• Sources: primary
  • Summary: The memorandum, dated 2026-08-12, directs the National Coordination Center to create a programme authorising Participating Companies to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign Cyber-Enabled Transnational Criminal Organizations, with each operation requiring written approval from co-Executive Directors drawn from the Department of Justice and the Department of Homeland Security, who may not approve operations likely to cause loss of life or to rise to the use of force under international law. Participating Companies sign contracts with DOJ or DHS, may be required to post a bond or escrow of not less than 1 million dollars, must cease and report any operation that unintentionally touches a United States person or a system in the United States, and must report imminent attacks on US critical infrastructure. Operating procedures are due within 60 days and a status report within 180 days, the memorandum states that the programme runs in accordance with 18 U.S.C. 1030, and parts of the workflow sit in a classified annex.
  • Why it matters: The statute named is the one private offensive activity would otherwise sit against, so intrusion activity seen abroad may originate from a US programme operating under contract.
  • Follow-up: Track publication of the operating procedures due within 60 days and any named Participating Company.

send feedback on this story