Trump's latest cyber memo expands the administration's approach to offensive cyber actions by inviting private sector companies to the fight against TCOs.
On August 12th, 2026, President Trump signed a National Security Presidential Memorandum (NSPM), “Expanding Capabilities to Combat Transnational Cyber-Enabled Crime”. The first section of the memo describes Transnational Crime Organizations (TCOs) as “a growing threat to American citizens, businesses, and national security” by using “sustained cyber campaigns to perpetuate frauds that undermine American prosperity, security, and freedom.”
The memorandum praises the US private sector as “the most innovative and technologically advanced in the world,” and argues that this ensures a significant offensive cyber advantage for the United States in the fight against cyber-enabled TCOs (CE-TCOs). The memo orders the National Coordination Center (NCC) to establish, govern and sustain a program to authorize involved companies to “conduct Cyber Surveillance Operations and Cyber Effects Operations” on CE-TCOs. Participating companies will be vetted and commercially contracted by the DoJ or the Department of Homeland Security, and will be required to meet standards on technical proficiency, staff review, cyber operation performance, facility security, skill and ability, along with reliability. Companies large and small may be eligible, as the NCC plans for smaller companies to be used for more discrete missions. Federal and local governments will report CE-TCO threats to companies, who will strategize with the NCC to resolve them.’’
TCOs have been the target of several operations by the US. At the end of 2025, the US worked with the United Kingdom to take down 146 targets in the Prince Group Transnational Criminal Organization, a crime syndicate based in Southeast Asia that conducted cyber fraud on victims all over the world. Then, the Prince Group presented a critical opportunity for intervention, with one estimate from the US government placed the amount of money Americans lost to scams in the region astronomically high: “Americans lost at least $10 billion to Southeast Asia-based scam operations in 2024, a 66 percent increase over the prior year, with scams like those perpetrated by Prince Group TCO being particularly significant.”
Since the Prince Group Bust, the US has continued to combat transnational cyber crime. In April, the Department of Justice (DoJ), the Federal Bureau of Investigation (FBI), the US Secret Service and the Scam Center Strike Force (SCSF) worked together to stop two leaders of a large cyber-fraud operations based in Burma that scammed American victims by forcing their kidnapped employees to impersonate US bank representatives and even NYPD detectives. This crackdown was a clear example of defensive work against cybercrime, but the current administration has indicated that this is not be the only approach they’re willing to take to address the issue.
In March, Trump signed Executive Order 14390, Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens. The directive’s first section condemns TCOs and announces that the US will “counter attacks on Americans with a commensurate response that includes law enforcement, diplomacy, and potential offensive actions.” The inclusion of offensive actions in a cybersecurity context may seem unusual, but is inline with the White House’s cyber policy. The very first policy pillar of Trump’s Cyber Strategy for America, also released in March of this year, declares that the administration “will deploy the full suite of U.S. government defensive and offensive cyber operations” to aggressively stop cyber adversaries and criminal infrastructure. Now, this week’s directive on cyber crime is taking the offensive approach one step further.
The fact sheet for the memorandum uses the impact of TCOs to justify this plan of attack being taken up by the private sector. According to the summary, “73% of U.S. adults have experienced some kind of online scam or attack and 98% of Americans believe scams pose a threat to individuals in the U.S., with two-thirds saying it is a ‘major’ threat”, with over $20.8 billion being lost to cyber crime in 2025. Exploitative crimes can often also cause serious distress, as “one in seven young people who experienced sextortion as a minor reported harming themselves in response to the abuse.” While startling, these statements are supported by the FBI’s most recent Internet Crimes Complaint Center (IC3) report, with vulnerable populations (namely, the elderly) being disproportionately affected by malicious cyber activity.
Cyber effects and cyber surveillance operations are defined in the NSPM, with the former allowing “the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems,” and the latter hinging on infiltrating telecommunications, information, and computer networks “without authorization from the owner or operator or by exceeding authorized access” to gather intelligence, particularly to support cyber effects operations.
This new level of partnership between the US government has been called “a pretty big shift in US cyber policy” by Chris Wysopal, the co-founder of Veracode and a cybersecurity expert with a history of vulnerability research. The news has received a mixed response, with some looking forward to more from the NCC and others criticizing the NSPM. In any case, the next development on the memo (consensus on operating procedures for the program) will be big news in the near future, as the executive directors are meant to provide an update in no more than two months.