US lawmakers push ban on alleged hack-for-hire firms

The bipartisan request targets three Indian companies for alleged cyberattacks, espionage, and efforts to suppress reporting on their activities.
A bipartisan group of U.S. lawmakers is urging the Commerce Department to move against three alleged hack-for-hire firms tied to cyberattacks, espionage, and attempts to suppress reporting about their work. The request shines a light on a little-seen part of the cybercrime economy, where companies are allegedly hired to break into accounts and devices for clients involved in lawsuits or political disputes. As IT-PUB News reports, the move also raises a broader question about how far U.S. authorities should go when foreign firms are accused of targeting Americans. For businesses, the stakes are practical: a sanctions-style designation could cut those firms off from key U.S. technology and services.
The lawmakers want BellTroX, CyberRoot, and Sunkissed Organic Farms, which previously operated as Appin, added to the Commerce Department’s economic sanctions “entity list.” That would not be a criminal conviction, but it would make it much harder for U.S. companies to do business with them and would limit access to technology they may need to operate, including software licenses and cloud infrastructure.
Lawmakers accuse the firms of targeting Americans
In a letter sent Wednesday to Commerce Secretary Howard Lutnick, Democratic senators Ron Wyden of Oregon and Sheldon Whitehouse of Rhode Island, along with Republican congressman Pat Harrigan, said the three companies had spent more than a decade carrying out cyberattacks and targeted espionage against Americans, business owners, and their lawyers.
According to the letter, the companies used those attacks to “manipulate ongoing litigation.” The lawmakers also said the firms stole data from thousands of Americans and ran an “aggressive censorship campaign” to keep the public from learning more about their alleged activity.
They cast the matter as more than a cybersecurity issue. In their view, it is also about free speech and transparency. The letter argues that the companies used foreign courts to keep Americans in the dark about cyber threats affecting their own country, undermining the constitutional rights of U.S. citizens.
The Commerce Department’s entity list could hit hard
The entity list is one of the U.S. government’s tools for cutting off access to important services and technologies. If a company is added, U.S. firms are generally barred from doing business with it unless they receive special permission.
For alleged hack-for-hire operations, that could matter a great deal. The lawmakers’ aim is to make it harder for the companies to keep operating by limiting access to software, cloud services, and other infrastructure they may rely on.
It is not yet clear whether the Commerce Department will act on the request. A department spokesperson did not respond to TechCrunch’s request for comment.
Appin remains central to the censorship dispute
The letter follows years of reporting and media investigations into the hack-for-hire industry. Those reports have described cases in which hackers were allegedly paid to break into the inboxes and devices of executives, lawmakers, and military officials in order to influence lawsuits or gain leverage in them.
One of the companies named in the letter, Appin, has already been at the center of a legal fight over reporting on its activities. Reuters previously said it was forced by an Indian court order to take down its reporting on Appin while it appealed the ruling. A notice on the page at the time said Reuters “stands by its reporting.” The order was later lifted, and the story was republished.
The Electronic Frontier Foundation also previously defended Techdirt and the MuckRock Foundation from legal threats after Appin was described as engaging in “a campaign of bullying and censorship seeking to wipe out stories” about its role in mercenary hacking.
That history helps explain why the lawmakers’ request is drawing attention beyond cybersecurity circles. The case touches not just on alleged cyberattacks, but also on legal pressure and the ability of news organizations to report on alleged wrongdoing without being silenced through court action.
The letter also points to alleged Qatar links
The lawmakers’ letter also said the companies operated “at the behest of the Qatari government” and that their targets included a former senior Republican lawmaker. The source text does not say how those allegations were substantiated, though it notes that Appin has previously been linked to Qatar in earlier reporting.
That earlier reporting tied Appin to cyberattacks against FIFA officials, allegedly directed by Qatar as part of an effort to protect its plans to host the 2022 World Cup. A representative of the Qatari government in Washington, D.C., did not respond to TechCrunch’s request for comment.
The other two firms named in the letter have also faced outside scrutiny. Separate reporting by The New Yorker and the digital investigative unit Citizen Lab documented espionage activity by BellTroX and CyberRoot. TechCrunch said it sought comment from representatives of CyberRoot but did not hear back before publication, while BellTroX could not be reached.
Washington faces a decision on mercenary hacking
The request leaves the Commerce Department to decide whether to use trade restrictions against companies accused of running cyber operations for hire. Even before any decision, the lawmakers’ move shows that hack-for-hire firms are no longer being framed only as a niche cybersecurity issue. The argument now is that they threaten American victims, the legal process, and public access to reporting.
If the companies are added to the entity list, the consequences could reach beyond diplomacy. Cutting off access to tools and services used across the digital economy could make it much harder for them to function. If the department declines to act, the letter is still likely to keep pressure on Washington to respond more forcefully to the market for mercenary hacking.