La Casa Bianca apre alle cyber-operazioni offensive affidate alle aziende private
APT

Illustrative image generated with AI

White House Opens the Door to Offensive Cyber Operations Conducted by Private Companies

U.S. government launches program for private cybersecurity firms to engage in offensive operations against foreign cybercrime, under strict federal control.

Text generated by artificial intelligence, published without human review. AI transparency

New Program Targeting Foreign Cybercrime

A U.S. presidential memorandum signed Wednesday directs the National Coordination Center (NCC) to establish a program for engaging private cybersecurity companies in offensive operations against foreign cybercriminal organizations.

The initiative was made public on August 13, 2026. It aims to target groups involved in ransomware, phishing, financial fraud, sextortion, impersonation scams, and romance or financial fraud operations run through so-called compounds.

The U.S. government will retain overall control of the activities. Companies will therefore not receive blanket authorization to act independently against criminal infrastructure, but will operate within missions defined and approved by federal authorities.

The White House says U.S. consumers reported more than $20.8 billion in cybercrime losses in 2025. The stated goal is to leverage private-sector capabilities that, according to the memorandum, have not been used extensively enough to identify and disrupt online criminal networks.

It is not known whether any companies have already agreed to participate or whether operations have begun. No authorized companies, software products, malware, IP addresses, domains, or other technical indicators have been identified.

How Authorization and Federal Oversight Will Work

Each operation must be approved in advance by officials from the Department of Justice (DOJ) and the Department of Homeland Security (DHS). The memorandum requires every operational “package” to undergo written review and approval.

Before an operation begins, the company will receive formal instructions defining its objectives and limits. Oversight will be assigned to executive directors designated by the DOJ and DHS, while the NCC will coordinate the program.

Federal agencies will have two months to establish operating procedures, minimum participation standards, target-selection criteria, and the reporting requirements companies must follow when communicating their activities to the government.

Requirements are expected to include:

  • verifiable technical expertise;
  • documented experience in cyber operations;
  • facility security;
  • personnel vetting;
  • corporate reliability;
  • additional organizational and operational safeguards.

Companies will have to sign contracts with the DOJ or DHS and disclose all of their contractual relationships to the federal government. They will also undergo annual assessments to retain their authorization, submit periodic reports, and cooperate with federal, state, local, tribal, and territorial authorities.

The program may also allow access to government threat intelligence to support operational planning. This could improve mission effectiveness, but it makes controls over classified or sensitive information even more important.

Operational Limits and Error Handling

The memorandum excludes operations that could cause loss of life or reach the threshold of “use of force” or “armed attack” under international law.

It also establishes procedures for mistaken identification and exceeding authorized limits. If a company were to unintentionally target a U.S. person, a system located in the United States, or a system controlled by a U.S. citizen, it would be required to terminate the operation immediately.

It would also have to apply minimization measures, notify the NCC, and provide the information needed for subsequent notification to the Department of Justice.

Companies would also be required to report the following to the government:

  • imminent attacks against U.S. critical infrastructure;
  • plots or activities potentially capable of causing casualties.

Activities must comply with the U.S. Constitution, federal law, and applicable international obligations. However, the document provides less clarity on cases in which a transnational criminal group is linked to intelligence services, military organizations, or foreign governments.

This gray area is critical. An operation against an apparently criminal organization could have diplomatic or military consequences if its infrastructure were supported, protected, or controlled by a state.

Financial Safeguards and Corporate Liability

Participating companies will have to accept significant contractual constraints. The memorandum provides for a bond or escrow deposit of at least $1 million, which could be forfeited in the event of a breach.

The same threshold is also described as the minimum penalty applicable to a violation of any part of the contract. The released text does not clarify every detail of the mechanism, but the principle is clear: companies will face direct financial exposure for failing to comply with operational rules.

Other liability issues remain less certain. Cybersecurity experts have pointed to the limited explicit legal protections and the lack of detail on the procedures to follow when an operation causes damage or strikes the wrong target.

The personal safety of operators is another concrete concern. Participating companies, as well as their employees and executives, could become targets of retaliation. The risk could increase in operations against groups directly or indirectly supported by foreign governments.

Jason Kikta, CTO of Automox and a former executive with the Cyber National Mission Force, criticized the potential incentive to produce billable offensive activity. Chris Wysopal, co-founder of Veracode, described the plan as a significant shift in U.S. cyber policy and a substantial expansion of the private sector’s role in offensive operations.

A Shift in the Boundaries of Private Cybersecurity

The memorandum alters the traditional boundary between commercial defensive activities and state-led cyber operations. Until now, security companies have been able to analyze criminal infrastructure, collect indicators, cooperate with authorities, and support incident response.

The new model seeks to authorize them to intervene against criminal networks as well, while keeping control in the hands of the federal government. Potentially, the United States could gain greater capacity to disrupt ransomware, fraud, and infrastructure used to target citizens and businesses.

The risks include misattribution, collateral damage, international escalation, and the unintended involvement of U.S. systems. There is also uncertainty over liability when an authorized action produces unforeseen consequences.

Bennie Thompson, a Democratic representative from Mississippi and a senior member of the Homeland Security Committee, expressed concern about the legal implications and unintended effects. According to Thompson, oversight procedures remain unclear and the issue should be addressed by the administration in consultation with Congress.

The initiative follows an executive order issued in March that directed federal agencies toward a more aggressive approach to combating cybercrime. Also in March, National Cyber Director Sean Cairncross had already hinted at a possible offensive role for the private sector.

The program is therefore not yet a publicly documented operational campaign. It is primarily the creation of an institutional framework that could turn certain companies into authorized operators of offensive missions, under federal oversight but with responsibilities and risks that remain to be defined.

Read next

Sources

This article is an original reworking based on the sources below.

Related topicscybersecurityprivate companiesoffensive cyber operationsU.S. governmentcybercrimefederal oversightcyber policyransomware
Back to home