Bipartisan lawmakers seek sanctions against Indian hack-for-hire firms

A group of U.S. lawmakers has asked the Commerce Department to add BellTroX, CyberRoot, and Sunkissed Organic Farms (formerly Appin) to the entity list, accusing them of conducting cyberattacks and espionage against Americans to influence litigation. The companies are also accused of using foreign courts to suppress reporting on their activities. The request follows extensive reporting on the mercenary hacking industry.
The request targets three specific firms, with the Commerce Department's entity list serving as a mechanism to cut off their access to essential U.S. technology like cloud services and software. The lawmakers' letter specifically ties the firms to a broader pattern of litigation manipulation and data theft affecting thousands of individuals.
Notably, one of the named companies previously compelled an Indian court to order Reuters to remove its coverage, though the order was later reversed. Independent investigations by The New Yorker and Citizen Lab have also documented espionage activities linked to the other two firms, and the letter alleges Qatari government involvement, including targeting a former senior Republican lawmaker.
If the Commerce Department acts on this request, the targeted firms could face significant operational hurdles, potentially disrupting their ability to conduct cyber operations against U.S. citizens. This action may also set a precedent for how the U.S. government addresses foreign mercenary hacking, potentially deterring similar firms. However, the reliance on foreign courts for censorship highlights a broader challenge to press freedom and public awareness, which could affect how Americans learn about cyber threats targeting them.