CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◇ Industry News & Leadership Aug 13, 2026

White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs

Security Week Archived Aug 13, 2026 ✓ Full text saved

Contracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements. The post White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs appeared first on SecurityWeek .

Full text archived locally
✦ AI Summary · Claude Sonnet


    A presidential memorandum issued on Wednesday expands federal capabilities against foreign cybercrime by establishing a program that allows vetted private US companies to conduct offensive and intelligence-gathering cyber operations under federal control. Managed by the National Coordination Center (NCC), the program authorizes participating companies to execute ‘cyber surveillance operations’ and ‘cyber effects operations’ targeting foreign cyber-enabled transnational criminal organizations (TCOs).  The initiative operates under co-executive directors designated by the Attorney General and the Secretary of Homeland Security, ensuring all operational actions remain under direct federal supervision. To participate, US companies must undergo rigorous vetting and sign formal contracts with the Department of Justice (DOJ) or the Department of Homeland Security (DHS). These contracts may require a bond or escrow of at least $1 million, which will be forfeited if a company fails to comply with operational requirements.  Participating firms may enter commercial agreements with other private entities to receive threat intelligence, as well as with federal, state, and other agencies to identify specific foreign threats. The directive establishes clear boundaries for authorized activity. Cyber surveillance operations focus on covertly accessing systems to collect intelligence, while cyber effects operations cover actions that disrupt, degrade, or destroy adversary information systems and infrastructure.  However, the program explicitly bars operations that result in ‘critical outcomes’, which are defined as actions likely to cause loss of life, serious injury, or rise to the level of a use of force or armed attack under international law. Operational controls require written approval from the executive directors before any company takes action on a cyber package. Proposed operations must undergo multi-agency deconfliction involving law enforcement, the Department of State, the Department of the Treasury, the Department of War, the DOJ, and the Intelligence Community.  The White House noted that target selection is restricted to non-state criminal groups, though foreign entities are assumed to be independent of foreign governments unless clear intelligence proves otherwise. The memorandum enforces strict safeguards regarding domestic targets and US persons. If a contractor discovers an operation has accidentally breached a US person or a domestic system, it must immediately cease operations and notify the government. Related: US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ Related: White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative Related: White House Issues Memo to Bolster NSS Cybersecurity WRITTEN BY Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. More from Eduard Kovacs Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact Cisco Patches Firewall Zero-Day Exploited for DoS Attacks US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber Mozilla Issues New Firefox GPG Key Following Exposure OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns Latest News Venture Firm Team8 Secures Additional $365 Million Fortinet Patches Authentication Flaws in FortiWeb and FortiManager Critical VMware vCenter Vulnerability in Attackers’ Crosshairs Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ SharePoint Vulnerability Exploited Shortly After PoC Release Mindgard Raises $30 Million to Protect AI Systems Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset WhatsApp Unveils New Scam Alert Feature Trending Webinar: Rethinking Cyber Defense For AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move Erika Dean has been appointed Chief Information Security Officer at Tricentis. C1 has named Jeff St. Clair Chief Revenue Officer. John Opala has joined Ralph Lauren as Chief Information Security Officer. More People On The Move Expert Insights The AI Governance Gap Is A Leadership Problem: Waiting Won’t Close It Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin) Rethinking AI Security: Why CASB And DLP Need An Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management In The Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons From A Real-World SIM Swap And Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Flipboard Reddit Whatsapp Email
    💬 Team Notes
    Article Info
    Source
    Security Week
    Category
    ◇ Industry News & Leadership
    Published
    Aug 13, 2026
    Archived
    Aug 13, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗