HomeAmericaU.S. Expands Cyber Arsenal: White House Opens New Front Against Transnational Cybercrime

U.S. Expands Cyber Arsenal: White House Opens New Front Against Transnational Cybercrime

Date:

Related stories

spot_imgspot_imgspot_imgspot_img

The United States is taking a significant step toward bringing private-sector cybersecurity capabilities directly into the government’s fight against transnational cybercrime.

On August 12, 2026, President Donald J. Trump signed a presidential memorandum establishing a program that will allow vetted U.S. companies to conduct authorized cyber surveillance and cyber effects operations against foreign cyber-enabled transnational criminal organizations (CE-TCOs), under the direction and oversight of the U.S. government, according to the Wihte House.

The move expands the approach introduced by the White House in March, when Executive Order 14390 directed the federal government to strengthen its response to cybercrime, fraud, scam centers, ransomware, sextortion and other predatory schemes targeting Americans.

A new model for fighting cybercrime

At the heart of the August 12 memorandum is a simple idea: government agencies do not have to fight increasingly sophisticated cybercriminal networks alone.

The program will be managed by the National Coordination Center (NCC) and overseen jointly by designated officials from the Department of Justice and Department of Homeland Security. Participating companies must first undergo rigorous vetting and operate under contractual agreements with the U.S. government.

The memorandum specifically allows participating companies to receive relevant threat information from private-sector organizations and government agencies. They can then propose cyber operations to the NCC to address identified threats.

That could create a much tighter operational connection between cybersecurity companies, threat intelligence teams and government investigators.

But there is an important distinction: this is not a broad authorization for private companies to conduct offensive cyber operations independently.

The memorandum states that activities conducted through the program must remain under federal government control, supervision and legal authority.

What companies could actually do

The memorandum defines two major categories of activity.

Cyber Surveillance Operations involve accessing information systems without authorization, or beyond authorized access, primarily to collect information or intelligence. That intelligence could potentially support future operations.

Cyber Effects Operations, meanwhile, cover activities intended to manipulate, disrupt, deny, degrade or destroy information systems, networks, infrastructure or information.

The program therefore goes beyond conventional defensive cybersecurity.

It establishes a framework in which selected private companies could contribute capabilities to government-directed operations designed to identify, track and disrupt criminal infrastructure.

The memorandum also establishes boundaries around these activities. Operations cannot be approved if they are expected to cause a Critical Outcome, defined as likely loss of life or serious injury, or conduct that rises to the level of the use of force or armed attack under international law.

Strict oversight is built into the program

The White House memorandum places considerable emphasis on governance.

Within 60 days, program leaders are instructed to establish operating procedures covering company eligibility, technical capability, personnel vetting, facility security, operational workflows, target identification, reporting and legal review.

Every cyber operations package must receive written approval and direction from the program’s executive directors before action can begin.

Companies must also disclose relevant commercial relationships connected to the program.

The government may require participating companies to maintain a bond or escrow of at least $1 million, which could be forfeited if contractual requirements are violated.

The program also requires annual evaluations of participating companies.

Perhaps most importantly, companies must immediately stop an operation and begin minimization procedures if they discover that an operation has exceeded its authorized parameters for example, by unintentionally targeting a U.S. person or an information system located in the United States.

Why this matters beyond Washington

The significance of the memorandum extends well beyond the United States.

Cybercriminal organizations increasingly operate like distributed businesses. Infrastructure, stolen credentials, cryptocurrency services, malware development, money laundering, social engineering operations and scam centers can span multiple jurisdictions.

The March 2026 executive order already identified foreign transnational criminal organizations as a major threat and directed U.S. agencies to improve coordination, intelligence sharing and disruption efforts, including the use of commercial cybersecurity capabilities.

The new memorandum moves that concept closer to an operational framework.

For cybersecurity companies, it could create new opportunities to contribute specialized threat intelligence, infrastructure analysis and technical capabilities to government-led investigations.

For governments, it raises an equally important question: how can private-sector cyber expertise be used at speed without weakening legal safeguards, accountability or international norms?

That question will become increasingly important as governments around the world explore public-private approaches to combating cybercrime.

The opportunity and the risk

There is a compelling argument for closer cooperation.

Private cybersecurity companies often see malicious infrastructure, malware campaigns and criminal tactics before government agencies do. They operate global sensor networks, incident-response teams and threat-intelligence platforms that can provide visibility across thousands of organizations.

Bringing some of that visibility into government-led investigations could shorten the time between detection, attribution and disruption.

But offensive cyber activity also carries greater risk than conventional defensive security.

An operation targeting criminal infrastructure can encounter compromised third-party systems, shared hosting environments, legitimate services or infrastructure located in countries that have nothing to do with the criminal activity.

That makes authorization, target validation, deconfliction and incident reporting critical.

The memorandum appears designed to address precisely those risks by requiring government approval, legal review and operational controls.

Still, the effectiveness of the program will ultimately depend on how those controls work in practice.

A signal to the global cybersecurity industry

For the global cybersecurity industry, the memorandum sends a broader message: commercial cybersecurity capabilities are becoming increasingly integrated into national security strategies.

That trend is already visible across threat intelligence, incident response, vulnerability research, cloud security and critical-infrastructure defense.

The U.S. initiative takes the relationship a step further by creating a formal mechanism through which selected private companies could support government-controlled cyber operations.

For organizations operating internationally, this makes governance and operational discipline more important than ever.

Cybersecurity providers that work across borders will need to understand not only technical requirements, but also contractual obligations, data handling rules, legal authorities, jurisdictional boundaries and potential conflicts between national laws.

What it means for Middle East and Africa

The announcement is also relevant to cybersecurity leaders across the Middle East and Africa, where many organizations face cybercrime campaigns that cross borders and rely on infrastructure spread across several countries.

African financial institutions, telecom operators, governments, technology companies and critical infrastructure providers increasingly depend on international cybersecurity ecosystems. Threat intelligence gathered in one market can reveal infrastructure or tactics affecting organizations somewhere else.

The U.S. model could therefore contribute to a wider discussion about how governments and private-sector security companies can share intelligence and coordinate disruption while respecting national sovereignty and legal boundaries.

For CISOs and government security leaders in the region, the lesson is straightforward: cross-border cybercrime requires cross-border visibility and cooperation.

10 actions security teams should take now

The White House memorandum is focused on U.S. government operations, but organizations worldwide can take practical lessons from its emphasis on intelligence, authorization and operational control.

  1. Strengthen threat intelligence sharing. Establish trusted mechanisms for exchanging indicators, attacker infrastructure and campaign intelligence with relevant industry and government partners.
  2. Map your external attack surface. Regularly identify exposed domains, cloud resources, remote-access services, APIs and other internet-facing assets.
  3. Monitor criminal infrastructure. Track malicious domains, IP addresses, command-and-control infrastructure, leaked credentials and other indicators relevant to your sector.
  4. Improve identity protection. Enforce phishing-resistant MFA wherever possible and rapidly disable compromised accounts and credentials.
  5. Segment critical systems. Limit the ability of attackers to move from ordinary corporate networks into critical infrastructure, production systems or sensitive environments.
  6. Build an incident-response playbook. Define who can make decisions, who contacts law enforcement, how evidence is preserved and when external specialists are engaged.
  7. Preserve forensic evidence. Maintain appropriate logs and telemetry so that investigations can reconstruct attacker activity and support attribution.
  8. Vet cybersecurity partners carefully. Understand how security providers handle threat intelligence, customer data, cross-border operations and sensitive investigations.
  9. Test your third-party risk controls. Criminal organizations frequently exploit suppliers, service providers and compromised credentials to reach their ultimate targets.
  10. Invest continuously in cybersecurity training and awareness. Technology alone cannot stop phishing, business-email compromise, social engineering and fraud; employees remain an important layer of defense. Organizations can explore cybersecurity training and awareness programs to strengthen this human layer.

The bigger picture

The August 12 memorandum represents a notable evolution in the U.S. government’s cybercrime strategy.

Rather than treating commercial cybersecurity firms simply as vendors providing defensive technology, Washington is creating a formal framework for selected companies to contribute capabilities to government-controlled cyber operations against foreign criminal organizations.

The experiment will be watched closely.

If successful, it could demonstrate how government authority and private-sector technical expertise can work together to disrupt cybercriminal networks faster. If poorly governed, however, the model could raise difficult questions around accountability, jurisdiction, collateral impact and the boundaries between private cybersecurity and state cyber operations.

For now, the message from Washington is clear: the fight against transnational cybercrime is moving toward a more integrated model and the private cybersecurity sector is being asked to play a much larger role.

Related reading on CyberCory: Ransomware in 2026: Trends to Watch | Inside the Global Fight Against Cybercrime | Cybersecurity in the Age of AI

Source: The White House, Presidential Memorandum, “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime,” August 12, 2026. The White House’s March 6, 2026 Executive Order 14390 provides the preceding policy context for the new initiative.

Subscribe

- Never miss a story with notifications

- Gain full access to our premium content

- Browse free from up to 5 devices at once

Latest stories

spot_imgspot_imgspot_imgspot_img