The Digital Source For China's Tech Innovation Since 2000

Trump signs memo authorizing private sector to launch cyberattacks

August 15, 2026
ChinaTechNews.com Staff
President Donald Trump speaks during a meeting to sign an executive order about vaccines, Monday, Aug. 10, 2026, in the Oval Office of the White House in Washington. (AP Photo/Jacquelyn Martin)

President Donald Trump signed an order Wednesday authorizing select private companies to carry out government-sponsored cyberattacks against foreign criminal hacking groups – actions that have until now been the domain of U.S. national security agencies.

The memorandum enables the government to contract with U.S. firms to hack into and disrupt overseas digital networks belonging to “cyber-enabled transnational criminal organizations.”

The memo stipulates that the companies, under the supervision of the federal government, may breach computer systems to conduct surveillance and manipulate or destroy digital or physical infrastructure “controlled by information systems” but are barred from targeting foreign governments or taking actions that result in the “loss of life” or “serious injury.”

The move marks a significant shift from the more restrained approach of previous administrations, which prohibited companies that suffered intrusions from “hacking back” into their attackers’ systems for fear of geopolitical blowback. Now the Trump administration wants to enlist the private sector to help take the fight to criminal hackers.

“President Trump is unleashing every available tool to stop foreign-based organized criminal organizations that exploit Americans in cyberspace,” the White House said in a fact sheet accompanying the memo.

Some analysts and industry executives hailed the move, saying it should help the government degrade foreign criminals’ abilities to hack Americans. “Cyberattacks are cheap to launch and expensive to defend against,” said Joe Lin, co-founder and CEO of a Northern Virginia start-up that provides cyber offensive software for the U.S. government. “The more we can disrupt adversaries at scale using vetted commercial partners, the less our adversaries will be able to attack the United States.”

Other experts say it could pose legal and geopolitical risks for the federal government and the companies themselves.

ADVERTISEMENT

“What if a company carries out an operation against what it thinks is an Iranian or Russian criminal group, but that group is actually controlled, influenced or protected by Tehran or Moscow?” said Matt Curtis, who served as White House senior director for cyber policy in the Biden administration.

“Suddenly, what was intended as an operation against criminals could be viewed as a U.S.-authorized cyber operation against a nation-state actor … and potentially trigger retaliation or escalation,” he said.

The memo establishes a national coordination center to be run jointly by the Justice Department and the Department of Homeland Security, which will vet participating companies. The firms could be fined up to $1 million for contract violations.

The order raises questions about potential liability for companies under the Computer Fraud and Abuse Act, which makes it a federal crime to gain unauthorized access to internet-connected computers. If the company is acting as an agent of the U.S. government, it probably would not be bound by this law, some analysts say, but would still have to comply with Fourth Amendment protections requiring a warrant to hack into a domestic system. The order does not directly address this issue.

ADVERTISEMENT

The FBI’s top cyber official says the memo is an effort to normalize what is currently “ad hoc” collaboration between industry and government.

Just last month, for instance, the FBI and Google disrupted a botnet used by hundreds of criminal and nation-state hackers who didn’t want their attacks traced back to Beijing, Tehran and Moscow, and so routed them through at least 2 million proxy IP addresses to TV streaming boxes and home routers, FBI Assistant Director for Cyber Brett Leatherman said in an interview with The Washington Post.

Armed with a court order, the FBI seized hundreds of proxy domains and Google disabled accounts on its own networks that the botnet was using to control the malware.

The presidential memo, he said, is about “providing additional authority and capability” to “empower” U.S. industry in helping the government battle foreign cybercriminals.

Leatherman pointed to the Chinese state-sponsored Salt Typhoon espionage hack, discovered in late 2024, which compromised several of the largest American telecommunications firms and targeted the cellphones of U.S. political figures, including then-presidential candidate Donald Trump and his running mate JD Vance. At least one Chinese company assisted the campaign and was punished by the Treasury Department last year, Leatherman said.

ADVERTISEMENT

China and Russia often leverage private companies to carry off hacks that provide a measure of state deniability.

“They are industry people [in China] that are doing this,” Leatherman said, referring to Salt Typhoon. “If we don’t close the gaps … we’re going to continue to fall behind.”

U.S. agencies such as the FBI, the military’s U.S. Cyber Command and the National Security Agency may legally hack systems overseas. But private-sector companies do not have such independent authority.

Jason Kikta, a former U.S. Cyber Command operator, said using contractors to perform government work “makes us no better than China and Iran,” where, he noted, industry has conducted ransomware operations, attacked U.S. banks and carried out indiscriminate cyberspying operations.

“The U.S. has fought against such abuses for years, and this now makes us look hypocritical,” said Kikta, now chief technology officer at Automox, a cybersecurity firm.

Former military cyber lawyer Gary Corn noted that Cyber Command’s primary focus is on countering foreign nation-state threats – not criminals. The command lacks the numbers and resources to take on the criminal threat. So the administration’s move could help fill that “big gap,” said Corn, who was formerly the command’s top lawyer and now directs American University’s Technology, Law & Security Program.

Former White House aide Curtis, now CEO of the cybersecurity firm 190 Intel, said private companies have tremendous technical capability, data and speed. With the right guardrails, he said, “this could be a very effective way to disrupt criminal networks that are otherwise hard to reach.”

Charlie “Tuna” Moore, a former deputy commander of U.S. Cyber Command, has long called for the government to team with the private sector in conducting cyber offense. “It’s the only way to scale quality and quantity to defend the nation,” said Moore, now a visiting professor at Vanderbilt.

The memo contains a classified annex, which describes how the companies and law enforcement agencies will coordinate their actions with the military and intelligence agencies, a process known as “deconfliction.”

Moore noted that the military and spy agencies have extensive deconfliction rules, and it will be “critical” to see how well thought-out the new process is, he said.

“The overarching approach is very good,” he said. “The devil’s in the details.”

Other News:

  • Contact Us
  • About Us
  • Corrections and Disclosure
  • Privacy Policy
  • Terms & Conditions
  • Contact Us
  • About Us
  • Corrections and Disclosure
  • Privacy Policy
  • Terms & Conditions
© 2026 ChinaTechNews.com. A Service of Asia Media Network.