US Lawmakers Seek Ban on Three Hack-for-Hire Firms
3 min read
A bipartisan group of U.S. lawmakers is calling on the government to take action against three Indian companies accused of operating in the global hack-for-hire industry.
Democratic Senators Ron Wyden of Oregon and Sheldon Whitehouse of Rhode Island, along with Republican Congressman Pat Harrigan, sent a letter Wednesday to U.S. Secretary of Commerce Howard Lutnick asking the Commerce Department to place BellTroX, CyberRoot, and Sunkissed Organic Farms on its economic sanctions “entity list.”
The companies are accused of carrying out cyberattacks and espionage campaigns against Americans, including business owners, lawyers, executives and other high-profile targets. According to the lawmakers, some of the alleged hacking activity was intended to obtain information that could be used to influence ongoing legal disputes.
The Commerce Department’s entity list can significantly restrict a company’s access to U.S. technology. Once an organization is placed on the list, U.S. businesses generally face restrictions on transactions with that entity. The measure can also make it more difficult for targeted companies to access critical technology, including software licenses and cloud infrastructure.
Lawmakers accuse firms of targeting Americans
In their letter, the lawmakers said the three companies have been involved in cyber operations against Americans for more than a decade. They also accused the firms of stealing data from thousands of people and attempting to suppress reporting about their alleged activities.
The lawmakers described the efforts as an “aggressive censorship campaign,” arguing that foreign companies should not be able to use courts outside the United States to prevent Americans from learning about alleged cyber threats.
“This coordinated effort effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country,” the lawmakers said, while arguing that such actions undermine the constitutional rights of U.S. citizens.
It remains uncertain whether the Commerce Department will add the three companies to the entity list. The department did not respond to TechCrunch’s request for comment.
Appin previously faced media censorship claims
The request comes after years of investigations into the growing hack-for-hire industry. Multiple investigations have documented how cyber mercenaries can be paid to gain access to email accounts and devices belonging to executives, lawmakers and military officials, potentially giving clients an advantage in legal disputes or other conflicts.
Sunkissed Organic Farms, previously known as Appin, has faced particular scrutiny. An Indian court previously issued a global order requiring Reuters to remove reporting concerning the company while Reuters appealed the decision. At the time, Reuters said it stood by its reporting. The order was eventually lifted, and the report was republished.
The Electronic Frontier Foundation has also previously defended Techdirt and the MuckRock Foundation against legal threats connected to Appin. The digital rights organization described Appin’s actions as an attempt to remove reporting about its alleged involvement in mercenary hacking.
Alleged links to Qatar
The lawmakers’ letter also claims the hack-for-hire companies operated at the direction of the Qatari government and says one of their targets was a former senior Republican lawmaker.
Appin has previously been linked to Qatar. Earlier reporting connected the company to a cyberattack campaign targeting FIFA officials, allegedly directed by Qatar as part of efforts to protect its plans to host the 2022 World Cup.
The Qatari government’s representative in Washington, D.C., did not respond to a request for comment.
TechCrunch also contacted Anuj Khare, a director at Sunkissed Organic Farms, but did not receive a response.
Meanwhile, separate investigations by The New Yorker and the digital research group The Citizen Lab have documented alleged espionage activity involving BellTroX and CyberRoot, the other two companies named in the lawmakers’ letter.
TechCrunch contacted CyberRoot for comment but had not received a response before publication. BellTroX could not be reached.
Also read : Eric Wu’s NavigateAI Raises $25M to Tackle Construction’s Labor Crunch
