White House directs programme for private operations against foreign crime groups

US President Donald Trump has signed a White House memorandum directing the National Coordination Center (NCC) to establish, within 60 days, a programme under which approved US private-sector companies may conduct cyber operations against foreign Transnational Criminal Organizations (TCOs). The initiative envisages federal direction and oversight for companies selected to use their technical capabilities against cyber-enabled criminal activity targeting the United States.
The memorandum describes two authorised categories of activity. Cyber surveillance operations may access sensitive data without the owner’s or operator’s authorisation. Cyber effects operations may disrupt, deny, degrade or destroy information systems, networks or infrastructure. Each operation requires approval under the programme.
Scope and limits of the programme
Eligible targets are foreign groups conducting cyber-enabled crime against the US government, a US person or US interests. The memo excludes groups that are an institutional part of a foreign government or wholly operated under a foreign government’s direction, unless evidence establishes that connection.
The controls described in the memo are central to the proposed model. Companies must halt an operation if it goes beyond approved parameters or restrictions, including if it targets a US person, an information system located in the United States, or a system controlled by a US person. They must then apply minimisation procedures and immediately alert the NCC. The NCC is responsible for notifying the Department of Justice.
Response to cyber-enabled crime
The White House had announced plans in March to counter TCO-led cybercrime, fraud and predatory schemes affecting Americans. The accompanying fact sheet lists ransomware, malware, phishing, financial fraud, sextortion, pig-butchering scams and impersonation among the activities at issue. It puts reported losses to cyber-enabled crimes for American consumers at an estimated $20.8 billion.
The memorandum would expand the private sector’s role in offensive cyber operations against US adversaries. Experts cited in reporting have raised legal and security risks, while existing US laws prohibit private companies from conducting cyberattacks or disruption operations without court authorisation. The policy arrives amid a broader debate on state-backed disruption powers; evolving cyber threats and coordinated criminal activity illustrates the operational pressure created by evolving cyber threats and coordinated criminal activity.
What organisations should take from it
The memo does not authorise companies generally to conduct retaliatory hacking. It sets out a proposed, government-directed process for vetted firms and mandates approval, boundaries and reporting when operations stray into protected territory. For businesses facing cybercrime, the practical implication is to preserve evidence, maintain incident-response procedures and engage law enforcement rather than treat private disruption as an independent response option.

