NewsTradingSentimentCalendarCommunityBriefing
World

US Lawmakers Seek Sanctions for Indian Firms in Cyber Espionage Dispute

By Geopolitics Desk · 2026-09-12 · 3 min read
A server rack with blinking status lights in a dark room
Illustration: Tradingbird

Three US lawmakers have urged the Commerce Department to blacklist three Indian IT firms, alleging a long history of cyber espionage and targeted surveillance against American entities.

A bipartisan group of US legislators has formally requested that the Department of Commerce add three Indian technology companies to the Entity List. The move, initiated by Senators Ron Wyden and Sheldon Whitehouse alongside Representative Pat Harrigan, cites evidence of a sustained cyber operation spanning more than fifteen years. According to the lawmakers, the firms have engaged in targeted espionage against US citizens, businesses, and legal professionals, representing a significant challenge to national security interests.

The companies named in the request are BellTroX, CyberRoot, and Sunkissed Organic Farms Pvt. Ltd., the latter formerly known as Appin Technology. If the Bureau of Industry and Security approves the listing, these entities would face strict restrictions on accessing US software, cloud infrastructure, and cybersecurity tools. Such a designation would effectively block their ability to procure critical digital resources from American sources, a measure intended to curtail their operational capabilities.

Allegations of Long-Term Espionage

Reports from recent years have painted a detailed picture of these firms' activities. A 2023 analysis described one of the companies as a pioneer in the hack-for-hire industry, noting its evolution from an educational startup into a network that stole secrets from military officials and executives globally. Another 2022 report identified the remaining two firms as central players in the cybermercenary sector, alleging they were frequently hired by private investigators and Western lawyers to spy on opposing parties in business and legal disputes.

Tech giants and investigative journalists have also contributed to the growing body of evidence. Google and Meta Platforms have published reports linking specific hacking activity to these companies, while outlets such as The New Yorker and the Bureau of Investigative Journalism have identified them as hackers-for-hire. The GN geopolitics/cyber desk notes that this convergence of corporate and journalistic findings has strengthened the case for regulatory action, though the firms themselves continue to deny any wrongdoing.

Legal and Regulatory Implications

The dispute has already extended into the courts, with Reuters currently facing litigation in India brought by a group representing alumni of one of the named firms. The plaintiffs accuse the news organization of damaging the reputations of students and training centers, an allegation Reuters disputes. Meanwhile, the potential listing under the Entity List would carry substantial consequences, as transactions with listed entities are generally subject to a policy of denial for export licenses.

While it remains technically possible for US companies to do business with a listed entity, the Bureau of Industry and Security has emphasized that such dealings require extreme caution and a case-by-case review. Removing a company from the list is a rigorous process, requiring a formal request to the End-User Review Committee and final approval from senior officials. This mechanism serves as a key component of the broader US export control system, designed to prevent the diversion of controlled items toward activities that harm American interests.

Awaiting Government Decision

Requests for comment sent to representatives of the three firms and the Commerce Department have gone unanswered, leaving the situation in a state of regulatory limbo. The push for action comes amid other recent frictions over foreign surveillance and security concerns, including diplomatic tensions regarding a captured US drone. As the government weighs the request, the focus remains on the potential impact of such a listing on the global cybersecurity landscape and the legal complexities of cross-border digital operations.

Stakeholders are now watching for any official response from the Department of Commerce. If a decision is made, it will be published in the Federal Register, as is standard procedure for such regulatory actions. The outcome will signal the US government's approach to addressing state-linked and private cyber threats, potentially setting a precedent for how similar cases are handled in the future. For now, the three firms continue their operations, while the legislative pressure mounts.

Based on reporting by attackofthefanboy.com, compiled by the Tradingbird desk.

Read next

More in World

More from the World desk

All desk stories