  • The targets are foreign criminal groups, not foreign governments, and any operation involving a US person brings additional legal scrutiny, including from the Justice Department.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

President Donald Trump signed a memorandum on August 12 authorizing vetted US companies to conduct what it calls Cyber Surveillance Operations and Cyber Effects Operations against foreign criminal networks, including the crypto scam syndicates that took billions from Americans last year [1]. For operators, this is not a policy story about cyber doctrine; it is the opening of a procurement channel with an unusual risk profile attached.

The plumbing matters more than the announcement. The memo routes the work through the National Coordination Center, part of the Homeland Security Task Force, which must stand up a program for approved firms the memo labels "Participating Companies" [2][3]. The attorney general and the homeland security secretary lead it, and firms must contract with the Justice Department or DHS, pass vetting, and operate only as directed by the government [4]. Targets are foreign criminal organizations, not foreign governments, and any operation touching a US person triggers additional legal scrutiny, including from Justice [5].

The demand case is large. A White House fact sheet says American consumers reported more than $20.8 billion in losses to cyber-enabled crime in 2025, covering financial fraud, sextortion, and impersonation schemes run from outside the country [6]. The FBI's 2025 Internet Crime Report, as reported by Cryptopolitan, logged more than $11.3 billion across 181,565 cryptocurrency complaints, with filings up 21 percent [7]. That works out to roughly $62,000 per complaint [8], and puts crypto at about 54 percent of the reported total [9]. Many of the cases follow the pig butchering pattern: months of manufactured trust, then a fake trading platform [10].

Government-led enforcement is already producing recoveries at meaningful scale. An FBI-led operation with UAE, Thai, and Chinese authorities this year produced 276 arrests, nine scam centers closed, and more than $701 million in crypto restrained [11]. Treasury's Scam Center Strike Force has seized more than $700 million in crypto tied to Chinese organized crime running through Southeast Asian middlemen [12]. So the argument for private capacity is not that nothing works. It is arithmetic: Christopher Wray, the former FBI director, has said Chinese state-backed hackers outnumber FBI cyber personnel 50 to 1 [13], and Cynthia Kaiser, a former senior FBI cyber official, argues outside help could free the FBI and Cyber Command to concentrate on nation-state threats such as China [14].

The counterargument is about control and cost allocation. Andrew Schoka, formerly of US Cyber Command, warned of "a bunch of cyber privateers running around without any clear coordination or direction at the federal level" [15][16]. Chris Wysopal, co-founder of Veracode, raised the scenario of an operation against a foreign data center that accidentally hits a hospital, and said employees travelling overseas could become detention targets [17]. Jason Kikta, another former Cyber Command official, said there is "no clear oversight or review process on the determinations that will be made by unnamed political appointees," and that the order "pushes liability on to the companies" [18].

That last line is the whole commercial question. A firm signing one of these contracts is underwriting geopolitical, physical, and personnel risk on behalf of an agency, on terms nobody outside the process has seen.

Watch for the first named Participating Companies and what their contracts say about indemnification and insurance. Watch whether the additional scrutiny for US-person operations is defined in writing or left to discretion [5]. And watch corporate travel policy at any firm that signs, given Wysopal's detention point [17].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories