U.S. takes risky bet on private 'pirates' to combat cybercrime
President Trump has signed a memorandum allowing certain U.S. companies to hack foreign cybercriminal groups, an unprecedented move experts say could succeed or spiral out of control.
Intelligence analysis by Llama
The U.S. will let private companies spy on and attack transnational criminal organizations under a new Trump memorandum directing the Justice and Homeland Security departments to authorize the activity.
The U.S. government decided to let some private companies play computer spy games against bad guys in other countries who try to steal money through the internet. Some experts think it could work like a neighborhood watch, while others worry it might cause big problems nobody can fix.
Analysis
The $20 billion justification
The White House anchored its case for allowing private firms to conduct offensive cyber operations in a concrete number: more than $20 billion in losses attributed to ransomware, "sextortion," and online fraud suffered by Americans in 2025. That figure functions as the political payload of the memorandum, framing the policy as a response to an economic emergency rather than an expansion of state power. Whether the $20 billion is verifiable, comprehensive, or merely a useful round number for a press release matters less than the signal it sends: Washington is willing to treat cyber-enabled crime as a national-security-grade threat warranting tools previously reserved for state-on-state conflict. For Japan-based firms and policymakers, the implicit comparison is direct — Japan's domestic ransomware losses and fraud exposure have been climbing, and Tokyo has so far relied on defensive cooperation with foreign agencies rather than offensive authorization of its own private sector.
The Wednesday memorandum and the role of Justice and Homeland Security
By directing the departments of Justice and Homeland Security to grant eligible U.S. companies the legal cover to spy on and attack transnational criminal organizations, the memorandum routes the program through the two agencies with the deepest experience in cyber investigations — but also the two most accustomed to chain-of-custody rules and prosecutorial discipline. Whether those departments can impose meaningful oversight on profit-motivated private actors operating across borders is the central unanswered question. The phrase "certain U.S. companies" does the heavy lifting in the text, leaving undefined who qualifies, what thresholds they must meet, and what happens when an authorized hack spills onto servers belonging to a hospital, a foreign government, or a Japanese subsidiary of an American firm. The legal architecture is the policy, and the architecture is still being drawn.
The 'pirates' framing and the spiral risk
The Japan Times' headline word — "pirates" — captures the ambivalence that runs through expert reaction: privatized offensive cyber power is being authorized at a moment when accountability frameworks, attribution rules, and rules-of-engagement conventions have not kept pace. The article notes that specialists are split between those who see real potential to disrupt extortion networks and those who warn the move could "spiral out of control." The spiral scenarios are not theoretical. A private actor that mistakenly targets infrastructure in a third country, or that retaliates against a hostile probe, could trigger a diplomatic incident that the U.S. government neither authorized nor can easily disavow. For allies including Japan, the calculus is doubly delicate: cooperation with U.S. cyber authorities has become more valuable just as the boundaries of what those authorities are empowering have become less predictable.
Key points
- Trump signed a memorandum Wednesday allowing certain U.S. companies to spy on and attack transnational criminal organizations
- The directive went to the Justice and Homeland Security departments, which will set eligibility and scope
- The White House cited more than $20 billion in 2025 losses from ransomware, sextortion, and online fraud as justification
- Experts are split, with some warning the unprecedented move could spiral out of control
- The program raises unresolved questions about oversight, accountability, and collateral damage to third countries
If implemented with clear legal guardrails, the policy could meaningfully disrupt ransomware and sextortion networks that have cost Americans tens of billions of dollars, drawing on private-sector technical talent that federal agencies cannot match. Faster takedowns of criminal infrastructure and a credible deterrent threat could also reduce the overall volume of attacks reaching allied networks, including those in Japan.
Without robust oversight, deputized private companies could overstep their authorization, triggering diplomatic incidents or retaliatory cyber strikes against U.S. infrastructure. The precedent also blurs the line between law enforcement and offensive state action, potentially inviting copycat programs from rival governments and exposing multinational firms — including those with Japanese operations — to legal jeopardy in multiple jurisdictions.