White House Authorizes Private US Companies to Conduct Offensive Cyber Operations Against Foreign Criminal Networks (NSPM: "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime") — Threadlinqs Intelligence
As of 2026-08-13, White House Authorizes Private US Companies to Conduct Offensive Cyber Operations Against Foreign Criminal Networks (NSPM: "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime") is a informational-severity threat intel threat attributed to Unattributed (foreign Cyber-Enabled Transnational Criminal Organizations, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 11 indicators of compromise.
Threat ID: TL-2026-2012 · Severity: INFORMATIONAL · Status: ACTIVE · Category: THREAT_INTEL
Attribution: Unattributed (foreign Cyber-Enabled Transnational Criminal Organizations · FINANCIAL
President Trump signed a National Security Presidential Memorandum on August 12, 2026 authorizing vetted private companies to conduct offensive Cyber Surveillance Operations and Cyber Effects
On August 12, 2026, President Trump signed the National Security Presidential Memorandum "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," establishing the first formal U.S. government program permitting vetted private-sector companies to conduct offensive cyber operations against foreign criminal networks. The memorandum is the operational follow-through on Executive Order 14390, "Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens," which Trump signed on March 6, 2026 and which directed the Secretaries of State, Treasury, War (Defense), and Homeland Security, plus the Attorney General, to develop an action plan against cyber-enabled transnational criminal organizations (TCOs) targeting American families, businesses, and critical infrastructure through ransomware, phishing, financial fraud, sextortion, impersonation, and other extortion schemes. EO 14390 also directed the Attorney General to recommend, by June 4, 2026, a Victims Restoration Program to return funds seized from cybercrime TCOs to victims.
The NSPM defines two categories of authorized activity. "Cyber Surveillance Operations" are activities to collect intelligence from information systems without authorization from the owner/operator, or by exceeding authorized access, designed to remain undetected -- language that tracks the Computer Fraud and Abuse Act's (18 U.S.C. Section 1030) "exceeds authorized access" standard. "Cyber Effects Operations" are activities resulting in the manipulation, disruption, denial, degradation, or destruction of information systems, networks, and physical or virtual infrastructure. Both are authorized only against "Cyber-Enabled Transnational Criminal Organizations" (CE-TCOs) -- foreign groups conducting cyber-enabled crime against U.S. interests that are not institutional parts of a foreign government.
Program governance runs through the National Coordination Center (NCC), a body established under Executive Order 14159 (January 20, 2025), which will administer a "rigorous vetting" and certification process for Participating Companies covering technical proficiency, operational performance history, facility security, and personnel vetting. Two co-equal Executive Directors -- one designated by the Attorney General, one by the Secretary of Homeland Security -- must jointly coordinate and approve every operation in writing, except operations that would produce a "Critical Outcome": likely loss of life, serious injury, or an action rising to the level of use of force or armed attack under international law, which are categorically prohibited from approval. Participating companies must maintain a bond or escrow of not less than $1 million, forfeitable for non-compliance, and face at least annual review to retain program participation. Operations may not target U.S. persons or systems under U.S. control (as defined via Executive Order 12333) without prior authorization, judicial or otherwise; any unintended U.S.-person or domestic-system targeting must be ceased immediately, subjected to minimization procedures, and reported to the NCC and DOJ. The memorandum cites 18 U.S.C. Section 1030 (CFAA) and 44 U.S.C. Section 3502, and names DOJ, DHS, State, Treasury, the Department of War (Defense), Commerce, Energy, the Office of the Director of National Intelligence, CIA, NSA, OMB, and National Security Council components as involved agencies. Federal agencies are expected to issue detailed program requirements and procedures within roughly two months of signing; a classified addendum reportedly addresses target-selection criteria that has not been made public.
The White House frames the program around the scale of consumer harm: American consumers reported $20.8 billion in cyber-enabled crime losses in 2025; 73% of U.S. adults report having experienced an online scam or attack; 98% of Americans view scams as a threat (66% call it a "major" threat); and one in seven young people who experienced sexto
Target sectors: government administration, cybersecurity industry, police - law enforcement, financial services, legal services
Target regions: North America, Southeast Asia, Global
Timeline
- Executive Order 14159 signed, establishing the National Coordination Center that later administers the private-sector offensive cyber operations program.
- Rep. David Schweikert introduces the Cybercrime Marque and Reprisal Authorization Act (later the Scam Farms Marque and Reprisal Authorization Act, H.R. 4988), proposing congressional letters-of-marque authority against cyber-enabled scam-farm operators.
- President Trump signs Executive Order 14390, "Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens," directing federal agencies to develop an action plan against cyber-enabled TCOs.
- Deadline under EO 14390 for the Attorney General to submit a recommendation on establishing a Victims Restoration Program for cyber-enabled fraud victims.
- President Trump signs the National Security Presidential Memorandum "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," authorizing vetted private companies to conduct Cyber Surveillance and Cyber Effects Operations against foreign CE-TCOs.
- White House publishes an accompanying fact sheet citing $20.8 billion in 2025 cyber-enabled crime losses and detailing the program's scope.
- Help Net Security, CyberScoop, TechCrunch, The Record, Bloomberg, and other outlets report on the memorandum, including expert and congressional reaction.
- Approximate two-month target cited by reporting for federal agencies to issue detailed Participating Company vetting requirements and operational procedures.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 11 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, INFORMATIONAL, threat intelligence, cybersecurity, T1566, T1078, T1590, T1684.001, T1213, T1005, T1657, T1485, T1565