WASHINGTON — A bipartisan group of U.S. lawmakers has called on the Trump administration to impose swift sanctions on three India-based companies, alleging they operated as paid cyber-mercenary firms that targeted thousands of American citizens, businesses, and legal professionals in a corporate espionage campaign spanning more than 15 years.

In a joint letter sent Wednesday to U.S. Commerce Secretary Howard Lutnick, Democratic Senators Ron Wyden and Sheldon Whitehouse, alongside Republican Representative Pat Harrigan, demanded that BellTroX Ltd, CyberRoot Ltd, and Sunkissed Organic Pvt Ltd (formerly known as Appin Technology) be placed on the Commerce Department’s Entity List.

Adding these organizations to the Entity List would effectively sever their access to essential American tech exports, including cloud infrastructure, enterprise software, and cybersecurity tools.

Systematic Espionage and Litigation Manipulation

Citing multi-year investigations by media outlets and digital watchdog groups such as Reuters, The New Yorker, and The Citizen Lab, lawmakers stated that these hack-for-hire organizations systematically infiltrated sensitive networks across key U.S. sectors.

The targeted entities include private equity firms, pharmaceutical companies, and over 1,000 corporate attorneys across major American law firms. The primary goal of these cyber intrusions, according to the lawmakers, was to steal proprietary data and manipulate active court cases in favor of paying clients.

The lawmakers further alleged that these mercenary operators acted at the behest of foreign actors, including the government of Qatar. Alleged targets connected to these operations included individuals opposed to Qatar's 2022 FIFA World Cup hosting bid, as well as the family of a former Republican chairman of the House Permanent Select Committee on Intelligence.

A Campaign of Global Lawfare and Censorship

Beyond direct cyber intrusions, the lawmakers highlighted what they described as an aggressive strategy of "global lawfare" weaponized by these companies to silence investigative reporting.

The firms reportedly abused foreign legal jurisdictions to obtain court orders aimed at suppressing media coverage and forcing global takedowns of investigative reports detailing their operations. Lawmakers pointed out ongoing litigation brought by these Indian entities against major U.S. media and technology giants—including Google, Meta, Microsoft, and The New Yorker—intended to censor facts surrounding their illicit activities.

"This coordinated effort effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country and undermines the fundamental constitutional rights of U.S. citizens," the lawmakers wrote in their letter.

Growing Pressure on Washington

While federal prosecutors previously indicted individual operatives connected to these groups, lawmakers warned that these foreign hack-for-hire networks continue to operate with near impunity.

The request to place the companies on the Commerce Department's Bureau of Industry and Security (BIS) Entity List marks a significant escalation in U.S. efforts to curb commercial surveillance and private sector espionage groups. Neither the U.S. Department of Commerce nor representatives from the named Indian companies responded immediately to requests for comment.