Donald Trump empowers US private companies to conduct cyber-attacks
President Donald Trump signed a national security memorandum directing the US government to enlist vetted private companies in limited offensive cyber operations against foreign criminal organizations, with oversight from DHS and DOJ.
Intelligence analysis by Llama

Trump's Wednesday memorandum deputizes US private firms to conduct cyber surveillance and 'cyber effects operations' against transnational criminal organizations under federal supervision, requiring a $1m bond and creating a new DHS-led coordination program.
Imagine the president is telling trusted tech companies: 'You can help the government go after bad guys on the internet, but only if we say so and you put up $1 million as a safety promise.' It's like giving neighbourhood watch volunteers real walkie-talkies, with the police listening in.
Analysis
Transnational criminal organizations
The memo's explicit target is what the White House fact sheet calls "transnational criminal organizations" (TCOs), a category that the document links to ransomware attacks, financial frauds, and other cross-border crimes. The framing builds on a national cybersecurity policy released in March that pledged to "unleash the private sector" against foreign adversaries. By routing the new authority through the homeland security taskforce's national coordination center, the administration is signalling that DHS, rather than the military or intelligence community, will be the operational anchor for deputized companies. That choice narrows the mandate to criminal-organisation targets but also raises the question of how Washington will define who qualifies as a TCO, and where the line sits between criminal and state-sponsored hacking.
The $1m bond
A notable administrative detail is the requirement that participating companies maintain a bond or escrow of at least $1m. The mechanism reads as a partial answer to long-standing concerns about corporate liability when private actors are drawn into offensive operations. Past experiments with industry-led cyber action have run into fears of escalation, inadvertent consequences, and inter-agency coordination breakdowns, and a financial floor is one of the few concrete guardrails the memo names. Legal experts quoted in the broader policy debate have warned that companies could still face downstream exposure, particularly if a vetted operation spills into foreign infrastructure not covered by the original authorisation.
Cyber effects operations
The memo's most consequential language is the definition of "cyber effects," which it says can include the "manipulation, disruption, denial, degradation or destruction" of information systems, networks, and the physical or virtual infrastructure they control. That vocabulary is closer to military doctrine than to typical corporate cybersecurity defence, and it formalises a role that, until now, US private firms have only played informally through threat-intelligence sharing. International concern over such capabilities has intensified as newer artificial intelligence models have demonstrated the ability to break into outdated security systems, and the memo lands in a context where US water facilities in several states have already been disrupted by hackers earlier this year.
Key points
- Trump signed a national security memorandum on Wednesday directing the government to enlist vetted private companies in offensive cyber operations against foreign criminal organisations.
- Operations must be conducted at the direction of the US government and are limited in scope, with oversight split between DHS and the Department of Justice.
- Participating companies must maintain a bond or escrow of at least $1m and can be authorised to conduct 'cyber surveillance' and 'cyber effects operations' against specified targets.
- The memo defines 'cyber effects' to include manipulation, disruption, denial, degradation or destruction of information systems and the infrastructure they control.
- Legal experts have raised concerns about escalation, inadvertent consequences and the risks companies could face as they enmesh themselves in international digital conflicts.
If implemented carefully, the framework could mobilise private-sector technical talent against ransomware and financial-fraud networks more quickly than traditional government processes allow. The DHS and DOJ oversight structure gives agencies a way to direct operations without ceding control, potentially disrupting criminal infrastructure before it can be weaponised against US targets.
The policy could pull private companies into foreign digital conflicts in ways that expose them to retaliation, legal liability, or collateral damage to civilian systems. Past programmes have struggled with escalation and inter-agency coordination, and the memo's broad definition of "cyber effects" leaves substantial room for unintended consequences abroad.



