The Trump administration has enacted a series of policy changes and executive actions that significantly affect the United States' approach to cybersecurity, privacy, and surveillance. These measures include directives targeting so-called 'anti-American' activities, expanded definitions of domestic terrorism, and increased monitoring of both citizens and government employees. Notably, a national security directive (NSPM-7) and memos from the Attorney General have broadened the scope of surveillance and incentivized public reporting of suspected domestic threats, raising concerns about civil liberties and the potential chilling effect on free speech and dissent.
In parallel, federal agencies such as Immigration and Customs Enforcement (ICE) are seeking to upgrade their cybersecurity operations, with a focus on enhanced internal monitoring and data collection to support leak investigations and law enforcement activities. These efforts reflect a broader trend of linking cybersecurity operations with investigative functions, using automated tools to flag suspicious behavior and maintain comprehensive digital records. The cumulative effect of these policies is a marked increase in government surveillance capabilities and a shift in the balance between national security and individual privacy rights.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
Secretary of State Marco Rubio reportedly authorized a State Department campaign instructing U.S. embassies and consulates to counter foreign propaganda through coordinated messaging, including use of X, local influencers, academics, and community leaders. The reported guidance also called for coordination with Pentagon information operations and endorsed X Community Notes as a tool against anti-American narratives.
During 2025, the Trump administration carried out broad changes across federal agencies, including layoffs, leadership removals, budget cuts, and the dismantling of oversight and cybercrime-related functions. These actions were described as reducing federal cybersecurity, privacy, and investigative capacity while expanding government surveillance powers.
ICE sought to renew its Cyber Defense and Intelligence Support Services contract to expand collection, storage, and analysis of employee system logs and device data. The upgrade was intended to support faster internal investigations and tighter integration between cybersecurity and investigative offices.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
4 references tracked. Mallory keeps watching after this page renders.
techdirt.com
Open sourcetheguardian.com
Open sourcekrebsonsecurity.com
Open sourcewired.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.