Cybersecurity & Tech

Trump's Private Hacker Memo Is the Right Idea

Tom Uren
Friday, August 21, 2026, 8:00 AM
The latest edition of the Seriously Risky Business cybersecurity newsletter, now on Lawfare.
President Trump signs the 2018 Cybersecurity and Infrastructure Security Agency Act. (Official White House Photo by Joyce N. Boghosian, https://tinyurl.com/3bpk8cvz; Public Domain).

Trump's Private Hacker Memo Is the Right Idea

The U.S. government’s plan to enlist private-sector hackers to target cybercriminals is controversial, but it addresses a real problem and is surprisingly measured.

Last week, a presidential memo directed the Department of Homeland Security to establish a program authorizing private companies to conduct cyber operations against so-called cyber-enabled transnational crime organizations or CE-TCOs. The memo sets out the broad shape of the arrangement, and a classified annex further details the logistics.

The huge policy shift here is that private companies will be authorized to conduct cyber operations that were previously restricted to government entities. This includes what the memo calls "cyber surveillance" (intelligence gathering operations) and "cyber effects" operations (intended to manipulate or to cause disruption).

While the vibe of the initiative is consistent with President Trump's preference for the unrestrained use of state power, the memo itself is unexpectedly measured. Rather than recruiting the private sector to help with all of America's hacking needs, it identifies a current capacity gap where private-sector involvement would be helpful: CE-TCOs.

Defined as foreign groups conducting cyber-enabled crime against U.S. persons or interests that are not part of, or operated by, a foreign government, CE-TCOs are doing a huge amount of harm to the American people particularly via a variety of scams.

To date, traditional policing approaches have had limited impact on these crimes, so the government has increasingly turned to disruption and cyber operations. These have had some success, but the government's capacity to carry out these operations is constrained. The FBI can tackle only the highest-priority groups, the National Security Agency is focused on foreign intelligence, and U.S. Cyber Command is concerned with the nexus between warfare and cyber.

That means there are still hundreds of uncontested cybercrime groups fleecing Americans. There is plenty of room for more players to tackle this problem.

There are many cybercriminal groups with a potential target on their heads, and the process the memo describes for identifying CE-TCOs to go after is troublingly broad. They can be identified by either private-sector entities or by any "federal, state, local, tribal, and territorial" agency. We think it makes more sense for only agencies that help respond to scams or cybercrime to have authority to nominate CE-TCOs as targets.

Still, there are mechanisms in place to ensure operations aren't carried out recklessly.

For a start, companies involved will be vetted by the Department of Justice or the Department of Homeland Security before being permitted to participate in the program. They will need to demonstrate "appropriate levels of technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence, reliability, and other factors." With any luck this will mean fly-by-night opportunists will be excluded. [Will such assessments be performed on an ongoing basis?]

Operations must also be approved by the government before they are executed. It's up to the participating companies to develop their own cyber operations packages. These will then be assessed by program directors at the Department of Justice and the Department of Homeland Security. They'll review whether the proposed operations would interfere with other U.S. government activities, kill anyone, or be equivalent to an armed attack according to international law.

Participating companies will also have to provide a $1 million bond that will be forfeited if they break the conditions of their contracts.

Sounds reasonable so far.

Critics, however, are concerned about the possibility of these private actors accidentally hacking a foreign government, which in turn could trigger some sort of escalation or retaliation. This increases the possibility that foreign governments might target employees of the companies involved in the program.

We think these fears are overblown.

Although policymakers have worried about escalation from cyber incidents, even the most damaging of cyberattacks, the WannaCry and NotPetya worms, did not result in any significant problems for the perpetrating governments.

The U.S. government, particularly the intelligence community, also has incentives to make sure that proposed private-sector operations do not target foreign government entities. It wants to make sure that licensed hackers don't accidentally interfere with its own operations, so it will pay attention to make sure there are no conflicts.

It is true that there is often some overlap between criminals and the state in countries like Russia and China. But we doubt that any government will complain if its activities are impacted because criminals in its country were hacked.

As for the possibility that other governments will target people involved in these operations, that can be addressed with good operational security.

The fact sheet that accompanies the memo says Americans lost more than $20.8 billion to cyber-enabled crime in 2025. Given this loss, the government absolutely should be looking for innovative ways to bolster its capacity to counter these crimes.

There are things the memo doesn’t address that still need to be answered, however, like why companies would want to get involved in this program in the first place. When they have to stump up a $1 million bond, there are presumably good profits to be had. What's not clear is who pays and where exactly the money comes from.

This brings us to reporting requirements. As it stands, the memo requires the Department of Homeland Security to provide an annual report to just two government officials: Assistant to the President and Deputy Chief of Staff for Policy and Homeland Security Adviser Stephen Miller and National Cyber Director Sean Cairncross.

The Trump administration has identified a capacity gap in the fight against cybercriminals and has a plan to fill it. That's a good start, and we think the benefits of this program outweigh its potential risks. At the same time, however, it is a dramatic change in government cyber policy and there should be more oversight into how the program is operating, what it is achieving, and how it is being funded. Is it providing an acceptable return on investment, and what could make it better? We hope we learn enough about the program to be able to answer these questions.

Ukraine's Latest Hacking Campaign Is a Propaganda Win

This week the Record reported the GUR, Ukraine's military intelligence directorate, claimed it had carried out a cyberattack to amplify the effects of kinetic attacks against Russia’s largest online marketplace, Wildberries. The claims are overblown. But it is great propaganda.

The GUR said the operation was carried out in cooperation with the Cyber Corps, a purportedly pro-Ukraine civilian hacker group, and affected Wildberries' customer service, contact centers and payment infrastructure. It claimed the cyberattack took place on the same night as drone strikes against a Wildberries warehouse in Voronezh, in southwestern Russia.

We've argued previously that disruptive cyber operations need to be carefully orchestrated with kinetic operations to maximize their impact. So to hear the GUR saying that its exact goal was to use cyber operations to amplify kinetic attacks was music to our ears.

It wouldn't be Seriously Risky Business without a "but," though. As far as we can tell, these cyberattacks didn't do anything at all to help or amplify the kinetic attacks. It targeted Wildberries, sure. But its impact was additive and annoying rather than having any enabling or amplifying impact.

When comparing this attack with recent military actions, where cyber operations enabled or reduced the risk of carrying out conventional strikes, we're left wanting … much more.

Take, for example, the 2025 strikes against Iranian nuclear facilities. U.S. Cyber Command reportedly helped blind Iranian air defense systems. Earlier this year, the capture of Venezuelan President Nicolás Maduro was facilitated by switching off streetlights so that American forces could operate under the cover of darkness. And the decapitation strike against Iran's Supreme Leader Ali Khamenei was aided by an operation that disrupted nearby mobile phone towers so that his protection detail could not receive warning of an impending attack.

In each of these cases, the cyber element enabled or reduced the risk of carrying out conventional components of the strikes.

By contrast, Ukrainian drone strikes have been targeting Wildberries facilities since mid-July this year and have disabled seven of the company's 10 facilities, according to Ukraine's defense ministry. The impact of using cyber to disable call centers or payment systems pales in comparison to the lasting damage of bombs.

Cyber operations may not have amplified any kinetic one here, but that doesn't mean it was for nought. In fact, we think the exact opposite is happening here. A successful drone strike is being used to amplify the psychological impact of a cyberattack.

The notional justification for Ukraine's attacks on Wildberries is that it sells a range of dual-use goods including navigation systems, components for drones, and supplies for the Russian army. Perhaps more importantly, though, as with attacks on Russian oil refineries, it helps highlight the costs of the war to ordinary Russians.

In this case, it is the psychological impact that is important. And even just saying that cyberattacks and drone strikes amplified each other is great propaganda.

Three Reasons to Be Cheerful This Week:

  1. German bank hackers caught: German and Brazilian authorities cooperated to arrest members of a group that allegedly stole more than 30 million euros from German online banking customers. German federal police say the group exploited a vulnerability in the systems of a payment service provider and stole the funds within just a few days in November 2023.
  2. 94 scam centers shut down in Ukraine: Ukraine's cyber police disrupted the scam centers after carrying out more than 400 searches. Authorities seized more than $2 million and over 3,300 computers.
  3. Cryptocurrency exchange sues North Korea: The Bybit cryptocurrency exchange has announced it has filed a civil lawsuit against the North Korean government and its Reconnaissance General Bureau, the intelligence agency responsible for state-sponsored crypto hacking. North Korea stole $1.5 billion from Bybit last year, and the company has obtained an injunction freezing some of the stolen funds from being moved. Bybit has recovered $48 million of the stolen funds and frozen a further $30 million. We don't know how much joy they'll get from the suit, but we enjoy seeing novel strategies being pursued.

Risky Biz Talks

In our latest "Between Two Nerds" discussion, Tom Uren and The Grugq discuss "The Offence Death Cycle," a paper looking at how to take advantage of a defender’s ability to control a network to discover intruders.

From Risky Bulletin:

Slovakia finds Russian backdoor in traffic speed cameras: Slovakia's national security service NBU has issued a security alert against the use of NERO R-ONE high-speed traffic cameras.

The agency says the cameras contain a backdoor mechanism that will execute malicious code received via an SMS from a list of hard-coded Russian phone numbers.

The NBU started an investigation into the devices after multiple reports in Slovak media that the cameras were bought with a no-bid direct contract from a Cyprus shell company with fake certifications.

[more on Risky Bulletin]

The EU publishes its upcoming cybersecurity standards: The European Telecommunication Standards Institute has released 17 cybersecurity standards that vendors will have to follow to sell products in the EU when the EU Cyber Resilience Act (CRA) enters into effect in December 2027.

The standards cover 17 core technologies for major product categories including operating systems, routers, firewalls, virtual private networks, browsers, and password managers.

The standards describe a list of minimum security features each product category must implement to be CRA-compliant. Most of the standards usually require the same basic features, such as the ability to update the product once it's sold, that devices are sold with a software bill of materials, that they use modern cryptography, or that they ship with secure-by-default settings.

[more on Risky Bulletin]

AI agents had turf wars: Anthropic says agents "consistently" engaged in a turf war when they received the same tasks. Agents deployed self-replicating malware, locked rival accounts, and deployed scripts that ran in a loop to disable a competing agent's processes. Anthropic says the newer models like Mythos won by revoking rivals' access first and then negotiating truces. [Anthropic]


Tom Uren writes Seriously Risky Business, a big-picture, policy-focused cyber security newsletter. He also co-hosts the Seriously Risky Business and Between Two Nerds podcasts that appear on the Risky Business News feed. He was formerly a Senior Analyst in the Australian Strategic Policy Institute's (ASPI) Cyber Policy Centre where he contributed to various projects including on offensive cyber capabilities, information operations, the Huawei debate in Australia and end-to-end encryption.
}

Subscribe to Lawfare