Bipartisan Lawmakers Seek US Blacklist for Three Indian Hack-for-Hire Firms
Bipartisan lawmakers urge Commerce to blacklist BellTroX, CyberRoot and Sunkissed Organic Farms over alleged hacking and censorship targeting Americans.
Summary
On September 9, 2026, Democratic senators Ron Wyden and Sheldon Whitehouse and Republican congressman Pat Harrigan asked Commerce Secretary Howard Lutnick to add three Indian companies, BellTroX, CyberRoot and Sunkissed Organic Farms, formerly Appin, to the Entity List. They allege the firms spent more than a decade stealing data from thousands of Americans, business owners and lawyers to manipulate litigation, then used foreign courts to suppress coverage. Listing would effectively block US transactions and restrict access to essential software licenses and cloud infrastructure.
The lawmakers say the firms worked for Qatar and targeted a former senior Republican lawmaker. Appin was previously linked to Qatar-directed cyberattacks against FIFA officials intended to protect its plans for the 2022 World Cup. An Indian court issued a global order forcing Reuters to remove Appin reporting during an appeal, but later lifted it, allowing republication. The Electronic Frontier Foundation defended Techdirt and the MuckRock Foundation against Appin legal threats, while The New Yorker and Citizen Lab separately documented espionage involving BellTroX and CyberRoot. The Commerce Department has not said whether it will impose the requested restrictions.
Positives
- Three lawmakers from both parties jointly asked the Commerce Department to restrict BellTroX, CyberRoot and Sunkissed Organic Farms.
- Entity List designation could deny the three firms US software licenses, cloud infrastructure and business transactions.
- Reuters republished its Appin investigation after the Indian court order requiring its removal was lifted.
- The Electronic Frontier Foundation defended Techdirt and the MuckRock Foundation against Appin’s legal threats.
Risks & concerns
- Thousands of Americans allegedly had data stolen during more than a decade of attacks intended to influence litigation.
- Foreign court actions allegedly helped suppress US reporting about cyber threats and mercenary hacking operations.
- The lawmakers say the firms operated for Qatar and targeted a former senior Republican lawmaker.
- Appin was linked to attacks against FIFA officials connected to Qatar’s plans for the 2022 World Cup.
- The Commerce Department has not indicated whether it will add the three companies to the Entity List.