Private Sector Cooperation in Cybercrime Investigations
Governments are turning private-sector cybercrime help from voluntary to mandatory.

Most cybercrime happens on infrastructure that the government doesn't own. In the United States, the bulk of the systems that matter most, transportation networks, telecom carriers, banking platforms, belong to private companies, not federal agencies. That single fact decides everything downstream of it. The FBI can hold all the subpoena power, prosecutorial muscle, and sanctions authority in the world, but none of it means much if the logs, the network telemetry, and the server access sit behind a corporate firewall the government has no standing to open. Law enforcement's authority to act and its ability to see are two different things, and right now, the ability to see belongs to private companies by default.
The government can't fix this by hiring more agents or buying better software, because it doesn't own the infrastructure that would let it see. Whoever owns the pipes decides who gets to look inside them, and in the American system, that's rarely the federal government.
Three forces making the cooperation gap harder to ignore in 2026
Three pressures are converging to make this gap harder to live with, and each one feeds the others. First, attackers are getting faster. At Geneva Cyber Week in May 2026, discussion centered on how AI lets criminal groups automate and scale operations, sharpen social engineering, and muddy attribution, all of which shrinks the time defenders have to respond before damage is done.
Investigations have come to depend on private data as a starting point. Records held by online service providers now sit at the center of identifying and catching criminals, so private-sector cooperation carries more weight than the system has ever asked of it before.
Third, the public infrastructure built to coordinate all this is shrinking just as the job gets bigger. Agencies set up specifically to bridge sectors and share defenses have seen their budgets and staffing cut, so more of the coordination burden lands on private companies that were never meant to carry it alone. None of this is a crisis narrative for its own sake. In 2026, governments on both sides of the ocean turned cooperation from a nice idea into formal policy.
What governments have formalized as cooperation policy
Governments have stopped asking nicely. Both the U.S. and the EU have shifted from encouraging private companies to help with cybercrime investigations to writing that help into law and policy, which tells companies that showing up to cooperate is now closer to an expectation than a favor.
The clearest U.S. signal came in a White House memorandum dated August 12, 2026, which was issued under Executive Order 14390 from March 6, 2026. The memo calls the American private sector a source of "critical offensive cyber advantage" and sets up a formal program letting vetted companies run cyber surveillance and offensive operations against foreign criminal groups. Companies don't get to freelance here. Every operation needs written approval in advance, and the work happens under the direction and supervision of the relevant federal law enforcement and homeland security departments. The memo's talk of "unleashing the private sector" sounds dramatic, but the leash is still very much in the government's hand.
The FBI followed on September 9, 2026 with a new Cyber Strategy built around four pillars. Two of them, Support Victims and Increase Impact Through Partnerships, are aimed almost entirely at private-sector cooperation. A third, Investigate, Disrupt, and Impose Cost, leans on private telemetry and victim reporting to get its work done. The strategy spells out automated intelligence sharing with victims and deeper use of existing partnership programs as the backbone of how this plays out.
The EU took a different road to a similar place. Its NIS2 Directive doesn't ask companies to volunteer information in exchange for legal cover. It mandates cybersecurity requirements across critical sectors instead, and that contrasts with the U.S. model, which is built on liability shields and voluntary sharing under the Cybersecurity Information Sharing Act of 2015. Different mechanism, same direction of travel: cooperation is no longer optional in either system, even if one gets there through incentives and the other through mandates.
The mechanisms through which cooperation happens
Policy is one thing. Cooperation actually runs through a handful of mechanisms, and each one covers a different slice of the problem but carries its own built-in weakness.
The Cybersecurity Information Sharing Act of 2015 is the main legislative channel in the U.S. It encourages businesses to voluntarily hand over threat indicators, vulnerabilities, malware samples, malicious IP addresses, to the relevant federal homeland security agency. Among the handful of cybercrime-related laws that can point to measurable investigative impact, this one has earned its keep.
The FBI runs its side of partnership through three standing programs: InfraGard, the National Cyber-Forensics and Training Alliance, and the National Defense Cyber Alliance, backed up by outreach efforts like the CISO Academy, Cyber Executive Summits, and the Leadership in Cyber program. The goal on paper is sharp: shrink the time between detection and notifying partners from days down to hours, then from hours down to minutes.
Sector-specific sharing runs through Information Sharing and Analysis Centers, or ISACs. The National Council of ISACs formed in 2003, and it now coordinates 27 of these groups, each built to move threat information between private infrastructure owners and the government as fast as possible. The response to the Salt Typhoon intrusion helped push eight major telecom and cable companies, AT&T, Charter, Comcast, Cox, Lumen Technologies, T-Mobile, Verizon, and Zayo, to form the C2 ISAC specifically to trade threat intelligence in real time.
Every one of these mechanisms has a known flaw. Law enforcement tends to hand back sanitized intelligence that won't tip off an ongoing investigation, but companies are the ones handing over raw incident data. That's a trade companies notice: give detail, get a vague warning back. Add to that the plain fact that companies worry about legal exposure, reputational damage, and losing competitive ground the moment their breach becomes somebody else's case study. Even when shared data gets properly anonymized, high-profile incidents carry a real risk of re-identification, and the FBI itself has acknowledged this to researchers looking into the problem. None of this means the mechanisms are useless. It means they're incomplete, so companies weighing whether to participate are right to ask what they actually get back.
What major joint operations reveal about what cooperation enables
Look at the biggest cybercrime disruptions of the past several years: every one of them relied on more than government authority. Private companies supplied the access, the forensic depth, and in some cases the legal workaround that made the operation possible.
Take TrickBot in 2020. Microsoft coordinated with ESET, the Financial Services ISAC, NTT, Lumen's Black Lotus Labs, and Symantec, and together they got a U.S. District Court order to take down TrickBot's command-and-control infrastructure. The clever part wasn't the takedown itself. It was Microsoft's legal angle: suing under copyright law over TrickBot's criminal misuse of Microsoft's own software code. So the operation got a civil-law hook that worked across borders, where ordinary criminal prosecution would have stalled at the first jurisdiction line.
Operation Endgame, running May 27 through 29, 2024, stands as the largest multinational botnet takedown on record. It hit infrastructure behind six separate botnets, Bumblebee, IcedID, Pikabot, SystemBC, SmokeLoader, and TrickBot, and the results included four arrests, 16 searches across multiple locations, a long list of servers pulled offline, and control seized over thousands of domains. Dozens of organizations joined the latest phase, private cybersecurity firms among them. One of the main suspects had reportedly pulled in tens of millions of euros in cryptocurrency simply by renting out criminal infrastructure to other ransomware operators.
Operation Aquila, run out of a national government in February 2025, paired a national signals intelligence agency with a national police force to disrupt Zservers, a Russian bulletproof hosting provider. Zservers had hosted data stolen in the Medibank Private breach and had supplied infrastructure to LockBit ransomware operators. The disruption cleared the way for coordinated sanctions out of Australia, the U.S., and Britain, and Dutch authorities moved in parallel to seize Zservers-owned infrastructure sitting in Amsterdam.
Three operations, three different countries, three different legal strategies. Same throughline: government authority converted into actual disruption only once private companies supplied the telemetry, the forensic trail, or the cross-border legal tool needed to act on it.
The concentration problem: who benefits from cooperation and who is structurally left out
The current cooperative model works well for a small group and barely reaches everyone else: the NSA's Cybersecurity Collaboration Center shares threat analytics with the companies best positioned to put that intelligence to wide defensive use, so the biggest vendors get the most, by design. Stairwell founder and CTO Mike Wiacek has made the sharpest version of this argument on record: concentrating intelligence sharing among the largest players does protect the most people in raw numbers, but it also means the program misses out on the wider range of threat intelligence and human expertise that smaller, more varied organizations could bring to the table.
There's a second pressure pulling in the same direction. The broader cybersecurity market is drifting toward privatized, closed-source intelligence, partly because of competition and partly to keep sensitive findings out of adversaries' hands. That instinct makes commercial sense for an individual company, but it cuts against the open-sharing model that tends to produce the best outcomes for collective defense.
A joint law-enforcement report put a name to part of the problem: public-private partnerships still lack standardized rules of engagement, and investigations suffer for it. It's an admission that the framework governing cooperation is still missing pieces, not just underused.
The strongest defense of the current setup is simple: imperfect cooperation concentrated among a few large vendors still beats no cooperation. That's true as far as it goes. But it sidesteps the question of how cooperation scales as both attack and defense speed up. AI is speeding up both attack and defense timelines at once, and the range of organizations that need to contribute threat intelligence is only growing. So a model built around a handful of large players was never going to scale cleanly to meet that.
What effective participation requires from private sector organizations
None of the mechanisms described above work for an organization that shows up only after something has already gone wrong. Reporting channels, mature telemetry, and legal clarity all need to exist before an incident, because none of them can be improvised in the middle of one.
The FBI's Cyber Strategy states that early victim reporting supplies the evidence, indicators, and financial details investigators need to build a case, warn other potential victims, and move against the people responsible. An organization with no established habit of documenting incidents or reporting them quickly simply hands investigators less to work with when the moment arrives.
The strategy also commits every FBI field office to building direct relationships with local businesses ahead of time, so reporting channels are already open when an incident hits. An organization making first contact with the FBI during an active breach is starting from behind, compared to one that already has a known point of contact.
Legal readiness matters just as much. The usual reasons companies hesitate to cooperate, reputational risk, confidentiality worries, fear of losing competitive ground, uncertainty about liability, are largely addressed by protections already built into CISA 2015. Those protections only help the organizations that have actually read them and planned around them in advance, rather than discovering them for the first time while lawyers are on the phone during a breach.
The Geneva Cyber Week 2026 session flagged capacity building as an immediate need: practical training in handling AI-enabled attacks, preserving evidence properly, maintaining chain of custody, and using AI investigative tools responsibly. Those are the specific gaps where most organizations are currently thinnest.
And for security vendors in particular, the bar is set by example. The companies that contributed real, usable analysis to the Salt Typhoon advisory, Cisco Talos, CrowdStrike, Google Mandiant, Microsoft, and others, could do so because they already ran mature threat intelligence operations capable of producing government-grade findings. The value any security company brings to this kind of cooperation tracks directly with how deep and how current its own intelligence work already is, long before the call from a federal agency ever comes in.
Sources
- Geneva Cyber Week 2026: Artificial Intelligence, cybercrime and electronic evidence: risks, opportunities, and global cooperation - Cybercrime - www.coe.int
- Expanding Capabilities to Combat Transnational Cyber-Enabled Crime
- Policy Backgrounder: Administration Allows Private Sector to Battle Foreign Cybercrime
- Navigating the New Presidential Memorandum on Transnational Cyber Enabled-Crime: Wiley
- Cybersecurity: New Cyber Strategy; Cybercrime Executive Order
- Public-private partnerships on cybercrime
- White House Memorandum Establishes Framework for Government-Directed Private-Sector Cyber Operations


