|
Going On Offense
The U.S. could soon be unleashing a new weapon in its ongoing fight against international cybercrime.
In a memorandum on Aug. 12, President Donald Trump directed the National Coordination Center to create a program where American companies would attack foreign cybercriminal organizations. The NCC operates under the Justice Department and the Department of Homeland Security.
In the past, private companies supported government investigations by gathering evidence or taking out infrastructure. The new presidential memorandum changes that role, says Dan Schiappa, president of technology and services at Arctic Wolf Networks, a computer and network security firm. It allows vetted companies to take the lead in disrupting international cybercriminal rings, he says. “That's new, and it reflects how seriously governments and [industries] are treating the scale and sophistication of global cybercrime.”
Americans lost almost $21 billion to cybercrime last year, up more than 25% from 2024, according to the FBI’s 2025 Internet Crime Report. And cybersecurity is certainly a significant challenge for the banking industry. Ninety-two percent of bank leaders identified cybersecurity as one of the top risks facing their institution, according to Bank Director’s 2026 Risk Survey. Further, 37% said cybersecurity received heightened attention from regulators during their last exam.
Banks are unlikely to participate in state-sanctioned hacking due to the legal and geopolitical risk that activity could bring, Schiappa says. Instead, it will likely be smaller cybersecurity firms and startups eager to gain government contracts. “For most regulated financial institutions, the smarter play is staying focused on defense and letting this program play out,” he adds.
Aspects of the program are unclear right now, such as how the companies will be vetted and compensated for participating. There are also bad actors who blur the line between being state-sponsored and independent criminals, Schiappa says. Because of that, participants will need to validate who they are targeting to minimize the potential for an international incident.
If the effort is successful, it could pressure criminal organizations, including fraud rings and ransomware operators, that target the financial services sector, Schiappa says. Still, that could only make a difference “at the margins,” and banks must continue to be vigilant. “Banks that keep investing in strong defense will be in a better position than anyone who's counting on this policy to fix the problem for them,” he adds.
• Jackie Stewart, executive editor for Bank Director
|