The US government just dusted off one of the oldest tricks in the naval warfare playbook and applied it to cybersecurity. On August 12, 2026, President Donald Trump signed a National Security Presidential Memorandum authorizing vetted private companies to conduct government-directed offensive cyber operations against transnational criminal organizations, with a particular focus on groups that exploit digital assets for fraud, ransomware, and money laundering.
From executive orders to Senate bills
The NSPM didn’t materialize out of nowhere. It builds on Executive Order 14390, signed on March 6, 2026, which established an operational cell within the National Coordination Center specifically designed to coordinate cybercrime detection and response efforts between federal agencies and the private sector.
Under the new framework, participating private firms receive legal protections for conducting offensive operations, but only under stringent government oversight. Every operation requires dual-agency sign-offs, meaning no company gets to freelance its way through someone else’s network without multiple layers of federal approval.
Congress is moving in parallel. In July 2026, the Senate introduced S.5000, formally titled the Cyber Letters of Marque and Reprisal Act. The bill would grant the President explicit statutory authority to authorize private entities to conduct cyber operations against foreign threats. The naming isn’t subtle: letters of marque and reprisal are literally referenced in Article I of the US Constitution.












