Key facts
- U.S. lawmakers have asked the Commerce Department to add BellTroX, CyberRoot, and Sunkissed Organic Farms Pvt. Ltd. to its Entity List.
Three U.S. lawmakers have urged the Commerce Department to add three Indian IT firms to its Entity List, which would cut them off from U.S. software and cloud infrastructure. The firms are accused of over 15 years of targeted espionage against U.S. citizens and businesses.
The U.S. government's potential blacklisting of these Indian firms could disrupt their operations and signal a tougher stance on cross-border cyber espionage, potentially impacting companies involved in international legal and business disputes.
Three U.S. lawmakers have requested the Commerce Department to add three Indian IT firms to its Entity List, a move that would restrict their access to U.S. software, cloud infrastructure, and cybersecurity tools. The lawmakers allege that these firms have engaged in over fifteen years of targeted espionage against U.S. citizens, businesses, and their legal representatives.
The firms in question are BellTroX, CyberRoot, and Sunkissed Organic Farms Pvt. Ltd., formerly known as Appin Technology Pvt. Ltd., along with its subsidiaries. Media coverage and reports from major tech companies have identified these entities as fronts for hack-for-hire operations. Reuters previously identified CyberRoot and BellTroX as significant players in the cyber mercenary industry, often hired by Western lawyers and private investigators for surveillance during legal and business disputes. A 2023 report by Reuters described Appin as a pioneer in the field, evolving from an educational startup into a major hack-for-hire operation that targeted executives, politicians, military officials, and wealthy individuals globally.
Representatives for Sunkissed, CyberRoot, and the Commerce Department did not respond to requests for comment. BellTroX could not be reached. Executives from all three companies have denied any wrongdoing. Other publications, including The New Yorker and the Bureau of Investigative Journalism, as well as tech giants Meta Platforms and Alphabet-owned Google, have also linked these firms to hacking activities in their reports.