CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◇ Industry News & Leadership Aug 13, 2026

Uncle Sam Seeks Private Hackers to Disrupt Criminal Networks

Data Breach Today Archived Aug 13, 2026 ✓ Full text saved

White House Program Will Tap Private Sector for Surveillance and Cyber Operations The White House, in a major expansion of how it works with the private sector, has launched a program to engage private cybersecurity firms to conduct cyber reconnaissance and disruptive hack attacks against foreign criminal networks, under the oversight and guidance of the federal government.

Full text archived locally
✦ AI Summary · Claude Sonnet


    Cybercrime , Fraud Management & Cybercrime , Government Uncle Sam Seeks Private Hackers to Disrupt Criminal Networks White House Program Will Tap Private Sector for Surveillance and Cyber Operations Mathew J. Schwartz (euroinfosec) • August 13, 2026     Credit Eligible Get Permission Image: Shutterstock The White House will engage private cybersecurity contractors to conduct cyber reconnaissance and disruptive hack attacks against foreign criminals on the U.S. government's behalf. See Also: New Attacks. Skyrocketing Costs. The True Cost of a Security Breach. U.S. President Donald Trump on Wednesday issued a memoranda authorizing the creation of a program, overseen by the federal government, designed to allow private firms "to identify and disrupt criminal networks operating in cyberspace." This will include foreign groups that launch ransomware attacks, run phishing campaigns and engage in financial fraud, sextortion and sophisticated social engineering scams, the White House said. "This is a pretty big shift in U.S. cyber policy," said Chris Wysopal, chief security evangelist at application security firm Veracode, in a post to social platform Mastodon. "Not exactly 'hack back,' but definitely a major expansion of the private sector's role in offensive cyber operations," he said. The White House move follows U.S. consumers last year reporting over $20.8 billion being lost to cyber-enabled crime, according to the FBI's latest Internet Crime Report. The goal of the new program, which doesn't yet appear to have an official name, is "to use all instruments of national power, including the innovative capabilities of the private sector," to combat transnational criminal organizations, or TCOs, reads the memo, titled "Expanding Capabilities To Combat Transnational Cyber-Enabled Crime." The effort is also designed to build on Executive Order 14390 from March, which directed government agencies to devote more resources to combating foreign cybercrime groups. "By partnering with vetted U.S. companies subject to the direction and oversight of the federal government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud and other predatory schemes against American citizens," the new memo says. Under the terms of the program, "vetted private companies can now enter agreements with each other and with federal, state, local, tribal and territorial agencies, gather threat information on these networks and propose specific operations to disrupt them," said Ari Redbord, global head of policy and government affairs at TRM Labs, in a post to LinkedIn. "The government keeps direction, control and authority over every operation that runs, and the private sector sits inside the process instead of outside it," he said. Presidential memorandums, while similar to executive orders, differ in that they don't need to cite the president's legal authority for what's being ordered, and there's no requirement for the Office of Management and Budget to issue a "budgetary impact statement." Program Scope The program will be overseen by the Homeland Security Task Force's National Coordination Center, created by Trump last year and overseen by the departments of Justice and Homeland Security. A co-executive director from each agency will oversee the new program, and together approve participants, who must "enter into contractual agreements" with them, undergo "rigorous vetting" and comply with detailed operational guidance. The government can require participants to maintain a bond or funds in escrow worth at least $1 million, to forfeit if they violate program guidelines. Many criminal groups with apparent state ties are in scope for the program. The memo says any foreign, cyber-enabled transnational criminal organization - aka CE-TCO - that targets the U.S. government, interests or individuals can be targeted, and that "a foreign group will be assumed not to be an institutional part of a foreign government or wholly operated under a foreign government's direction unless clear intelligence exists establishing such connection." Permitted attacks, aka "cyber effects," include the targeting and surveillance of IT infrastructure, including "the internet, telecommunications networks, computers, information systems, industrial control systems, networks and embedded processors and controllers that results in the manipulation, disruption, denial, degradation or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon," the memo says. The program guidelines explicitly authorize surveillance that can entail accessing systems "without authorization from the owner or operator or by exceeding authorize access." That's notable because it paraphrases the Computer Fraud and Abuse Act, said Casey Ellis, founder of bug bounty program Bugcrowd, in a LinkedIn post. "It basically says 'Hey, so you know that thing that we explicitly told you not to do? Do that,'" he said. Cyber Letters of Marque Trump's move follows industry advocates and lobbyists in recent years promoting U.S. legislation that would allow contractors to join the cyber fight. Bills introduced in the House and Senate last year, which didn't come to a vote, would have authorized the president to issue "letters of marque" empowering private cybersecurity contractors to seize cryptocurrency wallets containing the proceeds from attacks against Americans. Such letters refer to a form of maritime deputization last deployed by the U.S. against Great Britain during the War of 1812, which authorized private ship owners - "privateers" - to capture and keep the property of pirates and other enemies of the state (see: American Hackers-for-Hire Proposal Sparks Heavy Criticism). The government's new program includes a long list of what is, and isn't, allowed. "The NCC shall conduct all program activities in accordance with the Constitution and all other applicable laws and international obligations of the United States," the memo says. The program also bans a list of "critical outcomes," which it defines as anything that is likely to "result in the loss of life or serious injury" or else "rise to the level of use of force or armed attack under international law." Other prohibitions include any targeting of U.S. individuals or IT systems they control, or any IT systems located in the United States. Any such targeting, inadvertent or otherwise, must be immediately reported to the NCC. Program participants will still be able to "engage in other lawful defensive cyber operations otherwise permitted to them" under law, with the exception that any activity specifically authorized by the program must be conducted with the full oversight of the NCC, the memo says. The White House said a classified annex to the memorandum sets out more details for how operations will work, including guidance for "operational deconfliction" with U.S. intelligence and law enforcement agencies, including the departments of Defense, Justice, State and Treasury.
    💬 Team Notes
    Article Info
    Source
    Data Breach Today
    Category
    ◇ Industry News & Leadership
    Published
    Aug 13, 2026
    Archived
    Aug 13, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗