Drooid Logo
Back to story perspectives

Full Breakdown

Trump Administration Authorizes Private Firms to Conduct Offensive Cyber Operations

8/17/2026, 2:18:28 AM

Core Event: New Private-Sector Cyber-Offense Program

On August 12, President Donald Trump signed a presidential memorandum creating a program that lets vetted private companies conduct “cyber surveillance operations” and “cyber effects operations” against foreign transnational criminal organizations (TCOs). Participating firms must sign contracts with the Department of Justice (DOJ) and the Department of Homeland Security (DHS), undergo vetting, and post a $1 million bond forfeited for non-compliance. The memorandum directs the Homeland Security Task Force’s National Coordination Center (NCC) to develop procedures, approve operations, and produce an annual progress report.

Background & Context

The United States has traditionally reserved offensive cyber work for law-enforcement, intelligence and military agencies. Earlier in 2026, an executive order expanded the government’s cyber-crime strategy, and cuts to the Cybersecurity and Infrastructure Security Agency (CISA) left federal capacity strained. Ransomware and other scams have surged, with the White House citing $20.8 billion in consumer losses in 2025. Recent attacks on more than 30 U.S. water-utility systems—attributed to Iran—highlight the perceived need for faster responses.

Data & Statistics

  • $20.8 billion in 2025 cyber-crime losses reported by the White House.
  • The memo requires a $1 million bond per participating company, refundable only if contractual obligations are met.

Official Statements & Responses

The DOJ and DHS have two months to resolve legal questions about authority, protections, and the scope of permissible disruptive actions. The NCC must approve each operation and ensure compliance with the memo’s procedures.

Criticism & Opposition

  • Chris Wysopal, co-founder of Veracode, warned that “you don’t want to have collateral damage when your blast radius is too big at the data center you were trying to take down, and you took down a transportation company or hospital’s servers.” He added, “I don’t think you can sort of offense your way to security.”

Critics cite the risk of unintended escalation, potential violations of foreign law, and difficulty accurately attributing cyber-criminal activity.

Verbatim Quotes

  • “There's a range of potential targets … like organized crime … people doing money laundering or other criminal activity,” — Joshua Steinman, former Trump official
  • “There are all these other components that are still outstanding,” — Stacy O'Mara, chief policy officer at Armadin
  • “Anything that our new cyber-enabled private sector actors do overseas will assuredly be against the domestic law of a host of countries wherein they act,” — Paul Rosenzweig

Conflicting Reports & Gaps

Sources agree the memo authorizes private offensive actions, but differ on detail:

  • The memo does not specify how vetting will be conducted or the criteria for target selection.

These gaps have prompted calls for clearer guidance before any operation is launched.

What’s Next

  • DOJ and DHS must address the outstanding legal questions within two months.
  • Companies must secure the required $1 million bond and complete federal vetting.
  • The NCC will review and approve individual “cyber operations packages” and issue an annual performance report.

The initiative shifts U.S. cyber policy toward private-sector partnership while raising significant legal and strategic concerns.