White House Greenlights Private Sector Hacking of Foreign Cybercriminals
The **White House** has issued a new directive, signed by U.S. President **Donald Trump**, authorizing the **National Coordination Center (NCC)** to establish a program. This program will allow private security companies to apply for approval to conduct cyber operations against foreign cybercrime organizations under government oversight. This marks a significant shift in U.S. cyber policy, expanding the role of the private sector in offensive cyber operations.

A new national security presidential memorandum (**NSPM**) has been signed, empowering the **NCC**, a component of the **Homeland Security Task Force**, to harness the capabilities of the U.S. private sector. The goal is to conduct targeted cyber operations against transnational criminal organizations, all under the strict control and authority of the U.S. Government.
### Rigorous Oversight and Compliance
The **NSPM** mandates that the Program's Executive Directors and the **Homeland Security Council** develop stringent procedures for reviewing and conducting these limited cyber operations. This framework is designed to ensure absolute compliance with the U.S. Constitution, federal laws, and applicable international agreements.
### A Framework for Private Sector Engagement
The established framework encourages private sector companies to willingly participate in the program. These firms will be encouraged to forge agreements with other private entities, as well as Federal, State, Local, Tribal, and Territorial agencies, to gather threat intelligence on transnational criminal organizations (TCOs) and propose cyber operations to address them.
### Vetting and Accountability Measures
Oversight of the program will fall to executive directors appointed by the **Justice** and **Homeland Security** departments. Participating security firms will undergo a thorough vetting process before entering into contracts. To ensure accountability, companies must maintain a bond or escrow of at least $1 million, which will be forfeited if contractual agreements are not met.
Furthermore, participants are obligated to immediately cease operations and notify the **National Coordination Center** if they discover any activity exceeding approved limits, including the unintended targeting of U.S. citizens or U.S.-based systems.
### Targeting Transnational Cybercrime
The White House has stated that the program's primary objective is to disrupt foreign criminal organizations engaged in a range of illicit activities. This includes ransomware attacks, sophisticated phishing campaigns, financial fraud, sextortion schemes, and impersonation scams. The initiative comes as U.S. consumers reported losing over $20.8 billion to cyber-enabled crime in 2025 alone.
### Industry Reactions
The directive has drawn significant attention from cybersecurity experts. **Chris Wysopal**, co-founder of **Veracode**, described the memo as a "pretty big shift in US cyber policy" and a "major expansion of the private sector's role in offensive cyber operations." Similarly, **Jason Kikta**, former leader of the **Cyber National Mission Force (CNMF)** and CTO of **Automox**, characterized it as "a perpetual motion machine for billable threats."