I once watched a red team engagement go sideways because someone forgot to scope out a shared hosting provider. We took down three unrelated small businesses along with the actual target. That was an authorized pentest, on a network we controlled, with lawyers on speed dial. Now imagine that same energy, except the target is a ransomware crew in a jurisdiction with no extradition treaty, the attacker is a private contractor chasing a government contract, and the blast radius includes servers you've never heard of.
That's basically what the White House just signed off on.
A National Security Presidential Memorandum issued August 13, 2026 creates a federal program letting vetted private security firms run "Cyber Surveillance Operations" and "Cyber Effects Operations" against foreign cybercriminal groups. Not nation-states — the memo specifically excludes groups wholly controlled by a foreign government, though it also says a group is presumed eligible unless intelligence proves otherwise. That's a hell of a presumption to build an offensive operation on.
The mechanics, as reported:
- Oversight runs through DOJ and DHS, coordinated by the National Coordination Center under the Homeland Security Task Force
- Targets include ransomware, sextortion, phishing, financial fraud, and impersonation scams
- Firms must post a $1 million escrow or bond, forfeitable for violations
- Any operation that touches a U.S. person triggers extra DOJ review and requires the firm to stop and report immediately
On paper this sounds like capacity-building. The government's pitch is that criminal groups cost Americans tens of billions annually, and private firms bring specialized tradecraft the FBI doesn't have bandwidth for. Fine. I don't dispute the problem is real — Uber, Zillow, Levi Strauss, Blackstone, CME, and multiple law firms have all eaten cybercrime losses in the last few years. But there's a massive gap between
