The Trump administration has approved a memorandum that opens up the possibility for federal law enforcement agencies in the United States to engage verified private companies in operations against foreign cybercriminal groups. This is not just about data sharing, but about preparing actions against the infrastructure of transnational networks attacking American organizations and citizens. The document was issued on August 12, 2026, and significantly changes the format of cooperation between the government and the commercial cybersecurity sector.
Under the new model, businesses will be able to participate in the detection, tracking, and disruption of criminal infrastructure. Companies will provide technical capabilities, analytics, and intelligence, while the overall coordination will be handled by the National Coordination Center at the Department of Homeland Security. Representatives from the Department of Justice and the Department of Homeland Security will be responsible for direction.
However, private contractors have not been given the right to independently attack suspicious servers or networks. All actions must go through government approval procedures. In fact, authorities are trying to integrate the private cyber business into the official framework of operations but do not grant it the freedom to act at its own discretion.
Chris Wysopal, co-founder of Veracode, called the decision a significant shift in American cyber policy but emphasized an important distinction. Classic retaliatory hacking assumes that a company attempts to penetrate the server from which it believes the attack is coming. In such a scenario, it is easy to misidentify the target and violate the American Computer Fraud and Abuse Act.
The new scheme is structured differently. A private company can assist with equipment, telemetry, technical expertise, and threat data, but the final decision remains with the government. It is the authorities who determine when and on which infrastructure to apply pressure.
American consumers reported losses of over $20.8 billion from cybercrime in 2025. Additionally, 73% of adult residents in the US have encountered some form of internet fraud at least once.
The reasons for this step are quite obvious. International extortion groups use front owners, rent servers in different countries, fragment their infrastructure, and are often far from the technical nodes through which attacks occur. Simply blocking a domain or filing a complaint with a hosting provider no longer resolves the issue.
In March 2026, the White House already outlined this direction in the new cyber strategy. It mentioned the need to expand business capabilities to detect and disrupt hostile networks. The new memorandum turns this idea into a practical mechanism.
The new order is focused on foreign criminal networks associated with extortion, ransomware attacks, and financial fraud. Private companies will be able to work both among themselves and together with federal, regional, and local authorities.
The American approach goes beyond British practice. The UK has had the National Cyber Force since 2020, which applies offensive cyber capabilities against state and criminal threats. In 2023, London separately outlined the principles for using such tools and emphasized that they are appropriate primarily when ordinary response methods do not yield results.
Washington is moving forward: the private sector is no longer just a supplier of protective solutions but is transforming into a potential participant in state cyber operations.
Modern attacks are becoming cheaper and increasingly automated. Agent-based AI systems are already capable of taking on a significant part of the attack chain: from identifying vulnerable targets to exploiting discovered weaknesses.
The weakest point of this new structure is determining the real perpetrator of the attack. Nick Carr, the technical director of the Microsoft Threat Intelligence Center and former chief technical analyst at CISA, acknowledged that even large organizations find it difficult to regularly and accurately establish who is truly behind a specific campaign.
Criminals rarely act directly. They use rented servers, proxies, hacked devices, and intermediary nodes. A group that outwardly resembles a ransomware gang may sometimes be backed by a state operator. In such cases, operations against infrastructure go beyond the fight against crime and risk becoming an international incident.
For Russian users and companies, this is not an abstract threat either. If American contractors consider part of the infrastructure to be an element of a criminal chain, rented capacities, infected machines, or intermediary nodes in various jurisdictions, including Russia, could be at risk.
The downside of this model is evident. A private company's error in identifying the infrastructure of criminals could affect unrelated organizations. If a state player is behind the network, the consequences could extend far beyond a technical incident.
For the Russian audience, practical risks look like this:
A separate question is how the new program will operate in conditions where the criminals themselves actively use AI. Automation accelerates both the attack and the defense. Commercial players have vast amounts of data on malicious domains, the infrastructure of ransomware groups, and cryptocurrency transactions, so the pace of confrontation will increase.
Already now, several factors should be incorporated into the threat model:
Against this backdrop, initiatives are already emerging in the U.S. where state and non-state participants are trying to secure vulnerable sectors. For example, the Water Watch Center, created by the DEF CON Franklin project in collaboration with the National Rural Water Association, helps small water utilities defend against cyberattacks. This program emerged after breaches in water supply systems in at least 12 states, where criminals gained remote access to industrial controllers.
The signed memorandum indicates a broader shift: the fight against cybercrime is moving from purely investigative and analytical work to operational actions. The U.S. gains access to the technical capabilities of the private sector, but this also raises the stakes for any mistakes. For Russian organizations, this means that the actions of American contractors can now be formally integrated into offensive operations and affect infrastructure far beyond immediate targets.
This content is provided for general informational purposes only and doesn't constitute financial, investment, legal, or tax advice. Any events, rewards, online promotions, or related information mentioned herein should not be considered a recommendation, solicitation, or invitation to purchase, sell, trade, or otherwise deal in any crypto assets. Crypto assets are highly volatile and may result in loss. The availability of WEEX services, products, and related events may vary by region. You are responsible for ensuring that your participation is in accordance with applicable local laws and regulations.





























