On August 12, 2026, the Administration published a National Security Presidential Memorandum (“NSPM”) (“Expanding Capabilities to Combat Transnational Cyber-Enabled Crime”) that signals the Administration’s focus on private-sector participation in offensive cyber operations by establishing a federally supervised program to enable private sector participants to conduct offensive cyber operations against “Cyber-Enabled Transnational Criminal Organizations” (“CE-TCOs”).
The NSPM follows Executive Order 14390, which, together with the U.S. National Cybersecurity Strategy, demonstrated the U.S. government’s continued focus on disrupting foreign cyber-enabled criminal organizations that engage in fraud, scams, and related cyber-enabled schemes. The NSPM, which states that “it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime,” signals a potential shift in the U.S. government’s approach to offensive cyber operations by non-government actors. At the same time, the NSPM makes clear that any such operations would be conducted only after U.S. government vetting and authorization, under federal coordination and oversight, and consistent with U.S. law. This post summarizes the NSPM and identifies practical takeaways for private-sector entities that may be considering whether to participate in the program. Additional implementation guidance is expected by mid-October 2026 (60 days after the NSPM publication).
Continue Reading White House Releases National Security Presidential Memorandum on Expanding Capabilities to Combat Transnational Cyber-Enabled Crime