Press "Enter" to skip to content

Lawmakers Want to Cut Off Three Companies Accused of Hacking Americans

Imagine paying a company to break into someone’s email. That is the business model U.S. lawmakers are now trying to shut down.

A bipartisan group of U.S. lawmakers has asked the U.S. government to blacklist three hack-for-hire firms based in India. These are companies that carry out cyberattacks for paying clients. The lawmakers say the firms spied on Americans for years, stole private data, and used foreign courts to bury news coverage of what they were doing.

Here is what the request actually asks for, who is behind it, and why it reaches all the way to the Qatari government and the 2022 World Cup. We will keep the technical parts plain and define them as we go.

What a Hack-for-Hire Firm Actually Is

Start with the term itself. A hack-for-hire firm is a company you pay to break into someone’s accounts or devices.

The client hands over a target and a fee. The firm does the breaking in. The stolen emails, files, or messages then go back to whoever paid. This is often called mercenary hacking, because the attacker has no personal stake—just a paycheck.

You do not need to understand how a phishing email works to grasp the danger here, in the same way you do not need to understand lock-picking to know a burglar is a problem. The point is simple. Someone with money can rent access to your private life.

The targets are rarely random. Lawmakers say these firms went after business owners, their lawyers, and other Americans to gain an edge in ongoing lawsuits. Break into the right inbox, and you can shape how a legal fight plays out.

Keep this straight: mercenary hacking is not about spying for a country. It is spying for whoever pays the bill.

The Three Companies Named

The letter names three Indian companies. Two use their own names. One has changed its name over time.

Here are the firms the U.S. lawmakers want blacklisted:

  1. BellTroX
  2. CyberRoot.
  3. Sunkissed Organic Farms, which used to operate under the name Appin.

That last one is worth a second look. Sunkissed Organic Farms sounds like a produce stand, not a hacking operation. But according to the lawmakers, it is the same outfit that once went by Appin, a name that appears repeatedly in reporting on the hack-for-hire industry.

The lawmakers say all three have spent more than a decade running cyberattacks and targeted espionage against Americans. They accuse the firms of stealing data from thousands of people to manipulate litigation—meaning to tilt the outcome of court cases.

The takeaway for you: a clean-sounding company name tells you nothing about what a company does. Judge by conduct, not branding.

The Tool Lawmakers Want to Use: The Entity List

The request centers on one specific tool. It is called the entity list.

The entity list is a blacklist kept by the U.S. Department of Commerce. When a company lands on it, U.S. businesses are effectively barred from doing business with that company. No selling to it. No working with it.

Why does that hurt? Because modern hacking operations still run on ordinary technology. They need software licenses and cloud infrastructure to function, just like any other tech business. Cut off that access, and the operation gets much harder to run.

Think of it like revoking a contractor’s access to every hardware store in the country. They may still know how to build, but they cannot buy the tools or the lumber. The entity list works the same way for a hack-for-hire firm.

On Wednesday, three lawmakers sent a letter making this request directly. Democratic senators Ron Wyden of Oregon and Sheldon Whitehouse of Rhode Island joined Republican congressman Pat Harrigan. They urged Secretary of Commerce Howard Lutnick to add the three companies to the list.

The letter is a formal push, not a done deal. It is unclear whether the Department of Commerce will actually act, and a spokesperson did not respond to a request for comment.

One thing to remember: economic sanctions like the entity list attack the money and the tools, not the people. The goal is to starve the operation of what it needs to run.

The Censorship Angle

The accusations go beyond hacking. The lawmakers say these firms also worked to silence the reporters covering them.

Here is the claim in plain terms. When journalists published stories about the hacking, the firms allegedly ran an aggressive censorship campaign to bury those stories. And they did it, the lawmakers say, by abusing foreign courts.

The pattern looks like this. A company gets a court in another country to order a story taken down. The news outlet then faces a legal fight just to keep its reporting online.

The clearest example involves Appin. The company secured a court order in India that forced Reuters to pull its reporting while the news agency appealed. During that time, a notice on the page said Reuters “stands by its reporting.” The order was later lifted, and Reuters put the story back up.

Other outlets faced similar pressure. The digital rights group Electronic Frontier Foundation stepped in to defend two organizations, Techdirt and the MuckRock Foundation, against legal threats. The group described the effort as a campaign of bullying and censorship aimed at wiping out stories about the company’s role in mercenary hacking.

The lawmakers framed this as a threat that reaches ordinary citizens. They warned that foreign entities are using foreign courts to keep the American public is in the dark about cyber threats aimed at their own country, and that this undermines the constitutional rights of U.S. citizens.

Why this matters: a hack steals your data. A censorship campaign hides the fact that it happened. The second problem can be worse than the first.

The Qatar Connection

This is where the story stops being only about three companies. The lawmakers say the hacking was done on behalf of a government.

According to the letter, the hack-for-hire companies operated at the behest of the Qatari government. Their targets, the lawmakers say, included a former senior Republican lawmaker.

Appin has been tied to Qatar before this letter. Earlier reporting linked the company to a wave of cyberattacks against FIFA officials. That effort was reportedly directed by Qatar as part of a push to protect its plans to host the 2022 World Cup.

A representative for the Qatari government in Washington, D.C. did not respond to a request for comment. An email to Anuj Khare, a director at Sunkissed Organic Farms, went unreturned.

You do not need to follow international politics closely to see why this raises the stakes, in the same way you do not need to be a lawyer to know the difference between a pickpocket and an organized crime ring. When a government allegedly hires the hackers, the target list gets bigger and the consequences get heavier.

The takeaway for you: the request is not just about punishing three firms. It is about a government allegedly renting cyberattacks against Americans.

The Reporting Behind the Claims

These accusations did not appear out of nowhere. They rest on years of investigation.

The letter follows extensive media reporting on the hack-for-hire industry. Those investigations documented how paid hackers break into the inboxes and devices of executives, lawmakers, and even military officials to gain an advantage in lawsuits or sway their outcomes.

The other two named firms carry their own paper trail. Separate reporting by The New Yorker and the digital investigative unit Citizen Lab documented espionage activity by both BellTroX and CyberRoot.

Both companies were given a chance to respond. CyberRoot did not reply to a request for comment before publication. BellTroX could not be reached.

Keep this straight: the entity list request is built on documented reporting, not a single accusation. That history is why lawmakers are treating it seriously.

What This Means for You

Step back, and the practical lesson is broader than any one case. The hack-for-hire industry proves that private data has a price and that someone may be willing to pay for it.

You cannot personally shut down a mercenary hacking firm. But you can make yourself a harder target. Here are a few steps worth taking:

  1. Turn on two-factor authentication for your email and financial accounts.
  2. Use a password manager so every account has a long, unique password.
  3. Slow down before clicking links in unexpected emails, since phishing is a common way in.
  4. Keep your phone and computer updated, since old software is easier to break into.

None of this requires technical skill, in the same way locking your front door does not require a security degree. These habits raise the effort needed to reach you, and effort is exactly what a paid attacker wants to avoid.

Pick one: open your email settings right now and switch on two-factor authentication. Do it before you close this page.

Conclusion

The push by U.S. lawmakers to add BellTroX, CyberRoot, and Sunkissed Organic Farms to the Department of Commerce entity list is a direct move against the hack-for-hire industry, and it carries weight far beyond three Indian companies. The bipartisan letter from Ron Wyden, Sheldon Whitehouse, and Pat Harrigan accuses these mercenary hacking firms of running cyberattacks and targeted espionage against Americans, stealing data from thousands of people, abusing foreign courts in a censorship campaign, and operating at the behest of the Qatari government in efforts that reportedly reached FIFA officials and the 2022 World Cup. Whether Secretary Howard Lutnick and the Department of Commerce use economic sanctions to cut these firms off from cloud infrastructure and software licenses is still an open question. This is not a guarantee of action, but the request marks a serious attempt to hold the hack-for-hire world accountable.

The client picks the target and pays a fee, and the firm does the hacking. Because the attacker has no personal motive beyond money, this practice is often called mercenary hacking. Lawmakers say the firms named here targeted Americans to influence lawsuits.

2. What is the Commerce Department’s entity list, and what would it do?
The entity list is a blacklist run by the U.S. Department of Commerce. Once a company is added, U.S. businesses are effectively barred from doing business with it.


3. Which companies do the lawmakers want banned?
The letter names three Indian companies: BellTroX, CyberRoot, and Sunkissed Organic Farms, which previously went by the name Appin.


4. How does Qatar fit into this?
The lawmakers say the hack-for-hire firms operated at the behest of the Qatari government, and that their targets included a former senior Republican lawmaker.


5. What can I do to protect my own data?
Turn on two-factor authentication, use a password manager for long unique passwords, avoid clicking suspicious links, and keep your devices updated. 

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *