Lawmakers Call for Action Against Indian Firms
A bipartisan group of US lawmakers has formally urged Commerce Secretary Howard Lutnick to impose sanctions on three India-based technology companies. Democratic Senators Ron Wyden and Sheldon Whitehouse, alongside Republican Representative Pat Harrigan, specifically named BellTroX, CyberRoot, and Sunkissed Organic Farms Pvt Ltd (formerly Appin Technology Pvt Ltd) in their request.
The lawmakers allege that these firms are operating extensive "hack-for-hire" operations and conducting targeted cyber espionage against American citizens, US businesses, and legal professionals.
Allegations of Extensive Cyber Espionage
According to the letter sent to Secretary Lutnick, the India-based cyber-mercenary groups have been engaged in targeted espionage campaigns for over 15 years. These operations are said to have impacted thousands of Americans and US companies, including private-equity and pharmaceutical firms, as well as more than 1,000 lawyers associated with major US law firms.
The lawmakers' concerns center on a global hack-for-hire industry where commercial cyber groups allegedly conduct hacking and surveillance operations on behalf of clients. The three named companies are linked to campaigns aimed at obtaining sensitive information from individuals and organizations, including business executives, lawyers, and companies involved in commercial or legal disputes. Stolen information, the letter suggests, could be used to influence or gain an advantage in ongoing litigation.
Further allegations include some groups operating at the behest of foreign clients, with connections to efforts involving Qatar's World Cup bid and the targeting of individuals associated with US political and intelligence circles.
The Significance of the Entity List
The congressional request goes beyond merely seeking a criminal investigation; it aims to place the three companies on the Commerce Department's Entity List. This powerful US export-control mechanism can severely restrict a company's ability to obtain US-origin goods, software, and technology without a specific license.
If added to the list, the lawmakers argue these restrictions could cut the firms' access to critical American software, cloud infrastructure, and cybersecurity tools, potentially raising their operational costs and technological constraints. The final decision, however, rests with the Commerce Department and its Bureau of Industry and Security, not directly with the congressional request.
Concerns Over Suppressing Reporting
Adding another layer of concern, the lawmakers also highlighted alleged attempts to suppress reporting on these hacking activities. They accuse the companies and their associates of using legal proceedings in foreign jurisdictions to challenge or remove investigative reports concerning their operations. Such efforts, according to the lawmakers, constitute an aggressive campaign to limit public scrutiny of cyber-mercenary activities.
The letter also cited legal disputes involving prominent US technology and media companies, including Google, Meta, Microsoft, and The New Yorker, underscoring the broader implications for press freedom and digital security.
Denials and Broader Implications
The accused Indian companies have consistently denied any wrongdoing, and legal disputes concerning the reporting and the firms' activities remain ongoing. It is important to note that these are allegations, and the decision now moves to the US Commerce Department.
This congressional request comes at a sensitive juncture for US-India technology and trade relations, as both nations seek deeper cooperation in areas like semiconductors, artificial intelligence, and advanced technology. While the proposed action is narrowly focused on alleged cyber activity, placing these Indian entities on the Entity List would represent a significant US enforcement action, potentially impacting the broader bilateral relationship.