Skip to main content
Cyber DoctrinePolicy ShiftAug 12, 2026, 10:20 PM· 4 min read· #1 of 2 in defense security

Trump Authorizes Federal Law Enforcement to Use Cyber Tools Against Transnational Criminal Organizations

President Trump has signed a National Security Presidential Memorandum empowering federal law enforcement to conduct cyber operations against foreign criminal networks. The directive also establishes a framework for private sector companies to propose and assist in these operations under U.S. government oversight.

By Layla Zaher

Law Enforcement & Policy Makers 40%Financial & Corporate Sector 35%International Legal Observers 25%
Law Enforcement & Policy Makers
Advocates for aggressive disruption of criminal networks using all available national instruments.
Financial & Corporate Sector
Focuses on mitigating financial losses and leveraging private intelligence for active defense.
International Legal Observers
Emphasizes the complexities of sovereignty, international law, and the risks of public-private offensive operations.

At a glance

  • President Trump signed an NSPM authorizing federal law enforcement to use cyber tools against foreign criminal organizations.
  • The directive tasks the National Coordination Center with overseeing specific disruptive cyber operations.
  • Private sector companies are encouraged to share intelligence and propose operations under strict U.S. government control.
  • The policy shift follows a March 2026 executive order addressing $12.5 billion in cyber-enabled fraud losses.
  • The move expands offensive cyber capabilities beyond traditional military and intelligence agencies.

Why it matters now

By allowing domestic law enforcement agencies to conduct offensive cyber operations and formally integrating private sector capabilities, this directive fundamentally alters how the U.S. responds to cybercrime. It signals a shift from treating ransomware and financial fraud purely as criminal matters to treating them as national security threats requiring active disruption.

In 2024, American consumers reported losing more than $12.5 billion to cyber-enabled fraud, a figure that catalyzed a fundamental rethinking of how the United States defends its digital borders. On August 12, 2026, President Donald Trump signed a National Security Presidential Memorandum (NSPM) that structurally alters the federal response to this financial drain. The directive empowers U.S. federal law enforcement agencies to deploy offensive cyber tools to disrupt Transnational Criminal Organizations (TCOs) operating in foreign jurisdictions.[1][4]

Traditionally, the deployment of offensive cyber capabilities has been tightly restricted to military and intelligence nodes, primarily U.S. Cyber Command and the National Security Agency. Law enforcement agencies like the Department of Justice (DOJ) and the Department of Homeland Security (DHS) have historically focused on investigation, indictment, and defensive resilience. By authorizing these civilian agencies to conduct specific cyber operations abroad, the administration is effectively blurring the line between national defense and criminal justice.[1][2]

The operational hub for this new framework is the Homeland Security Task Force's National Coordination Center (NCC). According to the White House, the NCC is now tasked with creating a dedicated program to execute these disruptive operations. The program will be overseen jointly by executive directors from both the DOJ and DHS, ensuring that operations meant to dismantle foreign criminal networks remain tethered to law enforcement objectives rather than purely military ones.[1][3]

A central pillar of the NSPM is its formal integration of the private sector into state-directed cyber operations. The memorandum establishes a framework encouraging private companies to enter into agreements with federal, state, local, tribal, and territorial agencies. Through these agreements, corporate entities can share threat intelligence regarding TCOs and actively propose cyber operations to address those threats.[1][3]

The NSPM establishes a framework for private companies to propose cyber operations under government direction.
The NSPM establishes a framework for private companies to propose cyber operations under government direction.

This public-private synthesis acknowledges a structural reality of the modern internet: the American private sector owns and operates the vast majority of the infrastructure where these attacks occur. By leveraging corporate scale, speed, and technical capacity, the directive aims to secure an offensive advantage. However, the NSPM explicitly mandates that any resulting cyber operations must be conducted strictly under the direction, control, and authority of the U.S. government.[1]

By leveraging corporate scale, speed, and technical capacity, the directive aims to secure an offensive advantage.

The groundwork for this memorandum was laid earlier in the year. In March 2026, the administration issued Executive Order 14390, titled "Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens." That order directed federal agencies to produce a comprehensive action plan targeting the criminal groups responsible for ransomware, phishing, and financial extortion. It also mandated the creation of an operational cell within the NCC to coordinate these efforts.[4][5][6]

The March executive order identified TCOs as the primary architects of these sophisticated campaigns, noting that such networks often operate with the willing or tacit support of foreign regimes. The financial networks and shadow economies sustained by identity theft and exploitative labor practices have grown too complex for traditional extradition and prosecution models, necessitating a more active disruption strategy.[6][7]

The targets of these new authorities are highly organized syndicates that have evolved far beyond traditional organized crime. Modern TCOs exploit legitimate institutions for critical financial services, utilizing darknet drug trafficking, cyber-facilitated bank embezzlement, and mass ransomware deployment. The administration has emphasized that these groups disproportionately target vulnerable populations, including seniors and low-income families, draining life savings and disrupting critical infrastructure.[1][7]

Law enforcement agencies will now have access to offensive cyber tools traditionally reserved for military and intelligence units.
Law enforcement agencies will now have access to offensive cyber tools traditionally reserved for military and intelligence units.

Implementing this directive requires navigating complex international legal frameworks. Conducting cyber operations in foreign jurisdictions—even against non-state criminal actors—raises questions of sovereignty and international law. The NSPM directs the program's executive directors and the Homeland Security Council to establish rigorous review procedures to ensure that all operations comply with the U.S. Constitution and applicable international agreements.[1][6][8]

Furthermore, the administration's broader cyber strategy emphasizes using diplomatic channels alongside these new offensive tools. The State Department has been directed to engage with foreign governments to enhance cooperation with U.S. law enforcement. When nations provide safe haven to cybercriminals, the U.S. framework now includes potential measures such as limiting foreign assistance, imposing targeted sanctions, applying trade penalties, or expelling complicit foreign officials.[6]

The directive follows reports of massive financial losses to cyber-enabled fraud, which catalyzed the policy shift.
The directive follows reports of massive financial losses to cyber-enabled fraud, which catalyzed the policy shift.

The integration of private companies into offensive operations also introduces domestic regulatory challenges. The government must carefully manage these partnerships to prevent vigilantism or unauthorized "hack back" operations by private entities. The requirement that all actions remain under strict U.S. government direction is designed to mitigate this risk, ensuring that corporate innovation is harnessed without delegating state authority.[1]

Ultimately, the NSPM represents a systemic pivot in U.S. cybersecurity policy. By equipping law enforcement with tools previously reserved for the military and formally deputizing private sector intelligence, the administration is constructing a more aggressive, distributed architecture for combating transnational crime. The success of this model will depend on the NCC's ability to synchronize these disparate nodes into a cohesive operational force.[1][2][3]

Terms to know

National Security Presidential Memorandum (NSPM)
A directive issued by the President to manage policy and direct the actions of the executive branch regarding national security matters.
Transnational Criminal Organizations (TCOs)
Organized groups operating across international borders that engage in illegal activities, including cybercrime, financial fraud, and trafficking.
National Coordination Center (NCC)
A federal operational hub tasked with synchronizing the government's response to cyber threats and coordinating with the private sector.
Offensive Cyber Operations
Active measures taken in cyberspace to disrupt, degrade, or destroy the capabilities of an adversary or criminal network.

The backstory

  1. March 2026

    President Trump signs Executive Order 14390, directing agencies to develop an action plan against cybercrime and establishing an operational cell within the NCC.

  2. August 12, 2026

    The administration issues a National Security Presidential Memorandum authorizing law enforcement to conduct offensive cyber operations and integrating private sector proposals.

Different angles

Federal Law Enforcement

Agencies view the new authorities as necessary to combat untouchable criminal networks.

For the Department of Justice and the Department of Homeland Security, the NSPM addresses a long-standing operational bottleneck. Traditional law enforcement relies on indictments and extradition, tools that are largely ineffective against cybercriminals operating from non-extradition jurisdictions or state-sponsored safe havens. By gaining the authority to actively disrupt these networks—taking down servers, seizing cryptocurrency wallets, and dismantling botnets—agencies argue they can finally impose tangible costs on Transnational Criminal Organizations rather than merely investigating them after the fact.

Private Sector Security Firms

Cybersecurity companies see an opportunity to operationalize their threat intelligence.

Private cybersecurity firms possess unparalleled visibility into global network traffic and threat actor behavior, often identifying campaigns long before government sensors do. For these entities, the NSPM offers a legal and structured pathway to move beyond passive defense. By proposing operations to the National Coordination Center, companies can see their intelligence translated into active disruption. However, industry leaders are also cautious about the liability and retaliation risks associated with participating in state-directed offensive operations.

International Law Analysts

Legal experts raise concerns regarding sovereignty and the escalation of cyber norms.

Scholars of international law point out that conducting disruptive cyber operations in foreign jurisdictions—even against criminal groups—inherently violates the sovereignty of the host nation. While the U.S. argues these actions are justified when host nations are unwilling or unable to police their own territory, analysts warn this sets a precedent that other nations might exploit. Furthermore, the integration of private companies into these operations blurs the distinction between state actors and civilians under international conflict norms, potentially complicating the legal status of participating corporations.

Still unresolved

  • The specific technical thresholds that will trigger a government-directed cyber operation against a foreign target.
  • How foreign nations will respond legally and diplomatically to U.S. law enforcement conducting operations within their networks.
  • The exact liability protections afforded to private sector companies that participate in these joint operations.

Questions readers ask

Why is law enforcement getting offensive cyber tools?

Traditional law enforcement relies on indictments and extradition, which are often ineffective against cybercriminals in foreign safe havens. Offensive tools allow agencies to actively disrupt criminal infrastructure.

Can private companies now 'hack back' against attackers?

No. The directive allows private companies to propose operations and share intelligence, but any active cyber operations must be conducted strictly under the direction and authority of the U.S. government.

What kind of crimes are being targeted?

The directive targets large-scale cyber-enabled fraud, including ransomware attacks, phishing campaigns, and financial extortion run by transnational criminal organizations.

Sources

Source coverage

8 outlets

3 viewpoints surfaced

Law Enforcement & Policy Makers 40%Financial & Corporate Sector 35%International Legal Observers 25%
  1. [1]The White HouseLaw Enforcement & Policy Makers

    THWARTING CYBER CRIMES: Today, President Donald J. Trump signed a National Security Presidential Memorandum (NSPM)

    Read on The White House
  2. [2]Breaking The NewsLaw Enforcement & Policy Makers

    Trump signs NSPM to allow law enforcement to use cyber tools

    Read on Breaking The News
  3. [3]DevdiscourseLaw Enforcement & Policy Makers

    U.S. President Donald Trump issued a memorandum empowering federal law enforcement

    Read on Devdiscourse
  4. [4]Texas Bankers AssociationFinancial & Corporate Sector

    Trump signs executive order to fight cybercrime

    Read on Texas Bankers Association
  5. [5]American Bankers AssociationFinancial & Corporate Sector

    President Trump today signed an executive order directing federal law enforcement agencies

    Read on American Bankers Association
  6. [6]FreshfieldsFinancial & Corporate Sector

    Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens

    Read on Freshfields
  7. [7]Department of JusticeLaw Enforcement & Policy Makers

    Transnational Criminal Organizations (TCOs)

    Read on Department of Justice
  8. [8]Eversheds SutherlandInternational Legal Observers

    Policy changes on Security and National Defense

    Read on Eversheds Sutherland

Comments

Stay informed

Every angle. Every day.

Get defense security stories with full source coverage and perspective breakdowns delivered to your inbox.