Trump enlists private cyber contractors to hack foreign crime groups
The structure may invite comparisons with deniable cyber proxies, but written approvals and direct federal control are designed to address contractor liability, not obscure Washington's role.
By RuntimeWire Staff ยท Published
Primary source: The White House
Why it matters
The program creates a new federal market for offensive security companies, including startups, while placing them inside operations carrying unusual legal, diplomatic and technical risk.

President Donald Trump signed an August 12 memorandum creating what amounts to a government-controlled cyber mercenary program: vetted US companies can be contracted to penetrate, surveil and disrupt computer systems used by foreign cybercrime groups.
The boundary matters. These companies will be private offensive operators working under federal contract. They will not be freelance hackers choosing their own targets. The Department of Justice and Department of Homeland Security must approve every mission, and contractors must act on behalf of the US government under its legal authorities.
That structure limits comparisons to the deniable proxy model often associated with Russian cyber operations. Private actors will execute missions, but agency contracts, written approvals and government-issued instructions will make US direction explicit.
The arrangement may shift execution and some operational risk to contractors. On paper, though, it is not designed to hide Washington's role or reduce government responsibility for approved missions. Its liability strategy runs the other way: bring contractors inside the federal chain of authority so they can claim lawful authorization.
Participating companies will be allowed to conduct covert surveillance and what the memorandum calls "cyber effects operations" under federal law enforcement supervision. Those operations can include manipulating, disrupting, denying, degrading or destroying information systems, networks and infrastructure.
Surveillance can include accessing systems without the owner's authorization, remaining undetected and gathering intelligence for future disruption missions.
The program will be managed by the National Coordination Center, an interagency body that Trump assigned a cybercrime role through a March 6 executive order. DOJ and DHS will each appoint an executive director to oversee the program.
Every proposed operation will require written approval and instructions from both directors. Companies will operate through contracts with DOJ or DHS, and their actions must be conducted on behalf of the federal government.
A federal market for offensive cyber companies
The memorandum orders officials to write eligibility rules that accommodate both large contractors and smaller companies suited to specialized assignments.
That opens a federal market for offensive security founders who have historically sold tools, threat intelligence or technical expertise while leaving the government to execute intrusions.
Companies will need to show:
- Technical proficiency
- Operational experience
- Secure facilities
- Vetted personnel
- Reliability and competence
DOJ and DHS may also require each participant to maintain a bond or escrow account of at least $1 million, which can be forfeited for violating its contract.
Participants can sign commercial agreements with businesses that collect threat data through ordinary operations. State, local, tribal and territorial agencies can also identify criminal groups and give that information to contractors, which can then propose operations to the coordination center.
All of those relationships must be disclosed to the government.
That creates a business model beyond a conventional federal services contract. A security vendor could receive intelligence from banks, cloud providers, telecommunications companies or other frequent targets, prepare an operation and seek government authorization to execute it.
The implementation rules will decide how contractors are paid, how information is handled and which companies can meet the security requirements.
Officials have 60 days to write those procedures. The first program report is due within 180 days, followed by annual reports to the White House homeland security adviser and the national cyber director.
The government keeps target and mission control
The program is narrower than a general license for companies to retaliate against hackers.
Contractors cannot pick a target and strike independently. DOJ and DHS must review each operations package, coordinate with other national security agencies and authorize the activity before it begins.
The memorandum limits targets to foreign cyber-enabled transnational criminal organizations. It excludes groups that are institutional parts of foreign governments or operate wholly under a government's direction.
The program will presume a group is independent unless clear intelligence establishes a state connection.
That presumption puts attribution at the center of the risk. Ransomware groups and other cybercrime operations can have shifting relationships with intelligence services, government officials and local authorities. A mistaken classification could turn a law enforcement disruption into an operation against infrastructure tied to a foreign state.
The two program directors cannot approve an operation likely to cause death or serious injury, or one that would qualify as a use of force or armed attack under international law.
Contractors must stop an operation, minimize any collected information and alert the government if they unintentionally target a US person, a US-based system or a system controlled by a US person.
They must also notify the coordination center if an operation may produce one of those critical outcomes, or if they discover an imminent attack on US critical infrastructure.
The memo tries to solve the hack-back liability problem
Private hacking has long carried criminal and civil exposure under the Computer Fraud and Abuse Act, even when a company believes it is pursuing an attacker.
The statute contains an exception for lawfully authorized investigative, protective or intelligence activity by a US law enforcement or intelligence agency.
Trump's memorandum is structured around that exception. It requires agency contracts, federal approval and direct government supervision, and says participating companies will act under US authority.
That may reduce contractors' exposure under US law. It does not create the distance associated with a deniable proxy. The written chain of command strengthens the connection between an approved operation and the federal government.
A Lawfare analysis published before the program was established warned that executive action alone might not resolve contractor liability under federal, state and foreign laws.
The operating rules will need to address that exposure if DOJ and DHS expect smaller companies to accept missions that could trigger litigation, retaliation or disputes with foreign governments.
The government has already shown how a supervised intrusion can dismantle criminal infrastructure. In the 2023 operation against Hive ransomware, the FBI covertly penetrated the group's network, obtained decryption keys and later seized servers with German and Dutch authorities. DOJ said the operation helped avert more than $130 million in ransom demands.
Trump's program is designed to add private-sector capacity to that model. Its reach will depend on which contractors clear the vetting process, what legal protection their agreements provide and whether DOJ and DHS can supervise private operators without slowing the speed that made them attractive in the first place.