Lawmakers call on Treasury to sanction hackers-for-hire
Bipartisan US lawmakers asked Treasury to sanction three India-based hack-for-hire firms accused of long-running espionage against Americans.
Sens. Ron Wyden and Sheldon Whitehouse and Rep. Pat Harrigan urged Treasury to add Sunkissed Organic Farms (formerly Appin), BellTroX, and CyberRoot to the Entity List. The letter says the mercenary groups conducted targeted espionage against US citizens, businesses, and lawyers for over fifteen years, allegedly including work for Qatar's government such as targeting opponents of Qatar's World Cup bid and Kristi Rogers, wife of Senate candidate Mike Rogers. Adding the firms to the Entity List would restrict their access to American software, cybersecurity tools, and cloud infrastructure. The lawmakers also accuse the groups of lawfare campaigns to censor investigative reporting on their hacking activities.
- Bipartisan letter asks Treasury to add three India-based cyber-mercenary firms to the Entity List.
- Firms named: Sunkissed Organic Farms (formerly Appin), BellTroX, and CyberRoot.
- Groups accused of 15+ years of espionage against US citizens, businesses, and lawyers.
- Alleged Qatar-linked targeting included World Cup bid opponents and Kristi Rogers.
- Lawmakers also cite lawfare efforts to censor reporting on the hacking.
Full article668 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The groups have allegedly targeted American citizens and companies, including the wife of GOP Senate candidate Mike Rogers, a former representative running in a Michigan swing race.
Listen to this article
0:00
Learn more.
A bipartisan trio of lawmakers is asking the Treasury Department to sanction three India-based mercenary hack-for-hire groups that have reportedly stolen data from thousands of American citizens and companies.
Democratic Sens. Ron Wyden of Oregon and Sheldon Whitehouse of Rhode Island and Rep. Pat Harrigan, R-N.C., sought in a letter to Secretary Howard Lutnick Wednesday to have the mercenary firms added to the Treasury Department’s Entity List, which would limit their access to American software, cybersecurity tools and cloud infrastructure.
“Several India-based cyber-mercenary groups have spent more than fifteen years conducting targeted espionage against U.S. citizens, businesses and the lawyers representing them,” Wyden, Harrigan and Whitehouse wrote. “Compounding this security threat, these cyber mercenaries and their associates have engaged in an aggressive campaign of global lawfare to censor investigative reporting by prominent American media organizations. This coordinated effort effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country and undermines the fundamental constitutional rights of U.S. citizens.”
The three firms are Sunkissed Organic Farms, BellTroX and CyberRoot. The first of those three was formerly known as Appin and has been the subject of investigative reports and criminal probes. The Citizen Lab at the University of Toronto has delved into the work of BellTroX, and journalists also have reported on the activity of CyberRoot.
“The threat is further heightened by evidence that these groups have operated at the behest of the Qatari government, targeting opponents of Qatar’s World Cup bid and even the family of a former Republican Chairman of the House Permanent Select Committee on Intelligence,” the lawmakers wrote. “While one of these operatives has been indicted by the Department of Justice, the foreign hackers continue to operate with impunity.”
Reuters reported in 2023 that the family member was Kristi Rogers, wife of former House Intelligence Chairman Mike Rogers, now running for Senate as the GOP candidate against one of the midterms’ most important and contested races against Democrat Abdul El-Sayed.
Some of the hacking groups also have sought to censor reporting on their hacking activities, the lawmakers noted.
CyberScoop couldn’t reach the companies for comment. The Treasury Department also didn’t immediately respond to a request for comment, and the government of Qatar didn’t immediately respond to an email seeking comment on the letter. TechCrunch first reported on the letter.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
The Collective Cyber Defense letter wrote your next vendor questionnaire
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
The GTA VI leaks are breaking the internet. Security researchers have seen this before.
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/us-lawmakers-treasury-sanctions-india-hack-for-hire/