We Can Hit Their Servers Now. The Harder Question Is Who Is Protecting Them.

A compound in Southeast Asia staffed by trafficked workers runs romance scams on Americans. A storefront in the San Gabriel Valley converts the money into ordinary wires. Under the President's new cyber memorandum both are presumed to have no link to any government.
The presumption is defensible. It may well be correct in law. It is the most consequential sentence in the document, and almost no one discusses it.
What the memorandum actually authorizes
On August 12, 2026, the President signed a National Security Presidential Memorandum called Expanding Capabilities to Combat Transnational Cyber-Enabled Crime. It builds on Executive Order 14390 from March 6, 2026.
Here is the plain version. The National Coordination Center will run a program that lets vetted American companies conduct cyber surveillance and cyber effects operations against foreign criminal organizations. Federal direction and control stay in place. Two Executive Directors, one from Justice and one from Homeland Security, approve every operation in writing before anyone acts. Participating companies sign contracts, go through vetting, and can be required to post a bond of at least $1 million. They forfeit the bond if they break the terms. State, local, tribal, and territorial agencies can pass threat information to those companies. Operating procedures are due within 60 days, around October 11. The first program report is due within 180 days, around February 8, 2027.
I want to be clear before I raise any concern. This document describes the problem the way it looks from inside a case file. It names ransomware, phishing, financial fraud, sextortion, and impersonation as coordinated campaigns run by organizations rather than a pile of unrelated consumer complaints. It treats these as organizations operating from foreign jurisdictions, out of ordinary reach. And it goes after the thing that can be reached instead.
I have argued for exactly that shift in these pages. In June I wrote that the leverage point in these cases has moved from the offender to his infrastructure, because the man is beyond us and the servers are not. This memorandum is the policy version of that argument. Getting the authority built at all is the hard part, and it is done.
What comes next is a rubric that has not been written yet. That is where a practitioner has something useful to add.
The definition that does the quiet work
Section 4(c) defines the target. A Cyber-Enabled Transnational Criminal Organization is any foreign group that conducts cyber-enabled crime against the United States, its people, or its interests, "and that is not an institutional part of a foreign government or wholly operated under a foreign government's direction."
Then comes the sentence. "For the purposes of this memorandum, a foreign group will be assumed not to be an institutional part of a foreign government or wholly operated under a foreign government's direction unless clear intelligence exists establishing such connection."
Read that twice. The default is no state involvement. The burden runs toward acting, not toward hesitating.
The definition offers two boxes. State-run, or criminal. Almost everything I have documented in the last year lives between them.
Why the presumption is probably right
The strongest case for the presumption comes first, because it is strong.
If a network is an arm of a foreign government, then hitting it stops being law enforcement. It starts implicating what the memorandum itself calls Critical Outcomes in Section 4(b), actions likely to cause loss of life or to rise to the level of use of force under international law. That is a different legal regime with different authorities and different decision-makers. It does not belong in a program run by two Executive Directors at Justice and Homeland Security.
Without the presumption, every proposed operation stalls in an attribution argument that intelligence agencies have been having for twenty years and have never fully settled. Anyone who has watched a case die waiting for someone else to make a call knows exactly how that ends. Nothing happens, and the network keeps working.
So the presumption is not sloppiness. It is a routing rule that keeps groups inside the lane where somebody can actually act on them. I would probably have written it the same way.
The second thing a classification does
Here is the part that has not come up.
Deciding a network is purely criminal authorizes the disruption. It also determines whether a completely separate machine ever starts up.
Executive Order 14390, Section 4, directs the Secretary of State to engage foreign governments, demand enforcement against organizations operating inside their borders, and ensure that "nations that tolerate such predatory activity shall face consequences." The order lists them: limiting foreign assistance, targeted sanctions, visa restrictions, trade penalties, and expelling complicit foreign officials and diplomats.
Those consequences are aimed at tolerance. Not at state control. Tolerance is a lower bar and a much more common condition, and the March order says so plainly in its own opening: "In many cases, foreign regimes provide willing or tacit state support to cybercrime and predatory schemes, creating a shadow economy fueled by stolen identities, coercion, forced labor, and human trafficking."
So the March order tells us the regimes are often part of the story. The August memorandum, for its own good reasons, instructs the program to presume they are not.
Both are right for what they are trying to do. The gap is between them. A network worked as a pure criminal target generates an operational record built to answer one question, how do we disrupt this, and that record will not accumulate the evidence Section 4 needs to answer a different one, who is letting this happen.
The memorandum does put State in the loop. Section 3(a)(v) requires operational deconfliction across State, Treasury, War, Justice, and the intelligence community. That is real, and worth noting. But deconfliction is not evidence-building. Telling State that an operation is about to happen is not the same as handing State a documented pattern of a host government looking the other way for six years.
This runs straight through Southern California
I do not write about this from a distance. These networks operate where I work.
In June 2024, the Justice Department unsealed Operation Fortune Runner, charging two dozen defendants in a California-based laundering network tied to Chinese underground banking, cleaning drug proceeds for the Sinaloa Cartel. In August 2025, Treasury's Financial Crimes Enforcement Network published Advisory FIN-2025-A003, built on 137,153 Bank Secrecy Act filings describing roughly $312 billion in suspicious transactions tied to Chinese Money Laundering Networks. By March 2026, Treasury called those networks the dominant professional laundering service for transnational criminal organizations worldwide.
Ask the memorandum's question about any of them. Is this group an institutional part of a foreign government, or wholly operated under its direction? Almost certainly not. Is clear intelligence going to establish such a connection? Almost certainly not, because the relationship is built specifically so that it cannot be.
That is the whole design. When I wrote about those laundering networks in June, this is where I landed, and I would not change a word of it now: they do not need a directive from Beijing to matter. They are a privatized weapon that hollows out American communities while moving value the PRC's own citizens use to get capital out from under their own government. Everyone in that chain is using everyone else.
No directive. No control. Enormous strategic benefit to a state that simply declines to interfere. Under Section 4(c), that is a plain criminal organization, and the presumption is satisfied without anyone bending anything.
The Arcadia cases point the same direction from the other end. Eileen Wang, Yaoning Sun, and John Chen were all convicted of acting as illegal agents of a foreign government, three nodes in one Los Angeles cluster. Each took years of counterintelligence work before a single charge was filed. That is what it costs to establish a state connection clearly enough to charge it. Now imagine requiring that standard, in near real time, before a cyber operation can be scoped as anything other than ordinary crime.
We will meet the bar almost never. The presumption will hold almost always. That is not a flaw in the drafting. It is arithmetic.
The part the policy write-ups will not say plainly
Most analysis of this memorandum has landed on whether private companies should be conducting offensive operations at all. It is a fair debate and I understand why it draws the oxygen.
But it is not the thing that decides whether losses go down.
You can run this program exactly as designed, disrupt a great deal of infrastructure, and leave the environment that produced it completely untouched. Servers get seized, and somewhere a host government that was never named, never sanctioned, and never asked a hard question watches the operators rebuild. The measure of the program becomes the number of things we knocked over, and the reason they keep getting rebuilt never enters the record.
I have watched the smaller version of this play out in case after case. We seize the account, and the account comes back. We take the domain, and the domain comes back. The only cases that stayed fixed were the ones where somebody applied pressure to whoever was providing the shelter.
How we will know it is working, and how we could be fooled
The first program report lands around February 8, 2027. Let me put a prediction on the record now, so it can be graded later.
That report will count operations approved, infrastructure disrupted, networks degraded, and participating companies onboarded. Those are honest numbers and every one of them will be real. They will also tell us almost nothing about whether Americans lost less money.
We already know why. In May I wrote about Operation Ramz, an international action that took 53 servers offline. The network kept running. The arrests were in the Middle East and North Africa. The victims were here. Fifty-three servers is a real accomplishment and it is not a kill.
Americans reported losing more than $20.8 billion to cyber-enabled crime in 2025. That is the number this program exists to move. If the February report leads with disruption counts and the loss figure has not moved, the correct response is not to celebrate the disruption counts.
Two measures would tell us more than any of it. First, how long a disrupted network stays down, and what rebuilding costs the operators. Second, how many times a host government faced an actual consequence under Section 4 of the March order. If the answer to the second one is zero after a year of successful operations, that is the finding, not a footnote.
What to actually do
Five things. The first is the one that matters, and it is small.
- Put state-nexus indicators in the reporting rubric. Section 3(a)(viii) already requires participating companies to report in a way that will "advance a greater understanding of the activities and impact of foreign CE-TCOs." The operating procedures being drafted right now define what that reporting looks like. Add the tolerance signals to the template: hosting patterns that survive repeated takedowns, jurisdictions that never respond to legal process, protection that looks purchased, infrastructure that relocates within the same borders every time. The presumption can still hold. The operation still gets approved. The evidence just stops evaporating, and Section 4 gets something to work with.
- Route that reporting to State deliberately, not incidentally. Deconfliction under 3(a)(v) tells State what is about to happen. A tolerance file tells State what has been happening. Those are different products and only one of them supports a sanctions decision.
- Grade the program on losses and on consequences, not on takedown counts. Publish the disruption numbers, and publish them next to the loss figure and the count of Section 4 actions taken. A program this well built can survive an honest scoreboard.
- For state and local agencies, understand that the threat-information channel in Section 2(a)(iii)(B) now exists and start asking how to use it. Most local agencies have no idea it is there. We take the first report and conduct the only interview the victim will ever give, and that material is worth something upstream.
- For business owners, nothing here changes what lands in your inbox tomorrow. The wire is still going to look routine and the vendor email is still going to look like the vendor. Federal disruption operates on a scale and a timeline that will never reach your Tuesday.
Where this sits in the bigger picture
I keep coming back to the same frame. The threat runs on three seams: access through people, access through equipment, and access through money.
This memorandum is the strongest instrument we have built yet for going after the third one, and it deserves credit for that. The definition inside it just decides how far up the chain we are allowed to look while we do it.
Getting the authority was the hard part, and that fight is won. What is left is a template, due in October, that nobody outside a small room is thinking about. Templates decide what gets recorded. What gets recorded decides what can be acted on later. That is not a small thing, and it is still open.

