On August 12, 2026, the White House issued a significant National Security Presidential Memorandum, “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime” (“Memorandum”). The Memorandum directs the federal government to establish a program (“Program”) that would allow vetted U.S. private‑sector companies to conduct certain approved cyber operations against foreign cyber-enabled transnational criminal organizations under the auspices of the U.S. government.[1] The Memorandum follows the President’s March 2026 Cyber Strategy for America, which promised to “unleash the private sector by creating incentives to identify and disrupt adversary networks,” and Executive Order 14390 aimed at “Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens.”[2] The Program is intended to “expand the fight” against transnational‑criminal-organization-perpetrated cybercrime “by incorporating the ingenuity of the private sector.”

The Program creates a first-of-its-kind framework by which vetted private companies may engage in approved offensive cyber actions against certain targets with the federal government’s approval and supervision.

Program Overview

Structure

The Memorandum directs the federal National Coordination Center—the body designated by the White House in January 2025 as an “operational command center” for homeland security efforts—to create, manage and maintain the Program.[3] Two co-Executive Directors—one from the Department of Justice (designated by the Attorney General) and one from the Department of Homeland Security (designated by the Homeland Security Secretary)—will oversee the Program’s operations.

The Memorandum requires the co-Executive Directors, in coordination with the Homeland Security Council, to establish operating procedures for the Program (“Operating Procedures”) by October 11, 2026. The Operating Procedures must:

  • Establish “minimum standards” that participating companies must meet in order to take part in the Program, including technical proficiency, proven cyber operational performance, facility security, personnel vetting, “competence,” “reliability” and other factors;
  • Create an “operational workflow” for the Program that conforms to a “classified annex” to the Memorandum. That workflow must include “operational deconfliction” across federal law enforcement, the Department of State, the Department of the Treasury, the Department of War, the Department of Justice and the Intelligence Community.
  • Create “standardized rubrics and templates” for proposed cyber operations.
  • Include “reporting requirements” for participating companies that (1) advance understanding of the impact and activity of cyber-enabled foreign transnational criminal organizations and (2) ensure the National Coordination Center is “fully apprised of Participating Companies’ operational activities.”
  • Include compliance procedures to ensure that (1) Program activities receive “any necessary authorization, judicial or otherwise, prior to approval” in accordance with the government’s obligations under federal and international law and (2) participating companies whose actions exceed the scope of approval under the Program halt such actions, minimize any effects and notify the government.

Scope

Participating Companies

Only private, U.S. companies are eligible for participation in the Program (“Participating Companies”). Companies can expect to undergo “rigorous vetting” prior to approval and, once approved, follow “strict procedures” pursuant to the forthcoming Operating Procedures. The Memorandum also requires Participating Companies to enter into contracts with either the Department of Justice or the Department of Homeland Security as a condition of the Program “to ensure that Participating Companies undergo rigorous vetting and that their performance adheres” to the Operating Procedures. Those contracts may, in turn, require companies to maintain a bond or escrow of $1 million or more conditioned on the company’s compliance with the contract. Additionally, Participating Companies may enter into “commercial agreements” with (1) other private-sector entities to receive “threat information collected in the course of those entities’ normal business activities” and (2) government agencies, so that those agencies may identify relevant cyber threats and support the threat response.

Authorized Actions

The Memorandum authorizes Participating Companies to engage in two categories of cyber operations with government approval. The first category, “Cyber Effects Operations,” involves offensive attacks on information technology infrastructure for the purpose of “manipulation, disruption, denial, degradation, or destruction” of that infrastructure. The second category, “Cyber Surveillance Operations,” involves network surveillance activity to collect “information or intelligence” or to support Cyber Effects Operations.

Before any cyber operation may be taken under the Program, the co-Executive Directors must review the proposal and “provide written approval and direction.” However, the Memorandum bars leadership from approving actions likely to result in “Critical Outcomes,” defined as actions likely to “result in the loss of life or serious injury” or “rise to the level of use of force or armed attack under international law.”

Authorized Targets

The Memorandum permits the Program to target only “Cyber-Enabled Transnational Criminal Organizations,” defined as foreign groups that conduct cyber-enabled crime against the U.S. government or U.S. persons or interests, but not including state actors or groups acting at a foreign state’s behest. Notably, the Memorandum states that foreign groups will be assumed not to be acting at the direction of a foreign state “unless clear intelligence exists establishing such a connection.”

Key Takeaways

U.S. companies considering the Program should keep the following points in mind:

  • Private, U.S. companies may have significant new opportunities. The Program may present a significant opportunity for cyber-enabled companies to partner with the government to take previously unavailable cyber actions against foreign threat actors and enter into valuable commercial agreements to support those actions. In particular, Participating Companies performing approved cyber operations at the direction of the federal government may fall within the Computer Fraud and Abuse Act’s exemption from liability for “lawfully authorized investigative, protective, or intelligence activity” of federal law enforcement and intelligence agencies.[4] The Memorandum’s specification that Program operations are “part of” “lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement” suggests that the White House intends for Program operations to fall within this liability exemption.
  • Participating Companies engaging in Program actions may be subject to new legal obligations as “state actors. The Program requires that Participating Companies act under the “control and oversight of the Federal Government” when carrying out covered operations. Accordingly, Participating Companies could be deemed state actors subject to the same constitutional and statutory requirements that regulate federal law enforcement. Certain Cyber Surveillance Operations and other actions may therefore require a warrant or court order before they can be carried out by a Participating Company. Notably, the Memorandum requires that operations receive “any necessary authorization, judicial or otherwise,” prior to approval.
  • Risk allocation between Participating Companies and the federal government is uncertain. The risk to Participating Companies engaging in Program-approved cyber operations is undetermined. It is not clear on the face of the Memorandum whether Participating Companies themselves will carry out these operations or merely offer support to government officials leading the operation. The answer has implications for the allocation of risk between the federal government and Participating Companies. For example, in the United States, the Yearsley doctrine might offer a defense to certain claims against Participating Companies acting within the Program’s scope.[5] If claims were brought in other countries, the potential availability of similar defenses would depend on the specific country and circumstances.
  • Participating Companies should consider the terms of any Program contract. The Memorandum requires Participating Companies to contract with either the Department of Justice or the Department of Homeland Security as a condition of Program participation. A potential Participating Company should carefully consider the terms of that contract, particularly with respect to the allocation of liability, indemnity, performance obligations and compliance risk.
  • Public companies considering Program participation should evaluate potential disclosure obligations. Collaborating with the federal government on surveillance and national security efforts may generate additional disclosure obligations for public companies. The attendant risk and burden of compliance should be part of any evaluation by a company considering becoming a Participating Company.
  • Program operations may carry practical risk for Participating Companies. Offensive cyber actions carry inherent risk that Participating Companies should consider. For example, deploying a cyber action against a threat actor may lead the attacker to retaliate, potentially creating a cycle of escalating countermeasures and increasing the risk of conflict or harm to the company and innocent third parties present on the same system.

Companies interested in the Program should closely monitor Program announcements, including publication of the Operating Procedures on or before October 11, 2026. Interested companies should also assess Program eligibility as well as the risks and obligations associated with participation. Companies with threat information of value should also evaluate whether to enter into commercial agreements with Participating Companies as contemplated in the Memorandum.

* * *

[1] National Security Presidential Memorandum, Expanding Capabilities to Combat Transnational Cyber-Enabled Crime (August 12, 2026), available here.

[2] President Trump’s Cyber Strategy for America (March 2026), available here; Exec. Order No. 14,390, 91 C.F.R. 47 (2026), available here.

[3] Exec. Order No. 14,159, 90 C.F.R. 18 (2025), available here.

[4]18 U.S.C. § 1030(f).

[5] See GEO Group, Inc. v. Menocal, 607 U.S. 438, 448 (2026).