World· Government

Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms

A bipartisan group of U.S. lawmakers urged the Commerce Department to add three Indian hack-for-hire firms — BellTroX, CyberRoot and Sunkissed Organic Farms (formerly Appin) — to the agency’s export-control “entity list,” asserting the companies have carried out cyberattacks and used foreign courts to suppress reporting. The request, sent in a letter to Commerce leadership, argues that listing would block U.S. companies from supplying critical technology and cloud services to the firms.

By AI NewsroomPublished 24 minutes agoUpdated 24 minutes ago0 views
Group of bipartisan lawmakers ask US government to ban several hack-for-hire firms

Why It Matters

If the Commerce Department places these firms on the entity list, it would limit their access to software licenses and cloud infrastructure that U.S. businesses provide, potentially disrupting alleged mercenary-hacking operations. The lawmakers’ allegations also highlight broader concerns over use of foreign courts and legal threats to hide cyberattacks and influence litigation involving U.S. citizens.

Key Facts

  • Lawmakers: Senators Ron Wyden (D-OR) and Sheldon Whitehouse (D-RI), and Congressman Pat Harrigan (R) sent the letter
  • Recipient: U.S. Secretary of Commerce Howard Lutnick
  • Requested action: Add BellTroX, CyberRoot, and Sunkissed Organic Farms (formerly Appin) to the Commerce Department’s entity list
  • Entity list effect: Bars U.S. businesses from transacting with listed entities and can restrict access to software licenses and cloud infrastructure
  • Allegations by lawmakers: The firms conducted cyberattacks and targeted espionage against Americans and used foreign courts to suppress reporting and manipulate litigation, allegedly stealing data from thousands of Americans

A bipartisan group of U.S. lawmakers has formally asked the Commerce Department to place three Indian companies on its export-control “entity list,” saying the firms operate as mercenary hack-for-hire services. In a letter shared with TechCrunch, Senators Ron Wyden and Sheldon Whitehouse and Representative Pat Harrigan asked Commerce to add BellTroX, CyberRoot and Sunkissed Organic Farms (which previously operated as Appin) to the list, a designation that would prevent many U.S. companies from doing business with them. The lawmakers argue the entity-list designation would impede the firms’ ability to obtain critical technology such as software licenses and cloud infrastructure from U.S. providers. According to the letter, the companies have for more than a decade carried out cyberattacks and targeted espionage against Americans, business owners and lawyers in efforts the lawmakers describe as aimed at manipulating litigation and silencing public reporting. The letter cites a pattern of legal and online suppression tied to these firms. It notes an instance in which Appin secured a global court order in India that briefly compelled Reuters to remove reporting about the company; Reuters later republished the material after the order was lifted. Digital-rights groups have also described campaigns of legal pressure and censorship tied to Appin, and the Electronic Frontier Foundation defended news outlets targeted by those efforts. Lawmakers additionally allege the firms at times acted on behalf of foreign interests, saying the companies “operated at the behest of the Qatari government” and that their targets included a former senior Republican lawmaker. Prior reporting has linked Appin to cyberattacks directed at FIFA officials related to preparations for the 2022 World Cup. Independent investigations by The New Yorker and the Citizen Lab have also reported on alleged espionage activity by BellTroX and CyberRoot. TechCrunch sought comment from the named companies and from Commerce; the outlet reported no responses prior to publication and said a Commerce spokesperson did not reply to requests for comment. It remains unclear whether the Commerce Department will act on the lawmakers’ request to designate the firms on the entity list.

Keep Reading