Trump Cyber Strategy Taps Private Firms to Fight Foreign Hackers
“For most of American history, letters of marque were paper. The 2026 version runs on code.”
President Donald Trump’s recently launched cyber strategy appears to enlist private companies in the fight against foreign hackers.
The presidential memorandum, released late Wednesday, comes as the Trump administration has repeatedly pushed for more aggressive action to counter foreign scams and cyberattacks, which the White House said cost Americans nearly $21 billion last year.
The memo represents one of the biggest shifts in U.S. cyber policy undertaken in recent years. It would empower tech and security companies — whose data and control over internet infrastructure often offer unique insight into foreign hacking operations — to mount state-sanctioned digital strikes.
Companies that want to participate would be required to sign contracts with both the Department of Justice and the Department of Homeland Security and to undergo what the memo describes as “rigorous vetting” while working with the government. The overall effort would be overseen by a National Coordination Center, established in an earlier Trump administration executive order, with co-executive directors from DOJ and DHS.
The memorandum, Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, creates a federal program that lets carefully vetted U.S. cybersecurity companies help identify and disrupt foreign criminal groups that commit online fraud and other cybercrime against Americans. These companies would operate only with U.S. government approval, direction, and oversight through the Departments of Justice (DOJ) and Homeland Security (DHS). It also requires safeguards to prevent improper targeting (especially of U.S. people or systems) and requires companies to stop and report any activity that goes beyond an approved operation.
This is a pretty big shift in U.S. cyber policy.
The White House is setting up a program that would let private cybersecurity companies conduct government-authorized operations against foreign cybercriminal groups, including surveillance and disruption of their infrastructure.…
— Chris Wysopal (@WeldPond) August 13, 2026
The move comes as coordinated attacks on U.S. water systems expose how internet-connected industrial controls can turn basic public services into geopolitical targets.
The DOJ and DHS are expected to develop plans for the new program over the next 2 months.
Participating companies must also deposit $1 million in an escrow account. The deposit will be forfeited “should the Participating Company enter non‑compliance with its contractual agreement described” in the memo.
Many of the specifics of the policy remain undefined. These details will be crucial to determining how effective and judicious the program will be. The memo directs the Justice and Homeland Security departments to deliver the particulars in the next 60 days.
Some cybersecurity experts have concerns about the practical implementation of this scheme.
Paul Rosenzweig is in that camp. He leads a consulting firm in Washington, D.C., and was deputy assistant homeland security secretary for policy under President George W. Bush.
“It’s not an incomparably bad idea, but it’s a bad idea,” said Rosenzweig.
He also says the order doesn’t address the number of practical and legal issues any private actor would have to deal with if they hacked a foreign organization.
“Anything that our new cyber-enabled private sector actors do overseas will assuredly be against the domestic law of a host of countries wherein they act,” Rosenzweig said. “The internet is not bounded in by sovereign borders in the same way that physical space is.”
The memo wouldn’t allow private businesses to launch cyberattacks on other governments, but many foreign cybercriminals operate in a grey area between state-sponsored and not. Targeting the wrong group could end up inciting an international incident.
As I have noted before, using artificial intelligence in hacking efforts creates a whole new level of risk in cybersecurity. It would be wonderful to actually get ahead of problems instead of dealing with them after they occur.
The Trump administration’s proposal recognizes a basic reality: cybercriminals exploit open networks and weak defenses faster than government bureaucracies can often respond. Properly vetted private-sector expertise could give our nation a needed advantage, if there are tight oversight and effective execution.
Consider the memorandum the letters of marque for the internet era.
For the first time, private American companies can be authorized to break into foreign criminal networks and burn them down. Nobody has said yet who actually pulls the trigger. https://t.co/lAfYbIwj54
— Mack Claffey (@mackclaffey) August 18, 2026
Donations tax deductible
to the full extent allowed by law.






Comments
I don’t hate this idea, but there needs to be serious guardrails.
More importantly is holding foreign governments accountable for the actions of the scammer networks operating on their soil. Perhaps a better use of tariffs is using them to recompense the victims. Once a scam operation is traced to it’s roots, a temporary punitive tariff is used to recoup the victims losses. And cancel all their visas and send their fellow citizens home until victim compensation is complete.
Spread the pain.
(TBH, I support the death penalty for scammers.)
Sure. We’re going to hack but ONLY foreign powers.
Just like the “secret court” that ended up being used against a US president.
Congratulations, Gen Z — you get to live your own 9/11, all over again.
Hey, gang! I have an idea! Let’s get the Flock Camera company involved; they seem very good at digging in and getting all manner of information!
They’re but one (of many) nodes on the periphery of the network. If you want to get to the core of it, the company to follow is Palantir.
PPP (Private – Public Partnership) has been the vehicle to raise money for infrastructure projects that the government would not direct money to support. Toll roads were the first phase and this concept is constantly praised by different organizations and support groups to get their desired end. The political/elite no longer are concerned about protecting their image (look to the remaking the social image of Rockefeller and Carnegie). The world’s wealth has been doing this forever, and perhaps their programming of us in the United States is losing traction with the public at large. From my perspective they are exactly like crime families seeking and then exerting control over their turf. Government is simply an instrument they have always used to get to their ends.
I read this twice and I gather that you think that the rich will always work with and try to shape the government to their own benefit.
I remain unclear however what you believe this privateer approach towards hackers has to do with your comment. Could you expand please?
Do they do air control too?
Asking for a friend
Are any of these private companies named “Decima Technologies”?
Just asking.
I was taken aback to discover there was one now — in India.
It may or may not be the same outfit that claims to be in Virginia.
We have a serious cyber problem. Our systems are just being penetrated for malicious purposes but they are being penetrated to steal data. It’s not just
government data but corporate data. There are a lot of countries now at work: Russia China Norks Cuba Iran Isis Pakistan and who knows who else.
I recently read about a Nork scheme to get US government/corporations to hire Norks for IT by using middlemen hosted in third countries and even in the US. Once a Nork is hired and an insider and more knowledgeable hacker can use that account to penetrate further, Blocking such hires has been difficult. AIs to aid in passing through the hiring process. So there are a lot of different schemes afoot.
No, blocking those hires hasn’t been all that difficult. At least for companies that care. Almost all of the one’s I’ve interviewed with have cared and have done things to ensure I was really who they were interviewing and would be hiring.
Pssst – GWB
The FBI is investigating how an unidentified federal agency was recently swept up in a yearslong campaign involving North Korean remote IT workers fraudulently obtaining jobs at major companies and other organizations.
The North Korean campaign has been notorious for using remote IT contract jobs to infiltrate both Fortune 500 companies and smaller private sector firms.
https://federalnewsnetwork.com/technology-main/2026/08/fbi-investigating-north-korean-remote-it-staffer-working-for-u-s-agency/
Thanks. Sounds like the article I read.
Leave a Comment