US Allows Private Companies to Participate in Offensive Cyber Operations Against Foreign Hackers
The Trump administration has approved a memorandum that opens up the possibility for federal law enforcement agencies in the United States to engage verified private companies in operations against foreign cybercriminal groups. This is not just about data sharing, but about preparing actions against the infrastructure of transnational networks attacking American organizations and citizens. The document was issued on August 12, 2026, and significantly changes the format of cooperation between the government and the commercial cybersecurity sector.
Under the new model, businesses will be able to participate in the detection, tracking, and disruption of criminal infrastructure. Companies will provide technical capabilities, analytics, and intelligence, while the overall coordination will be handled by the National Coordination Center at the Department of Homeland Security. Representatives from the Department of Justice and the Department of Homeland Security will be responsible for direction.
However, private contractors have not been given the right to independently attack suspicious servers or networks. All actions must go through government approval procedures. In fact, authorities are trying to integrate the private cyber business into the official framework of operations but do not grant it the freedom to act at its own discretion.
This is not a direct authorization for retaliatory hacking
Chris Wysopal, co-founder of Veracode, called the decision a significant shift in American cyber policy but emphasized an important distinction. Classic retaliatory hacking assumes that a company attempts to penetrate the server from which it believes the attack is coming. In such a scenario, it is easy to misidentify the target and violate the American Computer Fraud and Abuse Act.
The new scheme is structured differently. A private company can assist with equipment, telemetry, technical expertise, and threat data, but the final decision remains with the government. It is the authorities who determine when and on which infrastructure to apply pressure.
American consumers reported losses of over $20.8 billion from cybercrime in 2025. Additionally, 73% of adult residents in the US have encountered some form of internet fraud at least once.
The reasons for this step are quite obvious. International extortion groups use front owners, rent servers in different countries, fragment their infrastructure, and are often far from the technical nodes through which attacks occur. Simply blocking a domain or filing a complaint with a hosting provider no longer resolves the issue.
In March 2026, the White House already outlined this direction in the new cyber strategy. It mentioned the need to expand business capabilities to detect and disrupt hostile networks. The new memorandum turns this idea into a practical mechanism.
What operations fall under the new rules
The new order is focused on foreign criminal networks associated with extortion, ransomware attacks, and financial fraud. Private companies will be able to work both among themselves and together with federal, regional, and local authorities.
- operations against foreign criminal structures related to extortion, ransomware, and financial schemes;
- collaboration between private companies and government agencies at various levels;
- gathering intelligence on cybercriminal networks and preparing response options;
- impacting the information systems of criminals, including disrupting operations, manipulating, or destroying individual elements of infrastructure.
The American approach goes beyond British practice. The UK has had the National Cyber Force since 2020, which applies offensive cyber capabilities against state and criminal threats. In 2023, London separately outlined the principles for using such tools and emphasized that they are appropriate primarily when ordinary response methods do not yield results.
Washington is moving forward: the private sector is no longer just a supplier of protective solutions but is transforming into a potential participant in state cyber operations.
Modern attacks are becoming cheaper and increasingly automated. Agent-based AI systems are already capable of taking on a significant part of the attack chain: from identifying vulnerable targets to exploiting discovered weaknesses.
The Main Risk - Attribution Error
The weakest point of this new structure is determining the real perpetrator of the attack. Nick Carr, the technical director of the Microsoft Threat Intelligence Center and former chief technical analyst at CISA, acknowledged that even large organizations find it difficult to regularly and accurately establish who is truly behind a specific campaign.
Criminals rarely act directly. They use rented servers, proxies, hacked devices, and intermediary nodes. A group that outwardly resembles a ransomware gang may sometimes be backed by a state operator. In such cases, operations against infrastructure go beyond the fight against crime and risk becoming an international incident.
For Russian users and companies, this is not an abstract threat either. If American contractors consider part of the infrastructure to be an element of a criminal chain, rented capacities, infected machines, or intermediary nodes in various jurisdictions, including Russia, could be at risk.
What Changes in Practice:
- The boundary between state and commercial cyber operations is becoming less clear;
- Private businesses gain more influence over the preparation of operations and the selection of technical targets;
- The state gains access to telemetry that companies often collect faster than law enforcement;
- The legal framework for actions against foreign criminal infrastructure is expanding.
The downside of this model is evident. A private company's error in identifying the infrastructure of criminals could affect unrelated organizations. If a state player is behind the network, the consequences could extend far beyond a technical incident.
For the Russian audience, practical risks look like this:
- The vulnerability of infrastructure linked to foreign hosting, either physically or legally, increases;
- The likelihood of collateral damage to Russian clients during operations against international ransomware groups rises;
- It becomes more important to understand where one's own resources are located and through which foreign providers they operate;
- Threat models will need to be revised considering the actions of American private contractors.
A separate question is how the new program will operate in conditions where the criminals themselves actively use AI. Automation accelerates both the attack and the defense. Commercial players have vast amounts of data on malicious domains, the infrastructure of ransomware groups, and cryptocurrency transactions, so the pace of confrontation will increase.
Already now, several factors should be incorporated into the threat model:
- The expansion of participants in offensive operations from the U.S.;
- An increase in the number of non-public impacts on infrastructure outside of judicial procedures;
- A higher likelihood of collateral damage due to erroneous attribution;
- An enhanced role of private telemetry in selecting targets for operations.
Against this backdrop, initiatives are already emerging in the U.S. where state and non-state participants are trying to secure vulnerable sectors. For example, the Water Watch Center, created by the DEF CON Franklin project in collaboration with the National Rural Water Association, helps small water utilities defend against cyberattacks. This program emerged after breaches in water supply systems in at least 12 states, where criminals gained remote access to industrial controllers.
The signed memorandum indicates a broader shift: the fight against cybercrime is moving from purely investigative and analytical work to operational actions. The U.S. gains access to the technical capabilities of the private sector, but this also raises the stakes for any mistakes. For Russian organizations, this means that the actions of American contractors can now be formally integrated into offensive operations and affect infrastructure far beyond immediate targets.
-- Price
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.
You may also like

Bitcoin Spot Demand: The Signal That Hadn't Reappeared Since the October 2025 Record

Vietcombank Warns of AI-Driven Fraud

$1 Billion in 48 Hours: X Prepares Crypto Trading Function on Feed

The forex complex: How retail traders are adapting to volatile 2026 markets

Trump Beats the Fed: How Trading Boom Explodes in the UAE

Crypto investors should favor systematic strategies over Fed predictions, Moon Pursuit Capital says

Crypto: Solana ETFs Record Their Biggest Day of the Year

Xbox and PlayStation Reassess Their Multiplatform Strategy, Emphasizing Exclusivity Again

Interview: Aptos CEO on AI Agents, Stablecoins, and Machine Commerce

BlackRock Lowers Minimum Investment for Bitcoin ETF to $1 Million

Previously Bearish on Crypto Market, Jiang Zhuoer Quickly Turns Bullish: Ethereum is the Engine of the Bull Market

Michael Saylor Targets Bitcoin Orthodoxy: 'Satoshi Is Not a Prophet'

Strive by Vivek Ramaswamy Becomes the 7th Largest Public Holder of Bitcoin

The Best AI Models for Trading: A Comparison of the Top 10 Models

Enflame, the Chinese competitor of Nvidia in AI chips, goes public

AI is in a Credit Expansion Phase: The Stronger AI Becomes, the More the Federal Reserve Needs to Cut Rates

Short-Term U.S. Treasury Holdings Decrease by $29 Billion, Testing Demand for Stablecoins

Analysis of Mining Machine Asset Depreciation and Tax Cost Recovery

Bitcoin Transfer by Metaplanet: Sale or Just Custody on Coinbase?

Opinion: The Bull Market Has Arrived, How to Position in This Cycle?

80% of Gas Stations in Russia Face AI-95 Gasoline Shortage

Bitcoin Bull Run: Arthur Hayes Sees Crypto Market Soaring Higher

Goldman Sachs Optimistic About Crypto Brokerage Trading Platforms: Can the Market Support a New Cycle?

Strive CEO: The Bitcoin Bull Market Has Just Begun, ASST Has Passed Its Bottom

Ravencoin (RVN) Price Forecast for 2026–2050

AI Agent's 'Coming of Age': What Step Is Missing from Simulation Training to Real Trading?

Bitcoin Just Hit $80,000: Last Week WEEX's Prediction Came True — What's Next?
Bitcoin hit $80,000 as WEEX predicted last week. See what drove the breakout, current key levels, and whether $90,000 is next.

Mining Artificial Intelligence: Why Bitcoin Miners Are Changing Their Business Model

CFTC Considers the Viability of Perpetual Futures in GPU Computing












