GBHackers

Trump Administration Authorizes Cyber Operations Against Foreign Criminal Networks


The Trump administration has issued a presidential memorandum that establishes a federal program allowing vetted U.S. private-sector companies to conduct government-directed cyber surveillance and cyber operations against foreign cyber-enabled transnational criminal organizations (CE-TCOs).

This initiative expands Executive Order 14390, issued on March 6, 2026, which directed federal agencies to combat cybercrime, fraud, and predatory schemes affecting Americans.

The new program aims to integrate the private sector’s technical capabilities into law enforcement and intelligence-led efforts to disrupt foreign criminal networks operating online.

Trump Administration Authorizes Cyber Operations

The National Coordination Center (NCC), established under Executive Order 14159, will create and manage this program. Participating companies must be U.S.-based firms accepted into the program. They will operate under the oversight and operational control of the federal government.

The Department of Justice (DOJ) and the Department of Homeland Security (DHS) will jointly oversee the initiative through two Program Executive Directors.

They may approve operations after coordination, but cannot authorize actions likely to produce “Critical Outcomes,” including loss of life, serious injury, or actions that could be classified as a use of force or an armed attack under international law.

Participating companies will be required to sign contracts with the DOJ or DHS, undergo rigorous vetting, and adhere to operating procedures established within 60 days.

This guidance will cover technical capability, personnel reliability, facility security, prior cyber-operation performance, reporting obligations, and legal compliance.

Surveillance and Disruption Authority

The memorandum distinguishes between two operational categories:

  • Cyber Surveillance Operations involve covert, unauthorized access to systems for intelligence collection, including activities that may support future disruptive operations.
  • Cyber Effects Operations encompass the manipulation, disruption, denial, degradation, or destruction of information systems, networks, infrastructure, or data.

These definitions suggest that approved private-sector operators could support intelligence collection against criminal infrastructure, such as botnet command-and-control servers, fraud platforms, phishing infrastructure, ransomware ecosystems, and other systems attributed to foreign CE-TCOs.

However, every operation must be reviewed and approved in writing by the Program Executive Directors before any action is taken.

The memorandum defines a CE-TCO as a foreign group that conducts cyber-enabled crimes against the U.S. government, U.S. persons, or U.S. interests, provided it is not an institutional component of a foreign government or wholly controlled by one.

The program explicitly requires compliance with the Constitution, applicable U.S. laws, international obligations, and the Computer Fraud and Abuse Act under 18 U.S.C. §1030.

Procedures must ensure that any activity affecting U.S. persons or domestic systems receives the necessary legal or judicial authorization before approval.

If a participating company exceeds its approved scope, such as unintentionally targeting a U.S. person or U.S.-based information system, it must halt the operation, implement minimization procedures, and immediately notify the NCC and DOJ.

Participating companies must also report imminent threats to U.S. critical infrastructure and disclose any commercial relationships that provide threat intelligence.

The DOJ and DHS may require firms to maintain at least a $1 million bond or an escrow account, which may be forfeited for noncompliance with contractual terms.

The memorandum mandates annual reviews of participating companies. It requires the submission of a program status report within 180 days, followed by yearly assessments.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world



Source link