in effect
Executive Order 14390, signed March 6, 2026, directs multiple federal agencies to coordinate a stronger government response to cybercrime, fraud, and predatory schemes — such as ransomware, phishing, sextortion, and scam centers — carried out by foreign criminal organizations. It sets specific deadlines for agencies to review current tools, produce an action plan, and engage foreign governments.
Within 60 days, the Departments of State, Treasury, Defense, Justice, and Homeland Security must review existing legal, technical, and diplomatic frameworks for fighting foreign-based cybercrime. Within 120 days, those agencies must deliver an action plan to the President that also creates a new operational coordination cell inside the National Coordination Center to lead federal anti-cybercrime efforts. Within 90 days, the Attorney General must recommend a Victims Restoration Program that would return money seized from criminal organizations back to fraud victims. The State Department is directed to press foreign governments to act against these criminal groups and to pursue consequences — including sanctions, visa restrictions, trade penalties, and expulsion of complicit diplomats — against nations that tolerate such activity. CISA is directed to expand training and threat-intelligence sharing with state, local, tribal, and territorial governments.
American individuals and businesses targeted by cyber fraud, ransomware, sextortion, or scam operations are the intended beneficiaries, particularly through the proposed victim restoration fund and expanded public alerts. Federal agencies — especially DOJ, DHS, State, and Treasury — face new coordination requirements and reporting deadlines. Foreign governments whose territory hosts criminal organizations, and diplomats potentially complicit in those schemes, face the prospect of sanctions, trade penalties, and visa restrictions.