Wednesday, September 9, 2026

A bipartisan coalition of U.S. lawmakers has formally requested that the federal government impose a ban on several hack-for-hire firms—companies that execute cyberattacks on behalf of paying clients. The legislators allege that these entities have targeted American citizens and exploited foreign judicial systems to suppress U.S. reporting on their operations.

On Wednesday, Democratic Senators Ron Wyden of Oregon and Sheldon Whitehouse of Rhode Island, alongside Republican Congressman Pat Harrigan, sent a letter to U.S. Secretary of Commerce Howard Lutnick. They urged him to place three Indian companies on the department’s economic sanctions “entity list.”

Inclusion on this list effectively prohibits U.S. businesses from conducting transactions with the designated entity, aiming to restrict their access to critical technologies necessary for operation, such as software licenses and cloud infrastructure.

In the letter, which was shared with TechCrunch, the lawmakers assert that BellTroX, CyberRoot, and Sunkissed Organic Farms (formerly known as Appin) have spent over a decade conducting cyberattacks and targeted espionage against American citizens, business owners, and their legal counsel to “manipulate ongoing litigation.”

The lawmakers claim these mercenary hacking outfits have stolen data from thousands of Americans and accuse them of executing an “aggressive censorship campaign” to suppress public awareness of their alleged activities.

“This coordinated effort effectively allows foreign entities to exploit foreign courts to keep the American public uninformed about cyber threats to their own country, thereby undermining the fundamental constitutional rights of U.S. citizens,” the lawmakers stated.

It remains uncertain whether the Commerce Department will add the companies to its entity list, and a spokesperson did not respond to TechCrunch’s request for comment.

The lawmakers’ request to sanction these companies follows extensive reporting and media investigations into the hack-for-hire industry, which has documented how hackers are paid to infiltrate the inboxes and devices of executives, lawmakers, and military officials to gain an advantage in lawsuits or influence their outcomes.

One of the implicated companies, Appin, previously obtained a global court order from an Indian court forcing Reuters to remove its reporting on the company while Reuters appealed the order. The notice that appeared on the page at the time stated that Reuters “stands by its reporting.” The order was eventually lifted, and the report was republished.

The digital rights organization Electronic Frontier Foundation previously defended two news outlets, Techdirt and the MuckRock Foundation, from legal threats after Appin engaged in “a campaign of bullying and censorship seeking to wipe out stories” regarding the company’s involvement in mercenary hacking.

The lawmakers’ letter alleged that the hack-for-hire companies “operated at the behest of the Qatari government” and that their targets included a former senior Republican lawmaker.

Appin has previously been linked to Qatar. Earlier reporting connected Appin to a campaign of cyberattacks against FIFA officials, reportedly directed by Qatar to protect its plans to host the 2022 World Cup.

A representative for the Qatari government in Washington, D.C. did not respond to TechCrunch’s request for comment.

An email sent by TechCrunch to Anuj Khare, a director at Sunkissed Organic Farms, went unreturned.

Separate reporting by The New Yorker and the digital investigative unit The Citizen Lab has also documented espionage activities by the two other hack-for-hire firms named in the lawmakers’ letter, BellTroX and CyberRoot.

TechCrunch sought comment from representatives at CyberRoot but did not receive a response prior to publication. BellTroX could not be reached for comment.

Source link

Exit mobile version