U.S. Lawmakers Urge Ban on Three Indian Hack-for-Hire Firms

Bipartisan letter to Commerce Secretary seeks to block BellTroX, CyberRoot, and Sunkissed Organic Farms from accessing U.S. technology

edit
By LineZotpaper
Published
Read Time2 min
A bipartisan group of U.S. lawmakers has called on the Commerce Department to add three Indian companies—BellTroX, CyberRoot, and Sunkissed Organic Farms (formerly Appin)—to the economic sanctions entity list, accusing them of conducting cyberattacks against Americans and using foreign courts to suppress critical reporting.

Senators Ron Wyden (D-OR) and Sheldon Whitehouse (D-RI), along with Representative Pat Harrigan (R-NC), sent a letter to Secretary of Commerce Howard Lutnick urging the addition of the three firms to the department's entity list, which would effectively bar U.S. businesses from transacting with them and restrict their access to software licenses and cloud infrastructure.

The lawmakers allege that for more than a decade, these mercenary hacking companies have stolen data from thousands of Americans, carried out targeted espionage, and manipulated ongoing litigation on behalf of paying clients. They also accuse the firms of an “aggressive censorship campaign” aimed at suppressing public awareness of their activities by leveraging foreign courts.

“This coordinated effort effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country and undermines the fundamental constitutional rights of U.S. citizens,” the lawmakers wrote in the letter, which was shared with TechCrunch.

The request follows investigative reporting by Reuters that documented how hack-for-hire firms break into the inboxes and devices of executives, lawmakers, and military officials to gain advantages in lawsuits. One of the targeted companies, Appin, previously obtained a global order from an Indian court that temporarily removed Reuters' reporting on the firm; the order was later lifted and the story republished. The Electronic Frontier Foundation has also defended news organizations from legal threats by Appin.

It remains unclear whether the Commerce Department will act on the request. A spokesperson for the department did not respond to a request for comment.

§

Analysis

Why This Matters

  • The proposed ban targets a shadowy industry where companies are paid to hack opponents, often in legal disputes, threatening the security and privacy of U.S. citizens.
  • If added to the entity list, these firms would effectively lose access to critical U.S. technology, potentially crippling their operations.
  • The lawmakers' action signals growing U.S. concern over foreign mercenary hacking and its use to chill press freedom and litigation.

Background

Mercenary hacking, also known as "hack-for-hire," involves firms that conduct cyberattacks on behalf of clients, often to gain leverage in lawsuits or corporate disputes. These operations have targeted lawyers, executives, journalists, and even military officials. U.S. authorities have previously taken action against similar groups, but this is one of the first bipartisan calls to sanction specific Indian companies. The use of foreign court orders to suppress reporting adds a layer of legal intimidation beyond the hacking itself.

Key Perspectives

Lawmakers (Wyden, Whitehouse, Harrigan): The firms are endangering U.S. national security and the rights of Americans by engaging in cyberattacks and using foreign legal systems to silence critics. Adding them to the entity list is necessary to cut off their access to U.S. infrastructure. Accused Companies: No public statements have been reported. Appin has previously used Indian courts to try to block media coverage, suggesting they view such reports as defamatory. Critics/Skeptics: Some may question whether the entity list is the right tool, or whether such sanctions could face legal challenges. Others worry that targeting only a few firms does not address the broader hack-for-hire industry.

What to Watch

  • The Commerce Department's response: whether it opens an investigation or adds the firms to the entity list.
  • Possible legal actions from the targeted companies against the U.S. government or media organizations.
  • Further reporting on other hack-for-hire firms that may be linked to similar activities.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.