Trump Authorizes Private Firms to Conduct Cross-Border Cyber Hacking: A Breakthrough in Combating Cyber Threats or Opening Pandora's Box?

According to a statement released by the White House on August 12 local time, President Trump signed a national security presidential memorandum titled "Expanding the Capability to Combat Transnational Cybercrime." This new regulation marks a significant shift in U.S. cyber policy, for the first time formally authorizing vetted American private enterprises—under direct control and oversight by the federal government—to conduct offensive cyber operations against foreign transnational criminal organizations (TCOs).

First, Targeting Objectives and Types of Operations

The primary targets are "transnational criminal organizations (TCOs)" operating overseas and targeting U.S. citizens and institutions, including criminal syndicates engaged in ransomware attacks, phishing, financial fraud, extortion, and identity theft. The operational scope is explicitly limited to non-governmental criminal groups—not foreign state entities.

Authorized companies may carry out two types of actions: first, "cyber monitoring operations," involving covert access to target information systems for intelligence gathering; second, "cyber effect operations," which include manipulating, disrupting, incapacitating, or even destroying information systems and related virtual infrastructures controlled by criminal groups.

Second, Strict Oversight and Admission Criteria

Every action taken by participating companies must be pre-reviewed by the U.S. Department of Homeland Security and the Department of Justice, and receive written approval. Companies can only act on behalf of the U.S. government and cannot independently decide on attack targets.

Participating firms must undergo rigorous scrutiny and meet strict standards regarding technical capability, cybersecurity measures, and personnel reliability. They are required to deposit at least $1 million as a performance bond or place it in a trust account. If they violate rules or exceed authorized scope, the bond may be forfeited.

Operations must not result in casualties or serious harm, nor reach the threshold defined under international law as "use of force" or "armed attack." If a target accidentally includes U.S. citizens or networks, operations must be immediately suspended and reported to the government.

Third, Real-World Context Behind the Policy

White House data shows that reported cybercrime losses to U.S. consumers exceeded $20.8 billion in 2025—an increase significantly higher than previous years. With emerging threats driven by AI technologies, the current pace of U.S. military cyber operations is considered "unsustainable."

The memorandum notes that the innovative capacity of the U.S. private sector in identifying and combating cybercrime has "long been underutilized." This move aims to leverage the scale, speed, and creativity of private enterprises to compensate for gaps in governmental capabilities.

Fourth, Potential Controversies and Risks

While intended to strengthen enforcement, the policy has sparked widespread concerns.

Cybersecurity experts warn that servers used by criminal groups might belong to unwitting third parties. In cases of misidentification, collateral damage could occur, potentially triggering diplomatic and legal disputes between the U.S. and other nations.

The legal foundation of this memorandum has not yet been tested in court. If overturned later, participating companies could face retroactive criminal liability. Additionally, firms remain vulnerable to legal claims from U.S. states or countries where the targeted entities are located.

Former military officials caution that without clear federal coordination and command structures, this could spawn a wave of unregulated, autonomous "cyber privateers," making conflict coordination in cyberspace even more complex.

In summary, this represents the first time the U.S. government has extended authority for offensive cyber operations to the private sector, opening a new model of public-private collaboration in fighting cybercrime. However, its long-term effectiveness and legal legitimacy remain to be seen.

Original source: toutiao.com/article/1873506129851400/

Disclaimer: The views expressed in this article are those of the author(s) alone.