By Vladimir Tsakanyan
August 13, 2026
On August 12, 2026, President Trump signed a National Security Presidential Memorandum (NSPM) titled “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime.” The White House fact sheet frames it as consumer protection — Americans lost more than $20.8 billion to cyber-enabled crime in 2025, and 73% of U.S. adults have experienced online scams or attacks (White House Fact Sheet).
But the memorandum’s actual architecture is far more consequential. Washington is building a government-directed private cyber-offense ecosystem — deputizing vetted U.S. companies to conduct surveillance and disruption operations against foreign criminal networks. It is both strategically necessary and politically hazardous.
What the Memorandum Does
The NSPM establishes a Program within the National Coordination Center (NCC), originally created under Executive Order 14159 (“Protecting the American People Against Invasion,” January 2025). It authorizes vetted private companies to conduct two categories of operations against foreign “Cyber-Enabled Transnational Criminal Organizations” (CE-TCOs):
- Cyber Surveillance Operations — accessing foreign networks without authorization to collect intelligence, with intent to remain undetected.
- Cyber Effects Operations — manipulating, disrupting, denying, degrading, or destroying foreign information systems and infrastructure.
Operations are overseen by co-Executive Directors from DOJ and DHS, who must jointly approve each operation. Neither may authorize actions likely to cause “Critical Outcomes” — loss of life or actions rising to the level of armed attack under international law. Participating companies must contract with DOJ or DHS, undergo vetting, and may be required to maintain a $1 million bond. Operating procedures are due within 60 days; status reports within 180 days and annually thereafter.
The memorandum requires compliance with “the Constitution and all other applicable laws and international obligations of the United States, including section 1030 of title 18, United States Code” — the Computer Fraud and Abuse Act (CFAA) (White House Memorandum).
A Long-Debated Theory, Now in Practice
Since 1986, the CFAA has criminalized unauthorized computer access. Section 1030(f) exempts “lawfully authorized investigative, protective, or intelligence activity” by law-enforcement and intelligence agencies (18 U.S.C. § 1030). For years, scholars Jeremy and Ariel Rabkin argued this provision could allow the government to deputize private cybersecurity firms for offensive operations. A Georgetown Law analysis described this as the lowest-risk hack-back framework because it retains government control, but noted the theory was “untested” and “legally uncertain” — no court has interpreted Section 1030(f) in the 35 years since its enactment (Georgetown National Security Law Brief).
The August 2026 memorandum appears to operationalize this Rabkin-style deputization model through executive action. The text cites Section 1030 generally and frames private company activity as “lawful investigatory, protective, or intelligence operations” — language that closely mirrors Rabkin’s theory, though the memorandum does not explicitly invoke Section 1030(f) by subsection. Crucially, the executive branch has acted without Congressional authorization, statutory clarity, or the oversight mechanisms academic proposals recommended.
Congress considered but never enacted private hack-back authority. Representative Tom Graves introduced the Active Cyber Defense Certainty (ACDC) Act in 2017 and 2019 with bipartisan support, but it never reached a floor vote. The bill was criticized for lacking a government approval requirement — the FBI could acknowledge notification without reviewing or overseeing the operation. Former NSA Director Keith Alexander warned bluntly: “You can’t have companies starting a war” (Georgetown National Security Law Brief).
The memorandum is more cautious than ACDC — operations require government pre-approval — but also more ambitious. Rather than creating an affirmative defense for companies acting independently, it establishes a formal framework where private companies act as instruments of federal cyber operations. Congress declined to grant this authority. The executive branch took it anyway.
The Definition Problem
The memorandum defines CE-TCOs as foreign groups conducting cyber-enabled crime against U.S. interests that are “not an institutional part of a foreign government or wholly operated under a foreign government’s direction.” Critically, it adds: such groups “will be assumed not to be” state-connected “unless clear intelligence exists establishing such connection.”
This default assumption is analytically dangerous. In transnational cybercrime, the line between criminal organizations and state actors is notoriously blurred. Criminal groups operate in environments shaped by state tolerance, active protection, or blurred relationships with intelligence services. State-aligned proxies frequently conduct financially motivated operations that simultaneously serve state objectives.
By presuming non-state status unless “clear intelligence” proves otherwise, the framework creates a structural bias toward treating state-linked criminal proxies as pure criminals — potentially targeting them without the higher thresholds and diplomatic considerations that should apply to state-adjacent actors. This may be an intentional design choice for operational flexibility, but it risks both misattribution and geopolitical escalation.
The Geopolitical Stakes
The memorandum is addressed to the “Secretary of War” — a title restored by Executive Order 14347 in September 2025 as an “additional secondary title” for the Secretary of Defense, signaling “willingness and availability to wage war” (White House, September 2025). The inclusion of the Secretary of War, CIA Director, NSA Director, and Chairman of the Joint Chiefs on an ostensibly law-enforcement memorandum signals that the administration treats cyber-enabled crime as a national security threat, not merely a criminal-justice matter.
This fits a broader trajectory: EO 14390 (March 2026) directed federal action against cybercrime and fraud; a June 2025 executive order strengthened protections against foreign cyber threats; a June 2026 NSPM bolstered National Security Systems cybersecurity. Together, these instruments represent a comprehensive posture mobilizing the full spectrum of national power — now including private-sector offensive capabilities.
The geopolitical risks are twofold. First, because operations are conducted under government direction and control, they are likely attributable to the United States under international law. Under the standard articulated by State Department Legal Adviser Brian Egan in 2016 and reflected in the International Law Commission’s Articles on State Responsibility, conduct by non-state actors is attributable to a state when conducted under its “direction or control.” A Cyber Effects Operation that disrupts foreign infrastructure — even inadvertently — could be treated as U.S. state action, triggering diplomatic retaliation or escalation dynamics the private company never anticipated.
Second, the safe-haven problem persists. Cybercriminal organizations thrive in permissive jurisdictions through state tolerance, weak governance, or lack of extradition. Disrupting servers in those environments may yield short-term gains but does nothing to address the political conditions enabling these networks.
Democratic Governance Concerns
The memorandum contains a classified annex covering operational deconfliction workflows and the “adjudicatory framework” for ensuring operations target only CE-TCOs. While classification is justified for sensitive details, it means the framework’s most consequential decisions — targeting criteria, escalation thresholds, interagency coordination — will be made outside public scrutiny.
Safeguards for U.S. persons exist but are narrow. DOJ review and judicial authorization are required before operations directed at U.S. persons, and companies must cease and minimize if they inadvertently target domestic systems. But the overall framework relies on executive self-policing: the Program Executive Directors, Homeland Security Council, and DOJ are simultaneously operators and overseers. There is no independent review mechanism, no congressional reporting requirement, and no sunset clause.
The Georgetown analysis and other scholarship specifically recommended mandatory FBI pre-approval, regular congressional reporting, a sunset clause, and initial cooperation limited to only the most sophisticated companies. The memorandum includes government pre-approval and annual reports to executive officials, but omits the rest.
Will It Work?
The strategic logic has merit. The private sector possesses capabilities the government lacks — visibility into threat activity, technical sophistication, and speed. Microsoft, coordinating with U.S. Cyber Command, disabled 94% of the TrickBot botnet’s servers within one week before the 2020 election, disrupting a network that had infected over one million computers since 2016 (Georgetown National Security Law Brief).
But the risks are real. Attribution in cyberspace is notoriously difficult — former NSA Deputy Director Rick Ledgett warned that companies have presented “solid attribution” that turned out to be wrong. Attackers route operations through “hop points” in multiple countries, sometimes using 30 or more. A company could trace an attack to what it believes is a command-and-control server and instead disrupt a hospital whose systems the attackers had compromised as an intermediary.
Success depends on intelligence quality, targeting precision, technical competence of participating companies, and the government’s ability to manage a distributed network of private operators across sovereign borders. If strong, the Program could meaningfully degrade transnational cybercrime infrastructure. If weak, it could produce misattribution, collateral damage, and diplomatic crises that draw the United States into conflicts it did not intend to start.
Conclusion
For decades, the private sector’s role in cybersecurity has been defensive — hardening networks, sharing intelligence, reporting incidents. This memorandum moves private companies into the offensive domain under government direction, treating cyber-enabled crime as a national security threat requiring full mobilization of national power.
But the precedent is dangerous. The framework operates without Congressional authorization, independent oversight, or a sunset clause. It presumes non-state status for groups that may be state proxies. It risks international attribution of private operations to the United States. And its most consequential operational decisions are classified.
The strategic rationale is defensible. Transnational cybercriminals operate beyond U.S. law enforcement’s reach, cause tens of billions in annual losses, and target the most vulnerable Americans. The status quo — reactive enforcement, unanswered diplomatic requests, unenforceable indictments — has not worked.
Cybercrime policy is now foreign policy. The memorandum is a necessary escalation, not a silver bullet. And the most important decisions about how it will be used are the ones the public will never see.
Vladimir Tsakanyan is a cybersecurity policy analyst and political commentator covering cyber diplomacy, geopolitical threat intelligence, and the intersection of technology and national security.
Sources:
- White House Memorandum: Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, August 2026
- White House Fact Sheet, August 2026
- Executive Order 14347: Restoring the United States Department of War, September 2025
- 18 U.S.C. § 1030 — Computer Fraud and Abuse Act
- Georgetown National Security Law Brief: “Shot in the Dark: Can Private Sector Hackbacks Work?”


Leave a comment