The US government has authorized private companies to conduct government-directed offensive cyber operations against transnational criminal organizations. On August 12, 2026, President Donald Trump signed a National Security Presidential Memorandum, building on Executive Order 14390, which established an operational cell to coordinate cybercrime detection and response efforts.
The new framework provides legal protections for participating private firms, but only under stringent government oversight, requiring dual-agency sign-offs for every operation. Congress is also moving forward with the Senate-introduced S.5000, the Cyber Letters of Marque and Reprisal Act, which would grant the President explicit authority to authorize private entities to conduct cyber operations against foreign threats.
Primary Objectives
The framework aims to recover stolen funds and dismantle the infrastructure supporting crypto-enabled criminal networks, targeting mixers, fraud operations, and ransomware-as-a-service platforms. Neither the NSPM nor S.5000 targets specific cryptocurrencies or tokens, instead focusing on criminal behavior.
This approach represents a shift in US cybersecurity policy, from a defensive posture to limited offensive measures, bringing the fight to criminal organizations rather than waiting for them to strike.



