Boosting Fight Against Global Cyber Crime

The White House

By the authority vested in me as President by the Constitution and the laws of the United States of America, I hereby direct the following:

Section 1. Purpose. Transnational Criminal Organizations (TCOs) pose a growing threat to American citizens, businesses, and national security. These organizations conduct sustained cyber campaigns to perpetrate frauds that undermine American prosperity, security, and freedom. Through Executive Order 14390 of March 6, 2026 (Combating Cybercrime, Fraud, and Predatory Schemes Against American Citizens), I directed the Federal Government to take various actions to combat cyber‑enabled crime harming American citizens. This memorandum expands the fight against TCO-perpetrated cybercrime by incorporating the ingenuity of the private sector.

The American private sector is the most innovative and technologically advanced in the world, and its scale, speed, and capacity secure a critical offensive cyber advantage for the United States. Yet, American businesses' innovative capabilities have historically been underutilized in efforts to identify and disrupt criminal networks operating in cyberspace. Thus, it is the policy of the United States to use all instruments of national power, including the innovative capabilities of the private sector, to combat cybercrime. By partnering with vetted United States companies subject to the direction and oversight of the Federal Government, we will enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens.

Sec. 2. Establishing the Program. (a) The National Coordination Center (NCC), established pursuant to section 6(d) of Executive Order 14159 of January 20, 2025 (Protecting the American People Against Invasion), shall create, manage, and maintain a Program to authorize Participating Companies, as defined in section 4(f) of this memorandum, to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs), under the control and oversight of the Federal Government. As part of lawful investigatory, protective, or intelligence operations carried out by Federal law enforcement, this Program shall:

(i) be overseen by co-Executive Directors, one from the Department of Justice, designated by the Attorney General, and one from the Department of Homeland Security, designated by the Secretary of Homeland Security (Program Executive Directors). The Program Executive Directors shall be delegated authority to approve, after coordination with each other, cyber operations conducted within the Program by personnel of their respective departments, except that they may not approve operations resulting in Critical Outcomes, as defined in section 4(b) of this memorandum. Cyber operations shall only be approved after coordination between the Program Executive Directors, and any resulting operational action will be exclusively conducted on behalf of and under the supervision of the Federal Government pursuant to the Federal Government's lawful authorities;

(ii) require Participating Companies to enter into contractual agreements with the Department of Justice or the Department of Homeland Security, which shall ensure that Participating Companies undergo rigorous vetting and that their performance adheres to the strict operational procedures outlined in the implementation guidance directed in section 3 of this memorandum; and

(iii) permit Participating Companies to enter into commercial agreements with:

(A) private sector entities, from which the Participating Companies may receive for the purpose of proposing responsive cyber operations to the NCC any threat information collected in the course of those entities' normal business activities; and

(B) Federal, State, local, tribal, and territorial agencies, which will identify CE-TCO threats to the Participating Companies in a manner that enables them to propose cyber operations to the NCC that address those threats.

(b) The NCC shall conduct all Program activities in accordance with the Constitution and all other applicable laws and international obligations of the United States, including section 1030 of title 18, United States Code, thereby ensuring that Participating Companies are acting under the control and oversight of the United States Government.

Sec. 3. Implementing Guidance. (a) Within 60 days of the date of this memorandum, the Program Executive Directors shall, in coordination with the Homeland Security Council, establish consensus operating procedures for the Program that ensure the Federal Government's complete oversight and control of Participating Companies' performance. No operation may be approved unless it complies with these operating procedures. The procedures shall:

(i) establish minimum standards that Participating Companies must meet in order to take part in the Program, which shall include appropriate levels of technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence, reliability, and other factors that the Program Executive Directors, in coordination with the Homeland Security Council, determine are relevant or necessary for guaranteeing high confidence in a Participating Company's ability to perform successfully in the Program;

(ii) ensure that the Program's eligibility criteria enable participation by both large companies, which provide critical capacity, and smaller, more agile companies, which may be better suited for specialized or discrete tasks;

(iii) mandate that Participating Companies disclose to the NCC all contractual relationships entered into pursuant to section 2(a)(iii) of this memorandum;

(iv) authorize the Department of Justice and the Department of Homeland Security to mandate as a condition of their contractual agreements with Participating Companies under section 2(a)(ii) of this memorandum that such companies maintain a bond or escrow in an amount not less than $1 million, to be forfeited should the Participating Company enter non‑compliance with its contractual agreement described in section 2(a)(ii) of this memorandum;

(v) in conformance with the classified annex to this memorandum, set forth the operational workflow of the Program, which shall include operational deconfliction across Federal law enforcement, the Department of State, the Department of the Treasury, the Department of War, the Department of Justice, and the United States Intelligence Community;

(vi) in conformance with the classified annex to this memorandum, provide an adjudicatory framework to ensure operational activity targets only CE-TCOs and accounts for other United States Government equities;

(vii) set forth standardized rubrics and templates for target identification and the creation and processing of Cyber Surveillance and Cyber Effects Operations packages;

(viii) include reporting requirements for Participating Companies that will advance a greater understanding of the activities and impact of foreign CE-TCOs, especially as they relate to the American people and economy, and that will ensure the NCC is fully apprised of the Participating Companies' operational activities;

(ix) include procedures, including a review by the Department of Justice, that ensure any Program activity that is directed at a United States person or otherwise implicates the United States Government's obligations under the Constitution, Federal law, or international law receives any necessary authorization, judicial or otherwise, prior to approval of the operation;

(x) include procedures to ensure that a Participating Company that discovers operational activity exceeding the parameters and restrictions of the cyber operation approved by the Program Executive Directors — such as unintentional targeting of (1) a United States person, (2) an information system residing in the United States, or (3) an information system under the control of a United States person — shall cease such operation, conduct minimization procedures, and immediately notify the NCC, which shall notify the Department of Justice;

(xi) include procedures mandating that Participating Companies immediately notify the NCC, which shall notify the Department of Justice, if they discover an imminent cyber-attack against United States critical infrastructure or develop a reasonable belief that an approved Cyber Effects Operation or Cyber Surveillance Operation may result in Critical Outcomes;

(xii) clarify that Participating Companies may still engage in other lawful defensive cyber operations otherwise permitted to them, but that any activity authorized by the Program must be conducted subject to the oversight, operational control, and legal authorities of the United States Government;

(xiii) include procedures for evaluating each Participating Company for continued participation in the Program on at least an annual basis; and

(xiv) mandate that the Program Executive Directors review every cyber operations package and provide written approval and direction to the Participating Company before action may be taken.

(b) The Program Executive Directors shall regularly assess and continuously improve the Program's operational procedures to maintain effective and efficient execution of the objectives outlined in this memorandum. The NCC shall likewise utilize automation to streamline Program elements wherever appropriate, in accordance with applicable law and the requirements of this memorandum.

(c) The Program Executive Directors shall, within 180 days of the date of this memorandum and annually thereafter, produce a report detailing the status of the Program and submit it to the Assistant to the President and Deputy Chief of Staff for Policy and Homeland Security Advisor and the National Cyber Director.

Sec. 4. Definitions. For purposes of this memorandum:

(a) "Cyber Effects Operation" means activity conducted in or through the interdependent network of information technology infrastructure that includes the Internet, telecommunications networks, computers, information systems, industrial control systems, networks, and embedded processors and controllers that results in the manipulation, disruption, denial, degradation, or destruction of information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon.

(b) "Critical Outcomes." An action will be considered to generate a Critical Outcome if it is likely that it will:

(i) result in the loss of life or serious injury; or

(ii) rise to the level of use of force or armed attack under international law.

(c) "Cyber-Enabled Transnational Criminal Organization (CE-TCO)" means any foreign group that conducts cyber-enabled crime against the United States Government, a United States person, or United States interests, and that is not an institutional part of a foreign government or wholly operated under a foreign government's direction. For the purposes of this memorandum, a foreign group will be assumed not to be an institutional part of a foreign government or wholly operated under a foreign government's direction unless clear intelligence exists establishing such connection.

(d) "Cyber Surveillance Operation" means activities conducted in or through the interdependent network of information systems that includes the Internet, telecommunications networks, computers, information systems, industrial control systems, networks, and embedded processors and controllers for the primary purpose of collecting information or intelligence — including information that can be used for future Cyber Effects Operations — from information systems, networks, physical or virtual infrastructure controlled by information systems, or information resident thereon, with the intent to remain undetected. Cyber Surveillance Operations entail accessing such information systems without authorization from the owner or operator or by exceeding authorized access. Cyber Surveillance Operations include those actions essential and inherent to enabling Cyber Surveillance Operations, such as manipulation or temporary disruption that is not intended to cause physical effects or impact the usability of physical or virtual infrastructure.

(e) "Information system" has the same meaning as it has in section 3502 of title 44, United States Code.

(f) "Participating Companies" means private United States companies that have been accepted into the Program and will be authorized to conduct cyber operations under the direction of the United States Government.

(g) "United States person" has the same meaning as it has in Executive Order 12333.

Sec. 5. General Provisions. (a) Nothing in this memorandum shall be construed to impair or otherwise affect:

(i) the authority granted by law to an executive department or agency, or the head thereof; or

(ii) the functions of the Director of the Office of Management and Budget relating to budgetary, administrative, or legislative proposals.

(b) This memorandum shall be implemented consistent with applicable law and subject to the availability of appropriations.

(c) This memorandum is not intended to, and does not, create any right or benefit, substantive or procedural, enforceable at law or in equity by any party against the United States, its departments, agencies, or entities, its officers, employees, or agents, or any other person.

/Public Release. This material from the originating organization/author(s) might be of the point-in-time nature, and edited for clarity, style and length. Mirage.News does not take institutional positions or sides, and all views, positions, and conclusions expressed herein are solely those of the author(s).View in full here.