White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs
Security WeekArchived Aug 13, 2026✓ Full text saved
Contracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements. The post White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs appeared first on SecurityWeek .
Full text archived locally
✦ AI Summary· Claude Sonnet
A presidential memorandum issued on Wednesday expands federal capabilities against foreign cybercrime by establishing a program that allows vetted private US companies to conduct offensive and intelligence-gathering cyber operations under federal control.
Managed by the National Coordination Center (NCC), the program authorizes participating companies to execute ‘cyber surveillance operations’ and ‘cyber effects operations’ targeting foreign cyber-enabled transnational criminal organizations (TCOs).
The initiative operates under co-executive directors designated by the Attorney General and the Secretary of Homeland Security, ensuring all operational actions remain under direct federal supervision.
To participate, US companies must undergo rigorous vetting and sign formal contracts with the Department of Justice (DOJ) or the Department of Homeland Security (DHS). These contracts may require a bond or escrow of at least $1 million, which will be forfeited if a company fails to comply with operational requirements.
Participating firms may enter commercial agreements with other private entities to receive threat intelligence, as well as with federal, state, and other agencies to identify specific foreign threats.
The directive establishes clear boundaries for authorized activity. Cyber surveillance operations focus on covertly accessing systems to collect intelligence, while cyber effects operations cover actions that disrupt, degrade, or destroy adversary information systems and infrastructure.
However, the program explicitly bars operations that result in ‘critical outcomes’, which are defined as actions likely to cause loss of life, serious injury, or rise to the level of a use of force or armed attack under international law.
Operational controls require written approval from the executive directors before any company takes action on a cyber package. Proposed operations must undergo multi-agency deconfliction involving law enforcement, the Department of State, the Department of the Treasury, the Department of War, the DOJ, and the Intelligence Community.
The White House noted that target selection is restricted to non-state criminal groups, though foreign entities are assumed to be independent of foreign governments unless clear intelligence proves otherwise.
The memorandum enforces strict safeguards regarding domestic targets and US persons. If a contractor discovers an operation has accidentally breached a US person or a domestic system, it must immediately cease operations and notify the government.
Related: US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’
Related: White House Launches AI-Driven ‘Gold Eagle’ Vulnerability Coordination Initiative
Related: White House Issues Memo to Bolster NSS Cybersecurity
WRITTEN BY
Eduard Kovacs
Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
More from Eduard Kovacs
Chipmaker Patch Tuesday: Intel, AMD Fix Over 80 Vulnerabilities Combined
ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Phoenix Contact
Cisco Patches Firewall Zero-Day Exploited for DoS Attacks
US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’
Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities
OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber
Mozilla Issues New Firefox GPG Key Following Exposure
OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns
Latest News
Venture Firm Team8 Secures Additional $365 Million
Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’
SharePoint Vulnerability Exploited Shortly After PoC Release
Mindgard Raises $30 Million to Protect AI Systems
Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset
WhatsApp Unveils New Scam Alert Feature
Trending
Webinar: Rethinking Cyber Defense For AI-Speed Attacks
August 18, 2026
Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.
Register
Virtual Event: CodeSecCon 2026
August 19, 2026
CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!
Register
People on the Move
Erika Dean has been appointed Chief Information Security Officer at Tricentis.
C1 has named Jeff St. Clair Chief Revenue Officer.
John Opala has joined Ralph Lauren as Chief Information Security Officer.
More People On The Move
Expert Insights
The AI Governance Gap Is A Leadership Problem: Waiting Won’t Close It
Organizations are rushing to implement AI without fully grasping where its legal protections begin and end. (Steve Durbin)
Rethinking AI Security: Why CASB And DLP Need An Interaction-Aware Layer
Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor)
Timeless Compliance: Why Better Questions Beat Bigger Frameworks
The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea)
Is Patching Dead? Vulnerability Management In The Post-Mythos Era
You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au)
When Identity Verification Fails: Lessons From A Real-World SIM Swap And Near Account Takeover
Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George)
Flipboard
Reddit
Whatsapp
Email