On August 12, 2026, President Trump signed a National Security Presidential Memorandum regarding Expanding Capabilities to Combat Transnational Cyber-Enabled Crime (the “Memorandum”) directing U.S. law enforcement to target and disrupt transnational criminal organizations. To accomplish this goal, the Memorandum establishes a program allowing private sector companies to partner with the government to fight “Cyber-Enabled Transnational Criminal Organizations” (“CE-TCOs”): foreign groups conducting cyber-enabled crime against the United States.
Program Highlights
The program will be managed by the National Coordination Center and overseen by two Executive Directors from the Department of Justice (“DOJ”) and Department of Homeland Security (“DHS”) (referred to collectively as the “Program Executive Directors”). Through the program, the government can enter into contractual agreements with “participating companies” that will then be empowered to conduct “Cyber Surveillance Operations” and “Cyber Effects Operations” against CE-TCOs.
Cyber Surveillance Operations include covert intelligence gathering: essentially, gaining unauthorized access to CE-TCOs’ computers and systems to collect information “with the intent to remain undetected.” Cyber Effects Operations includes activity that would result in the “manipulation, disruption, denial, degradation, or destruction” of CE-TCOs’ systems and infrastructure; the Memorandum gives participating companies the ability to do to CE-TCOs what they are doing to their victims.
There are safeguards in place to limit the operation. Candidates are required to undergo a thorough vetting process before they can become “participating companies,” and they are not allowed to unilaterally operate once they have joined the program: they must submit a cyber operations package every time they would like to take action, which the Program Executive Directors must coordinate to approve. The Memorandum gives the DOJ and DHS the authority to require participating companies to maintain a bond escrow of at least $1 million, which they would then agree to forfeit if they become noncompliant with their contractual obligations.
Notably, the Memorandum does not give the Program Executive Directors the authority to approve operations that would result in “Critical Outcomes,” or outcomes that will likely “(i) result in the loss of life or serious injury; or (ii) rise to the level of use of force or armed attack under international law.”
Operational Risks
The fact sheet released along with the Memorandum positions the program as a response to the fact that American consumers reported losing $20.8 billion to cyber-enabled crime in 2025, as well as much more serious harm facilitated through cyber-enabled crime. However, there are significant questions as to whether it can contain itself in the bounds of international law—the Critical Outcomes provision notwithstanding—due to its goal of conducting cyber operations in foreign jurisdictions. Although participating companies will be prohibited from targeting foreign groups that are an institutional part of a foreign government or operating under a foreign government’s direction, there are a number of ways in which a participating entity could end up doing so, even unintentionally. CE-TCOs may be assumed not to be affiliated with a foreign government; in fact, the Memorandum explicitly includes in the definition of CE-TCOs that, “[f]or the purposes of this memorandum, a foreign group will be assumed not to be an institutional part of a foreign government or wholly operated under a foreign government’s direction unless clear intelligence exists establishing such connection.”
In reality, the lack of clear intelligence to confirm that a CE-TCO is part of a government’s covert or undisclosed operation could mislead participating companies to target CE-TCOs with those ties. Coupled with the difficulty participating companies may have in correctly attributing the correct operator behind a system, there is a distinct possibility that unrelated organizations could find themselves targets of the program. Additionally, if a participating company is unaware of the other infrastructure to which a CE-TCO’s infrastructure is connected, it could have a cascading effect of unintended consequences on unsuspecting organizations in foreign territory.
These concerns reside at the domestic level as well. The Memorandum itself acknowledges the risk that individuals and organizations in the United States may not be entirely safe from participating companies’ operations: it requires the program’s operating procedures to address scenarios where “(1) a United States person, (2) an information system residing in the United States, or (3) an information system under the control of a United States person” may be unintentionally targeted.
Legal Liability of Participating Companies
Should participating companies unintentionally target or impact entities that do not fall within the definition of CE-TCO, the Memorandum itself does not provide much recourse. The $1 million minimum bond is a relatively low figure to amount to much more than a slap on the wrist, and the bond is to the government, not potential victims. Furthermore, the Memorandum does not create a private right of action; it specifically states that it “does not create any right or benefit, substantive or procedural, enforceable at law or in equity by any party against the United States, its departments, agencies, or entities, its officers, employees, or agents, or any other person.”
Importantly, the Memorandum does not contain a civil liability shield, which means it may be possible that participating companies could be sued under other statutes, common law torts, or foreign law. Furthermore, there are some important questions as to whether activities of participating companies can withstand a Computer Fraud and Abuse Act (“CFAA”) civil or criminal liability challenge by way of 18 U.S.C Section 1030(f) (“the law enforcement exception”), as a result of the activity being overseen and directed by the government. That seems to at least be the intent of the Memorandum by stating that the NCC “shall conduct all Program activities in accordance with…section 1030 of title 18, United States Code, thereby ensuring that Participating Companies are acting under the control an oversight of the United States Government.”
Program Implementation Timeline
Before the program officially begins, the Program Executive Directors are tasked with creating eligibility standards for both large companies and “smaller, more agile companies,” due to the differing nature of the services they can provide. They also must create operating procedures within the sixty days following the Memorandum’s release: October 11, 2026.