US Cybercrime Memorandum Raises Jurisdiction and Telemetry Concerns for European Organizations

· Original article ↗

Summary

A White House memorandum creates a government-approved program for vetted US companies to conduct cyber surveillance and disruption operations against criminal groups abroad. The article examines potential risks for non-US organizations.

Key points

  • The August 12, 2026 memorandum establishes a program in which vetted private US companies can propose cyber surveillance or effects operations against criminal groups abroad, subject to written government approval.
  • The article says companies may enter agreements to provide threat information collected in ordinary business activities, potentially creating a channel for security telemetry to inform operations.
  • The memorandum's specific safeguards focus on US persons and systems; the author argues non-US organizations have fewer procedural protections and no enforceable rights under the program.
  • The article warns that operations against criminal infrastructure could affect legitimate systems used or controlled by European organizations.
  • Operating procedures were due within 60 days, with further details expected in October 2026.
  • The author recommends asking security vendors where telemetry is held, which legal systems govern them and their subprocessors, and whether contracts permit onward sharing.

Article Details

Event Type
US policy memorandum establishing a program for government-approved private-sector cyber surveillance and disruption operations against criminal groups abroad.
Impact
No operation or resulting harm is reported. Guardsix warns that non-US organizations could face risks from the sharing of security telemetry or operations affecting systems outside the United States. The article states that the memorandum's specific stop-and-notify procedures concern US persons and systems.

People

Vendors

Products

Countries

Industries