Bipartisan Lawmakers Urge U.S. to Blacklist Indian Hack-for-Hire Firms
Bipartisan U.S. lawmakers ask Commerce to blacklist three Indian hack-for-hire firms accused of targeting Americans.
The letter was signed by Democratic Senators Ron Wyden of Oregon and Sheldon Whitehouse of Rhode Island, and Republican Representative Pat Harrigan. The lawmakers allege that BellTroX, CyberRoot, and Sunkissed Organic Farms — which formerly operated as Appin — have for more than a decade conducted cyberattacks and targeted espionage against Americans, business owners, and their lawyers to manipulate ongoing litigation.
The Commerce Department’s entity list effectively bars U.S. businesses from transacting with named entities, restricting their access to software licenses, cloud infrastructure, and other critical technology. The lawmakers say the firms have stolen data from thousands of Americans and waged an “aggressive censorship campaign” to suppress public awareness of their alleged activities.
“This coordinated effort effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country and undermines the fundamental constitutional rights of U.S. citizens,” the lawmakers wrote in the letter. A Commerce Department spokesperson did not respond to TechCrunch’s request for comment, leaving unclear whether the department will act.
The request follows extensive reporting and media investigations into the hack-for-hire industry, which have documented how hackers are paid to break into the inboxes and devices of executives, lawmakers, and military officials to gain advantage in lawsuits or influence outcomes. Appin previously secured a global court order from an Indian court forcing Reuters to take down its reporting about the company; Reuters said it stood by its reporting while appealing, and the order was later lifted and the article republished. The Electronic Frontier Foundation also defended Techdirt and the MuckRock Foundation after Appin engaged in what the group described as a campaign of bullying and censorship.
The lawmakers’ letter said the hack-for-hire firms “operated at the behest of the Qatari government” and that targets included a former senior Republican lawmaker. Earlier reporting tied Appin to cyberattacks against FIFA officials, reportedly directed by Qatar to protect its plans to host the 2022 World Cup. A representative of the Qatari government in Washington, D.C. did not respond to a request for comment.
The other two companies, BellTroX and CyberRoot, have been documented in previous espionage reporting by The New Yorker and The Citizen Lab. TechCrunch sought comment from Anuj Khare, a director at Sunkissed Organic Farms, and from CyberRoot representatives, but did not receive responses. BellTroX could not be reached.