Trump Unleashes Private Hackers on the Foreign Scammers Robbing Americans

Image Credit: The Trump White House - Public domain/Wiki Commons

On August 12, President Donald Trump signed a national security memorandum that does something no American president had been willing to do before: it authorizes vetted private companies to go on offense in cyberspace, breaking into and disrupting the foreign criminal networks that have spent years draining Americans’ bank accounts. For decades, “hacking back” was treated as a line Washington would not let the private sector cross, out of fear that a company’s counterstrike could spark a confrontation with a foreign government. Trump just erased that line.

The directive builds a formal, government-run program that turns America’s most powerful asset, its technology industry, against the ransomware crews, romance-scam rings, and sextortion operations that run their schemes from overseas and cash out at the expense of retirees, children, and working families. Critics are already calling the newly empowered firms “cyber privateers.” Supporters see something simpler: a long-overdue decision to point the country’s sharpest weapon at the criminals who have been robbing its most vulnerable citizens with something close to impunity.

Inside the program Trump just created

The memorandum orders the Homeland Security Task Force’s National Coordination Center to build a program, run by two Executive Directors, one from the Department of Justice and one from the Department of Homeland Security, that can authorize private companies to hit foreign criminal networks, according to the White House fact sheet. Companies that clear the vetting become “Participating Companies,” and they are cleared to carry out two kinds of missions against what the order calls Cyber-Enabled Transnational Criminal Organizations.

The first, a “Cyber Surveillance Operation,” lets a company quietly break into a criminal network’s systems to collect intelligence, including the information needed to plan a follow-up strike. The second, a “Cyber Effects Operation,” goes further, authorizing the “manipulation, disruption, denial, degradation, or destruction” of the criminals’ systems and data, the text of the memorandum states. In plain terms, a private American firm can now be deputized to wipe out the servers a scam operation runs on, provided the government signs off first.

The guardrails that keep it from becoming a free-for-all

The memo is not a blanket license for corporations to start shooting back on their own. It creates no general right to retaliate. Every single operation has to receive written pre-approval from the two federal directors, aimed at a specific target, before a company may act, and the whole effort is meant to run “on behalf of and under the supervision of the Federal Government.” Participating firms must post a bond or escrow of at least $1 million that they forfeit if they break their contract, and the directors are barred from approving any operation likely to cause what the order calls “Critical Outcomes,” meaning the loss of life or anything rising to the level of an armed attack under international law.

The order also carves out hard protections for Americans. If a company’s operation strays onto a U.S. person or a computer inside the United States, it must stop, minimize what it collected, and immediately alert the government. Any activity that touches a U.S. person requires separate legal authorization, judicial or otherwise, and the Justice Department reviews it. Every participating company gets re-evaluated at least once a year. So while the headline is that Trump has turned private hackers loose, the fine print keeps them on a short government leash, a distinction the administration is clearly betting will survive the inevitable court challenges.

The $20 billion behind the decision

The scale of the theft is what the White House is leaning on to justify the shift. American consumers reported losing more than $20.8 billion to cyber-enabled crime in 2025 alone, and roughly 73 percent of U.S. adults say they have been hit by some kind of online scam or attack. The people getting hurt worst are exactly the ones least able to absorb it: the administration says seniors, children, and low-income families are disproportionately targeted, with scammers “draining life savings” and “stealing the benefits of years of work.” The fact sheet notes that among young people who suffered sextortion as minors, one in seven reported harming themselves in response.

Those are the numbers conservatives have spent years pointing to while the federal response stayed largely defensive, focused on warning victims after the money was already gone. The argument running through the memorandum is blunt: the criminals adapted faster than the bureaucracy, the “absence of meaningful consequences” let the networks thrive, and the only institution with the speed and skill to change that equation is the private sector the government had been keeping on the sidelines.

Why no president would touch this before

The reason earlier administrations refused to authorize private hack-back was fear of blowback. A company that misidentifies its target, or that strikes infrastructure a hostile state considers its own, could hand Washington a diplomatic crisis it never chose. That worry is why the practice was effectively forbidden and why the new program has drawn immediate warnings that it could escalate conflicts or invite mistakes, with skeptics reaching for the “privateer” label to compare the firms to the state-sanctioned raiders of an earlier century, as CNN reported.

The memorandum tries to blunt that criticism by drawing its targets narrowly. It applies only to foreign groups that are not “an institutional part of a foreign government” or operating under a government’s direction, and it assumes a group is fair game unless clear intelligence ties it to a state. Whether that line holds up in practice is the open question, but the political calculation is not subtle. Trump is betting that voters who have watched foreign crooks empty their neighbors’ accounts will take a president willing to hit back over one who stays cautious, and that the “first in U.S. history” framing, as TechCrunch described it, reads as strength rather than recklessness.

One more front in a wider crackdown

The memorandum did not arrive in a vacuum. It expands an executive order Trump signed in March directing the government to go after cybercrime, fraud, and predatory schemes aimed at American families, and it slots in alongside the TAKE IT DOWN Act, the law targeting online sexual extortion and deepfake abuse that produced its first conviction in April 2026. The administration ties the whole effort to a broader claim that crime is falling on its watch, pointing to record-low murder rates and steep declines in violent crime through the first half of 2026.

The politics of it are straightforward. For years, cyber fraud was the crime that seemed to have no cop on the beat, a threat that generated warnings and press releases while the money kept flowing overseas. By deputizing private industry to strike back, Trump has reframed a technical policy fight as a question of nerve: whether the country is willing to let its best hackers hunt the criminals preying on its grandparents, or whether it will keep filing complaints after the fact. The critics will get their day in court. In the meantime, the president has planted a flag on the offensive side of a war the government spent a decade fighting on defense.

This article was produced with the assistance of AI tools and reviewed by an editor before publication.

Leave a Reply

Your email address will not be published. Required fields are marked *