A new White House memo signed by U.S. President Donald Trump instructs the National Coordination Center (NCC) to establish a program that would allow private security companies to apply for approval to hack foreign cybercrime organizations.
Signed on Wednesday, the national security presidential memorandum (NSPM) enables the NCC (part of the Homeland Security Task Force) to leverage the U.S. private sector's capabilities to conduct cyber operations targeting transnational criminal organizations under the control and authority of the U.S. Government.
"The NSPM directs the Program's Executive Directors and the Homeland Security Council to create rigorous procedures for the review and conduct of these limited cyber operations at the direction of the U.S. Government, ensuring strict compliance with the U.S. Constitution and laws, as well as applicable international agreements," according to a fact sheet published yesterday.
"The NSPM establishes a framework where private sector companies that willingly participate in the program are encouraged to enter into agreements with other private entities as well Federal, State, Local, Tribal, and Territorial agencies to gather TCO threat information and propose cyber operations that address those threats."
The program will be overseen by executive directors designated by the Justice and Homeland Security departments, and security firms participating in the program will undergo vetting before entering into contracts with one of the two departments.
Additionally, the memorandum requires procedures ensuring operations comply with the U.S. Constitution, federal law, and U.S. international obligations, while participating companies will have to maintain a bond or escrow of at least $1 million that will be forfeited if they don't comply with the contractual agreements.
They must also immediately stop operations if they discover activity exceeding approved limits, including unintended targeting of U.S. citizens or U.S.-based systems, and notify the National Coordination Center.
The White House said the program is intended to disrupt foreign criminal organizations involved in ransomware attacks, phishing campaigns, financial fraud, sextortion schemes and impersonation scams. It added that U.S. consumers have reported losing more than $20.8 billion to cyber-enabled crime in 2025.
Veracode co-founder Chris Wysopal said the memo is a "pretty big shift in US cyber policy" and "a major expansion of the private sector's role in offensive cyber operations," while former Cyber National Mission Force (CNMF) leader and Automox CTO Jason Kikta described it as "a perpetual motion machine for billable threats."