A landmark shift in US cybersecurity policy has been announced, with the White House instructing private security companies to participate in offensive hack-back operations against foreign cybercrime organizations. A national security presidential memorandum (NSPM) signed by President Donald Trump enables the National Coordination Center (NCC) to tap into the expertise of these firms, allowing them to conduct cyber operations targeting transnational criminal groups under government control.
The program, which will be overseen by executive directors designated by the Justice and Homeland Security departments, marks a significant expansion of the private sector’s role in offensive cybersecurity. According to the White House, this initiative aims to disrupt foreign organizations involved in ransomware attacks, phishing campaigns, financial fraud, sextortion schemes, and impersonation scams that have cost U.S. consumers more than $20.8 billion in 2025.
To participate in the program, security firms will undergo rigorous vetting before entering into contracts with either of the two departments. Participating companies must also maintain a bond or escrow of at least $1 million, which will be forfeited if they fail to comply with contractual agreements. Furthermore, operations will be subject to procedures ensuring compliance with U.S. laws and international obligations.
The program’s framework allows participating companies to collaborate with other private entities and government agencies to gather threat information and propose cyber operations that address these threats. This collaborative approach is a major departure from traditional cybersecurity strategies, which often rely on individual organizations taking on the burden of defending against sophisticated attacks.
Cybersecurity experts have hailed the memo as a significant shift in US cyber policy. Veracode co-founder Chris Wysopal described it as “a pretty big shift” that represents “a major expansion of the private sector’s role in offensive cyber operations.” Automox CTO Jason Kikta has dubbed it “a perpetual motion machine for billable threats,” highlighting the potential for lucrative opportunities in this new area.
While the program aims to disrupt foreign cybercrime organizations, there are concerns about the potential risks and unintended consequences. As with any government-approved hack-back operation, there is a risk of collateral damage or unintended targeting of U.S. citizens or systems. Participating companies will be required to immediately stop operations if they discover such activity and notify the National Coordination Center.
As this new initiative unfolds, it remains to be seen how effective it will be in disrupting foreign cybercrime organizations. Nevertheless, one thing is clear: the US government is taking a bold step forward in leveraging private sector expertise to combat the growing threat of cyber-enabled crime. For cybersecurity professionals and individuals alike, this development serves as a reminder that collaboration, information sharing, and innovation are crucial in staying ahead of the rapidly evolving threat landscape.
To stay safe online, it’s essential to remain vigilant about potential threats and take proactive measures to protect yourself and your organization from cybercrime. This includes keeping software up-to-date, using strong passwords, and being cautious when receiving unsolicited emails or attachments. As this new initiative unfolds, we will continue to monitor its progress and provide updates on any developments that may impact the security community.
Source: Bleeping Computer — 2026-08-13