On August 12, the White House signed a national security presidential memorandum that directs the National Coordination Center (NCC) to employ vetted U.S. companies in cyber operations targeting foreign transnational criminal organizations, all under federal oversight. The move is a response to a staggering increase in cybercrime: the FBI logged over one million complaints in 2025, with reported losses hitting $20.9 billion—a 26% jump from the prior year.

While the rationale is clear, the program's most consequential details are still unwritten. The NCC's executive directors have a 60-day window to establish operating procedures, and no operation can be approved until those are in place. The debate over 'hacking back' has long centered on capability—if we can disrupt criminal infrastructure, why not do it? But the harder questions emerge when offensive cyber operations shift from government agencies to private hands.

Read also
Policy
EPA Scraps Power Plant Climate Rules, Opens Door to More Emissions
The Trump administration finalized a rule gutting climate emissions limits for coal- and gas-fired power plants, a move projected to release 123 million extra metric tons of CO2 by 2035.

The appeal is obvious: cybercriminals operate at speed and exploit jurisdictional gaps, and private firms could bring agility and specialized expertise. Yet speed is only one metric of success. Before the first operation gets the green light, the NCC needs clear standards on collateral risk, targeting, intelligence preservation, and accountability.

Cyber infrastructure rarely sits in neat isolation. Taking down a virtual private server used for command-and-control might be hosted on shared infrastructure with legitimate businesses. Even a limited operation could disrupt unrelated organizations—in a worst-case scenario, a hospital or municipal service could be caught in the crossfire. That risk grows once adversaries know offensive operations are coming. Co-tenancy can become a defensive tactic, as criminals intentionally place their infrastructure alongside sensitive targets to make disruption politically and operationally costly. What looks like an accident today could become the adversary's deliberate design tomorrow.

Accountability is another thorny issue. The government authorizes, a private company executes, and if harm follows, it becomes unclear who the affected hosting provider or legitimate business can pursue. Government oversight can reduce some risk but cannot eliminate it. The NCC's procedures should specify who can accept collateral risk, what level of downstream harm is unacceptable, and who bears responsibility when those limits are crossed.

Even when the target is clear, operators face a choice: disrupt immediately or preserve access to gather intelligence and identify the individuals behind the campaign. Historically, patience has paid off. Infrastructure is cheap and easily replaced, but the people running criminal enterprises are harder to remove. A USENIX Security 2025 study found that more than half of the sites seized in one takedown wave returned within a median of one day, while all services seized in a second wave were back within two days. Acting too fast can also destroy evidence that might support arrests or larger coordinated operations.

Artificial intelligence may be shifting that calculation. Cyberattacks can now move and scale faster than ever, while multinational investigations, extraditions, and arrests still move at human speed. If infrastructure is actively causing harm, disrupting it at the moment of discovery may protect more victims than preserving access for an arrest that could take years—or never happen. The NCC's procedures should allow immediate action when the speed and scale of harm demand it, while preserving intelligence whenever possible.

The program could also create a valuable channel for private firms to share information about criminal infrastructure, tactics, victims, and connections across campaigns with government agencies pursuing broader investigations. But the final issue is bigger than any single operation. Russia and China have long benefited from tolerated, state-aligned, or proxy actors that create distance between governments and offensive cyber activity. The U.S. model is not the same as tacitly tolerating criminal hackers, but other governments will study it closely.

Once Washington establishes a framework for private companies to participate in offensive cyber operations, others may adopt the concept without the same safeguards. The NCC should write its rules with reciprocity in mind: Would the U.S. consider the same conduct legitimate if another government authorized one of its companies to carry it out? Success cannot be measured solely by how quickly something is knocked offline. The real challenge is to create rules that account for what an operation might disrupt, what intelligence it might sacrifice, and what precedent it might set before anyone pulls the trigger.