Invest1 publisher3 min readPublished
Washington deputises private cyber firms, and hands their customers a liability question
A memorandum dated August 12, 2026 lets vetted companies disrupt criminal networks under DOJ and DHS supervision. The entry ticket is a $1 million bond, according to Crypto Briefing.
The Investor · Invest desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- On August 12, 2026, the White House issued a presidential memorandum authorizing vetted private companies to conduct offensive cyber operations against transnational criminal organizations, with pig butchering scams squarely in the crosshairs.
- Private firms operating under federal supervision from the Department of Justice and the Department of Homeland Security can now actively surveil and disrupt the criminal networks behind these scams.
- The memorandum builds on an executive order issued in March 2026 that established a National Coordination Center for tackling cyber-enabled transnational criminal organizations (CE-TCOs).
- Each participating company needs to post a bond of at least $1 million and undergo thorough vetting before being approved for operations.
- Once cleared, firms can conduct cyber surveillance and "effects operations," meaning they can actively disrupt criminal infrastructure rather than just watch it.
Compiled by The InvestorSomething wrong?How this is made
Why it matters
A presidential memorandum issued on August 12, 2026 authorises vetted private companies to run offensive cyber operations against transnational criminal organisations, with pig butchering networks named as a priority target, according to Crypto Briefing [1]. The consequence for operators is not the policy itself but the plumbing: the firms that sell you blockchain analytics and threat intelligence may now also be conducting armed disruption on the government's behalf [13].
The mechanics are narrow on paper. Participating firms work under supervision from the Department of Justice and the Department of Homeland Security, and can both surveil and disrupt criminal infrastructure rather than merely observe it, a category the memorandum calls "effects operations" [2][5]. Companies cannot target US persons without explicit authorisation, and DOJ and DHS retain oversight throughout [6]. The memorandum builds on a March 2026 executive order that created a National Coordination Center for cyber-enabled transnational criminal organisations [3]. Entry requires thorough vetting and a bond of at least $1 million [4].
That bond is the number to sit with. Crypto Briefing reports that a single pig butchering network can process hundreds of millions of dollars in stolen funds, so liability from a botched disruption could dwarf the bond [16]. Against $200 million of throughput, a $1 million bond covers half of one percent [17]. Legal experts cited by the publication also note that the Computer Fraud and Abuse Act, which broadly criminalises unauthorised computer access, contains no clean carve-out for government-sanctioned private operations [14], and that hitting infrastructure hosted abroad risks diplomatic friction with the countries where these networks sit [15].
The relevant supply chain is already identifiable. Crypto Briefing notes that Chainalysis, TRM Labs and Elliptic work closely with federal agencies today, and says the memorandum potentially converts that relationship from passive analysis into active intervention [13]. Anyone who buys screening, monitoring or investigations from a vendor now has a diligence question that did not exist in July: whether that vendor is bonded and vetted under this programme, whether its analysts are working the same data for both your compliance file and a federal effects operation, and what happens to your contract if an operation goes wrong.
The target set explains the urgency. Pig butchering scams cultivate victims through dating apps and social media before steering them into fraudulent investment platforms [8], US victims report billions of dollars in losses annually [9], and many of the enterprises behind them operate from compounds in Myanmar, Cambodia and Laos staffed by trafficked workers held under threat of violence [10]. Victims are typically directed to deposit through crypto platforms, legitimate and fake, with proceeds laundered across wallets, mixers and cross-chain bridges [12]. The Treasury Department has sanctioned infrastructure tied to these networks, and sanctions have not stemmed the flow [11]. The stated pivot is from chasing losses after the fact to disrupting operations before they cash out [7].
Watch three things. First, whether the bond floor moves, since $1 million is a rounding error next to the sums a single network handles [4][16]. Second, whether any CFAA safe harbour is legislated rather than asserted by memorandum, because supervision by DOJ and DHS is not the same as immunity [6][14]. Third, whether the named analytics vendors say publicly if they are in or out [13]. A firm that declines keeps a cleaner evidentiary position for its customers; a firm that participates acquires capabilities, and a counterparty risk that its clients did not underwrite.