ZeroFox Intelligence Flash Report - U.S. Private Companies to Conduct Cyber Attacks
|by Alpha Team

ZeroFox Intelligence Flash Report - U.S. Private Companies to Conduct Cyber Attacks
Product Serial: F-2026-08-20a
TLP:CLEAR
In this Flash Report, ZeroFox researchers report on the recent direction by President Trump to the National Coordination Center (NCC) to develop a program authorizing vetted U.S. companies to conduct cyber surveillance and disruption operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs).
Standing Intelligence Requirements
For the most up-to-date list of ZeroFox’s Intelligence Requirements, please visit:
https://cloud.zerofox.com/intelligence/advisories/14956
Link to Download
View the full report here
Key Findings
- On August 12, 2026, U.S. President Donald Trump signed a National Security Presidential Memorandum (NSPM) directing the National Coordination Center (NCC) to develop a program authorizing vetted U.S. companies to conduct cyber surveillance and disruption operations against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs).
- The NSPM authorizes two activities that 18 U.S.C. § 1030 had previously not allowed for commercial actors: Cyber Surveillance Operations (covering clandestine collection from adversary systems) and Cyber Effects Operations (covering disruption, degradation, or destruction). Operating procedures and participation standards are due by mid-October.
- ZeroFox assesses that criminal groups are likely to develop defensive adaptations in response to adversary capabilities that combine U.S. commercial engineering speed with federal legal cover rather than be deterred by them.
- ZeroFox assesses with moderate confidence that the program will almost certainly proceed. However, it is likely that the October deadline will yield interim rather than complete procedures and that first-cohort vetting will run into 2027, given that the NSPM did not provide details regarding how the NCC should implement the program.
Tags: tlp:clear, dark web, threat actor