LogoLogo

Podcasts

Newsletters

Videos

Catalog

People

About

Search

Seriously Risky Business Newsletter

August 20, 2026

Srsly Risky Biz: Trump's Private Hacker Memo Is the Right Idea

Written by

Tom Uren
Tom Uren

Policy & Intelligence

Your weekly dose of Seriously Risky Business news is written by Tom Uren and edited by Amberleigh Jack and Patick Gray. This week's edition is sponsored by Socket Security.

You can hear a podcast discussion of this newsletter by searching for "Risky Business News" in your podcatcher or subscribing via this RSS feed.

Photo by Quilia on Unsplash

The US government’s plan to enlist private sector hackers to target cybercriminals is controversial, but it addresses a real problem and is surprisingly measured.  

Last week, a presidential memo directed the Department of Homeland Security to establish a program authorising private companies to conduct cyber operations against so-called "Cyber-Enabled Transnational Crime Organisations" or CE-TCOs. The memo sets out the broad shape of the arrangement and a classified annex further details the logistics. 

The huge policy shift here is that private companies will be authorised to conduct cyber operations that were previously restricted to state entities. This includes what the memo calls "cyber surveillance" (intelligence gathering operations) and "cyber effects" operations, (intended to manipulate or to cause disruption).

While the vibe of the initiative is consistent with President Donald Trump's preference for the unrestrained use of state power, the memo itself is surprisingly measured. Rather than recruiting the private sector to help with all of America's hacking needs, it identifies a current capacity gap where private sector involvement would be helpful: CE-TCOs.

Defined as foreign groups conducting cyber-enabled crime against US persons or interests that are not part of, or operated by, a foreign government, CE-TCOs are doing a huge amount of harm to the American people particularly via a variety of scams. 

To date, traditional policing approaches have had limited impact on these crimes, so the government has increasingly turned to disruption and cyber operations. These have had some success, but the government's capacity to carry out these operations is constrained. The FBI can only tackle the highest-priority groups, NSA is focussed on foreign intelligence, and Cyber Command is concerned with the nexus between warfare and cyber. 

That means there are still hundreds of uncontested cyber crime groups fleecing Americans. There is plenty of room for more players to tackle this problem.

There are many cybercriminal groups with a potential target on their heads, and the process the memo describes for identifying CE-TCOs to go after is ridiculously broad. They can be identified by either private sector entities or by any "federal, state, local, tribal, and territorial" agency. We think it makes more sense for only agencies that help respond to scams or cybercrime to have authority to nominate CE-TCOs as targets.

Still, there are mechanisms in place to ensure operations aren't carried out recklessly. 

For a start, companies involved will be vetted before being permitted to participate in the program. They will need to demonstrate "appropriate levels of technical proficiency, proven performance of cyber operations, facility security, personnel vetting, competence, reliability, and other factors". With any luck this will mean fly-by-night opportunists will be excluded. 

Operations must also be approved by the government before they are executed. It's up to the participating companies to develop their own cyber operations packages. These will then be assessed by program directors at the Departments of Justice and Homeland Security. They'll make sure the proposed operations won't interfere with other US government activities, kill anyone or be equivalent to an armed attack according to international law.

Participating companies will also have to provide a USD$1 million bond that will be forfeited if they break the conditions of their contract. 

Sounds reasonable so far.

Critics, however, are concerned about the possibility of accidentally hacking a foreign government triggering some sort of escalation or retaliation and the possibility that foreign governments might target employees of the companies involved in the program. 

We think these fears are overblown. 

Although policymakers have worried about escalation from cyber incidents, even the most damaging of cyber attacks, the WannaCry and NotPetya worms, did not result in any significant problems for the perpetrating governments. 

The US government, particularly the intelligence community, also has incentives to make sure that proposed private sector operations do not target foreign government entities. It wants to make sure that licensed hackers don't accidentally interfere with its own operations, so it will pay attention to make sure there are no conflicts. 

It is true that there is often some overlap between criminals and the state in countries like Russia and China. But we doubt that any government will complain if its activities are impacted because criminals in its country were hacked. 

As for the possibility that other governments will target people involved in these operations, that can be addressed with good operational security. 

The fact sheet that accompanies the memo says Americans lost more than USD$20.8 billion to cyber-enabled crime in 2025. Given this loss, the government absolutely should be looking for innovative ways to bolster its capacity to counter these crimes. 

There are things the memo doesn’t address that still need to be answered, however, like  why companies would want to get involved in this program in the first place. When they have to stump up a USD$1 million bond, there are presumably good profits to be had. What's not clear is who pays and where exactly the money comes from.

This brings us to reporting requirements. As it stands the memo requires the Department of Homeland Security to provide an annual report to just two government officials: Assistant to the President and Deputy Chief of Staff for Policy and Homeland Security Advisor Stephen Miller and National Cyber Director Sean Cairncross. 

The Trump administration has identified a capacity gap in the fight against cybercriminals and has a plan to fill it. That's a good start, and we think the benefits of this program outweigh its potential risks. At the same time, however, it is a dramatic change in government cyber policy and there should be more oversight into how the program is operating, what it is achieving and how it is being funded. Is it providing an acceptable return on investment and what could make it better? We hope we learn enough about the program to be able to answer these questions. 

Ukraine's Latest Hacking Campaign Is a Propaganda Win

This week The Record reported the GUR, Ukraine's military intelligence directorate, claimed it had carried out a cyber attack to amplify the effects of kinetic attacks against Russia’s largest online marketplace, Wildberries. The claims are overblown. But it is great propaganda.

The GUR said the operation was carried out in cooperation with the Cyber Corps, a purportedly pro-Ukraine civilian hacker group, and affected Wildberries' customer service, contact centres and payment infrastructure. It claimed the cyber attack took place on the same night as drone strikes against a Wildberries warehouse in Voronezh, southwest Russia. 

We've previously argued that disruptive cyber operations need to be carefully orchestrated with kinetic operations to maximise their impact. So to hear the GUR saying that its exact goal was to use cyber operations to amplify kinetic attacks was music to our ears.

It wouldn't be Seriously Risky Business without a "but", though. As far as we can tell, these cyber attacks didn't do anything at all to help or amplify the kinetic attacks. It targeted Wildberries, sure. But its impact was additive and annoying rather than having any enabling or amplifying impact.

When comparing this attack with recent military actions, where cyber operations enabled or reduced the risk of carrying out conventional strikes, we're left wanting… much more. 

Take, for example, the 2025 strikes against Iranian nuclear facilities. US Cyber Command reportedly helped blind Iranian air defence systems. Earlier this year, the capture of Venezuelan President Nicolás Maduro was facilitated by switching off streetlights so that American forces could operate under the cover of darkness. And the decapitation strike against Iran's Supreme Leader Ali Khamenei was aided by an operation that disrupted nearby mobile phone towers so that his protection detail could not receive warning of an impending attack.

In each of these cases the cyber element enabled or reduced the risk of carrying out conventional components of the strikes.

By contrast, Ukrainian drone strikes have been targeting Wildberries facilities since mid-July this year and have disabled seven of the company's ten facilities according to Ukraine's defence ministry. The impact of using cyber to disable call centres or payment systems pales in comparison to the lasting damage of bombs.   

Cyber operations may not have amplified any kinetic one here, but that doesn't mean it was for nought. In fact we think the exact opposite is happening here. A successful drone strike is being used to amplify the psychological impact of a cyber attack. 

The notional justification for Ukraine's attacks on Wildberries is that it sells a range of dual-use goods including navigation systems, components for drones and supplies for the Russian army. Perhaps more importantly, though, as with attacks on Russian oil refineries, it helps highlight the costs of the war to ordinary Russians.

In this case, it is the psychological impact that is important. And even just saying that cyber attacks and drone strikes amplified each other is great propaganda.  

Watch James Wilson and Tom Uren discuss this edition of the newsletter:

Three Reasons to Be Cheerful This Week:

  1. German bank hackers caught: German and Brazilian authorities cooperated to arrest members of a group that allegedly stole more than €30 million from German online banking customers. German federal police say the group exploited a vulnerability in the systems of a payment service provider and stole the funds within just a few days in November 2023.
  2. 94 scam centres shut down in Ukraine: Ukraine's cyber police disrupted the scam centres after carrying out more than 400 searches. Authorities seized more than US$2 million and over 3,300 computers. 
  3. Cryptocurrency exchange sues North Korea: The Bybit cryptocurrency exchange has announced it has filed a civil lawsuit against the North Korean government and its Reconnaissance General Bureau, the intelligence agency responsible for state-sponsored crypto hacking. North Korea stole USD$1.5 billion from Bybit last year, and the company has obtained an injunction freezing some of the stolen funds from being moved. Bybit has recovered $48 million of the stolen funds and frozen a further $30 million.  We don't know how much joy they'll get from the suit, but we enjoy seeing novel strategies being pursued.

Sponsor Section

In this Risky Business sponsor interview, Casey Ellis chats with Socket founder Feross Aboukhadijeh about npm 12’s move to disable install scripts by default.

Risky Biz Talks

You can find the audio edition of this newsletter and other fine podcasts and interviews in the Risky Biz News feed (RSS, iTunes or Spotify).  

In our last "Between Two Nerds" discussion Tom Uren and The Grugq discuss The Offence Death Cycle, a paper looking at how to take advantage of a defender’s ability to control a network to discover intruders.

Or watch it on YouTube!

From Risky Bulletin:

Slovakia finds Russian backdoor in traffic speed cameras: Slovakia's national security service NBU has issued a security alert against the use of NERO R-ONE high-speed traffic cameras.

The agency says the cameras contain a backdoor mechanism that will execute malicious code received via an SMS from a list of hardcoded Russian phone numbers.

The NBU started an investigation into the devices after multiple reports in Slovak media that the cameras were bought with a no-bid direct contract from a Cyprus shell company with fake certifications.

[more on Risky Bulletin]

The EU publishes its upcoming cybersecurity standards: The European Telecommunication Standards Institute has released 17 cybersecurity standards that vendors will have to follow to sell products in the EU when the EU Cyber Resilience Act enters into effect in December of 2027.

The standards cover 17 core technologies for major product categories including operating systems, routers, firewalls, VPNs, browsers and password managers.

The standards describe a list of minimum security features each product category must implement to be CRA-compliant. Most of the standards usually require the same basic features, such as the ability to update the product once it's sold, that devices are sold with an SBOM, that they use modern cryptography, or that they ship with secure-by-default settings.

[more on Risky Bulletin]

AI agents had turf wars: Anthropic says agents "consistently" engaged in a turf war when they received the same tasks. Agents deployed self-replicating malware, locked rival accounts, and deployed scripts that ran in a loop to disable a competing agent's processes. Anthropic says the newer models like Mythos won by revoking rivals' access first and then negotiating truces. [Anthropic]

Recent Newsletters

  • Srsly Risky Biz: Trump's Private Hacker Memo Is the Right Idea
  • Risky Bulletin: Slovakia finds Russian backdoor in traffic speed cameras
  • Risky Bulletin: The EU publishes its upcoming cybersecurity standards
  • Risky Bulletin: White House lets private companies carry out offensive cyber ops
  • Srsly Risky Biz: Data Theft Extortion Is Booming! Hooray!

Recent Videos

  • Risky Business (849): Trump will unleash contractors on cybercriminals
  • James Kettle on inventing new attack techniques with LLMs
  • Between Two Nerds: The eye of Sauron
  • Soap Box: Zero Trust(ish) Networks
  • Srsly Risky Biz: Data extortion is booming. Hooray!

Recent Podcasts

  • Srsly Risky Biz: Trump's private hacker memo is the right idea
  • Risky Bulletin: Slovakia finds Russian backdoors on its speed cameras
  • Risky Business #849 -- Trump will unleash contractors on cybercriminals
  • Between Two Nerds: The eye of Sauron
  • James Kettle on inventing new attack techniques with LLMs
Risky Business Media

Risky Business

  • Home
  • Podcasts
  • Newsletters
  • Video
  • Sitemap

Risky Business Media

  • About
  • People
  • Advertising
  • Sponsor Enquiries: sales@risky.biz

Risky Connections

  • Risky Business on Apple Podcasts
  • Risky Business on Spotify
  • Risky Bulletin on Apple Podcasts
  • Risky Bulletin on Spotify
  • Risky Business Features on Apple Podcasts
  • Risky Business Features on Spotify
  • Risky Business Stories on Apple Podcasts
  • Risky Business Stories on Spotify
  • YouTube
  • LinkedIn

Risky Contacts

Risky Business Media Pty Ltd
PO Box 774
Byron Bay NSW 2481
General Email: editorial@risky.biz

© Risky Business Media 2007–2026. All rights reserved.
ABN 73 618 465 517