Thu 13 Aug 2026 / 13:37 ET
Kernel
Security 3 min read

Trump private cyber operations program puts firms under federal control

Trump’s new memorandum lets vetted firms support approved operations against foreign cybercrime groups, with rules still due in 60 days.

Dana Voss

By Dana Voss / Security Correspondent

Trump private cyber operations program puts firms under federal control
img: The Record

President Donald Trump has ordered the creation of a federally directed program for Trump private cyber operations, allowing vetted U.S. companies to support specified surveillance and disruptive actions against foreign cyber-enabled criminal organizations. The August 12 memorandum assigns the National Coordination Center, a Homeland Security Task Force body, to run the program with the Justice Department and Department of Homeland Security in charge.

The distinction is doing a lot of work here. The order does not give security companies a general license to retaliate against hackers. Firms could act only on behalf of, and under the control, supervision and oversight of the federal government, according to the memorandum.

What can private companies do under Trump’s cyber operations program?

Participants may propose operations based on threat information obtained through agreements with businesses or government agencies. If approved, they may conduct cyber-surveillance operations and cyber-effects operations against designated foreign cyber-enabled transnational criminal organizations.

Reuters reported that “cyber effects” can include manipulating, disrupting, denying, degrading or destroying information systems, networks, information-system-controlled infrastructure, or data. The public memorandum does not identify particular targets, companies or operations, so the real-world scope is not yet public.

The White House says the program is intended to disrupt groups involved in ransomware, phishing, financial fraud, sextortion and impersonation scams. It said U.S. consumers reported more than $20.8 billion in cyber-enabled-crime losses during 2025. That is the administration’s rationale for the policy, not evidence that the program will reduce those losses.

Who approves the operations?

Two executive directors, one designated by the attorney general and one by the homeland security secretary, will oversee the program. They must coordinate before approving an operation, and the memorandum says they cannot approve operations that produce defined “Critical Outcomes.” The public excerpt does not spell out that definition.

Companies must sign contracts with DOJ or DHS and undergo vetting. The forthcoming standards must cover technical ability, prior cyber-operations performance, facility security, personnel screening, competence and reliability. The order contemplates both large firms and smaller companies suited to specialized work.

Within 60 days, DOJ, DHS and the Homeland Security Council must write the operating procedures. No operation may receive approval before it meets those rules, the memorandum says.

What safeguards would apply?

  • Participating firms must disclose contractual relationships made under the program’s threat-information provisions.
  • DOJ or DHS can require a bond or escrow account of at least $1 million, forfeitable for contractual noncompliance.
  • Program activity must comply with the Constitution, applicable U.S. law and U.S. international obligations.
  • If a company finds it has exceeded approved limits, including by unintentionally targeting a U.S. person or U.S.-based system, it must stop, minimize the activity and notify the National Coordination Center, The Record reported.

Bloomberg characterized the policy as bringing private firms into national-security cyber operations that have largely been handled by government agencies. Reuters reported that private-sector involvement in offensive cyber work has previously drawn concern over escalation, unintended consequences and coordination between agencies. Those questions remain unresolved while the government writes the program’s operating rules.

This story draws on original reporting from The Record.

More Security/

view all ↗