For as long as cybercrime has existed, there was one bright red line in American law: only the government hacks. Companies could defend their networks, report intrusions, and grit their teeth — but striking back at the criminals on the other side of the keyboard? That was illegal, full stop.
A new White House memo just smudged that line in a big way.
The Memo That Changes the Game
President Trump has signed a directive instructing the National Coordination Center to build a program letting vetted private companies go on offense against foreign Transnational Criminal Organizations — the ransomware gangs, fraud rings, and scam empires that drain billions from American citizens and businesses every year.
The memo’s language is blunt: by partnering with “vetted United States companies subject to the direction and oversight of the Federal Government,” the US will “enhance our ability to counter TCO threats and combat transnational cybercrime, fraud, and other predatory schemes against American citizens.”
Under the plan, approved companies could run two types of operations. Cyber surveillance operations can access sensitive data without the owner’s authorization — think quietly mapping a ransomware gang’s servers from the inside. Cyber effects operations go further: disruption, denial, and degradation. In plain terms, breaking the criminals’ infrastructure before it breaks yours.
The NCC has 60 days to stand the program up.
Why the Government Is Doing This
The logic is simple math. Federal agencies like the FBI and Secret Service are outnumbered. Ransomware crews operating out of safe-harbor countries hit hospitals, schools, pipelines, and city halls faster than any government task force can respond. The private sector — cybersecurity firms, tech giants, specialized contractors — has world-class talent sitting on the sidelines, legally barred from doing what it knows how to do.
Supporters of the memo call it a force multiplier: deputize the best hackers in America, aim them at the cartels, and finally match the speed of the threat.
Critics see a minefield. What happens when a private “authorized” operation trips into a foreign government’s systems by mistake? What stops a company from overstepping and claiming it was acting under its approval? And what precedent does it set when other countries — including adversaries — point to this memo to justify their own “private” hackers, who may not feel very private at all?
Those questions don’t have answers yet. The 60-day setup window is where the real rulebook will be written.
Meanwhile, Regular Americans Are the Bait
While Washington rewires offensive cyber policy, ordinary job seekers are being hunted with one of the slickest phishing campaigns researchers have ever documented.
Security firm CTM360 has uncovered a global operation it’s calling “RecruitTrap.” Over just two months, researchers identified more than 3,000 phishing URLs impersonating real recruiters and interview processes tied to over 50 organizations across 14 industries.
The scam is elegant and nasty. You get what looks like a genuine interview invitation — the right branding, the right recruiter name, a professional scheduling page. When you “sign in” to confirm your slot, a fake browser window opens inside your real browser — a trick called Browser-in-the-Browser — and quietly harvests your Google or Facebook credentials. In the most advanced versions, the attackers relay your multi-factor authentication prompt in real time, walking straight past the security layer everyone told you was bulletproof.
Marketing professionals are the top target, and that’s no accident. A compromised marketing account opens the door to ad platforms, corporate social media, customer databases, and internal email — everything a criminal needs to scam thousands of people at scale.
Apple Sounds the Spyware Alarm — Again
Add one more headline to the pile: Apple has sent a fresh wave of threat notifications to users it believes were targeted by mercenary spyware — commercial surveillance tools so sophisticated they’re typically aimed at journalists, activists, politicians, and diplomats. The company says it has now notified users in more than 150 countries since it began the program in 2021, with this latest round spanning 110 countries.
Apple doesn’t name the attackers. It doesn’t have to. The message is clear: state-grade spying tools have become a global industry, and the target list keeps growing.
Corporate America Is Already Feeling It
This isn’t theoretical for US businesses. Logistics giant Ceva saw operations disrupted by a cyberattack this month, and the hacker behind the massive Snowflake data-theft spree — which touched some of the biggest brands in the country — just pleaded guilty in a US courtroom. Ransomware crews with ties abroad continue to treat American hospitals and city governments as ATMs. That drumbeat of damage is exactly what the White House memo is responding to: the sense that defense alone has failed, and that deterrence requires consequences for the attackers, not just invoices for the victims.
Security executives are split in private. Some relish the chance to finally disrupt the infrastructure that hammers their networks daily. Others quietly dread being drafted into geopolitical crossfire — a company caught running an “authorized” operation against the wrong target could face lawsuits, sanctions blowback, or retaliation from criminals who don’t care about memos. Expect intense lobbying over the vetting rules in the 60-day setup window, because the fine print will decide who carries the risk when an operation goes sideways.
What You Should Actually Do
Strip away the geopolitics and the advice for everyday Americans is refreshingly boring — and it still works.
Be suspicious of any interview invitation that asks you to log in before you log a single conversation. Check the actual URL, not the logo on the page. Turn on hardware security keys or app-based authentication where you can — they’re far harder to relay than text-message codes. Keep your phone and browser updated; the rootkits and zero-days making headlines this month, from a signed Windows rootkit tied to the Mustang Panda espionage group to an actively exploited GeoServer flaw, mostly succeed against systems that skipped their patches.
The offense-versus-defense balance in cyberspace is shifting fast. Washington just bet that hitting back is the future. Whether you’re a Fortune 500 security team or a job seeker with a Gmail account, the message of August 2026 is the same: the fight is coming to you — so be harder to hit.













