President Donald Trump has signed a presidential memorandum that creates a pathway for companies to take part in government-led cyber operations against foreign criminal groups.
The policy targets cyber-enabled transnational criminal organizations, or CE-TCOs, accused of committing online crimes that harm Americans and businesses. The memorandum directs the National Coordination Center, or NCC, to establish and manage the program.
Participating companies may conduct cyber surveillance operations and cyber effects operations, but only under the direction, control, and oversight of the federal government.
The Department of Justice and Department of Homeland Security will jointly supervise the effort through two program executive directors.
Cyber surveillance operations are defined as covert activity to collect intelligence from computer systems, networks, telecommunications infrastructure, or embedded devices.
The definition includes unauthorized access or exceeding authorized access to remain undetected and gather information. That intelligence may support a future operation.
Cyber effects operations have a more active purpose. They may manipulate, disrupt, deny, degrade, or destroy information, systems, networks, or infrastructure managed through information technology.
The memorandum draws a clear line around actions likely to cause death, serious injury, or an effect that amounts to a use of force or armed attack under international law.
These are classified as critical outcomes and cannot be approved by the program executive directors. The program does not give companies a free hand to conduct hack-back activity.
Every operation package must be reviewed and receive written approval and direction before any action takes place. Companies will work on behalf of the government under the government’s lawful authority.
The NCC must also coordinate operations across federal law enforcement, intelligence agencies, and departments responsible for foreign policy, treasury, and defense matters.
To participate, companies must sign contracts with either the Justice Department or Homeland Security. They will undergo technical, security, and personnel vetting. The future operating procedures must allow both large providers and smaller firms to perform specialist work.
Participating companies must disclose relevant commercial relationships and may be required to maintain a bond or escrow of at least $1 million, which can be forfeited for non-compliance.
White House reports that the policy requires companies to immediately halt operations, minimize collected data, and notify the NCC if they accidentally target a U.S. person or system.
Justice Department review and any required legal or judicial authorization must occur before an operation that implicates constitutional, federal, or international-law obligations is approved.
The memorandum gives the program executive directors 60 days to establish operating procedures with the Homeland Security Council. They must report on the program within 180 days and annually afterward.
For defenders and threat-intelligence teams, the move could directly create a formal route for sharing business-collected threat data and proposing government-supervised disruption of criminal infrastructure. Its practical impact will depend on the classified workflow, target rules, legal reviews, and selection of participating firms.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…