
A new presidential memo and Senate bill authorize private firms to conduct offensive cyber operations against criminal networks that exploit crypto for fraud and ransomware.
The US government just dusted off one of the oldest tricks in the naval warfare playbook and applied it to cybersecurity.
President Donald Trump signed a National Security Presidential Memorandum on August 12, 2026 authorizing vetted private companies to conduct government-directed offensive cyber operations against transnational criminal organizations, with a particular focus on groups that exploit digital assets for fraud, ransomware, and money laundering.
The NSPM builds on Executive Order 14390, signed March 6, 2026, which established an operational cell within the National Coordination Center to coordinate cybercrime detection and response between federal agencies and the private sector.
Under the framework, participating firms receive legal protections for offensive operations but only under stringent oversight. Every operation requires dual-agency sign-offs – no company freelances its way through someone else's network without multiple layers of federal approval.
Congress is moving in parallel. The Senate introduced S.5000 in July 2026, formally titled the Cyber Letters of Marque and Reprisal Act. The bill would grant the president explicit statutory authority to authorize private entities to conduct cyber operations against foreign threats. The naming is literal: letters of marque and reprisal are referenced in Article I of the US Constitution.
The NSPM's framework targets two primary objectives: recovering stolen funds and dismantling infrastructure that supports crypto-enabled criminal networks. That means going after mixers, fraud operations, ransomware-as-a-service platforms, and exchange networks that facilitate illicit flows.
Neither the NSPM nor S.5000 targets any specific cryptocurrency or token. The framework is technology-neutral, aimed at criminal behavior rather than particular protocols or assets.
The approach marks a shift in US cybersecurity posture. For years the default was defensive: build walls, patch vulnerabilities, monitor for intrusions. This framework explicitly endorses limited offensive measures, bringing the fight to criminal organizations rather than waiting for them to strike.
The Senate bill remains in committee. No date has been set for a floor vote.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.