Close Menu
Online 24 NewsOnline 24 News
  • Home
  • USA
  • Canada
  • UK
  • Germany
  • World
  • Business
  • Technology
  • Health
  • Lifestyle
  • Entertainment
  • Sports
Trending

Inside Hayden Panettiere’s On-Off Relationship With Brian Hickerson: He ‘Couldn’t Leave Her Alone’ (Exclusive)

August 19, 2026

Cybercrime Enforcement Is Now Open To Private Bidders

August 19, 2026

California congressman left GOP to try to survive redistricting competition

August 19, 2026
Facebook X (Twitter) Instagram
Login
  • For Advertisers
  • Contact
Online 24 NewsOnline 24 News
Join Us Newsletter
  • Home
  • USA
  • Canada
  • UK
  • Germany
  • World
  • Business
  • Technology
  • Health
  • Lifestyle
  • Entertainment
  • Sports
Online 24 NewsOnline 24 News
  • USA
  • Canada
  • UK
  • Germany
  • World
  • Business
  • Technology
  • Health
  • Lifestyle
  • Entertainment
  • Sports
Home»Business
Business

Cybercrime Enforcement Is Now Open To Private Bidders

August 19, 20266 Mins Read
Facebook Twitter Pinterest LinkedIn Copy Link Email Tumblr Telegram WhatsApp

On August 12, a new Presidential Memorandum authorized the federal government to deputize vetted private corporations to conduct activities in support of law enforcement operations against cyber-enabled transnational criminal organizations. It is an innovative answer to a scourge of cybercrime that costs Americans billions of dollars a year. It also creates legal risk that no company has been asked to carry before, and that no court has tested.

According to the White House’s fact sheet accompanying the memorandum, Americans reported losing “over $20.8 billion” to cyber-enabled crime in 2025, including ransomware, phishing, financial fraud, sextortion, and impersonation schemes online. 73% of U.S. adults report having experienced an online scam or attack. Seniors, children, and low-income families are disproportionately targeted. Many of the cyber-enabled transnational criminal organizations (CE-TCOs) behind these scams and attacks originate abroad, and U.S. law enforcement cannot reach them fast enough. Private sector capabilities are better equipped to do so, but they are typically barred by law from touching attackers’ systems. The Computer Fraud and Abuse Act, enacted in 1986, criminalizes accessing a computer “without authorization” and knowingly transmitting code that intentionally causes damage. Its drafters could not have foreseen today’s challenges of combatting cybercrime.

What The Cybercrime Memo Authorizes Private Firms To Do

The memo crafts a framework for private firms to conduct cyber surveillance operations and cyber effects operations against CE-TCOs under federal government contract and supervision. It defines a CE-TCO as “any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests, and that is not an institutional part of a foreign government or wholly operated under a foreign government’s direction.” That definition appears designed to keep participating firms focused on criminal enterprises and out of interstate conflicts.

The National Coordination Center, which the Trump administration initially created for immigration enforcement, will create and manage “the Program.” After rigorous vetting, companies accepted into the Program will be authorized to conduct two types of cyber operations under the contract and direction of the Departments of Justice or Homeland Security. Cyber Surveillance Operations discreetly collect information and intelligence and involve unauthorized access of information systems. Cyber Effects Operations produce “manipulation, disruption, denial, degradation, or destruction” of information systems, networks, or infrastructure. Firms in the Program may receive threat information from other private entities and from federal, state, local, tribal, and territorial agencies, and may propose operations to the NCC. The memo states that the Program will be conducted in accordance with the CFAA, implying that it falls into the Act’s exception for “lawfully authorized investigative, protective, or intelligence activity,” because firms act under government control and oversight.

Some commentators have incorrectly characterized the memo as authorizing cyber letters of marque or privateers. The Constitution grants Congress power to assign letters of marque , not the President. Firms in the Program can propose but do not select their own targets, and require a federal contract and written government approval to operate. Also, Congressional notification and approval are absent from the memo. The Program’s only reporting requirement runs to the Homeland Security Advisor and the National Cyber Director. This will likely raise alarm in a Congress already debating operations in Iran.

The memo includes important safeguards designed to ensure that private firms act lawfully and under government direction. Directors from both the Department of Homeland Security and the Department of Justice must give written approval and direction for every cyber operations package. Directors may not approve operations “likely to result in the loss of life or serious injury” or that “rise to the level of the use of force or armed attack under international law.” All Program activities must occur in accordance with the Constitution and international and U.S. law. Any activity directed at a U.S. person or implicating U.S. legal obligations requires additional authorization. Justice and Homeland Security may also require a bond or escrow of at least $1 million from participating firms, forfeited for any non-compliance.

The Cybercrime Program’s Untested Legal Issues

The memo is an important step in combatting transnational cybercrime. But the CFAA exception it invokes has never been tested in court. It remains unclear whether that exception shields participating firms from liability, and under what circumstances. Neither the CFAA nor state computer crime statutes can be superseded by a DoJ or DHS contract. Anyone suffering damage or loss can still sue, and a Justice Department statement that it will not prosecute firms in the Program is not ironclad.

The line between law enforcement operations and the use of force can be thin. States have never agreed on when cyber operations rise to the level of the use of force or an armed attack. A private-sector operation that destroys property or causes damage at scale, with wide-ranging effects, may be treated by another state as equivalent to an armed attack. If that happens, the United States could be legally responsible for private sector conduct it may never have intended. Attribution and discernment of operational intent also may not be clear to adversary TCOs or states. Misperception of these operations raises potential risk to both the United States and participants in the Program.

Who Pays When Cybercrime Law Enforcement Operations Go Wrong

Employees conducting these operations face additional risk. They do not have sovereign immunity. Damage can occur inside foreign states, and the TCOs they target may well have affiliations with those states. If a foreign state treated these law enforcement operations as armed conflict, the private sector employees running them would not be combatants under international law and would not have POW or other protections. They may also face repercussions or retaliation under foreign hacking laws. A Chinese citizen was recently arrested on vacation in Italy and extradited to the U.S. for allegedly hacking American companies for a Chinese firm. U.S. contractors countering CE-TCOs will likely be considered criminals by other states, and any of them could be at risk when traveling abroad.

Criminal infrastructure runs on commandeered systems, including hospital servers, university networks, and small business routers. The memo says nothing about what happens when private corporations cause collateral damage to those third parties, or who will be responsible for it. Firms may also face reputational risk from participation, along with disclosure and insurance concerns. Nothing addresses what happens when a properly targeted foreign system holds Americans’ stolen data, or what rights those American victims, individual or corporate, have.

Operating procedures are due in 60 days and will likely answer some of these questions. The real test will be in court or in practice. A program that saves Americans from cybercrime will be a great success for public/private partnerships. But the program will need strong safeguards to ensure that a corporation does not accidentally start a war.

Read the full article here

Share. Facebook Twitter Pinterest LinkedIn Email Reddit Telegram
Facebook X (Twitter) TikTok Instagram
Copyright © 2026 YieldRadius LLP. All Rights Reserved.
  • For Advertisers
  • Privacy Policy
  • Terms of use
  • Contact

Type above and press Enter to search. Press Esc to cancel.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?