US Lawmakers Push to Blacklist Indian Hack-for-Hire Firms Over Qatar-Linked Espionage

A bipartisan letter accuses BellTroX, CyberRoot and Appin's corporate successor of a decade-long spying campaign – and names a former GOP lawmaker’s family among the targets.

Three Indian firms stand accused of running commercial hacking campaigns against Americans for over 15 years. US lawmakers now want them cut off from American cloud and software infrastructure. Photo: Chris Ried/Unsplash
Three Indian firms stand accused of running commercial hacking campaigns against Americans for over 15 years. US lawmakers now want them cut off from American cloud and software infrastructure. Photo: Chris Ried/Unsplash

Three US lawmakers have asked the Trump administration to add three Indian technology firms to a federal trade blacklist, citing more than 15 years of alleged espionage against American citizens, businesses and lawyers.

Democratic Senators Ron Wyden and Sheldon Whitehouse, joined by Republican Representative Pat Harrigan, sent the letter to Commerce Secretary Howard Lutnick on Wednesday, urging him to add BellTroX InfoTech Services, CyberRoot Risk Advisory and Sunkissed Organic Farms Pvt. Ltd. – the company formerly known as Appin Technology – to the Commerce Department’s Entity List, a trade-restriction catalogue maintained by the Bureau of Industry and Security that bars listed firms from receiving American technology exports or doing business with US entities.

“This coordinated effort effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country and undermines the fundamental constitutional rights of U.S. citizens,” the lawmakers wrote in the letter to the federal commerce department.

Which are the firms?

Appin, once marketed as a New Delhi cybersecurity training outfit, was the subject of a 2023 Reuters investigative series that found the company had run hacking operations for private clients targeting politicians, executives, military officials and lawyers across multiple continents. Founded in 2003, it formally renamed itself as Sunkissed Organic Farms in 2017. Security researcher Tom Hegel of SentinelLabs has described Appin as “the progenitor from which several present-day hack-for-hire enterprises have emerged”.

BellTroX InfoTech Services came to prominence in 2020 when Citizen Lab linked it to “Dark Basin”, a hack-for-hire operation that used more than 27,000 disguised phishing links to target thousands of individuals and organisations across six continents, including US non-profits, financial firms and journalists. Citizen Lab’s John Scott-Railton called it “one of the largest spy-for-hire operations ever exposed”. The Justice Department later charged BellTroX operator Sumit Gupta, an Appin alumnus, with conspiracy to commit computer intrusion; he has not been extradited from India.

CyberRoot Risk Advisory was identified in a 2022 Reuters investigation as running hacking campaigns for corporate clients, with targets including lawyers and investors caught up in high-stakes legal and business disputes.

Allegations

The lawmakers stopped short of filing charges – that authority sits with the Justice Department – but lay out a detailed case for administrative action. They accuse the firms of running unauthorised computer intrusions for paying clients, conduct that can violate the Computer Fraud and Abuse Act, and say the companies stole data from thousands of Americans to help clients manipulate ongoing litigation.

Notably, the letter also claims that the firms operated at the behest of the Qatari government and that their targets included family members of a former senior Republican lawmaker – an allegation that echoes earlier reporting tying Appin to a Qatar-directed campaign against FIFA officials ahead of the 2022 World Cup. A Qatari government representative in Washington did not respond to Reuters’ requests for comment.

The lawmakers also accuse the firms of running an “aggressive censorship campaign” to bury reporting on their activities. In December 2023, a New Delhi court ordered Reuters to remove its Appin investigation after a complaint from an entity calling itself the Association of Appin Training Centers. The media house said at the time that it “stands by its reporting” and appealed; the order was later overturned and the story restored. The Electronic Frontier Foundation separately defended two US outlets, Techdirt and MuckRock, against legal threats linked to the same campaign.

Have the firms responded?

None of the three companies have made a public statement or responded to media queries as yet. There is, however, a standing denial on record from Appin co-founder Rajat Khare, who has fought years of media coverage tying him to the hack-for-hire industry. Through his US law firm, Clare Locke, Khare has said that he “has never operated or supported, and certainly did not create, any illegal 'hack for hire' industry”, and that his career has instead been dedicated to “cyber-defence and the prevention of illicit hacking”. The law firm Clare Locke partner, Joseph Oliveri, has said Khare “does not comment on legal proceedings, but he defends himself judicially in all relevant jurisdictions against any attacks that target him and illegitimately damage his reputation”.

What is the Entity List?

The Entity List, run under the Export Administration Regulations, restricts companies deemed a risk to US national security or foreign policy. A listing blocks firms from buying American software, hardware or components without a government licence – licences that are routinely denied. The Trump administration added Israeli spyware maker NSO Group to the list in 2021 over its Pegasus tool, and the Intellexa consortium behind Predator spyware followed in 2024.

What could happen next?

If these companies are listed, the impact could ripple beyond the three named firms. India’s hack-for-hire sector – along with smaller clusters in Israel and North Macedonia – depends heavily on Western technology infrastructure, so cutting off access could squeeze the wider industry.

India has historically been reluctant to cooperate with foreign investigations into its domestic hacking industry, and no Indian national has yet been extradited to the US on related charges. The UN, the European Parliament and civil society groups have called for binding global rules on commercial surveillance tools, though progress has been slow. The Commerce Department has not announced a decision, and it remains unclear whether the Trump administration will act on the request.

Authors

Author
NWS North America desk

NWS North America Desk

Know More