US expands private-sector role in offensive cyber operations against foreign criminal groups

President Donald Trump has signed a memorandum creating a new US government programme to use cyber operations against foreign-based transnational criminal organisations. The programme will also allow vetted private companies to contribute threat intelligence and propose offensive cyber operations under federal direction and control.

US expands private-sector role in offensive cyber operations against foreign criminal groups

President Donald Trump has signed a memorandum expanding the US government’s ability to conduct cyber operations against foreign-based transnational criminal organisations (TCOs) that target people in the United States.

The memorandum directs the National Coordination Center of the Homeland Security Task Force to establish a programme for conducting cyber surveillance and cyber effects operations. These operations can include activities intended to manipulate, disrupt, deny, degrade, or destroy information systems or infrastructure, as well as covertly accessing computer systems to collect intelligence.

The programme will be overseen by two executive directors: one designated by the US Attorney General from the Department of Justice and another designated by the Secretary of Homeland Security. They will have authority to approve operations carried out under the programme.

There are limits on the operations. An operation cannot be approved if it is expected to cause loss of life or serious injury, or if it would amount to a use of force or armed attack under international law.

A notable element of the programme is the planned involvement of private-sector companies. Vetted companies will be able to share information about cyber threats and propose cyber operations in coordination with federal, state, local, tribal, and territorial authorities. Companies participating in the programme will operate under the direction and control of the federal government and will have to meet technical, security, and personnel requirements established through their contracts.

This creates a role for private companies that goes beyond the defensive activities commonly associated with cybersecurity partnerships between governments and industry. Rather than only sharing information about threats or helping protect networks, participating companies could contribute to operations intended to interfere with or access systems operated by foreign criminal organisations.

The programme also raises questions about how offensive cyber operations could affect systems that are not part of a criminal network. Criminal groups may use infrastructure shared with legitimate organisations, meaning an operation targeting criminal systems could potentially disrupt other services.

There are also questions about operations involving criminal groups that have connections to foreign governments. The memorandum restricts operations that would constitute a use of force or armed attack under international law, but determining when a cyber operation reaches that threshold can be legally and technically difficult.

The status of private-sector personnel involved in such operations could also raise legal questions. Unlike military personnel or government officials, employees of participating companies would remain private actors while conducting activities under government direction and control.

The programme places primary responsibility for approving and overseeing the operations within the executive branch, through the Department of Justice and Department of Homeland Security. This has prompted questions about the extent of congressional or judicial oversight over the activities carried out under the new framework.

Go to Top