Lawmakers ask Treasury to place the firms on the Entity List
Sen. Ron Wyden (D-Ore.), Sen. Sheldon Whitehouse (D-R.I.) and Rep. Pat Harrigan (R-N.C.) asked the Treasury Department to add three India-based mercenary hack-for-hire firms to the department’s Entity List. In a letter sent to Secretary Howard Lutnick, the lawmakers argued that listing would restrict the groups’ access to American software, cybersecurity tools and cloud infrastructure — tools they say the firms have used in campaigns targeting U.S. citizens and companies.
The three firms named: Sunkissed Organic Farms, BellTroX and CyberRoot
The lawmakers identified Sunkissed Organic Farms, BellTroX and CyberRoot as the targets for the requested sanctions. According to the letter, Sunkissed Organic Farms is the firm formerly known as Appin and has been the subject of investigative reporting and criminal probes. Researchers at the Citizen Lab at the University of Toronto have investigated BellTroX, and journalists have reported on CyberRoot’s activity. CyberScoop noted it could not reach the companies for comment.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleAllegations of state-directed targeting and global “lawfare”
The letter accuses some of these groups of operating at the behest of the Qatari government, specifically citing operations against opponents of Qatar’s World Cup bid and targeting the family of a former Republican chairman of the House Permanent Select Committee on Intelligence. Reuters reported in 2023 that the family member named was Kristi Rogers, wife of former House Intelligence Chairman Mike Rogers, who the source says is running for Senate as the GOP candidate against Democrat Abdul El-Sayed.
Beyond direct espionage allegations, the lawmakers wrote that these groups and their associates have pursued “an aggressive campaign of global lawfare to censor investigative reporting by prominent American media organizations.” The letter frames that activity as a national-security concern because it “effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country and undermines the fundamental constitutional rights of U.S. citizens.”
Law enforcement, Treasury and parties named in the letter
The lawmakers’ letter notes that while one of the operatives has been indicted by the Department of Justice, the groups “continue to operate with impunity.” CyberScoop reported that the Treasury Department did not immediately respond to a request for comment, and that the government of Qatar did not immediately respond to an email seeking comment on the letter. TechCrunch first reported on the lawmakers’ letter; CyberScoop published the piece summarizing the request to Treasury.
What this means for technologists, policymakers, and affected enterprises
- Technologists and security teams: If the Treasury adds these firms to the Entity List, those teams may see fewer overt service connections between American vendors and the named organizations — the practical result would be limits on access to U.S. software, cloud infrastructure and cybersecurity tools identified in the letter.
- Policymakers and regulators: The request ties export-control tools (the Entity List) to consequences for commercial and criminal cyber operations, signaling a push to use economic controls in response to mercenary hacking and cross-border legal pressure campaigns.
- Affected enterprises and legal teams: Companies and lawyers whose data was allegedly targeted are named implicitly in the lawmakers’ claims; they may press for further law-enforcement action, civil remedies, or stronger contract protections against third-party exposure if sanctions proceed.
The lawmakers’ letter frames a familiar-but-stark choice for Treasury: use an economic lever designed to choke access to U.S. technologies, or allow groups the lawmakers say have a long history of targeting Americans to continue operating with access to those same technologies. Treasury’s response, and whether it places Sunkissed Organic Farms, BellTroX and CyberRoot on the Entity List, will determine whether those restrictions move from a policy request to a regulatory reality.




