A bipartisan coalition of U.S. lawmakers has requested the government to impose sanctions on several hack-for-hire companies accused of conducting cyberattacks on behalf of paying clients. Senators Ron Wyden and Sheldon Whitehouse, along with Congressman Pat Harrigan, sent a letter to the Secretary of Commerce urging the addition of three Indian firms—BellTroX, CyberRoot, and Sunkissed Organic Farms (formerly Appin)—to the department’s entity list. This designation would restrict these companies from accessing essential U.S. technologies, including software and cloud services.
The lawmakers allege that these firms have targeted Americans, business owners, and their legal representatives for over a decade, engaging in cyber espionage and data theft to influence ongoing litigation. They also highlight an aggressive campaign by these companies to silence public reporting through foreign courts, which they argue undermines constitutional rights and keeps the public unaware of cyber threats.
The request follows investigative reporting that exposed how hack-for-hire firms infiltrate the communications of executives, lawmakers, and military officials to gain leverage in legal disputes. Notably, Appin previously obtained a court order in India to remove Reuters’ reporting on its activities, though the order was later overturned.
The letter also mentions that these companies have operated at the direction of the Qatari government, with targets including a former senior Republican lawmaker. Past reports have linked Appin to cyberattacks aimed at FIFA officials to protect Qatar’s 2022 World Cup hosting plans.
Requests for comment from the Commerce Department, the implicated companies, and the Qatari government were not returned. The lawmakers’ push to sanction these firms highlights growing concerns over the role of mercenary hackers in international cyber espionage and the challenges of addressing such threats through legal and regulatory means.