Wyden, Harrigan and Whitehouse Call on Commerce Department to Sanction Mercenary Foreign Hacking Firms
September 09, 2026 Wyden, Harrigan and Whitehouse Call on Commerce Department to Sanction Mercenary Foreign Hacking Firms Bipartisan Members of Congress Urge Secretary Lutnick to Take Action Against Three Indian Companies Linked to Hacks of Thousands of Americans and U.S. Companies; Hacking Companies Silenced U.S. Journalists, News Outlets and Technology Companies In Foreign Courts To Censor Reporting WASHINGTON, D.C. — U.S. Senator Ron Wyden, D-Ore., Sen. Sheldon Whitehouse, D- R.I. and Rep. Pat Harrigan, R-N.C., called for Commerce Secretary Howard Lutnick to take action against three companies based in India that have hacked and stolen data from thousands of Americans and U.S. companies. “Several India-based cyber-mercenary groups have spent more than fifteen years conducting targeted espionage against U.S. citizens, businesses and the lawyers representing them,” Wyden, Harrigan and Whitehouse wrote to Lutnick . “Compounding this security threat, these cyber mercenaries and their associates have engaged in an aggressive campaign of global lawfare to censor investigative reporting by prominent American media organizations. This coordinated effort effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country and undermines the fundamental constitutional rights of U.S. citizens.” According to investigations by Reuters and The Citizen Lab , these companies conducted widespread hacking campaigns targeting private equity firms, pharmaceutical companies, and more than 1,000 attorneys across major U.S. law firms to manipulate ongoing litigation. There is evidence that these groups have operated at the behest of the Qatari government, targeting opponents of Qatar’s World Cup bid and the family of a former Republican Chairman of the House Permanent Select Committee on Intelligence. These same companies also have attempted to censor reporting about their hacking campaigns by abusing foreign courts — at one point forcing a global takedown of Reuters’ investigation. The Indian companies have ongoing lawsuits against U.S. technology and media companies, including Google, Meta, Microsoft and The New Yorker to silence criticism and bury facts about their illegal hacking campaigns. The members called on the Commerce Department’s Bureau of Industry and Security to add three companies identified by Reuters and Citizen Lab as the perpetrators of these major hacking operations— to the Entity List to cut off their access to American software, cloud infrastructure, and cybersecurity tools: Sunkissed Organic Farms Pvt. Ltd. (formerly known as “Appin Technology Pvt. Ltd.”) and its subsidiaries, including: Adaptive Control Security Global Corporate Pvt. Ltd. (formerly known as “Appin Software Security Pvt. Ltd.” or “Appin Security Group”) ABP Holdings Pvt. Ltd. (formerly known as “KGW Appin Knowledge Solutions Pvt. Ltd.”) BellTroX Pvt. Ltd. CyberRoot Pvt. Ltd. The full letter is available here . ### Print Email Tweet Previous Article
9105c33b-996c-48a1-bc20-9ef8ea4b945fIssued within 24 hours
Other senators' releases published in the day before or after this one.