Normal view

The government is recruiting tech companies to help fight its cyber battles

13 August 2026 at 18:58

President Donald Trump is paving a legal pathway for U.S. companies to launch cyberattacks on foreign cybercriminal gangs — a significant and potentially controversial measure that would put approved tech and cybersecurity firms on the front lines of digital combat.

The presidential memorandum, released late Wednesday, comes as the Trump administration has repeatedly pushed for more aggressive action to counter foreign scams and cyberattacks, which the White House said cost Americans nearly $21 billion last year.

The memo represents one of the biggest shifts in U.S. cyber policy undertaken in recent years. It would empower tech and security companies — whose data and control over internet infrastructure often offer unique insight into foreign hacking operations — to mount state-sanctioned digital strikes.

While many such companies already work closely with U.S. intelligence and law enforcement agencies, a web of legal and political constraints has long prevented them from taking direct action inside foreign networks.

Companies that want to participate would be required to sign contracts with both the Department of Justice and the Department of Homeland Security and to undergo what the memo describes as “rigorous vetting” while working with the government. The overall effort would be overseen by a National Coordination Center, established in an earlier Trump administration executive order, with co-executive directors from DOJ and DHS.

However, the memo states that no operations by the companies would be approved until the executive directors at DOJ and DHS establish “consensus procedures” with the White House Homeland Security Council guaranteeing “complete oversight and control of Participating Companies’ performance.”

Those procedures, it notes, should be drafted within 60 days. They are likely to be extensive.

They will outline steps for participating companies to obtain approval for proposed offensive hacking operations, so the government can confirm that the targets are criminal gangs and ensure that operations are consistent with U.S. law and don’t undermine ongoing U.S. intelligence efforts. Companies could propose surveillance operations to help identify criminals or “effects” operations to degrade the systems they use to stage their attacks.

Participating companies would have to pass minimum standards for technical expertise and personnel vetting, and would be required to notify the federal government if they believe approved operations may result in the loss of life or rise to the level of use of force under international law.

Some see the memo as a critical step to help the U.S. government counter foreign cybercriminal gangs that operate outside the reach of U.S. law enforcement.

“For years we’ve called the American technology industry a strategic asset but left it on the cyber sidelines,” Joe Lin, the CEO and co-founder of Twenty, a start-up that builds offensive cyber tools for the U.S. government, said in a statement. “This administration is changing the paradigm.”

The memo notes that companies will only be authorized to target criminals that are “not an institutional part of a foreign government or wholly operated under a foreign government’s direction.”

Even with the help of the U.S. intelligence community, making that distinction could be difficult.

Adversaries such as Russia, China and Iran have persistently targeted U.S. critical infrastructure, including water systems, ports, and telecommunications infrastructure, while multinational crime syndicates have defrauded billions of dollars annually from Americans via complex online schemes.

But many cyber gangs in Eastern Europe are thought to operate with the tacit consent of the Russian government, while state hackers in Iran and China sometimes moonlight as cybercriminals to earn extra money or deflect blame for their governments’ attacks.

More broadly, it is not always easy for digital investigators to determine who is responsible for a given cyberattack, or who different computer networks belong to — another risk the memo contemplates.

Companies that accidentally carry out operations targeting a U.S. citizen or network will be required to immediately pause the operation and notify the U.S. government, the memo states. It does not appear to preclude activities that are deliberately “directed” at a U.S. person, so long as they receive “any necessary authorization, judicial or otherwise, prior to approval of the operation.” Under U.S. law, a “U.S. person” can refer to an American business or organization.

Many lawmakers and security experts have broadly supported calls for the private sector to play a larger role in responding to cybercrime, though not all approve of granting them the ability to launch active hacking efforts.

In recent years, some House members have debated the idea of issuing “letters of marque” to private companies to carry out cyberattacks on behalf of the U.S. government, similar to the U.S. Navy authorizing private ships to disrupt British shipping during the War of 1812.

As part of a more assertive cyber posture, Trump has turned to U.S. Cyber Command to mount digital attacks in tandem with U.S. military operations, including in Iranand Venezuela. He signed an executive order this March to clamp down on countries that fail to take action against scam centers operating within their borders.

That same month, the White House called on the private sector to broadly help it “disrupt” foreign adversaries in its new national cyber strategy, though it stopped short of telling private companies to take riskier and more consequential steps, such as directly launching attacks against foreign criminals.

Some of the most prolific online fraud operations are believed to emanate from scam compounds in Southeast Asia. But hackers from North Korea — who for years have stolen hundreds of millions in cryptocurrency from victims around the world — would likely be exempt from targeting by U.S. companies since they work at the direction of the North Korean government.

DOJ announces new crackdown on Russian disinformation in 2024 election


The Justice Department has seized more than 30 web domains that it said were part of a broader, ongoing, surreptitious effort by the Russian government to influence the 2024 U.S. election and American public opinion, federal authorities announced Wednesday.

The seized sites were linked to a Russian campaign known as “Doppelganger,” one of the most prolific and public campaigns spreading disinformation linked to Moscow in recent years. Experts recently saw evidence of the campaign spreading Russian disinformation related to the failed assassination attempt against former President Donald Trump, and the Biden administration has worked to counter the campaign's efforts in recent months.

The legal actions, which also included the indictment of two Russian employees of the Kremlin-backed media outlet RT, underscored previous warnings this year by the Biden administration that foreign adversaries are looking to interfere in the upcoming vote. The new details about the Russian efforts are likely to increase concerns about continuing interference by foreign governments as the U.S. presidential campaign enters its final stretch.

“The Justice Department's message is clear: We have no tolerance for attempts by authoritarian regimes to exploit our democratic system of government,” Attorney General Merrick Garland said at a press conference announcing the crackdown.

Russia has targeted American elections with disinformation for years, most notably during the 2016 presidential campaign, when Russia was linked to disinformation campaigns designed to sway the vote toward Trump. In response to a reporter’s question, Garland said the Kremlin’s aim has not changed.

FBI Director Christopher Wray said he hopes the countermeasures against the Russian propaganda drive will deter other U.S. adversaries, such as China and Iran, from meddling in the election.

“Knock it off,” Wray said.

Garland added: “We will be relentlessly aggressive in countering and disrupting attempts by Russia and Iran, as well as China or any other foreign malign actor to interfere in our elections and undermine our democracy.”

The 32 seized websites used domain names similar to those for prominent U.S. news sources like The Washington Post and Fox News, but directed unwitting readers to Russian-produced content that typically fueled Russian-government narratives or sought to foment division in the U.S., Garland said. Some were explicitly focused on the upcoming U.S. election, officials said.

“They were fake sites,” Garland said. “They were filled with Russian government propaganda that had been created by the Kremlin to reduce international support for Ukraine, bolster pro-Russian policies and interests and influence voters in the United States and in other countries.”

In addition, the State Department on Wednesday announced it is cracking down on operations of RT’s parent company Rossiya Segodnya and its subsidiary companies, and would be instituting a new visa restriction policy aimed at these groups. It also announced a $10 million reward for information on individuals involved in RT-linked Russian hacking group RaHDit.

The Treasury Department took further steps against the RaHDit group, sanctioning almost a dozen individuals linked to the group, including Aleksey Alekseyevich Garashchenko, a former Russian intelligence official who leads the group. In addition, top figures at RT were sanctioned, including RT Editor-in-Chief Margarita Simonyan.

The Russians dubbed a campaign to influence the U.S. elections in 2024 as “The Good Old U.S.A. Project,” according to a planning document the FBI said it obtained and included in a court filing supporting the seizure. The project’s organizers developed messaging for voters in six swing states, and aimed to use targeted social media advertising to track its impact. A key message of the project, according to the affidavit: “that the US should target their effort towards addressing its domestic issues instead of wasting money in Ukraine and other ‘problem’ regions.”

In addition to the “Doppelganger” domains, the project established look-alike pages on Facebook for major western news outlets, using names like “CNN California” and “California BBC,” U.S. officials said.

The Justice Department alleged that Sergei Vladilenovich Kiriyenko was behind the effort. Kiriyenko is the former prime minister of Russia, and currently is a top official in Russian President Vladimir Putin’s administration, playing a leading role in administering seized Ukrainian territory.

Garland called Kiriyenko a member of Putin’s “inner circle.”

This is not the first foreign interference effort aimed at U.S. elections this year. The announcement came weeks after the Iranian government was linked to a hack and leak operation against the Trump presidential campaign, and after similar targeting of the campaigns of President Joe Biden and of Vice President Kamala Harris was disclosed. On Tuesday night, the accounts of members of Trump’s family on social media platform X were also compromised. 

“Russia is not the only foreign power trying to interfere in our elections,” Garland said. “We have observed increasingly aggressive Iranian activity in this election cycle.”

The Justice Department also announced criminal charges against two Russians, Kostiantyn Kalashnikov and Elena Afanasyeva, accused them of continuing to covertly distribute media sponsored by RT in the U.S. even after that outlet formally shut down its U.S. operations following the Russian invasion of Ukraine in February 2022. That campaign involved placing videos on TikTok, Instagram, X and YouTube, prosecutors said.

An indictment unsealed Wednesday in federal court in Manhattan charges the two Russians with conspiracy to violate the Foreign Agents Registration Act and money laundering.

“While the views expressed in the videos are not uniform, the subject matter and content of the videos are often consistent with the Government of Russia' s interest in amplifying U.S. domestic divisions in order to weaken U.S. opposition to core Government of Russia interests, such as its ongoing war in Ukraine,” the indictment says.

❌