VMTech
Discuss a project

US lawmakers press Commerce to restrict three alleged hacking firms

US lawmakers press Commerce to restrict three alleged hacking firms

A bipartisan group of US lawmakers has asked the Department of Commerce to add three Indian companies—BellTroX, CyberRoot and Sunkissed Organic Farms, formerly known as Appin—to its Entity List. Democratic senators Ron Wyden of Oregon and Sheldon Whitehouse of Rhode Island, alongside Republican representative Pat Harrigan, sent the request to Commerce Secretary Howard Lutnick.

The lawmakers say the firms have carried out cyberattacks and targeted espionage against Americans, business owners and their lawyers for more than a decade. Their letter alleges that the activity was used to manipulate ongoing litigation and that data was stolen from thousands of Americans.

Entity List request targets access to technology

Placement on the Entity List would effectively prevent US businesses from transacting with a named company. The intended effect is to limit access to technology the companies need to operate, including software licences and cloud infrastructure.

The request is not itself a designation, and it remains unclear whether the Commerce Department will add any of the three companies. A Commerce Department spokesperson did not respond to a request for comment reported with the letter.

Allegations combine intrusion and legal pressure

The lawmakers described the named businesses as mercenary hacking companies and accused them of an aggressive censorship campaign intended to limit public awareness of their alleged conduct. They argued that the use of foreign courts to suppress reporting on cyber threats affecting Americans undermines the constitutional rights of US citizens.

The allegations follow media investigations into hack-for-hire operations, in which clients pay attackers to compromise inboxes and devices belonging to executives, lawmakers and military officials for advantage in litigation or to influence its outcome. The letter also says the companies operated at the behest of the Qatari government and targeted a former senior Republican lawmaker.

Reporting and previous legal disputes

Appin obtained a global order from an Indian court that required Reuters to remove reporting while Reuters appealed. Reuters stated that it stood by its reporting; the order was later lifted and the report was republished. The Electronic Frontier Foundation also defended Techdirt and the MuckRock Foundation against legal threats connected to reporting about Appin.

Separate reporting by The New Yorker and Citizen Lab has documented espionage activity attributed to BellTroX and CyberRoot. Representatives for the named companies either did not respond or could not be reached before publication of the report cited in the lawmakers’ letter.

Business implication

For businesses, the episode highlights why protection of executive email and devices, careful management of third-party access, and preservation of incident evidence matter when cyber intrusions may intersect with commercial or legal disputes.

#cybersecurity#hackforhire#thirdpartyrisk#security
Open analytics
On the site 0 views
min read 3 09.09.2026
Instagram

US lawmakers press Commerce to restrict three alleged hacking firms

Open the post on Instagram ↗