American businesses are facing a more coordinated cybercrime environment, with transnational criminal groups increasingly combining hacking, fraud, cryptocurrency and online infrastructure to target U.S. victims.
Recent federal enforcement actions show why companies need to treat cyber-enabled crime as both a cybersecurity and business-risk issue. In July 2026, the U.S. Department of Justice announced charges against three Russian nationals and two companies accused of supporting international cybercrime that allegedly caused more than $62 million in losses to U.S. victims. The FBI said Americans reported more than $20 billion in cybercrime losses during the previous year.
Federal agencies are increasing cooperation
The federal response increasingly involves cooperation between government agencies, technology companies, financial institutions and other private-sector organizations. The DOJ’s Global Cyber and Intellectual Property Crimes program works internationally with foreign law-enforcement and judicial partners to investigate cybercrime and collect electronic evidence in transnational cases.
A recent example came through the Scam Center Strike Force. During a June 2026 “Disruption Week,” private-sector companies voluntarily disrupted millions of social-media, email and internet accounts connected to transnational criminal organizations, while information supplied by the government helped companies freeze more than $3.8 million in cryptocurrency allegedly connected to stolen funds.
What the new federal approach means for businesses
There is not one single federal “cybercrime guideline” that replaces every existing cybersecurity obligation. Instead, businesses must navigate a combination of DOJ enforcement policies, FBI reporting guidance, SEC disclosure rules and cybersecurity recommendations.

The DOJ’s March 2026 Department-wide Corporate Enforcement Policy is particularly important for companies that discover criminal misconduct. It creates incentives for voluntary disclosure, cooperation and timely remediation and can provide significant benefits to companies that meet the policy’s requirements.
Incident response should start before a crisis
Businesses should establish relationships with federal and local law enforcement before a major cyber incident occurs. The FBI Office of Private Sector works with companies and critical-infrastructure organizations to exchange information and improve resilience against emerging threats.
For publicly traded companies, cybersecurity incidents can also create securities-law disclosure questions. The FBI’s guidance on SEC reporting explains how companies can seek a delay of certain disclosures when an incident creates substantial national-security or public-safety risks.
Five priorities for American companies
- Know your critical assets: Identify sensitive data, systems, intellectual property and financial accounts that criminals would most likely target.
- Strengthen authentication: Use multifactor authentication and strong, unique credentials across business systems.
- Verify financial changes: Independently confirm requests involving payments, vendors or beneficiary-account changes.
- Prepare an incident-response plan: Establish legal, technical, communications and law-enforcement contacts before an attack.
- Report quickly: Engage appropriate authorities early when a serious cyber incident or fraud scheme is discovered.
The FBI has long recommended independent verification of payment requests, stronger passwords and multifactor authentication as defenses against business-email-compromise schemes.

Why transnational cybercrime is becoming a board-level issue
Modern cyber-enabled crime rarely stays inside one jurisdiction. Criminal infrastructure, victims, payment networks, cloud services and cryptocurrency transactions can span multiple countries, making international cooperation essential.
For American businesses, that means cybersecurity cannot be treated solely as an IT responsibility. Legal, compliance, finance, executive leadership and security teams all have roles in detecting attacks, preserving evidence, managing disclosures and responding to law enforcement.
The federal government’s increasingly coordinated approach sends a clear message: companies are expected to build resilience, but they also have a growing opportunity to work directly with authorities when criminal activity crosses borders. Businesses that prepare before an incident can be in a much stronger position when the next transnational cyber threat arrives.
#Cybercrime #Cybersecurity #TransnationalCrime #CyberEnabledCrime #BusinessSecurity #FBI #DOJ #CyberRisk #DataSecurity