If a private cybersecurity firm wants to "hack back," it first has to put up a bond of at least $1 million, which gets forfeited for any violations. Then it has to wait for two government officials to sign off on paper before making a move. This isn't a scene from some movie — it's the process spelled out in black and white in a National Security Presidential Memorandum that Trump signed on August 12.

The memorandum establishes a program under the Department of Homeland Security's task force National Coordination Center, letting private companies join the fight against cybercrime committed by transnational criminal organizations. According to the purpose section of the document, the White House states this is meant to "leverage private-sector ingenuity to expand the fight against cybercrimes committed by transnational criminal organizations." The program is jointly overseen by executive directors from the Department of Justice and the Department of Homeland Security.

The process itself is more bureaucratic than one might expect: companies must first apply and pass vetting, then post a bond or escrow of at least $1 million, which will be forfeited for any rule violations. Companies can gather threat intelligence from other businesses or state and local agencies, and use it to propose an operational plan to the National Coordination Center — but the plan can only be executed after both executive directors provide written approval and instructions. Operational control remains with the government at all times; companies are merely the hand that pulls the trigger on command.

The "cyber monitoring operations" authorized under the memorandum include accessing systems without the owner's consent or beyond authorized scope, with the focus locked on criminal networks behind ransomware, phishing, financial fraud, and sextortion. The document also draws clear red lines: any action that could cause "significant consequences" is strictly prohibited, and if an operation inadvertently affects U.S. citizens or systems located in the U.S., it must be halted immediately and minimization procedures initiated. As for the actual rules governing targeting, those have been placed in a classified annex that remains out of public view for now; program implementation guidelines are expected within 60 days.

The White House's rationale centers on scale. According to the administration, Americans reported losing more than $20.8 billion to cyber-related crime in 2025, with cryptocurrency scams alone estimated to have caused $80.7 billion in losses. The document also notes that North Korean hackers have developed increasingly sophisticated money laundering methods, and that the government has already seized more than $25 million in cryptocurrency linked to investment fraud and romance scams — cited by the White House as exactly the kind of case where "scaling up private-sector power" could make a difference.

For now, what's been made public about the memorandum focuses mainly on procedures and red lines. Which companies will actually get approved and which networks will be targeted remains to be seen, pending the classified annex and implementation guidelines expected in 60 days.