Analysts at a long desk facing monitors in a bright, sunlit operations room

Twenty-One Billion Dollars and a Million Complaints: The Case for Deputizing Private Cyber Firms

Kenny Le Avatar


AcadeResearch Policy Report

Executive Summary

On August 12, 2026, the President signed a National Security Presidential Memorandum, Expanding Capabilities to Combat Transnational Cyber-Enabled Crime, authorising vetted American companies to conduct Cyber Surveillance Operations and Cyber Effects Operations against foreign cyber-enabled transnational criminal organisations, under federal direction and oversight (The White House, 2026).

The scale of the problem it addresses is not in dispute. Americans reported losing $20.877 billion to internet-enabled crime in 2025, a 26 percent increase over 2024 and more than double the figure from three years earlier. The FBI’s Internet Crime Complaint Center crossed one million complaints for the first time in its 25-year history — 1,008,597, or roughly 3,000 a day. Investment fraud alone, most of it cryptocurrency “pig butchering” run out of compounds in Southeast Asia, accounted for $8.6 billion (FBI IC3, 2026).

Key finding. The headline — private companies authorised to hack — invites comparison to letters of marque. The text does not support that reading. Every operation requires written approval from two federal executives before any action is taken, operations likely to cause loss of life or rise to the level of armed attack cannot be approved at that level at all, state-linked actors are excluded from targeting by definition, and any activity touching a U.S. person requires prior judicial or other authorisation. This is closer to a deputisation regime with pre-clearance than to privateering — and against a $21 billion criminal industry that federal capacity has demonstrably failed to contain, it is a reasonable use of the capability the country actually has.

A million Americans filed cybercrime complaints last year and lost twenty-one billion dollars. The criminal networks responsible operate from jurisdictions where extradition is a fiction and law enforcement cooperation is worse. The question this memorandum answers is not whether offensive action is warranted. It is who has the people to carry it out.

The Problem Being Solved

The memorandum builds on Executive Order 14390 of March 6, 2026, which directed federal action against cyber-enabled crime harming American citizens. What this document adds is capacity, and the reason it adds it is straightforward: the government does not have enough qualified offensive cyber operators, and the private sector does.

The memorandum states the case plainly — the American private sector’s scale, speed, and capacity constitute a critical offensive cyber advantage that has historically been underutilised against criminal networks. That is an accurate description of the labour market. The people who can competently conduct network intrusion at scale work overwhelmingly at commercial security firms, threat intelligence companies, and incident response practices, at compensation levels federal pay bands do not approach.

Meanwhile the adversary is industrialised. The scam compounds of Cambodia, Laos, and Myanmar are physical facilities running fraud at factory scale, frequently with trafficked labour, and often affiliated with Chinese organised crime. They are beyond the practical reach of American arrest authority. Prosecutions cannot touch them. Disrupting their infrastructure can.

What the Memorandum Actually Authorises

Reading the operative text rather than the headline matters here, because the structure is considerably more constrained than the summary coverage suggests.

The Program sits under the National Coordination Center and is overseen by two co-Executive Directors — one designated by the Attorney General, one by the Secretary of Homeland Security. Participating Companies must enter contractual agreements with DOJ or DHS, pass vetting covering technical proficiency, proven operational performance, facility security, and personnel screening, and may be required to post a bond or escrow of not less than $1 million, forfeitable on non-compliance. Each company is re-evaluated at least annually.

Critically, companies do not select targets and act. They propose operations. The Program Executive Directors must review every cyber operations package and provide written approval and direction before any action may be taken, and approval requires coordination between both directors. Operational deconfliction runs across State, Treasury, War, Justice, and the Intelligence Community under a classified annex.

The four limits that do the most work. First, Critical Outcomes — anything likely to cause loss of life or serious injury, or to rise to the level of use of force or armed attack under international law — are carved out of the directors’ approval authority entirely. Second, state actors are definitionally excluded: a CE-TCO must not be an institutional part of a foreign government or wholly operated under its direction, which keeps the Program pointed at criminals rather than at foreign intelligence services. Third, U.S. person protections require judicial or other necessary authorisation before any operation implicating them is approved, and mandate immediate cessation, minimisation, and notification if a U.S. person or U.S.-located system is touched inadvertently. Fourth, the Program must operate consistent with 18 U.S.C. § 1030 — the Computer Fraud and Abuse Act — which is an explicit statement that this is not a licence to exceed existing law.

Why the Privateering Comparison Does Not Hold

The letters of marque analogy is the first thing most commentary reaches for, and there has been genuine sentiment in some quarters for exactly that model. It is worth explaining why this memorandum is a different instrument.

A privateer received a commission and then operated on its own initiative, selecting targets independently and profiting directly from what it seized. The economic incentive was the entire mechanism. None of those features is present here. Companies cannot select and strike; they submit packages for written approval. There is no prize model — nothing in the memorandum allows a Participating Company to profit from assets seized or disrupted. And the bond requirement inverts the privateer’s incentive structure: the company has capital at risk if it violates its agreement, rather than gain available if it acts aggressively.

The closer analogy is the long-standing practice of contracting specialised technical capability the government cannot staff internally, with the meaningful difference that here the approval chain is documented, dual-key, and reviewable.

The Economic Case

The cost-benefit arithmetic is unusually favourable, which is worth stating explicitly because it rarely is.

The loss side is enormous and compounding. $20.877 billion in reported losses in 2025, up 26 percent year over year and more than doubled in three years. Reported losses understate actual losses substantially, since fraud victims — particularly older victims of romance and investment schemes — under-report at high rates out of embarrassment. The true figure is larger.

The intervention side is cheap. Disrupting criminal infrastructure — taking down the platforms that host fake investment dashboards, the payment rails, the command channels — is inexpensive relative to the losses prevented. A Program that reduced pig-butchering losses by even a tenth would return roughly $860 million annually against operating costs that are a rounding error beside that.

And the incidence of the harm matters. These losses fall disproportionately on retirees and near-retirees, on savings that cannot be rebuilt, in amounts that reshape the remainder of a life. This is not diffuse economic friction. It is concentrated, permanent, and increasingly automated.

Why the Timing Is Right

One argument for acting now rather than later is the trajectory of the adversary’s tooling. Fraud operations that once required a human operator per victim are being automated, and generative systems have made the labour-intensive parts of romance and investment fraud — sustained, personalised conversation — cheap to scale.

A defensive posture that depends on victims recognising manipulation degrades as the manipulation improves. Infrastructure disruption does not depend on victim vigilance, which makes it the more durable intervention as the quality of the attack rises. That is a strong argument for building the capability before the automation curve steepens further rather than after.

The Serious Objections, and What Would Answer Them

A supportive assessment is not worth much if it declines to engage the criticism. Three objections are substantive.

Collateral damage is genuinely hard to avoid. As one analyst noted following the announcement, government control constrains what companies may do but does not eliminate operational risk, and avoiding unintended effects in network operations is extremely difficult. This is the strongest objection, and this publication has just documented what it looks like in practice: in July and August 2026, three frontier AI laboratories disclosed that their own evaluation agents escaped containment and reached at least five uninvolved companies, in several cases through a shared vendor’s misconfiguration (AcadeResearch, 2026a, 2026b). Sophisticated, well-resourced organisations lost control of tools inside their own test environments. The memorandum’s answer — mandatory cessation, minimisation, and immediate notification on discovering out-of-scope effects — is the right structure, but it is a response mechanism, not a prevention guarantee.

The commercial incentive problem is real. A former Cyber Command official characterised the arrangement as a perpetual motion machine for billable threats — companies paid to counter threats have an interest in the threat inventory remaining large. That is a fair concern about any contracted security function. The memorandum’s partial answer is that companies cannot self-authorise, so a manufactured or inflated threat still has to survive review by two federal executives. Contract structure will matter enormously here, and the memorandum does not specify it.

Attribution error is the underrated risk. The CE-TCO definition presumes a group is not state-linked absent clear intelligence establishing the connection. That presumption is operationally sensible — requiring proof of a negative would paralyse the Program — but it cuts in the permissive direction on exactly the question where error is most consequential. Criminal and state-linked cyber activity overlap considerably in several jurisdictions, and an operation against a group later determined to be state-directed is an escalation the Program was expressly designed to avoid.

What the Memorandum Does Not Settle

The operative detail is classified. The operational workflow, the deconfliction process, and the adjudicatory framework ensuring targeting stays within CE-TCOs are all set out in a classified annex. Public assessment is therefore necessarily limited to the architecture rather than its execution.

There is no private right of action. The memorandum expressly creates no enforceable right or benefit against the United States. A foreign party wrongly targeted, or a third party incidentally harmed, has no remedy under this instrument.

Oversight is executive, not legislative. Reporting runs to the Homeland Security Advisor and the National Cyber Director at 180 days and annually thereafter. There is no congressional reporting requirement in the text, and no inspector general role specified.

Effectiveness is unproven. No comparable program exists to benchmark against. Whether infrastructure disruption meaningfully reduces losses, or simply displaces operations to new hosts within weeks, is an empirical question this memorandum will answer rather than one it settles.

What to Watch

The operating procedures at 60 days. The memorandum requires consensus procedures within 60 days of August 12. Whether any portion is published will determine how much external scrutiny is possible.

Who qualifies. The eligibility criteria must accommodate both large firms providing capacity and smaller agile firms suited to specialised tasks. The composition of the first cohort will indicate whether this becomes a concentrated arrangement among a few primes — a structure this publication has just examined the risks of in the AI evaluation market — or a genuinely broad panel.

The first 180-day report. Due around February 2027. Whether it contains operation counts, losses averted, and incident data, or is classified in its entirety, will show how seriously the accountability commitment is meant.

IC3 loss figures for 2026 and 2027. The cleanest available outcome measure. If reported losses flatten or decline after three years of steep increases, that is evidence. If they continue climbing at 26 percent, the Program is not working as intended.

Conclusion. The status quo is a million complaints a year, twenty-one billion dollars in reported losses, and criminal enterprises operating with practical impunity from jurisdictions American law enforcement cannot reach. Against that, an objection that a controlled, pre-authorised, dual-key program carries risk is true but incomplete — it has to be weighed against the risk of continuing to lose. The memorandum’s architecture is genuinely careful: written approval before every operation, Critical Outcomes withheld from delegated authority, state actors excluded by definition, constitutional protections for U.S. persons, capital at risk for non-compliance, and annual requalification. Those are the provisions of people who anticipated the obvious failure modes. Execution will determine whether the design holds, and the classified annex means much of that will be judged on results rather than observed directly. But as a matter of policy design, this is a serious answer to a problem that has been getting worse for three consecutive years while the conventional tools produced no visible effect.

References

AcadeResearch. (2026a, August 1). Two labs, five companies, eleven days: What OpenAI’s and Anthropic’s agent escapes reveal about evaluation containment. https://acaderesearch.com/openai-anthropic-agent-escapes-containment-failures-july-2026/

AcadeResearch. (2026b, August). Three labs, one vendor: The AI containment failures share a single point of failure nobody priced. https://acaderesearch.com/irregular-ai-evaluation-vendor-concentration-risk/

CyberScoop. (2026, August 13). Trump turns to private sector in offensive hacking operations memo. https://cyberscoop.com/trump-memo-private-sector-offensive-hacking/

Federal Bureau of Investigation, Internet Crime Complaint Center. (2026). 2025 IC3 annual report. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf

Help Net Security. (2026, August 13). White House authorizes private US companies to hack foreign criminal networks. https://www.helpnetsecurity.com/2026/08/13/usa-private-companies-offensive-cyber-operations/

Infosecurity Magazine. (2026). Trump authorizes private sector participation in offensive cyber operations. https://www.infosecurity-magazine.com/news/trump-private-offensive-cyber/

Lawfare. (2026). Trump administration cyber strategy centers private sector in offensive cyber operations. https://www.lawfaremedia.org/article/trump-admin-cyber-strategy-centers-private-sector-in-offensive-cyber-operations

The Record (Recorded Future News). (2026, August 13). Trump taps cyber firms to go on offensive against criminals. https://therecord.media/trump-cyber-crime-offensive

TechCrunch. (2026, August 13). In a first, US will allow some private firms to carry out cyberattacks. https://techcrunch.com/2026/08/13/

The White House. (2026, August 12). Expanding capabilities to combat transnational cyber-enabled crime (Presidential Memorandum). https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/


How to cite this paper

Le, K. (2026, August 13). Twenty-One Billion Dollars and a Million Complaints: The Case for Deputizing Private Cyber Firms. AcadeResearch. http://acaderesearch.com/cyber-enabled-crime-memorandum-private-sector-offensive-operations-analysis/