A new White House memo signed by U.S. President Donald Trump has instructed the National Coordination Center (NCC) to establish a program that would allow private sector companies to take advantage of their "innovative capabilities" to break into foreign Transnational Criminal Organizations (TCOs) and disrupt them.
"By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens," the memo reads.
To that end, the NCC has been tasked with setting up a program that allows authorized companies to conduct two types of operations against TCOs upon obtaining approval: cyber surveillance operations, which can access sensitive data without authorization from the owner or operator, and cyber effects operations, which can result in disruption, denial, degradation, or destruction of information systems, networks, or infrastructure.
The memorandum defines participating countries as private U.S. firms that have been accepted into the initiative and given the green signal to conduct cyber operations under the direction of the United States Government.
Targets include any foreign group that conducts cyber-enabled crime against the U.S. government, a U.S. person, or U.S. interests, and are "not an institutional part of a foreign government or wholly operated under a foreign government's direction" unless there is evidence establishing "such connection."
The program also requires the companies to stop operations that exceed approved parameters and restrictions, such as targeting of a U.S. person, an information system located in the U.S., or an information system located under the control of a U.S. person. In such cases, the companies are required to conduct minimization procedures and immediately alert the NCC, which is then responsible for notifying the Department of Justice.
Earlier this March, the White House announced plans to combat cybercrime, fraud, and predatory schemes carried out by TCOs that target American citizens. These include deploying ransomware and malware, phishing, financial fraud, sextortion, pig butchering scams, and impersonation.
According to an accompanying fact sheet, American consumers have reported an estimated $20.8 billion in losses to cyber-enabled crimes.
"By partnering with vetted U.S. companies, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens," the Fact Sheet said.
The Trump administration's move represents a significant expansion of the private sector's role in offensive cyber operations against U.S. adversaries, although experts opine it comes with several legal and security risks. Existing U.S. laws prohibit private companies from conducting cyber attacks or disruption operations without court authorization.
The development also comes as the German government approved a draft legislation that grants its foreign and domestic intelligence agencies sweeping powers to dismantle hostile servers, disrupt foreign cyber networks, and hack back against state-sponsored hackers, and sabotage adversaries' supply chains.



