A bipartisan coalition of U.S. lawmakers has requested that the government impose restrictions on several hack-for-hire companies accused of conducting cyberattacks targeting Americans. Senators Ron Wyden and Sheldon Whitehouse, along with Congressman Pat Harrigan, sent a letter to Commerce Secretary Howard Lutnick urging the addition of three Indian firms—BellTroX, CyberRoot, and Sunkissed Organic Farms (formerly Appin)—to the department’s economic sanctions entity list. This designation would prohibit U.S. businesses from engaging with these companies, limiting their access to critical technologies such as software licenses and cloud services.

The lawmakers allege that these firms have spent over a decade carrying out cyber espionage and attacks against individuals, business owners, and legal professionals in the U.S., often to influence ongoing litigation. They also accuse the companies of using foreign courts to suppress media coverage of their activities, thereby undermining transparency and constitutional rights.

Previous investigations have documented how hack-for-hire firms are hired to breach the devices and communications of executives, lawmakers, and military officials to gain advantages in legal disputes or other matters. Notably, Appin secured a court order in India to remove Reuters’ reporting on its operations, a move later overturned after an appeal.

The letter also notes ties between these companies and the Qatari government, including targeting a former senior Republican lawmaker. Past reports have linked Appin to cyberattacks aimed at protecting Qatar’s interests ahead of the 2022 World Cup.

Requests for comment from the Commerce Department and representatives of the named companies were not answered. The move to add these firms to the sanctions list highlights growing concerns about mercenary hacking operations and their impact on U.S. national security and legal processes.