Washington — Three U.S. lawmakers are urging the American government to blacklist three Indian companies over allegations that they were involved in years of targeted hacking and espionage against U.S. citizens, businesses and lawyers.
The bipartisan push puts BellTroX, CyberRoot and Sunkissed Organic Farms Pvt. Ltd. — formerly known as Appin Technology Pvt. Ltd. — under renewed international scrutiny and could potentially cut the companies off from critical American technology if the U.S. Commerce Department acts.
According to Reuters, Democratic Senators Ron Wyden and Sheldon Whitehouse, together with Republican Representative Pat Harrigan, asked the Commerce Department to add the companies and their subsidiaries to its Entity List, citing what they described as more than 15 years of alleged targeted espionage against Americans, businesses and legal representatives.
What Would a US Blacklist Mean?
Being added to the Commerce Department’s Entity List could severely restrict the companies’ ability to obtain U.S. technology and services.
According to the lawmakers’ request, the designation could cut the firms off from American software, cloud infrastructure and cybersecurity tools, potentially creating major operational obstacles for companies accused of participating in the global cybermercenary industry.
However, the companies have not been added to the Entity List, and it remains unclear whether the Commerce Department will accept the lawmakers’ request.
Lawmakers Raise Alarm Over Alleged Espionage
The lawmakers’ allegations go beyond isolated cyber incidents.
According to reporting by TechCrunch, the congressional letter accused the companies of conducting cyberattacks and targeted espionage against Americans for years, including alleged operations connected to business disputes and litigation. The lawmakers also raised concerns about what they described as efforts to suppress public reporting about the alleged hacking operations.
TechCrunch further reported that the letter alleged the firms had stolen data from thousands of Americans and cited claims involving the targeting of individuals connected to legal disputes. Those allegations have not resulted in a new public criminal conviction announced in connection with the current congressional request.
BellTroX and the ‘Dark Basin’ Investigation
BellTroX has been under international scrutiny for years.
In 2020, researchers at the University of Toronto’s Citizen Lab published a major investigation into a hack-for-hire operation they named Dark Basin.
Citizen Lab said the group had targeted thousands of individuals and hundreds of institutions across six continents, including journalists, advocacy groups, government officials, corporate executives and organizations involved in high-profile disputes.
The researchers said they linked Dark Basin to India’s BellTroX InfoTech Services with high confidence based on technical evidence and other investigative findings.
The Citizen Lab investigation described alleged phishing operations designed to steal credentials and gather information from targets. It also documented targeting involving American nonprofit organizations and advocacy groups.
BellTroX has previously denied wrongdoing, according to Reuters reporting.
Google Also Tracked Indian Hack-for-Hire Networks
The latest congressional action comes after years of warnings from major technology companies.
Google’s Threat Analysis Group said it had been tracking an interconnected network of Indian hack-for-hire actors since 2012. The company said some individuals involved had previously worked for offensive security providers including Appin and BellTroX.
Google described the hack-for-hire industry as a fluid ecosystem in which operators can allegedly work through intermediaries, including private investigative services.
The company said it had observed Indian hack-for-hire operators targeting organizations and individuals across multiple countries and sectors, including government, healthcare, telecommunications and businesses.
That international reach has made the industry particularly difficult for authorities and technology companies to track because alleged clients may remain separated from the people carrying out the cyber operations.
Meta Previously Linked BellTroX to Surveillance-for-Hire Activity
Meta has also publicly investigated BellTroX-linked activity.
In its 2021 surveillance-for-hire threat report, Meta said BellTroX had allegedly used fake accounts to impersonate politicians, journalists and activists and engage targets through social engineering.
Meta said the activity appeared designed to gather information, including email addresses that could potentially be used in later phishing attempts. The company said it removed accounts associated with the activity.
The findings added to concerns about the growing commercial market for cyber intrusion services, where private companies or intermediaries can allegedly hire hackers to target rivals, opponents or individuals involved in disputes.
CyberRoot and Appin Also Face Longstanding Scrutiny
Reuters previously identified CyberRoot and BellTroX as major players in India’s alleged cybermercenary ecosystem, reporting in 2022 that such companies were used in disputes involving Western lawyers and private investigators.
A separate Reuters investigation in 2023 described Appin as an early and influential player in the hack-for-hire industry, reporting that the organization had allegedly evolved from an educational startup into an international cyberespionage operation.
Reuters said executives at all three companies have denied wrongdoing.
The current congressional request identifies Sunkissed Organic Farms Pvt. Ltd. as the company formerly known as Appin Technology Pvt. Ltd. and seeks restrictions covering the company and its subsidiaries.
Why Hack-for-Hire Operations Are So Difficult to Stop
Unlike traditional cybercrime groups that may steal money or data for themselves, hack-for-hire operators are allegedly paid by outside clients to conduct targeted intrusions.
That business model can make investigations more complicated.
Citizen Lab warned that commercial hacking operations can involve layers of private investigators, intermediaries and clients, potentially creating distance between those requesting an operation and those allegedly carrying it out.
Google has similarly warned that hack-for-hire operations can work through third-party investigative services and other intermediaries, making attribution and accountability more difficult.
The result is a cybermercenary ecosystem capable of crossing borders and targeting individuals who may never know who allegedly commissioned an intrusion attempt.
Ongoing Legal Dispute Adds Another Layer
The controversy surrounding Appin-related reporting has also led to ongoing litigation in India.
Reuters is involved in a legal dispute with a group calling itself the Association of Appin Training Centers, which says it represents the interests of Appin alumni and has accused Reuters of damaging the reputations of training centers and students.
Reuters disputes those allegations, and the litigation remains ongoing.
What Happens Next?
For now, the congressional letter does not itself impose sanctions or restrictions.
The key question is whether the U.S. Commerce Department will act on the bipartisan request and add BellTroX, CyberRoot and Sunkissed Organic Farms to the Entity List.
If Washington moves forward, the decision could become one of the most significant U.S. actions yet against companies accused of operating in the commercial hack-for-hire industry.
The case also highlights a broader global problem: as governments and major technology companies intensify efforts against cybermercenaries, the business of allegedly selling digital espionage services to private clients remains difficult to dismantle.
And if the U.S. blacklist push succeeds, the next question may be even bigger: will other governments begin targeting the global hack-for-hire industry the same way?

Leave a Reply