Washington is moving beyond the usual defensive playbook and putting private American cyber talent on the front line. A new White House memorandum creates a tightly controlled path for vetted U.S. companies to help target foreign cybercriminal groups, with the federal government calling the shots and keeping the whole effort under supervision.
The idea is simple, even if the mechanics are not. Instead of only chasing down attacks after the damage is done, the administration wants a way to reach into the networks that power fraud, ransomware, and impersonation scams before those operations can keep ripping people off. That could mean gathering intelligence in secret, or, in narrower cases, actively disrupting the systems criminals depend on.
Cybercrime has become too big and too expensive to ignore. Federal complaint data shows losses in the tens of billions, and the White House says foreign-based criminal groups are behind some of the most damaging attacks hitting Americans, businesses, and government interests. The pressure point here is obvious: scams are faster, slicker, and harder to catch than ever.
Artificial intelligence has only made things messier. Criminals can now generate more convincing fake messages, voice tricks, and identity theft schemes that feel alarmingly real, which means stolen data can keep circulating long after the first breach. That is part of why the government is looking for new tools, not just better warnings.
Under the memorandum, participating companies could be used in two broad ways. One track focuses on covert surveillance, where a company may secretly access targeted systems to pull out intelligence without being noticed. The other track goes much further, allowing approved operations to manipulate, deny access to, degrade, or even destroy the digital infrastructure tied to a targeted group.
That does not amount to a free-for-all. Private companies are not being told to go rogue and start “hacking back” on their own, which would be a recipe for chaos. Every operation has to happen on behalf of the federal government, and every move is supposed to be reviewed and directed through official channels.
Before any company gets involved, it has to be accepted into the program and locked into an agreement with either the Department of Justice or the Department of Homeland Security. The government will vet firms for technical skill, security practices, reliability, and the people working on the operation, while also making room for smaller specialists that may be better suited to certain jobs.
There is also some real financial skin in the game. Officials can require a bond or escrow account of at least $1 million, which can be forfeited if a company breaks its agreement. That kind of requirement sends a clear message that the government wants partners, but only partners that can handle the heat.
The targets are not just any digital troublemakers. The memorandum focuses on Cyber-Enabled Transnational Criminal Organizations, foreign groups that use cybercrime against the U.S. government, Americans, or U.S. interests. It specifically leaves out organizations that are basically part of a foreign government or operating under one.
There are guardrails for when things go sideways, and that matters because this kind of work can cut close to the bone. If an operation unintentionally hits a U.S. person, a U.S.-based system, or a system controlled by a U.S. person, the company has to stop, follow minimization procedures, and notify the proper authorities right away.
There is also a hard stop on operations that could cross into deadly or war-like territory. Anything likely to cause loss of life, serious injury, or a use-of-force level outcome cannot be approved under the program, which puts a bright line around the most dangerous scenarios. Even then, operations touching constitutional, federal law, or international law issues still have to go through legal review before they can move ahead.
For now, the framework is in place, but the real playbook is still being written. Officials have a limited window to set the rules for eligibility, targeting, legal review, reporting, and oversight, and participating companies will have to keep proving they deserve to stay in the program. That means this is less of a finished operation than a fast-moving blueprint for a much more aggressive cyber campaign.
For everyday Americans, the shift is happening mostly behind the curtain. The new policy does not require any setting changes, downloads, or special sign-up, but it could change the pressure on criminal networks that keep coming after bank accounts, identities, and devices. The bigger question now is how tightly the federal government can control those private partners once the operations begin to roll.
