An Ohio woman received a text message from an unknown number. What followed appeared to be a friendship, built through conversations about hobbies, family, and religion. It was, in fact, the beginning of a cryptocurrency investment scam.
By the time she realized the truth, the scammers had taken approximately $663,000, including her life savings and Roth IRA. When the money ran out, they threatened her family. Her story is one among thousands. The FBI now receives approximately 3,000 complaints per day.
In response to this danger, a national security memorandum authorizes vetted US companies to conduct cyber surveillance and cyber effects operations against foreign criminal organizations. It’s a significant move. Although the concept of unleashing the private sector has long been discussed, previous administrations hesitated, fearful that the move could escalate cyber conflict.
Foreign criminal organizations target US citizens every day through cryptocurrency investment fraud, business email compromise, technology and customer-support scams, romance scams, and government and law enforcement impersonation scams. In 2025, the FBI reported $20.9 billion in losses, up from $16.6 billion in 2024 and $12.5 billion in 2023. Cyber-enabled fraud alone accounted for $17.7 billion, or 85% of reported losses. These are reported losses, so the true scale is likely higher.
Like it or not, Americans are targets, and the US government is overwhelmed. The Government Accountability Office describes a “persistent shortage” of federal cybersecurity and IT professionals, while the Department of War identifies attrition as a threat to its cyber capabilities. At US Cyber Command, personnel are “almost never out of the fight,” according to the command’s psychologist. As many as five people working in or closely with US Cyber Command died by suicide during a roughly month-long period in the summer of 2026.
Critics will argue that private companies conducting surveillance or effects operations risk escalation. China and Russia’s authoritarian governments have long relied on private sector hackers. The new executive order leaves unanswered which companies would be authorized to conduct cyberhacking and what would happen if the companies take actions that go beyond their authorization. Critics may also argue that outsourcing a governmental function could be abused.
Yet, the dangers seem overwrought. The program does not authorize companies to choose their enemies or to conduct operations on their own authority. Participating companies would act on behalf of and under the oversight of the federal government.
Cyberattacks remain below the threshold of an armed attack and constitute a part of a continuous, bounded competition rather than automatically thrusting states toward armed conflict. The new US program targets foreign criminal organizations, not nation-states. Participating companies would be vetted, and their operations would require government approval. This is a calculated use of private capability for a public mission, not reckless cyber hack-back.
If nation-state involvement emerges, the new US policy should require clear handoff procedures. This often happens. Criminal organizations may appear to be behind cyberattacks, only for evidence to emerge of government sponsorship. In these cases, the US military’s Cyber National Mission Forceshould be called upon to fight the most sophisticated nation-state hackers.
Given the rise in cyber fraud, the government cannot afford to leave qualified private-sector capabilities unused. Companies provide specialized personnel, infrastructure expertise, technical access, and operational capacity that the government cannot quickly reproduce or maintain.
The new US policy recognizes the government’s limitations in confronting the growing, cumulative threat of sophisticated international scams. It’s also an acknowledgment of the reality of the global cyber war.
Emily Otto is a Fellow with the Tech Policy Program and Transatlantic Defense and Security Program at the Center for European Policy Analysis (CEPA). Currently a PhD Student at Johns Hopkins SAIS, she served as a Cyber Operations Officer with the Cyber National Mission Force and the Cyber Protection Brigade under US Cyber Command.
Bandwidth is CEPA’s online journal dedicated to advancing transatlantic cooperation on tech policy. All opinions expressed on Bandwidth are those of the author alone and may not represent those of the institutions they represent or the Center for European Policy Analysis. CEPA maintains a strict intellectual independence policy across all its projects and publications.
Tech 2030
A Roadmap for Europe-US Tech Cooperation