Hack-for-hire firms face potential ban in the US
One company has been linked to cyberattacks against FIFA officials.

Hack-for-hire firms face potential ban in the US. By Unsplash, Saradasish Pradhan.
- US lawmakers asked Commerce Secretary Howard Lutnick to sanction BellTrox, CyberRoot, and Sunkissed Organic Farms.
- The lawmakers say the Indian firms stole data from thousands of Americans and US companies.
- They accuse the firms of helping clients influence lawsuits and silence journalists through foreign courts.
- The Commerce Department has not decided whether to add the companies to its entity list.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
A bipartisan group of US lawmakers has asked the government to sanction 3 infamous Indian hack-for-hire companies, which have been carrying out cyberattacks on behalf of paying clients. The firms are also accused of trying to silence media outlets reporting on their activities.
In a letter to Secretary of Commerce Howard Lutnick, Democratic senators Sheldon Whitehouse and Ron Wyden, as well as Republican congressman Pat Harrigan, urge him to add the Indian firms to the department’s economic sanctions “entity list.”
US businesses are barred from transacting with foreign entities on the list. The aim is to restrict such firms from accessing critical technology such as software licenses and cloud infrastructure.
The US lawmakers want this to happen to “India-based cyber-mercenary” groups – BellTrox, CyberRoot, and Sunkissed Organic Farms, previously known as Appin, saying they have spent more than 15 years conducting targeted espionage against US citizens, businesses, and their lawyers.
We write to request that you take action against foreign mercenary hackers who have targeted and stolen data from thousands of Americans and US companies,the letter states.
According to the lawmakers, the groups’ activity equals systematic subversion of the US legal and financial sectors in order to manipulate ongoing litigation. In other words, clients buying the hackers’ services are usually rich and eager to influence the US judicial system.
The authors of the letter also cite evidence that these groups – Sunkissed Organic Farms specifically – have operated at the behest of the Qatari government, targeting opponents of Qatar’s World Cup 2022 bid at FIFA, the highest governing body of world soccer.
“These hackers are also actively weaponizing foreign legal systems to chill the speech of American journalists and US technology companies,” the lawmakers also write.
This is well documented. When Reuters reported on Appin in 2022, the company managed to secure a global court order from an Indian court and forced the news agency to take down the report, even though the order was later lifted and the report is live.
Has your password leaked?
“The company grew from an educational startup to a hack-for-hire powerhouse that stole secrets from executives, politicians, military officials, and wealthy elites around the globe,” Reuters wrote.
The lawmakers further mention ongoing lawsuits against major American media institutions and tech companies, including Google, Meta, Microsoft, and The New Yorker.
“The United States cannot allow mercenary hackers to target Americans and undermine our legal system, nor stand by as foreign nationals weaponize foreign judicial systems to enforce censorship within our borders,” the letter says.
It’s still too early to say whether the Commerce Department will add the Indian companies to its entity list.
What complicates things is the fact that both India and Qatar are major non-NATO allies of the US, and President Donald Trump is already flying aboard the Qatar-gifted Air Force One, worth $400 million.