Lawmakers ask Commerce to sanction Indian firms involved in mercenary hacking
Lawmakers ask Commerce to sanction Indian firms involved in mercenary hacking
The “hack-for-hire” entities have systematically targeted newsrooms covering corporate fraud, legal teams in high-stakes litigation and NGOs.
A bipartisan, bicameral group of lawmakers is asking the Commerce Department to sanction a trio of Indian firms involved in mercenary hacking activities against U.S. citizens and companies.
Sens. Ron Wyden, D-Ore., and Sheldon Whitehouse, D-R.I., alongside Rep. Pat Harrigan, R-N.C., asked Commerce Secretary Howard Lutnik on Wednesday to impose penalties on Sunkissed Organic Farms — previously branded as Appin — BellTroX and CyberRoot, according to a letter sent Wednesday.
The three firms were exposed in a 2023 Reuters investigation into a global “hack-for-hire” industry operating out of India. BellTroX was also identified in a 2020 Citizen Lab investigation into mercenary hacking activities.
The entities systematically targeted newsrooms covering corporate fraud, legal teams in high-stakes litigation and NGOs. Their reach also extended to senior executives at firms like WeWork and Wirecard, foreign heads of state and U.S. political figures.
The Reuters reporting gained notable publicity after a New Delhi court ordered its temporary removal, triggering a global censorship controversy. Appin-linked entities backed the suit with legal threats to over a dozen media outlets, while the Indian government revoked Reuters reporter Raphael Satter’s residency status in retaliation. Following press freedom backlash, an Indian court ultimately overturned the injunction in late 2024, allowing the news service to fully restore the investigation online.
“Compounding this security threat, these cyber mercenaries and their associates have engaged in an aggressive campaign of global lawfare to censor investigative reporting by prominent American media organizations,” the lawmakers wrote. “This coordinated effort effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country and undermines the fundamental constitutional rights of U.S. citizens.”
India’s embassy in Washington, D.C., and the Commerce Department did not immediately respond to a request for comment on the letter. Nextgov/FCW also attempted to reach multiple email addresses affiliated with the three companies. Emails that appear to be tied with BellTrox and CyberRoot kicked back.
“The United States cannot allow mercenary hackers to target Americans and undermine our legal system nor stand by as foreign nationals weaponize foreign judicial systems to enforce censorship within our borders,” the lawmakers added.
How it works
Once you click Generate, Ollama reads this article and crafts 5 comprehension questions. Your answers are graded against the article content — general knowledge won't be enough. Score 70+ to count toward your certificate.
Questions are cached — you'll always get the same 5 for this article.