US Allows Private Companies to Participate in Offensive Cyber Operations Against Foreign Hackers
The Trump administration has approved a memorandum that opens up the possibility for federal law enforcement agencies in the United States to engage verified private companies in operations against foreign cybercriminal groups. This is not just about data sharing, but about preparing actions against the infrastructure of transnational networks attacking American organizations and citizens. The document was issued on August 12, 2026, and significantly changes the format of cooperation between the government and the commercial cybersecurity sector.
Under the new model, businesses will be able to participate in the detection, tracking, and disruption of criminal infrastructure. Companies will provide technical capabilities, analytics, and intelligence, while the overall coordination will be handled by the National Coordination Center at the Department of Homeland Security. Representatives from the Department of Justice and the Department of Homeland Security will be responsible for direction.
However, private contractors have not been given the right to independently attack suspicious servers or networks. All actions must go through government approval procedures. In fact, authorities are trying to integrate the private cyber business into the official framework of operations but do not grant it the freedom to act at its own discretion.
This is not a direct authorization for retaliatory hacking
Chris Wysopal, co-founder of Veracode, called the decision a significant shift in American cyber policy but emphasized an important distinction. Classic retaliatory hacking assumes that a company attempts to penetrate the server from which it believes the attack is coming. In such a scenario, it is easy to misidentify the target and violate the American Computer Fraud and Abuse Act.
The new scheme is structured differently. A private company can assist with equipment, telemetry, technical expertise, and threat data, but the final decision remains with the government. It is the authorities who determine when and on which infrastructure to apply pressure.
American consumers reported losses of over $20.8 billion from cybercrime in 2025. Additionally, 73% of adult residents in the US have encountered some form of internet fraud at least once.
The reasons for this step are quite obvious. International extortion groups use front owners, rent servers in different countries, fragment their infrastructure, and are often far from the technical nodes through which attacks occur. Simply blocking a domain or filing a complaint with a hosting provider no longer resolves the issue.
In March 2026, the White House already outlined this direction in the new cyber strategy. It mentioned the need to expand business capabilities to detect and disrupt hostile networks. The new memorandum turns this idea into a practical mechanism.
What operations fall under the new rules
The new order is focused on foreign criminal networks associated with extortion, ransomware attacks, and financial fraud. Private companies will be able to work both among themselves and together with federal, regional, and local authorities.
- operations against foreign criminal structures related to extortion, ransomware, and financial schemes;
- collaboration between private companies and government agencies at various levels;
- gathering intelligence on cybercriminal networks and preparing response options;
- impacting the information systems of criminals, including disrupting operations, manipulating, or destroying individual elements of infrastructure.
The American approach goes beyond British practice. The UK has had the National Cyber Force since 2020, which applies offensive cyber capabilities against state and criminal threats. In 2023, London separately outlined the principles for using such tools and emphasized that they are appropriate primarily when ordinary response methods do not yield results.
Washington is moving forward: the private sector is no longer just a supplier of protective solutions but is transforming into a potential participant in state cyber operations.
Modern attacks are becoming cheaper and increasingly automated. Agent-based AI systems are already capable of taking on a significant part of the attack chain: from identifying vulnerable targets to exploiting discovered weaknesses.
The Main Risk - Attribution Error
The weakest point of this new structure is determining the real perpetrator of the attack. Nick Carr, the technical director of the Microsoft Threat Intelligence Center and former chief technical analyst at CISA, acknowledged that even large organizations find it difficult to regularly and accurately establish who is truly behind a specific campaign.
Criminals rarely act directly. They use rented servers, proxies, hacked devices, and intermediary nodes. A group that outwardly resembles a ransomware gang may sometimes be backed by a state operator. In such cases, operations against infrastructure go beyond the fight against crime and risk becoming an international incident.
For Russian users and companies, this is not an abstract threat either. If American contractors consider part of the infrastructure to be an element of a criminal chain, rented capacities, infected machines, or intermediary nodes in various jurisdictions, including Russia, could be at risk.
What Changes in Practice:
- The boundary between state and commercial cyber operations is becoming less clear;
- Private businesses gain more influence over the preparation of operations and the selection of technical targets;
- The state gains access to telemetry that companies often collect faster than law enforcement;
- The legal framework for actions against foreign criminal infrastructure is expanding.
The downside of this model is evident. A private company's error in identifying the infrastructure of criminals could affect unrelated organizations. If a state player is behind the network, the consequences could extend far beyond a technical incident.
For the Russian audience, practical risks look like this:
- The vulnerability of infrastructure linked to foreign hosting, either physically or legally, increases;
- The likelihood of collateral damage to Russian clients during operations against international ransomware groups rises;
- It becomes more important to understand where one's own resources are located and through which foreign providers they operate;
- Threat models will need to be revised considering the actions of American private contractors.
A separate question is how the new program will operate in conditions where the criminals themselves actively use AI. Automation accelerates both the attack and the defense. Commercial players have vast amounts of data on malicious domains, the infrastructure of ransomware groups, and cryptocurrency transactions, so the pace of confrontation will increase.
Already now, several factors should be incorporated into the threat model:
- The expansion of participants in offensive operations from the U.S.;
- An increase in the number of non-public impacts on infrastructure outside of judicial procedures;
- A higher likelihood of collateral damage due to erroneous attribution;
- An enhanced role of private telemetry in selecting targets for operations.
Against this backdrop, initiatives are already emerging in the U.S. where state and non-state participants are trying to secure vulnerable sectors. For example, the Water Watch Center, created by the DEF CON Franklin project in collaboration with the National Rural Water Association, helps small water utilities defend against cyberattacks. This program emerged after breaches in water supply systems in at least 12 states, where criminals gained remote access to industrial controllers.
The signed memorandum indicates a broader shift: the fight against cybercrime is moving from purely investigative and analytical work to operational actions. The U.S. gains access to the technical capabilities of the private sector, but this also raises the stakes for any mistakes. For Russian organizations, this means that the actions of American contractors can now be formally integrated into offensive operations and affect infrastructure far beyond immediate targets.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

AI Scam Hits $3.2 Million Per Incident, Crypto Security Battlefield Shifts from 'Code' to 'Scams'

Matt Damon to Keynote at Ripple Swell 2026 in New York

How Paintings Could Have Become Part of the Digital Economy, but Didn't

Shein's IPO and China's PMI: What Changes for Markets

From Pay to One-Stop Asset Management, BiyaPay Expands Global Diverse Financial Services Boundaries

Trump's Cryptocurrency Scheme Rakes in $1.4 Billion While Investors Lose $4.7 Billion

AI Creates Abundance, BTC Creates Scarcity: What Web3 Truly Changes Is Not Production Relations, But Value Relations

Cryptocurrency Arbitrage and Price Scanning: How Quants Identify Inefficiencies in Funding Rates and Spreads Using Trading APIs

DRAM Shortage Until 2030: How to Position Yourself on Memory Giants?

Why Stablecoins Can't Serve as Credit Despite Being Transferable and Store of Value?

Bernstein Comments on Seven Memory Types: After HBM, DRAM and NAND Compete for the Next Trillion-Dollar Market

After Impacting Two Generations, Meta Ordered to Pay $18 Billion

What is Thinking Cat (HMM)? Reasons Why Ownerless Tokens Can Still Fail

Derivatives Begin to Drive Spot Markets: South Korea's Asset Pricing Power is Flowing Out

ECB Official Calls on Central Banks to Embrace Blockchain

The 25th Word: A Secret Vault in Your Ledger Signer

Tom Lee's Latest Interview: Four Catalysts That Will Drive ETH Up This Year

After a 10-Week Buying Pause, Is Strategy Finally Returning to 'Buy, Buy, Buy' Mode?

Barron Trump Hides from Public Life Due to Assassination Fears, Melania Respects His Decision

Bitcoin is no longer just a risky asset, says BlackRock executive

Saylor Sounds the Horn, and This Time He Really Has Ammunition

The Battle of HIP-4 Begins: Who Will Become the New trade.xyz?

NAVI Prime: How the Largest Lending Protocol on Sui Innovates to Pave the Way for a $10 Billion Fund After $30 Billion in Loans Over Three Years?

Scott Bessent and Kevin Warsh Ordered the US Bond Curve and There Was No Tantrum Over the Upcoming Rate Hike

Amber CEO: A Confession and Rebirth of a 'Wayward' Public Company Boss

KSD Publishes English Guide on Foreign Investors' Use of Korean Government Bond Collateral

Dunamu (Upbit's Parent Company) Partners with Visa to Develop Stablecoin Payments and AI Commerce Remittance Business

Bank of America’s Hartnett: Contrarian Investors Await Two Key Signals, Ready to Shift to Risk-Off Mode

Solana Reduces Issuance by 18.9 Million SOL; BTC Quantum Experiment Underway










