Democratic senators Ron Wyden of Oregon and Sheldon Whitehouse of Rhode Island, and Republican congressman Pat Harrigan, on Wednesday sent a letter to U.S. Secretary of Commerce Howard Lutnick, urging him to add three Indian companies to the department’s economic sanctions “.”
The list effectively bars U.S. businesses from transacting with a named entity, with the aim of restricting the companies from accessing critical technology needed to function, including software licenses and cloud infrastructure.
The lawmakers say that these mercenary hacking companies have stolen data from thousands of Americans, and accuse the hackers of an “aggressive censorship campaign” to suppress public awareness of their alleged activities.
“This coordinated effort effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country and undermines the fundamental constitutional rights of U.S. citizens,” the lawmakers said.
It’s not clear if the Commerce Department will add the companies to its entity list, and a spokesperson did not respond to TechCrunch’s request for comment.
The letter’s request to add the companies to the entity list follows and on the hack-for-hire industry, documenting how hackers are paid to break into the inboxes and devices of executives, lawmakers, and military officials to gain an advantage in lawsuits or influence their outcomes.
One of the companies, Appin, previously secured a global court order from an Indian court forcing Reuters to take down its while Reuters appealed the order. The notice that appeared on the page said that Reuters “stands by its reporting.” The order was later lifted and the report republished.
The digital rights group Electronic Frontier Foundation two news organizations, Techdirt and the MuckRock Foundation, from legal threats after Appin engaged in “a campaign of bullying and censorship seeking to wipe out stories” about the company’s involvement in mercenary hacking.
The lawmakers’ letter said that the hack-for-hire companies “operated at the behest of the Qatari government” and that their targets included a former senior Republican lawmaker.
Appin has been linked to Qatar before. Earlier reporting Appin to a campaign of cyberattacks against FIFA officials, reportedly directed by Qatar as part of an effort to protect its plans to host the 2022 World Cup.
A representative from the Qatari government in Washington, D.C. did not respond to TechCrunch’s request for comment.
An email from TechCrunch to Anuj Khare, a director at Sunkissed Organic Farms, went unreturned.
Separate reporting by and digital investigative unit has also documented espionage activity by the two other hack-for-hire firms named in the lawmakers’ letter, BellTroX and CyberRoot.
TechCrunch sought comment from representatives at CyberRoot, but did not hear back prior to publication. BellTroX could not be reached for comment.
