The US government just dusted off one of the oldest tricks in the naval warfare playbook and applied it to cybersecurity. On August 12, 2026, President Donald Trump signed a National Security Presidential Memorandum authorizing vetted private companies to conduct government-directed offensive cyber operations against transnational criminal organizations, with a particular focus on groups that exploit digital assets for fraud, ransomware, and money laundering.
From executive orders to Senate bills
The NSPM didn’t materialize out of nowhere. It builds on Executive Order 14390, signed on March 6, 2026, which established an operational cell within the National Coordination Center specifically designed to coordinate cybercrime detection and response efforts between federal agencies and the private sector.
Under the new framework, participating private firms receive legal protections for conducting offensive operations, but only under stringent government oversight. Every operation requires dual-agency sign-offs, meaning no company gets to freelance its way through someone else’s network without multiple layers of federal approval.
Congress is moving in parallel. In July 2026, the Senate introduced S.5000, formally titled the Cyber Letters of Marque and Reprisal Act. The bill would grant the President explicit statutory authority to authorize private entities to conduct cyber operations against foreign threats. The naming isn’t subtle: letters of marque and reprisal are literally referenced in Article I of the US Constitution.
Why the private sector matters here
The NSPM’s framework is designed to channel private sector expertise toward two primary objectives: recovering stolen funds and dismantling the infrastructure that supports crypto-enabled criminal networks. This means going after the mixers, the fraud operations, the ransomware-as-a-service platforms, and the exchange networks that facilitate illicit flows.
Neither the NSPM nor S.5000 targets any specific cryptocurrency or token. The framework is technology-neutral, aimed at criminal behavior rather than particular protocols or assets.
The approach represents a meaningful philosophical shift in US cybersecurity policy. For years, the default posture was defensive: build walls, patch vulnerabilities, monitor for intrusions. This new framework explicitly endorses limited offensive measures, bringing the fight to criminal organizations rather than waiting for them to strike.
Disclosure: This article was edited by Editorial Team. For more information on how we create and review content, see our Editorial Policy.

1 hour ago
11









English (US) ·