A bipartisan group of lawmakers wants the Commerce Department to add an Indian hack-for-hire firm to the same blacklist used to cut off NSO Group, the Israeli surveillance company that sold spyware to authoritarian governments. The request targets Appin, a company that has spent years stealing secrets from targets worldwide and then suing anyone who writes about it.

Senators Ron Wyden and Sheldon Whitehouse, both Democrats, and Representative Pat Harrigan, a Republican, sent a letter this week to Commerce Secretary Howard Lutnick asking him to place Appin and several related entities on the Bureau of Industry and Security's Entity List. The designation would cut the companies off from American technology and business partners, making it significantly harder for them to operate.

The letter describes a two-part problem: a global hacking operation that has targeted American citizens, businesses, and law firms for more than fifteen years, followed by an aggressive censorship campaign designed to keep the American public from learning about any of it.

What Appin Does

Appin positions itself as a cybersecurity and training company, but investigations by Reuters and other outlets have documented its true business model. The company grew into what Reuters described as a "leading cyberespionage firm" that "stole secrets from executives, politicians, military officials and wealthy elites around the globe."

The lawmakers' letter details specific targets. Appin and its associates have hacked into private equity firms, pharmaceutical companies, and more than 1,000 attorneys across major American law firms. The goal was not just data theft but manipulation of ongoing litigation, using stolen information to influence legal outcomes.

The letter also alleges that these groups operated at the behest of the Qatari government, targeting opponents of Qatar's World Cup bid and even the family of a former Republican chairman of the House Permanent Select Committee on Intelligence. One of the operatives involved has been indicted by the Department of Justice, but the broader network continues to function.

The companies named in the lawmakers' request include Appin, CyberRoot, BellTroX, Adaptive Control Security Global Corporate, ABP Holdings, and a company called Sunkissed Organic Farms. The inclusion of an organic farms company alongside cyberespionage firms highlights how these operations hide behind innocuous corporate structures.

The Censorship Campaign

What makes Appin unusual among hack-for-hire firms is not just the scope of its operations but the lengths it has gone to suppress reporting about them. When Reuters published its investigation into the company, Appin convinced an Indian court to order the story taken down. The ruling applied globally, including to copies hosted by the Internet Archive.

The company then extended its legal pressure to American publishers. TechDirt received demands to remove its coverage of the Reuters takedown, with Appin claiming that publishing excerpts from the Reuters article violated the Indian court order. The Electronic Frontier Foundation intervened on TechDirt's behalf, explaining why the demands had no legal basis in American law. TechDirt refused to comply, and Appin did not follow up.

Other publications were less resilient. Lawfare, a prominent legal blog, redacted portions of its coverage and kept those redactions in place for two years, even after Reuters successfully appealed the Indian court ruling and restored its original article. The Behind the Bastards podcast pulled episodes about Appin's founder, Rajat Khare, even after retitling them to avoid using his name directly.

The lawmakers' letter describes this pattern as "aggressive global lawfare" designed to "censor investigative reporting by prominent American media organizations." The effort allows foreign entities to use foreign courts to keep the American public uninformed about cyber threats to their own country.

Appin has also sued major American technology companies, including Google, Meta, and Microsoft, as well as The New Yorker. These lawsuits function as a form of pressure even when they lack merit, forcing defendants to spend resources on legal defense and creating a chilling effect on future reporting.

The Entity List Approach

The Entity List is the Commerce Department's most powerful tool for restricting access to American technology. When a company is added, it requires a license to purchase American-made components, software, or equipment. Denying those licenses effectively cuts the target off from a significant portion of the global technology supply chain.

BIS used the Entity List against NSO Group in 2021, after evidence emerged that the company's Pegasus spyware had been used to target journalists, activists, and political figures in multiple countries. The designation severely damaged NSO's business and demonstrated that the tool could be effective against surveillance and hacking companies.

The bipartisan nature of the Appin request is notable. Harrigan is a Republican, while Wyden and Whitehouse are Democrats, suggesting the issue transcends the usual partisan divisions on technology policy. The letter does not address why no Republican senators signed on, though the absence may reflect the political dynamics around foreign policy and trade with India.

Adding Appin to the Entity List would increase the company's costs and limit its access to American technology, but it would not address the censorship half of the problem. The Entity List is an export control tool, restricting the flow of American technology to foreign entities. It does not prevent American companies from providing services, meaning Appin could still hire American law firms to pursue its litigation campaigns.

The lawmakers' letter implicitly acknowledges this gap. To address the speech suppression, Congress would need to pass a federal anti-SLAPP law that provides a mechanism for dismissing meritless lawsuits designed to silence journalists and publishers. No such law currently exists at the federal level, though many states have enacted their own versions.

Why This Matters

The Appin case illustrates a problem that extends well beyond one Indian company. Hack-for-hire firms operate in a legal gray zone, selling surveillance and intrusion capabilities to governments and private clients while using the court systems of multiple countries to shield themselves from accountability.

The censorship campaign is particularly troubling because it targets the information ecosystem that American citizens depend on to understand threats to their own security. When a foreign hacking firm can convince an Indian court to order Reuters to remove an investigation, and then use that order to pressure American publishers into silence, the result is a foreign entity effectively controlling what Americans can read about cybersecurity threats.

The Entity List designation would not solve this problem entirely, but it would send a signal that the American government considers these operations a national security threat. It would also increase the practical difficulties Appin faces in maintaining its hacking infrastructure, just as the NSO designation did.

Whether the Commerce Department acts on the request remains to be seen. The letter arrives at a moment when the administration has shown willingness to use export controls aggressively, though not always for reasons that align with press freedom or cybersecurity concerns. The bipartisan nature of the request gives it some political cover, but the decision ultimately rests with Lutnick and the BIS.

For now, Appin continues to operate, its hacking business intact and its censorship campaigns ongoing. The company's ability to silence American publishers through foreign court orders represents a vulnerability in the information environment that the Entity List alone cannot fix. But it would be a start.