Three U.S. lawmakers have urged the Trump administration to place three India-based companies on the U.S. Commerce Department's Entity List, alleging that they have been associated with long-running hack-for-hire and cyber-espionage operations targeting Americans, businesses and legal professionals.
Democratic Senators Ron Wyden and Sheldon Whitehouse and Republican Representative Pat Harrigan sent a letter to Commerce Secretary Howard Lutnick seeking action against BellTroX, CyberRoot and Sunkissed Organic Farms Pvt. Ltd., formerly known as Appin Technology Pvt. Ltd., along with its subsidiaries.
The companies have previously denied wrongdoing, and the U.S. government has not announced a decision to add them to the Entity List.
Lawmakers Raise Concerns Over Alleged Cyber-Espionage
The lawmakers allege that India-based cyber-mercenary groups have conducted targeted espionage against U.S. citizens, companies and lawyers for more than 15 years.
According to Reuters, the three firms have previously been linked in media investigations and reports from major technology companies to alleged hack-for-hire activity. The allegations include cyber operations connected to business and legal disputes.
Hack-for-hire operations differ from conventional cybercrime in that individuals or organisations allegedly pay outside operators to obtain information or conduct digital surveillance on their behalf. Such activity can create additional challenges for businesses and individuals involved in sensitive disputes.
What the US Entity List Could Mean
The Commerce Department's Entity List is an export-control mechanism used to restrict certain transactions involving designated entities.
If the three companies were added, access to specified U.S.-origin technology, software and other controlled items could face additional restrictions. Reuters reported that such a designation could affect access to U.S. software, cloud infrastructure and cybersecurity tools.
However, a congressional request is not the same as an Entity List designation. Any decision would have to come from the relevant U.S. authorities.
BellTroX and Earlier Cybersecurity Investigations
BellTroX has previously been examined by cybersecurity researchers in connection with alleged hack-for-hire activity.
A 2020 Citizen Lab investigation known as Dark Basin linked the operation to BellTroX with high confidence and reported that targets included journalists, advocacy organisations, government officials, executives and other individuals across multiple countries.
The latest congressional request therefore comes after years of investigations by researchers, journalists and technology companies into the broader cyber-mercenary ecosystem.
Technology Companies Have Also Reported Related Activity
The concerns have not been limited to government officials and journalists. Reuters reported that technology companies including Meta and Google have previously published reports linking hacking activity to firms named in the lawmakers' request.
The wider issue has also attracted attention because alleged commercial cyber-espionage can affect businesses involved in litigation, corporate disputes and other sensitive matters.
For companies operating internationally, maintaining strong cybersecurity controls alongside proper financial and compliance systems is increasingly important. Businesses should also ensure that sensitive financial information is protected through appropriate access controls and monitoring.
What Happens Next?
The U.S. Commerce Department has not announced whether it will accept the lawmakers' request. The three companies have denied wrongdoing, and the allegations remain subject to scrutiny.
If the Commerce Department ultimately adds the companies to the Entity List, the decision could impose significant technology and trade restrictions on the named entities.
For businesses, the episode highlights the growing importance of cybersecurity, third-party risk management and protection of confidential information. Strong business setup in dubai and other international operations should be accompanied by appropriate cybersecurity and compliance safeguards from the outset.