Mayer Brown·CYBERSECURITY

New NSPM authorizes vetted private firms to conduct offensive cyber ops against foreign criminal groups

Vetted U.S. contractors may soon conduct government-directed offensive cyber operations against foreign cyber-enabled criminal organizations, creating immediate compliance, liability, and constitutional questions for participating companies.

On August 12, 2026, President Trump signed a National Security Presidential Memorandum establishing a program under which vetted private U.S. companies—acting under federal direction and control—may carry out cyber surveillance and cyber effects operations against foreign cyber-enabled transnational criminal organizations. The program is overseen by dual executive directors from the Departments of Justice and Homeland Security, with all operations required to comply with the Computer Fraud and Abuse Act and other applicable law. Within 60 days, operating procedures will define vetting standards, deconfliction processes, and guardrails. Companies must enter into contractual agreements with DOJ or DHS, and those holding relevant threat intelligence may also sell data to participating firms. Open legal questions include whether participating companies are state actors for Fourth Amendment and FISA purposes, how liability is allocated for operations exceeding approved parameters, and how extraterritorial activities will be reconciled with international law.

cybersecurityoffensive-cyber-operationsnational-securitycfaastate-actor
Read the original firm alert →Saturday, August 15, 2026

Stay ahead

Join the digest.

One email when the daily AmLaw 100 briefing ships. No noise, no pitch decks — just the grade 4–5 signal.