White House Authorizes Private US Companies to Conduct Offensive Cyber Operations Against Foreign Criminal Networks (NSPM: "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime")

White House Authorizes Private US Companies to Conduct (TL-2026-2012), also tracked as Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, is a informational-severity tracked intrusion set, first published 2026-08-13. It has no confirmed attribution, affects U.S. Government DOJ/DHS-vetted private-sector cybersecurity companies, maps to 9 MITRE ATT&CK techniques (T1005, T1078, T1213), and is covered by 9 detection rules and 11 indicators of compromise.

Key facts for TL-2026-2012

Threat ID
TL-2026-2012
Also known as
Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, NSPM on Private-Sector Offensive Cyber Operations, Hack-Back Authorization Memorandum, Private-Sector Cyber Surveillance and Effects Operations Program
Severity
INFORMATIONAL
Status
ACTIVE
Category
THREAT_INTEL
First published
2026-08-13
Last reviewed
2026-08-13
Attribution confidence
LOW
Motivation
FINANCIAL
Target sectors
government administration, cybersecurity industry, police - law enforcement, financial services, legal services
Target regions
North America, Southeast Asia, Global
Detection rules
9
Indicators of compromise
11

President Trump signed a National Security Presidential Memorandum on August 12, 2026 authorizing vetted private companies to conduct offensive Cyber Surveillance Operations and Cyber Effects Operations against foreign cyber-enabled transnational criminal organizations (CE-TCOs), under joint DOJ/DHS oversight via the National Coordination Center, with a $1 million bond/escrow requirement, mandatory annual review, and a prohibition on targeting U.S. persons or domestic systems without prior authorization.

How White House Authorizes Private US Companies to Conduct works

On August 12, 2026, President Trump signed the National Security Presidential Memorandum "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," establishing the first formal U.S. government program permitting vetted private-sector companies to conduct offensive cyber operations against foreign criminal networks. The memorandum is the operational follow-through on Executive Order 14390, "Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens," which Trump signed on March 6, 2026 and which directed the Secretaries of State, Treasury, War (Defense), and Homeland Security, plus the Attorney General, to develop an action plan against cyber-enabled transnational criminal organizations (TCOs) targeting American families, businesses, and critical infrastructure through ransomware, phishing, financial fraud, sextortion, impersonation, and other extortion schemes. EO 14390 also directed the Attorney General to recommend, by June 4, 2026, a Victims Restoration Program to return funds seized from cybercrime TCOs to victims.

The NSPM defines two categories of authorized activity. "Cyber Surveillance Operations" are activities to collect intelligence from information systems without authorization from the owner/operator, or by exceeding authorized access, designed to remain undetected -- language that tracks the Computer Fraud and Abuse Act's (18 U.S.C. Section 1030) "exceeds authorized access" standard. "Cyber Effects Operations" are activities resulting in the manipulation, disruption, denial, degradation, or destruction of information systems, networks, and physical or virtual infrastructure. Both are authorized only against "Cyber-Enabled Transnational Criminal Organizations" (CE-TCOs) -- foreign groups conducting cyber-enabled crime against U.S. interests that are not institutional parts of a foreign government.

Program governance runs through the National Coordination Center (NCC), a body established under Executive Order 14159 (January 20, 2025), which will administer a "rigorous vetting" and certification process for Participating Companies covering technical proficiency, operational performance history, facility security, and personnel vetting. Two co-equal Executive Directors -- one designated by the Attorney General, one by the Secretary of Homeland Security -- must jointly coordinate and approve every operation in writing, except operations that would produce a "Critical Outcome": likely loss of life, serious injury, or an action rising to the level of use of force or armed attack under international law, which are categorically prohibited from approval. Participating companies must maintain a bond or escrow of not less than $1 million, forfeitable for non-compliance, and face at least annual review to retain program participation. Operations may not target U.S. persons or systems under U.S. control (as defined via Executive Order 12333) without prior authorization, judicial or otherwise; any unintended U.S.-person or domestic-system targeting must be ceased immediately, subjected to minimization procedures, and reported to the NCC and DOJ. The memorandum cites 18 U.S.C. Section 1030 (CFAA) and 44 U.S.C. Section 3502, and names DOJ, DHS, State, Treasury, the Department of War (Defense), Commerce, Energy, the Office of the Director of National Intelligence, CIA, NSA, OMB, and National Security Council components as involved agencies. Federal agencies are expected to issue detailed program requirements and procedures within roughly two months of signing; a classified addendum reportedly addresses target-selection criteria that has not been made public.

The White House frames the program around the scale of consumer harm: American consumers reported $20.8 billion in cyber-enabled crime losses in 2025; 73% of U.S. adults report having experienced an online scam or attack; 98% of Americans view scams as a threat (66% call it a "major" threat); and one in seven young people who experienced sextortion as minors reported self-harm. The fact sheet names ransomware, phishing, financial fraud, sextortion, impersonation scams, non-consensual intimate-image distribution, and deepfake abuse as the targeted crime types, and highlights seniors, children, and low-income families as disproportionately targeted victim populations, without naming specific foreign countries or regions in the public text.

Expert and congressional reaction has been mixed. Veracode co-founder Chris Wysopal called it "a pretty big shift in US cyber policy" that nonetheless stops short of broader "hack-back" authority. Former Cyber Command official Jason Kitka dismissed it as "a perpetual motion machine for billable threats." Jake Williams of Hunter Strategy warned the policy is "half-baked" and that Americans conducting these operations while traveling overseas "could easily be classified as non-uniformed combatants," raising detention risk; reporting separately noted precedent concern around foreign prosecution, citing a Chinese hacker extradited from Italy for offensive work against American firms. House Homeland Security Committee Ranking Member Rep. Bennie Thompson (D-MS) criticized the administration for acting via presidential memorandum rather than working with Congress to establish clear statutory authorities, legal procedures, and resources. National Cyber Director Sean Cairncross had signaled the administration's direction toward private-sector offensive cyber authority as early as March 2026.

Legal analysis (Lawfare) identifies substantial unresolved risk: the CFAA's exemption for "lawfully authorized investigative, protective, or intelligence activity" has never been tested in court as applied to private contractors acting on the government's behalf, leaving participating companies exposed to prosecution risk despite informal government assurances pending congressional action. Cross-border operations also risk violating foreign computer-crime statutes -- the U.K. Computer Misuse Act and German criminal code are cited as examples -- creating litigation, prosecution, and diplomatic-incident exposure, particularly given that technical attribution of an adversary's true identity and infrastructure remains imperfect despite improvements since earlier "hack-back" policy debates; misidentification or unaccounted collateral effects could harm innocent third parties and expose companies to CFAA and tort liability.

The NSPM sits alongside a parallel legislative effort: Rep. David Schweikert (R-AZ) introduced the Scam Farms Marque and Reprisal Authorization Act (H.R. 4988, originally the Cybercrime Marque and Reprisal Authorization Act, introduced August 20, 2025), which would have Congress exercise its Article I authority to let the President issue formal "letters of marque and reprisal" -- a mechanism last used against Britain in the War of 1812 and dormant since World War II -- against cyber-enabled scam-farm operators, framing scam-farm fraud against Americans as an "act of war." Coverage of the bill and the broader hack-back debate points to "scam farms" concentrated in Southeast Asia (Myanmar, Cambodia) as a major source of the fraud losses the NSPM cites, with some Southeast Asian scam-center operations reported as tied to Chinese-government-linked networks. This represents a departure from decades of U.S. policy that reserved offensive cyber operations exclusively to government entities such as U.S. Cyber Command, and revives a long-running, previously rejected "hack-back" and "active cyber defense" policy debate in a new, more centrally supervised form.

MITRE ATT&CK techniques used in TL-2026-2012

Collection

T1005 Data from Local System; T1213 Data from Information Repositories

Initial Access

T1078 Valid Accounts; T1566 Phishing

Impact

T1485 Data Destruction; T1565 Data Manipulation; T1657 Financial Theft

Reconnaissance

T1590 Gather Victim Network Information

Defense Evasion

T1684.001 Impersonation

Affected products and versions in White House Authorizes Private US Companies to Conduct

  • U.S. Government — DOJ/DHS-vetted private-sector cybersecurity companies participating in the offensive cyber operations program
    Vulnerable versions: Vetted Participating Companies conducting Cyber Surveillance Operations or Cyber Effects Operations; Company personnel operating internationally under the program; Foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs) engaged in ransomware, phishing, financial fraud, sextortion, and impersonation schemes; Third parties whose infrastructure could be misidentified as CE-TCO infrastructure during an authorized operation

Remediation for White House Authorizes Private US Companies to Conduct

Immediate actions

  • Legal/compliance teams at cybersecurity companies evaluating program participation should independently assess CFAA Section 1030 exposure -- the law-enforcement/intelligence-activity exemption has not been tested in court for private contractors, and informal government assurance does not equal a legal safe harbor
  • Companies with personnel who travel internationally should assess detention and extradition risk before any hands-on-keyboard offensive engagement, given expert warnings about potential 'non-uniformed combatant' classification abroad
  • SOC/threat-intel teams should monitor for any Participating Company vetting standards, program guidance, or classified-addendum disclosures expected within roughly two months of the August 12, 2026 signing
  • Organizations operating infrastructure that could be misidentified as CE-TCO infrastructure (e.g., shared hosting, CDNs, VPS providers in regions associated with scam-farm activity) should review incident-response playbooks for handling inbound offensive activity from a vetted third party, since attribution is explicitly acknowledged as imperfect

Longer-term hardening

  • Track forthcoming DOJ/DHS National Coordination Center rulemaking and Participating Company certification standards for technical-proficiency and personnel-vetting requirements once published
  • Monitor parallel congressional action, including H.R. 4988 (Scam Farms Marque and Reprisal Authorization Act) and any statutory liability-shield legislation Congress may pursue in response to the untested CFAA exemption issue
  • Track EO 14390's Victims Restoration Program development for potential victim-remediation/fund-recovery pathways relevant to affected customers
  • Watch for foreign-government legal or diplomatic responses (e.g., under the U.K. Computer Misuse Act or equivalent statutes) that could affect companies with cross-border operations or personnel

Timeline of White House Authorizes Private US Companies to Conduct

  • Executive Order 14159 signed, establishing the National Coordination Center that later administers the private-sector offensive cyber operations program.
  • Rep. David Schweikert introduces the Cybercrime Marque and Reprisal Authorization Act (later the Scam Farms Marque and Reprisal Authorization Act, H.R. 4988), proposing congressional letters-of-marque authority against cyber-enabled scam-farm operators.
  • President Trump signs Executive Order 14390, "Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens," directing federal agencies to develop an action plan against cyber-enabled TCOs.
  • Deadline under EO 14390 for the Attorney General to submit a recommendation on establishing a Victims Restoration Program for cyber-enabled fraud victims.
  • White House publishes an accompanying fact sheet citing $20.8 billion in 2025 cyber-enabled crime losses and detailing the program's scope.
  • President Trump signs the National Security Presidential Memorandum "Expanding Capabilities to Combat Transnational Cyber-Enabled Crime," authorizing vetted private companies to conduct Cyber Surveillance and Cyber Effects Operations against foreign CE-TCOs.
  • Help Net Security, CyberScoop, TechCrunch, The Record, Bloomberg, and other outlets report on the memorandum, including expert and congressional reaction.
  • Approximate two-month target cited by reporting for federal agencies to issue detailed Participating Company vetting requirements and operational procedures.

Sources cited for White House Authorizes Private US Companies to Conduct

Threats related to White House Authorizes Private US Companies to Conduct

Detection coverage for TL-2026-2012

As of 2026-08-13, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2012 across Splunk SPL, Microsoft KQL and Sigma, covering 11 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats