US Lawmakers Put Hack-for-Hire Firms in the Crosshairs

Cybercrime has increasingly become a service business. U.S. lawmakers now want to treat some of its alleged providers like sanctioned technology companies.

A bipartisan group of U.S. lawmakers has asked the Commerce Department to add three alleged hack-for-hire companies to its Entity List, which would significantly restrict their ability to access U.S. technology and services.

The lawmakers named BellTroX, CyberRoot and Sunkissed Organic Farms, formerly associated with the Appin name, while alleging that the companies have participated in cyberattacks targeting Americans. The firms have faced allegations connected to mercenary hacking and espionage campaigns; not all accusations have been adjudicated in court.

The request represents a broader shift in cybersecurity policy.

Governments aren't only targeting hackers anymore.

They're targeting the businesses around them.

Hacking has become professionalized

Cybercrime is often imagined as an anonymous individual sitting behind a laptop.

The reality can look much more corporate.

Hack-for-hire firms offer capabilities to paying clients.

Targets can include executives, lawyers, activists, political figures, journalists or business rivals.

The motivation may not be stealing money.

Sometimes the objective is intelligence.

Emails.

Legal documents.

Private communications.

Information that gives a client an advantage in a dispute.

That business model makes mercenary hacking particularly difficult to address because the attacker and the ultimate beneficiary may be separated by multiple intermediaries.

Sanctions attack the infrastructure around hackers

Adding a company to the Commerce Department's Entity List doesn't physically prevent someone from attempting a cyberattack.

It creates economic friction.

Listed companies can face severe restrictions on accessing U.S. software, hardware and technology.

That can matter because cyber operators still depend on ordinary infrastructure.

Cloud services.

Security tools.

Servers.

Developer platforms.

Payments.

Software licenses.

Cutting access to those services can make operating significantly more difficult.

It's the same logic governments increasingly use against spyware vendors and other companies accused of enabling digital surveillance.

Cybersecurity is becoming a foreign-policy tool

This is part of a larger transition.

Cybersecurity once belonged primarily to IT departments and intelligence agencies.

Now it increasingly intersects with trade policy, diplomacy, sanctions and export controls.

Governments can respond to digital threats by prosecuting hackers.

But they can also make it harder for companies associated with those operations to participate in the global technology economy.

That matters because modern cyber operations rarely exist completely outside legitimate infrastructure.

Even sophisticated attackers often rely somewhere on mainstream internet services.

The hack-for-hire market creates a difficult accountability gap

There is another problem.

Clients can potentially hire outsiders to perform activities they would never attempt directly.

That makes attribution complicated.

Who is responsible?

The person who hacked the email account?

The company employing that person?

The intermediary?

Or the client who paid for the intelligence?

As hacking services become increasingly commercialized, regulators will have to answer those questions more frequently.

What happens next?

The Commerce Department has not publicly committed to adding the named companies to the Entity List.

But the request itself is significant.

Mercenary hacking is increasingly being treated not merely as a criminal matter but as an industry with suppliers, customers and economic dependencies.

The cybersecurity response is evolving accordingly.

Governments may discover that one of the most effective ways to fight hackers isn't simply finding the person behind the keyboard.

It's making the business around the keyboard harder to operate.

Our latest news