Lawmakers Target Hack-for-Hire Firms With Export Controls

A bipartisan group of U.S. lawmakers asked Commerce on Wednesday to add BellTroX, CyberRoot, and Sunkissed Organic Farms to the Entity List after years of reporting that tied them to hacking campaigns against Americans, business owners, and their lawyers. The request came from Sens. Ron Wyden and Sheldon Whitehouse, and Rep. Pat Harrigan. The point of the list is practical: it can cut a named company off from U.S. software licenses, cloud services, and other technology it needs to operate abroad. The lawmakers also say the firms and their allies used foreign courts to suppress reporting about their work, including a Reuters takedown fight involving Appin. If Commerce acts, the pressure lands on the operators’ ability to keep running, not just on their bank accounts or reputations. For organizations in litigation or public controversy, the case is a reminder that hired hackers can be used to shape the record as well as to break into inboxes and devices.

Part of the PlainSec briefing for 2026-09-09

Every edition of this story: Lawmakers Target Hack-for-Hire Firms With Export Controls

Sources