FAULT LINES
Signals That Move Strategy
Rules of the Game · Americas · Cyber

Trump Memorandum Authorizes Private Firms to Conduct Offensive Cyber Operations Against Criminal Networks

The Trump administration released a presidential memorandum Wednesday allowing vetted private companies to conduct offensive cyber operations against transnational criminal organizations, with advance approval required from Justice and Homeland Security departments. Operations targeting cybercrime, fraud, and scams are barred from causing loss of life or rising to the level of armed attack under international law.
AI synthesis, editor-reviewed · 1 source · August 13, 2026
Photo: The Record (Recorded Future)

The memorandum's silence on nation-state entanglement is the operative constraint. State Department evidence already ties Chinese criminal syndicates to PLA-adjacent projects; if DOJ approves operations against those networks, the US has just outsourced offensive cyber operations against Chinese state infrastructure to private contractors operating under thinner legal review than military cyber command would face. The second move: liability cascades to the contractor if a mistaken target or collateral effect surfaces — the memorandum offers no indemnity language, leaving participating firms exposed to civil suits and foreign retaliation claims.

WHY IT MATTERS

Private cyber contractors now have explicit legal cover to conduct offensive operations inside criminal infrastructure — a threshold the US government has historically reserved for itself and military/intelligence agencies.

The DOJ and DHS approval gate theoretically prevents rogue operations, but the memorandum is silent on protocol when targets are entangled with nation-state actors, a condition State Department officials confirmed exists in Chinese organized crime syndicates running Southeast Asian scam centers. Watch whether the first approved operation targets a network tied to a foreign government; if it does, the approval process becomes a proxy for state-level cyber escalation dressed in criminal-enforcement language.

WHAT THIS DOESN’T TELL US

What is the legal definition of 'rise to the level of use of force' in the memorandum — does it include destructive operations on criminal infrastructure (wiping servers, corrupting databases) that cause no direct loss of life, or only kinetic/network-wide disruptions?

Sources: The Record (Recorded Future)
LinkedInX

Fault Lines

Strategic intelligence, synthesized daily — with a public track record. Every call graded against what actually happened.

Front page → Get the weekly brief →