Trump plan would let private firms conduct cyberattacks abroad
President Donald Trump, in a national security memorandum issued about a month ago, directed the US government to partner with "vetted" private companies to conduct cyberattacks and surveillance against foreign transnational criminal networks targeting US citizens. The FBI announced its first unclassified cyber strategy and has run joint operations this year with Google, Microsoft, Meta and CrowdStrike. The shift accompanies staff and programme cuts at the State Department and CISA. Experts cautioned that nation-state retaliation against US companies is a concern.
Source
Foreign Policy · read the original report ↗
Desk check · compared with the source
What the desk checked (5)
- Trump directed the government, via a national security memorandum about a month ago, to partner with 'vetted' private companies for cyberattacks and surveillance on foreign criminal networks. — Attributed in source to a presidential national security memorandum; text of memorandum not quoted beyond the word 'vetted'.
- The FBI announced its first-ever unclassified cyber strategy at the Billington Cybersecurity Summit. — Attributed in source, with quotes from FBI cyber division assistant director Brett Leatherman.
- The FBI has conducted joint operations with Google, Microsoft, Meta and CrowdStrike this year. — Stated in source without a named document or spokesperson; company names appear in source.
- The Trump administration cut cyber staff and programmes at the State Department and CISA. — Asserted by the source's authors; no specific figures or official source given.
- The US military is reportedly preparing to bring in private contractors for cyberoperations. — Hedged as 'reportedly' in the source; no source named.
Analysts’ view opinion
This is more than a cybersecurity tweak — it is a limited outsourcing of state power in cyberspace to private hands. Even as staff and programmes are cut at the State Department and CISA, the strategy seeks to expand offensive reach by turning "vetted" firms like Google, Microsoft, Meta and CrowdStrike into operational partners rather than mere intelligence-sharing contacts. It is a pragmatic answer to a capacity shortfall, but it shifts the burden of retaliation from government targets onto private companies.
- Adversaries already blur the line between state and criminal hackers; this memorandum suggests Washington is willing to blur its own line in response.
- Cutting defensive institutions while scaling up offence risks an imbalance in the overall deterrence posture.
- An FBI official himself acknowledged the core danger: strikes on state-linked hacking groups could invite retaliation against US tech firms and their users rather than the government.
- Who makes the "vetted" list, and what controls and legal protections apply, remains the decisive unanswered question for accountability.
- If American companies are seen as instruments of state cyber operations, other countries may treat their own and foreign tech vendors with similar suspicion — a strategic signal for the global tech market.
What to watch — Watch which companies step forward as the tip of the spear, what approval and legal-protection framework is built around them, and the form the first retaliation takes.
The story does not establish the memorandum's full contents, the vetting or approval process, which firms have signed up for offensive roles, or whether any retaliation has yet occurred.
Deep dive
Research brief · 8 facts · 7 dates · exam-readyThe brief
Context
Foreign Policy's Situation Report reports a fundamental reshaping of how Washington approaches cyberwarfare in President Donald Trump's second term. Alongside deep staff and programme cuts at bodies such as the State Department and the Cybersecurity and Infrastructure Security Agency (CISA), the administration has pushed offensive cyber operations against adversaries, as the US did in Venezuela and Iran. In a national security memorandum issued about a month before the report, Trump directed the government to partner with "vetted" private companies to conduct cyberattacks and surveillance against foreign transnational criminal networks targeting US citizens. The FBI has simultaneously unveiled its first unclassified cyber strategy, seeking to make industry an "operational partner".
Key facts
- Trump laid out the proposal in a national security memorandum around a month before the report, directing partnership with "vetted" private companies for cyberattacks and surveillance abroad.
- The targets named are foreign transnational criminal networks that target US citizens.
- The Trump administration, with Elon Musk's help, has cut staff and programmes at the State Department and CISA.
- The US has conducted offensive cyberattacks in both Venezuela and Iran, per the source.
- The FBI announced its first-ever unclassified cyber strategy at the Billington Cybersecurity Summit in Washington, calling for more joint operations with private companies.
- The FBI has already run joint operations this year with Google, Microsoft, Meta and cybersecurity firm CrowdStrike to disrupt criminal hackers.
- The US military is reportedly preparing a similar shift to bring in private contractors for cyberoperations.
- Named adversary hacking sources include Chinese, Russian, Iranian and North Korean hackers, plus criminal and "hacktivist" groups.
Timeline
- Around one month before the reportTrump issues a national security memorandum directing partnerships with "vetted" private firms for offensive cyber operations and surveillance.
- During 2025 (this year, per source)FBI conducts joint operations with Google, Microsoft, Meta and CrowdStrike to disrupt criminal hackers.
- Week before publicationFBI announces first-ever unclassified cyber strategy at the Billington Cybersecurity Summit; national cyber director Sean Cairncross speaks on engaging private industry.
- Friday, Sept. 18Parliamentary elections begin in Russia, running through Sept. 20.
- Tuesday, Sept. 22Opening of the general debate at the 81st session of the UN General Assembly.
- Wednesday, Sept. 23Morocco poised to hold parliamentary elections.
- Thursday, Sept. 24Trump set to host Chinese President Xi Jinping at the White House.
Who has a stake
- White House / Trump administration — Seeks more offensive cyber capacity despite budget and staff cuts; national cyber director Sean Cairncross frames it as "engaging with private industry in a new way".
- FBI cyber division — Wants industry as an "operational partner" rather than only a threat-intelligence sharer, per assistant director Brett Leatherman, while keeping operations lawful.
- Google, Microsoft, Meta, CrowdStrike — Build the software governments and businesses use, are prime targets of adversarial hackers, and may become the "tip of the spear" facing retaliation.
- State Department and CISA — Have lost staff and programmes under cuts, weakening the government's own cyber posture.
- Nation-state adversaries (China, Russia, Iran, North Korea) — Accused of blurring government-private lines using criminal hackers and hacktivists; could retaliate against US companies.
- Former officials/experts (Anne Neuberger, Megan Rolander) — Cautiously optimistic; Neuberger will watch which companies sign up, assuming government will not approve "the cowboys".
Why it matters
Outsourcing offensive cyber operations to private firms blurs the line between state and corporate actors, the very practice Washington criticises in China, Russia, Iran and North Korea. If companies become instruments of state action, they may also become legitimate-seeming targets for nation-state retaliation, with global spillover for the software and cloud services used worldwide, including in India.
UPSC angle
Prelims pointers
- CISA: Cybersecurity and Infrastructure Security Agency, a US body that saw staff and programme cuts under the Trump administration.
- Trump's national security memorandum directs partnership with "vetted" private firms for cyberattacks and surveillance on foreign transnational criminal networks.
- FBI announced its first-ever unclassified cyber strategy at the Billington Cybersecurity Summit, Washington.
- Sean Cairncross is the White House national cyber director; Brett Leatherman is assistant director of the FBI's cyber division.
- Anne Neuberger was deputy national security advisor for cyber and emerging technology in the Biden administration.
- The 81st session of the UN General Assembly general debate opened on Sept. 22.
Mains framing
The US move to enlist \"vetted\" private companies in offensive cyber operations reflects a capacity problem: the administration has cut cyber staff and programmes at the State Department and CISA even as it pursues more offensive action, as seen in Venezuela and Iran. Adversaries such as China, Russia, Iran and North Korea already blur state and non-state lines, using criminal hackers and hacktivist groups that operate with near impunity, and firms like Google, Microsoft, Meta and CrowdStrike hold much of the relevant expertise and technology, as the FBI's first unclassified cyber strategy acknowledges. The implications are significant: private actors performing state functions raise questions of legality, accountability and proportionality, and invite nation-state retaliation against companies whose products underpin civilian systems worldwide. Experts interviewed are cautiously optimistic, stressing that government controls must screen out reckless actors and that operations must be lawful and protective of partner organisations. A credible way forward, on the evidence in the source, rests on strict vetting, clear legal authorisation, government approval of each operation, and safeguards for the personnel and organisations drawn into the fight.
Key terms
- National security memorandum
- A presidential directive; here the instrument by which Trump ordered partnerships with vetted private firms for offensive cyber work.
- CISA
- US Cybersecurity and Infrastructure Security Agency, which has faced staff and programme cuts under the Trump administration.
- Offensive cyberoperations
- Hacking-back activity against adversaries rather than only defending US systems, as done in Venezuela and Iran per the source.
- Hacktivist groups
- Non-state hacking groups that target critical US systems in alignment with, though not always affiliated to, foreign regimes.
- Operational partner
- FBI's term for companies that join actual operations, not merely exchange threat intelligence.
- Billington Cybersecurity Summit
- Washington event where the FBI unveiled its first unclassified cyber strategy and the national cyber director spoke.
Practice questions
- Does outsourcing offensive cyber operations to private firms undermine the norms the US seeks to uphold in cyberspace? Discuss with reference to Trump's national security memorandum.
- Examine the risks of nation-state retaliation when private technology companies become operational partners in state cyber operations.
- "Capacity shortfalls, not doctrine, are driving the privatisation of cyberwarfare." Critically evaluate in light of cuts at the US State Department and CISA.
Grounded only in the source report — figures and dates are the source's, not inferred.
