Bipartisan members of the U.S. Congress are urging the government to take stronger action against the "hack-for-hire" industry. Lawmakers have sent a letter to U.S. Secretary of Commerce Howard Lutnick, requesting that three Indian companies be added to the Commerce Department’s Entity List to restrict their access to critical U.S. resources such as software licenses and cloud services.
Name three Indian companies
The bipartisan group of lawmakers includes Senator Ron Wyden and Senator Sheldon Whitehouse from the Democratic Party, and Representative Pat Harrigan from the Republican Party. The three companies named in the letter are Appin, BellTroX, and CyberRoot.
Lawmakers stated that companies hired to carry out cyberattacks have stolen data from thousands of Americans, targeting corporate executives, legislators, and military officials. These attacks are often used in litigation strategies or to influence the outcome of cases.
Entity List restricts access to technology
Once listed on the Entity List, U.S. companies are generally prohibited from conducting transactions with the associated entity. Such restrictions directly impact the target company’s ability to obtain software licenses, cloud infrastructure, and other critical technical services.
The lawmakers also accused these companies of using overseas courts to suppress media coverage and undermine the American public’s right to be informed about cyber threats. The letter stated that such practices enable foreign entities to exploit foreign judicial systems to restrict U.S. society’s access to information about cyberattacks targeting the country.
Media investigations drive pressure
This pressure comes amid sustained investigations by multiple media outlets and research institutions in recent years into the "hacking-for-hire" industry. Related surveys reveal that some companies accept paid contracts to infiltrate email accounts and devices in order to gain an advantage in litigation, business competition, or political activities.
Among other things, Appin previously obtained a global injunction from an Indian court ordering Reuters to take down reports about its business. That injunction has since been lifted, and the reports have been republished. The Electronic Frontier Foundation has also previously assisted Techdirt and the MuckRock Foundation in responding to legal threats surrounding Appin.
The letter also stated that these companies had acted "at the request of the Qatari government," targeting individuals including a former senior Republican congressman. Earlier reports had also linked Appin to cyberattacks against FIFA officials, suggesting these operations were tied to Qatar’s interests in bidding for and hosting the 2022 World Cup.
Additional information: As of the publication of this report, the U.S. Department of Commerce has not indicated whether it will accept this request, and representatives from Qatar and the named companies have not responded to media requests for comment.
