Aug 16, 2026 · AI News

White House Launches Program Letting Vetted Security Firms Hack Foreign Cybercrime Groups

White House cyber operations briefing showing a holographic robot reviewing a map of foreign cybercrime networks targeted by vetted security firms

President Donald Trump signed a national security presidential memorandum on August 12, 2026, directing the National Coordination Center (NCC) to build a program that lets vetted U.S. private security companies conduct offensive cyber operations against foreign cybercrime organizations under federal control. The framework, described in a White House fact sheet released the same day, is intended to disrupt ransomware gangs, phishing operations, financial fraud networks, sextortion schemes, and impersonation scams run by transnational criminal organizations (TCOs) based outside the United States.

The memo names TCOs as a growing threat to U.S. citizens, businesses, and national security and frames private-sector cyber capabilities as an underused offensive asset that can be brought to bear against criminal networks operating abroad.

What the program allows vetted firms to do

The NCC, which sits inside the Homeland Security Task Force, will create, manage, and maintain the program and authorize participating companies to carry out Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs). All operations must be conducted on behalf of, and under the supervision of, the federal government, and in line with the U.S. Constitution, federal law, and applicable international agreements.

Participating companies must enter into contractual agreements with either the Department of Justice or the Department of Homeland Security. Both departments will designate co-executive directors to oversee the program. Operations that produce “Critical Outcomes,” a category defined in the memo, cannot be approved by the executive directors alone.

Vetted firms are also encouraged to sign commercial agreements with other private entities and with federal, state, local, tribal, and territorial agencies, both to collect TCO threat information gathered during normal business activity and to propose cyber operations that respond to specific threats.

Vetting, bonding, and oversight rules

Security firms that want to participate must undergo rigorous vetting before signing a contract with one of the two lead departments. Each participating company is required to maintain a bond or escrow account of at least $1 million, which is forfeited if the firm fails to comply with its contractual obligations.

The memorandum also imposes hard operational guardrails. Companies must immediately halt any operation if they discover activity that exceeds the approved scope, including the unintended targeting of U.S. citizens or U.S.-based systems, and must notify the NCC without delay.

Scale of the cyber-enabled crime problem cited by the White House

The fact sheet frames the program as a response to a surge in online scams hitting U.S. consumers. According to the figures the White House cites, American consumers reported losing more than $20.8 billion to cyber-enabled crime in 2025. The fact sheet also states that 73% of U.S. adults have experienced some form of online scam or attack, that 98% of Americans believe scams pose a threat to individuals in the United States, and that two-thirds of those polled describe that threat as major.

The fact sheet singles out seniors, children, and low-income families as disproportionately targeted, and notes that one in seven young people who experienced sextortion as a minor reported harming themselves in response.

What the memo says about foreign-based criminal groups

The memorandum describes TCOs as running sustained cyber campaigns from foreign jurisdictions to commit fraud against Americans, and argues that the private sector’s scale and speed offer an offensive cyber advantage that the federal government has historically underused. It directs the federal government to use all instruments of national power, including vetted private-sector capabilities, against these networks.

The memo also cites prior administration actions as part of the same effort, including Executive Order 14390 (Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens), signed March 6, 2026, and an earlier executive order signed June 2025 on strengthening critical protections against foreign cyber threats.

Reactions from the security industry

Responses from outside observers quoted in coverage of the memo described the change as a significant shift in U.S. cyber policy and a major expansion of the private sector’s role in offensive cyber operations. One industry figure characterized the framework as a mechanism that could generate a steady flow of billable threat-intelligence work for participating firms, underscoring how closely the program ties private contractors into federal cyber operations.

FAQ

What does the new White House hack-back program actually do?

It creates a program managed by the National Coordination Center that lets vetted U.S. private security companies conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign transnational criminal organizations, under contracts with the Department of Justice or the Department of Homeland Security and under federal supervision.

Who oversees participating companies?

Co-executive directors designated by the Attorney General and the Secretary of Homeland Security oversee the program. Operations that would produce Critical Outcomes, as defined in the memo, cannot be approved by the executive directors alone.

What safeguards and financial requirements apply to participating firms?

Companies must be rigorously vetted, must maintain a bond or escrow of at least $1 million that can be forfeited for noncompliance, and must immediately stop any operation that exceeds approved limits, including any unintended targeting of U.S. citizens or U.S.-based systems, and notify the National Coordination Center.

Related coverage


This article summarizes reporting from bleepingcomputer.com.