On August 12, a new Presidential Memorandum authorized the federal government to deputize vetted private corporations to conduct activities in support of law enforcement operations against cyber-enabled transnational criminal organizations. It is an innovative answer to a scourge of cybercrime that costs Americans billions of dollars a year. It also creates legal risk that no company has been asked to carry before, and that no court has tested.
According to the White House’s fact sheet accompanying the memorandum, Americans reported losing “over $20.8 billion” to cyber-enabled crime in 2025, including ransomware, phishing, financial fraud, sextortion, and impersonation schemes online. 73% of U.S. adults report having experienced an online scam or attack. Seniors, children, and low-income families are disproportionately targeted. Many of the cyber-enabled transnational criminal organizations (CE-TCOs) behind these scams and attacks originate abroad, and U.S. law enforcement cannot reach them fast enough. Private sector capabilities are better equipped to do so, but they are typically barred by law from touching attackers’ systems. The Computer Fraud and Abuse Act, enacted in 1986, criminalizes accessing a computer “without authorization” and knowingly transmitting code that intentionally causes damage. Its drafters could not have foreseen today’s challenges of combatting cybercrime.
The Cybercrime Program’s Untested Legal Issues
The memo is an important step in combatting transnational cybercrime. But the CFAA exception it invokes has never been tested in court. It remains unclear whether that exception shields participating firms from liability, and under what circumstances. Neither the CFAA nor state computer crime statutes can be superseded by a DoJ or DHS contract. Anyone suffering damage or loss can still sue, and a Justice Department statement that it will not prosecute firms in the Program is not ironclad.
The line between law enforcement operations and the use of force can be thin. States have never agreed on when cyber operations rise to the level of the use of force or an armed attack. A private-sector operation that destroys property or causes damage at scale, with wide-ranging effects, may be treated by another state as equivalent to an armed attack. If that happens, the United States could be legally responsible for private sector conduct it may never have intended. Attribution and discernment of operational intent also may not be clear to adversary TCOs or states. Misperception of these operations raises potential risk to both the United States and participants in the Program.
Who Pays When Cybercrime Law Enforcement Operations Go Wrong
Employees conducting these operations face additional risk. They do not have sovereign immunity. Damage can occur inside foreign states, and the TCOs they target may well have affiliations with those states. If a foreign state treated these law enforcement operations as armed conflict, the private sector employees running them would not be combatants under international law and would not have POW or other protections. They may also face repercussions or retaliation under foreign hacking laws. A Chinese citizen was recently arrested on vacation in Italy and extradited to the U.S. for allegedly hacking American companies for a Chinese firm. U.S. contractors countering CE-TCOs will likely be considered criminals by other states, and any of them could be at risk when traveling abroad.
Criminal infrastructure runs on commandeered systems, including hospital servers, university networks, and small business routers. The memo says nothing about what happens when private corporations cause collateral damage to those third parties, or who will be responsible for it. Firms may also face reputational risk from participation, along with disclosure and insurance concerns. Nothing addresses what happens when a properly targeted foreign system holds Americans’ stolen data, or what rights those American victims, individual or corporate, have.
Operating procedures are due in 60 days and will likely answer some of these questions. The real test will be in court or in practice. A program that saves Americans from cybercrime will be a great success for public/private partnerships. But the program will need strong safeguards to ensure that a corporation does not accidentally start a war.