How the US plan to fight transnational cyber crime affects you

How the US plan to fight transnational cyber crime affects you
A 12 August 2026 White House memorandum authorizes vetted private US companies to conduct government-directed cyber surveillance and effects operations against criminal groups abroad, creating new jurisdictional and telemetry-sharing risks for non-US organizations. The article argues that European hospitals, grid operators, and municipalities must now ask not just where their data sits, but whose authority controls the security tools they use. #WhiteHouse #CLOUDAct #NIS2 #CADA

Keypoints

  • The White House memorandum creates a formal program for private US companies to perform cyber surveillance and cyber effects operations under written government approval.
  • Operations are aimed at criminal groups abroad and are overseen by the National Coordination Center, with review from Justice and Homeland Security.
  • The memo allows commercial sharing of ordinary security telemetry, such as logs, metadata, detections, and samples, as input to proposed operations.
  • The safeguards in the memo are largely jurisdictional and focused on US persons and US systems, leaving non-US organizations with little direct recourse if targeted.
  • The article warns that legitimate European organizations could be caught in operations against “criminal infrastructure” because abused servers often sit in third-party environments.
  • It frames the memo as an expansion of cloud dependency risk, where provider authority and legal jurisdiction matter as much as data residency.
  • Guardsix positions its sovereign platform as a European alternative that keeps telemetry inside the customer estate and avoids routing data through a provider cloud.

MITRE Techniques

  • [T1595 ] Active Scanning – The memorandum enables approved companies to gather information from systems to support later operations, which can include discovering exposed assets (‘accessing information systems without the owner or operator’s authorisation… with the intent to remain undetected’)
  • [T1589 ] Gather Victim Identity Information – Participating companies may collect information about targets and related infrastructure as part of surveillance operations (‘collect information, including information that supports later operations’)
  • [T1201 ] Password Policy Discovery – No specific password discovery is described, so this technique is not explicitly mentioned in the article and is not included.
  • [T1499 ] Endpoint Denial of Service – Cyber Effects Operations may include denial or disruption of information systems (‘manipulation, disruption, denial, degradation or destruction of information systems’)
  • [T1485 ] Data Destruction – The memorandum explicitly allows destruction of data held on targeted systems (‘or the data held on them’)
  • [T1565 ] Data Manipulation – The program authorizes manipulation of information systems and potentially the data stored on them (‘manipulation, disruption, denial, degradation or destruction of information systems’)
  • [T1041 ] Exfiltration Over C2 Channel – Telemetry and threat information can be shared from private entities into a government-directed program for operational use (‘receive from them threat information collected in the course of those entities’ normal business activities’)

Indicators of Compromise

  • [Organizations / Systems ] cited as affected or at risk – European hospitals, grid operators, municipalities, and US-based security vendors
  • [Legal / Policy References ] framework and comparative context – White House memorandum, CLOUD Act, Section 702 of the Foreign Intelligence Surveillance Act, NIS2, proposed Cloud and AI Development Act (CADA)
  • [Financial Amounts ] contractual enforcement terms – $1 million bond / deposit, and other N/A items


Read more: https://guardsix.com/blog/the-us-plan-to-fight-transnational-cyber-crime