Invest1 distinct publisher3 min readUpdated
A memorandum signed on August 12 lets vetted US firms run offensive cyber operations against foreign criminal networks. The unpriced term is who absorbs the downside.
The Investor · Invest desk

Compiled by The InvestorSomething wrong?How this is made
President Donald Trump signed a memorandum on August 12 authorizing vetted US companies to conduct what it calls Cyber Surveillance Operations and Cyber Effects Operations against foreign criminal networks, including the crypto scam syndicates that took billions from Americans last year [1]. For operators, this is not a policy story about cyber doctrine; it is the opening of a procurement channel with an unusual risk profile attached.
The plumbing matters more than the announcement. The memo routes the work through the National Coordination Center, part of the Homeland Security Task Force, which must stand up a program for approved firms the memo labels "Participating Companies" [2][3]. The attorney general and the homeland security secretary lead it, and firms must contract with the Justice Department or DHS, pass vetting, and operate only as directed by the government [4]. Targets are foreign criminal organizations, not foreign governments, and any operation touching a US person triggers additional legal scrutiny, including from Justice [5].
The demand case is large. A White House fact sheet says American consumers reported more than $20.8 billion in losses to cyber-enabled crime in 2025, covering financial fraud, sextortion, and impersonation schemes run from outside the country [6]. The FBI's 2025 Internet Crime Report, as reported by Cryptopolitan, logged more than $11.3 billion across 181,565 cryptocurrency complaints, with filings up 21 percent [7]. That works out to roughly $62,000 per complaint [8], and puts crypto at about 54 percent of the reported total [9]. Many of the cases follow the pig butchering pattern: months of manufactured trust, then a fake trading platform [10].
Government-led enforcement is already producing recoveries at meaningful scale. An FBI-led operation with UAE, Thai, and Chinese authorities this year produced 276 arrests, nine scam centers closed, and more than $701 million in crypto restrained [11]. Treasury's Scam Center Strike Force has seized more than $700 million in crypto tied to Chinese organized crime running through Southeast Asian middlemen [12]. So the argument for private capacity is not that nothing works. It is arithmetic: Christopher Wray, the former FBI director, has said Chinese state-backed hackers outnumber FBI cyber personnel 50 to 1 [13], and Cynthia Kaiser, a former senior FBI cyber official, argues outside help could free the FBI and Cyber Command to concentrate on nation-state threats such as China [14].
The counterargument is about control and cost allocation. Andrew Schoka, formerly of US Cyber Command, warned of "a bunch of cyber privateers running around without any clear coordination or direction at the federal level" [15][16]. Chris Wysopal, co-founder of Veracode, raised the scenario of an operation against a foreign data center that accidentally hits a hospital, and said employees travelling overseas could become detention targets [17]. Jason Kikta, another former Cyber Command official, said there is "no clear oversight or review process on the determinations that will be made by unnamed political appointees," and that the order "pushes liability on to the companies" [18].
That last line is the whole commercial question. A firm signing one of these contracts is underwriting geopolitical, physical, and personnel risk on behalf of an agency, on terms nobody outside the process has seen.
Watch for the first named Participating Companies and what their contracts say about indemnification and insurance. Watch whether the additional scrutiny for US-person operations is defined in writing or left to discretion [5]. And watch corporate travel policy at any firm that signs, given Wysopal's detention point [17].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Trump signed a memorandum on August 12 letting vetted US firms run Cyber Surveillance Operations and Cyber Effects Operations against foreign criminal networks, including crypto scam operations that took billions from Americans last year.
The memorandum directs the work through the National Coordination Center, which is part of the Homeland Security Task Force.
The Center must create a program for approved firms, which the memo calls "Participating Companies", to carry out Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations.
The attorney general and the homeland security secretary will lead the effort; companies must enter into contracts with the Justice Department or DHS, undergo vetting, and work only as directed by the government.
The targets are foreign criminal groups, not foreign governments, and any operation involving a US person brings additional legal scrutiny, including from the Justice Department.
A White House fact sheet says American consumers reported more than $20.8 billion in losses to cyber-enabled crime in 2025, including financial fraud, sextortion, and impersonation schemes organized by groups based outside the country.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Named officials on the record, but one outlet and no primary document
The memo's structure, contracting requirements and targeting limits are described in specific terms, and four named current-or-former officials plus a named vendor executive are quoted directly. Against that, the cluster contains a single publisher, no link to or excerpt of the memorandum text, and the loss and seizure statistics are relayed from government sources and the outlet's own prior reporting rather than independently verified.
Authorization exists; the program does not yet visibly
What is observed is a legal authorization, not uptake. The National Coordination Center must still create the participation program, and no Participating Company, contract, award value or operation under the memo is disclosed. The concrete arrest and seizure results cited belong to existing government-run enforcement, which is context rather than adoption of this mechanism.
Framed as a live license; substance is an unstaffed authorization
Headline and lead present firms as already having a federal license to break into foreign networks, while the reported facts describe a program that must still be stood up, with no vetted firms, contracts or operations named. Mitigating the gap, the piece carries three substantive critiques and does not claim results for the new mechanism.
Government loss figures and a vendor voice; commercial ties undisclosed
The headline harm numbers originate with the White House fact sheet and FBI report, parties with an interest in justifying the expansion, and two of the named commentators are a security-vendor co-founder and former federal cyber officials whose present affiliations and potential interest in such contracts are not disclosed. The publisher is a crypto trade outlet that appends its own investment disclaimer and cites its earlier coverage as a statistical source.
Coherent single-source account, unconfirmed elsewhere
Internal consistency is good and attribution is specific, but a one-publisher cluster with no primary document, no government response to the oversight criticisms and no corroborating outlet caps confidence at moderate.
product
White House lets vetted firms hack back and leaves liability blank for 60 days1 distinct publisher
product
A dozen states, no marquee targets: the water hacks show where the attack surface actually is1 distinct publisher
security
77 years, stacked: the 764 sentence that resets what a sextortion report is worth1 distinct publisher
invest
Washington deputises private cyber firms, and hands their customers a liability question1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 14, 2026