A new directive from the White House, signed by U.S. President Donald Trump, has initiated a significant policy shift aimed at improving national efforts to counter transnational criminal organizations (TCOs) involved in cybercrime. This memorandum instructs the National Coordination Center (NCC) to establish a new framework that will leverage the innovative capabilities of private sector companies to combat these threats.
The memorandum emphasizes the importance of collaboration between vetted U.S. companies and the Federal Government. This partnership is expected to enhance the nation’s capacity to address various TCO threats, including cybercrime, fraud, and other nefarious schemes aimed at harming American citizens. The memo outlines a proactive strategy, underscoring that by forming these alliances, the government aims to better protect its citizens from scams that exploit vulnerabilities in the digital realm.
In accordance with the directive, the NCC has been assigned the responsibility of creating a specialized program within a 60-day period. This program will permit authorized companies to conduct two primary types of operations against TCOs once they have received government approval. The first type of operation is cyber surveillance, which allows access to sensitive data without the consent of the data’s owner or operator. The second type involves cyber effects operations, which can lead to the disruption, denial, degradation, or even destruction of critical information systems, networks, or infrastructure.
The memorandum makes clear that only select private U.S. firms will be eligible to participate in this initiative. These firms must be officially recognized and approved to conduct cyber operations under the guidance of the U.S. Government. The scope of the targets is also defined: foreign entities engaged in cyber-enabled crimes against the U.S. government, American citizens, or U.S. interests are within the purview of these operations. However, it is stipulated that these entities cannot be part of a foreign government or under its direct control unless proven otherwise.
To maintain the integrity and legal compliance of these operations, the memo outlines restrictions that must be adhered to during cyber operations. Companies are required to halt any actions that go beyond their authorized parameters, such as targeting a U.S. person or accessing information systems situated within U.S. territory or under American control. In instances where such breaches occur, companies must implement minimization procedures and promptly inform the NCC, which is responsible for notifying the Department of Justice.
Earlier in March, the White House had already laid the groundwork for combating cybercrime, fraud, and predatory operations executed by TCOs that pose risks to American citizens. This includes combating notorious tactics such as ransomware deployment, phishing schemes, financial fraud, sextortion, pig butchering scams, and impersonation.
According to a fact sheet released alongside the memorandum, American consumers reported losses totaling approximately $20.8 billion due to cyber-enabled crimes. This staggering figure highlights the pressing need for enhanced defensive and offensive measures against cyber threats. The initiative aims to turn the tide against such alarming statistics by utilizing the strengths of the private sector.
However, the Trump administration’s approach, while ambitious, raises concerns among experts who point out potential legal and security risks. U.S. laws currently restrict private entities from launching cyberattacks or disruption operations without explicit court authorization. Thus, the expansion of private sector involvement in offensive cyber operations against foreign adversaries could lead to complex legal dilemmas and unintended consequences.
The timing of this memorandum coincides with significant developments internationally, particularly in Germany, where the government has approved new legislation enabling domestic and foreign intelligence agencies to dismantle hostile servers, disrupt foreign cyber networks, and take offensive actions against state-sponsored hackers. The comparison illustrates a growing trend among nations to empower intelligence agencies and private entities to tackle cyber threats with increased aggressiveness.
In essence, the initiative by the Trump administration marks a significant pivot in the fight against cybercrime, reflecting a recognition of the necessity for innovative partnerships in an increasingly digital world. By harnessing the capabilities of the private sector under government supervision, the United States seeks to fortify its defenses against the risks posed by transnational criminal organizations operating in the shadows of the internet. As this policy takes shape, its implications for civil liberties, legal frameworks, and international cyber relations remain to be fully understood and debated.

