The U.S. government is preparing to let some private companies conduct offensive cyber operations on its behalf, a major shift from the long-standing line between private-sector defense and government-run hacking operations. TechCrunch reports that the White House said Wednesday a newly published presidential memorandum will allow vetted private companies to launch operations against international criminal gangs and hackers. Engadget reports that President Donald Trump signed a new national security presidential memorandum authorizing private companies to conduct cyberattacks on “transnational criminal organizations” for the federal government. The administration’s stated rationale is to draw on private-sector capability against cybercrime targeting Americans. According to TechCrunch, the memorandum points to ransomware attacks, financial scams and sextortion; Engadget also lists phishing and financial fraud among the threats the policy is meant to address. The authority is not a general license for companies to “hack back” at any attacker. TechCrunch reports that participating companies would operate under federal supervision, with operations requiring sign-offs from representatives of the Justice Department and Homeland Security. The memorandum also directs the government to create procedures intended to prevent operations from targeting Americans or U.S.-based systems. The permitted activity, as described by TechCrunch, could include surveillance operations, such as using spyware to collect intelligence, as well as disruptive attacks aimed at destroying criminals’ data or systems. That is a meaningful expansion beyond the traditional U.S. position that private companies may defend their own networks but may not launch offensive cyber operations without legal authorization. Both outlets stress that the mechanics are still unsettled. TechCrunch says the program is in its early days and that the government has not fully established how it will operate. Engadget reports that standards for vetting companies and procedures for carrying out attacks are expected within 60 days; TechCrunch describes guidance due within the next two months and says it would consider companies of all sizes, including smaller firms suited to specialized operations. One concrete requirement is already specified: participating firms must put up $1 million. TechCrunch describes it as an escrow deposit that can be forfeited if a company violates program rules, while Engadget calls it a $1 million bond forfeitable for failure to follow government direction. The legal risk is not fully answered by the memorandum. Engadget notes that while the policy may protect approved companies from U.S. prosecution, it does not explain what would happen if foreign governments brought criminal charges against companies or employees for attacks on computers located in their jurisdictions. TechCrunch reports the policy is likely to face legal challenges and opposition from critics who argue private industry should not be involved in government hacking operations. TechCrunch also reports that participating companies would have to notify the government if they discover an imminent cyberattack against critical U.S. infrastructure, including power grids or water providers. Engadget says the memorandum was signed “in the aftermath of a wave of cyberattacks on water facilities in Minnesota and Michigan that are now linked to Iran.” Who benefits: Vetted private companies with offensive capabilities may gain a formal path to work on government-directed operations. The federal government says the policy is meant to use private-sector capability and innovation against cybercrime. Who's exposed: Participating firms face compliance risk, forfeiture of the $1 million bond or escrow, and unresolved exposure under foreign law. Companies outside the program should not treat the memo as permission to conduct hack-back operations.