U.S. Lawmakers Issue Bipartisan Call to Ban Hack-for-Hire Companies

U.S. bipartisan lawmakers push to sanction Indian hack-for-hire companies exploiting stolen data in litigation.
U.S. lawmakers from both parties have jointly called on the government to sanction and ban Indian hack-for-hire companies accused of stealing sensitive information to manipulate legal proceedings. The article examines the commercialized hacking industry's operations, the NSO Group sanctions precedent, the threat to judicial integrity, and provides enterprise defense strategies including FIDO2 hardware keys and multi-layered security measures.
The Core Story: Bipartisan Action Against Commercial Hacking Threats
U.S. lawmakers from both parties recently sent a joint letter to the government, demanding sanctions and bans on multiple companies engaged in "hack-for-hire" operations. This rare bipartisan action has thrust the long-standing gray market of commercialized hacking services into the public spotlight.
The letter specifically names three Indian companies, accusing them of hiring hackers to steal sensitive information and using illegally obtained data to influence the outcomes of legal proceedings. This means the stolen information was not only used for traditional corporate espionage but also directly infiltrated judicial processes in an attempt to manipulate the direction of legal disputes.

Deep Dive into the Hack-for-Hire Industry
What Are Commercial Hacking Services?
"Hack-for-hire" refers to commercial entities that provide network intrusion services on a for-profit, on-demand basis. Unlike state-backed APT groups, these companies typically operate under the guise of legitimate businesses or private investigation firms, with clients that may include corporations, law firms, private investigators, or even individuals.
It's worth noting that APT (Advanced Persistent Threat) groups are usually directly funded or indirectly supported by national intelligence agencies, possessing ample resources, highly customized attack tools, and long-term persistence capabilities. Well-known APT groups such as Russia's APT28 (Fancy Bear) and China's APT41 typically align their attack targets with national strategic interests. By contrast, commercial hacking companies are driven primarily by profit, serve a more diverse clientele, and while their technical sophistication may not match top-tier APT groups, they excel in flexibility, low cost, and broad coverage — forming a sizable underground economic ecosystem.
Typical Attack Methods Revealed
The core operations of hack-for-hire groups revolve around three key stages:
- Phishing attacks: Creating fake login pages or sending malicious emails to trick targets into surrendering account credentials
- Credential theft: After gaining access to email accounts, cloud storage, or enterprise systems, exfiltrating large volumes of sensitive communications and documents
- Intelligence delivery: Organizing stolen materials and delivering them to the commissioning party for use in business negotiations, litigation, or public pressure campaigns
Security research institutions have repeatedly exposed active hack-for-hire clusters operating in India, with these groups launching sustained phishing campaigns against high-value global targets, serving clients across multiple countries and industries.
The Rise of India's Hack-for-Hire Industry
India has become one of the world's major hubs for the hack-for-hire industry. A 2022 in-depth investigation by Reuters exposed several Indian companies, including BellTroX InfoTech Services, revealing their long-standing business model of providing hacking services to global clients. These companies typically register and operate under the cover of "private investigation" or "business intelligence" services, leveraging India's vast IT talent pool and relatively lax cybercrime enforcement environment to build a complete industrial chain. From recruitment to training, from attack execution to intelligence delivery, the operations have taken on distinctly factory-like, assembly-line characteristics. Organizations such as Google's Threat Analysis Group (TAG) and Citizen Lab have published multiple reports tracking targeted attacks by these Indian hacking clusters against journalists, lawyers, activists, and corporate executives.
Why This Action Matters
A Rare Bipartisan Consensus
In today's highly polarized U.S. political environment, issues that unite both parties are few and far between. This bipartisan consensus signals that cybersecurity threats — especially foreign entities' interference with the American judicial system — are now viewed as a national security issue that transcends partisan lines.
The Threat to Judicial Integrity
The most alarming aspect of this case is that stolen information was used to sway the course of litigation. This goes beyond mere commercial competition — it represents a direct erosion of judicial fairness. When one party illegally obtains the other side's internal communications, legal strategies, or settlement bottom lines, the foundation of fair litigation is completely undermined. In the U.S. legal system, while evidence obtained through illegal means may be excluded in criminal cases under the "Fruit of the Poisonous Tree" doctrine, the rules governing its application in civil litigation are far more complex. More critically, even if illegally obtained information is never directly submitted as evidence, it can help one party gain advance knowledge of their opponent's litigation strategy, weaknesses, and bottom lines, thereby gaining an asymmetric advantage in negotiations and courtroom proceedings — a form of hidden influence that is nearly impossible for courts to detect and correct.
The Government's Toolkit
Based on past cases, the U.S. government typically employs multiple measures to address such threats:
- Entity List controls: Adding implicated companies to the Commerce Department's list, restricting their access to U.S. technology and products
- Treasury Department sanctions: Freezing the U.S. assets of related entities and prohibiting U.S. businesses and individuals from transacting with them
- Visa restrictions: Imposing entry bans on implicated individuals
- Criminal prosecution: Initiating criminal charges against individuals through the Department of Justice
Among these, the Entity List managed by the U.S. Commerce Department's Bureau of Industry and Security (BIS) is one of the most important tools in the export control system. Foreign entities placed on this list must have their U.S. suppliers obtain a special license before they can acquire U.S. technology, software, and commodities governed by the Export Administration Regulations (EAR), and license applications are typically reviewed under a "presumption of denial" standard. This means listed companies are virtually unable to purchase chips, software, communications equipment, and other critical products containing U.S. technology, dealing a severe blow to their business operations.
The NSO Group Sanctions Precedent
The U.S. has previously placed Israeli spyware companies (such as NSO Group) on the Entity List, and the current call to act against Indian hack-for-hire companies represents a continuation of this regulatory approach. NSO Group is an Israeli cyber intelligence company whose Pegasus spyware gained notoriety for its ability to perform zero-click intrusions on iPhone and Android devices — "zero-click" meaning the target user doesn't need to click any link or take any action; simply receiving a specially crafted iMessage is enough for complete device compromise. The software was used by multiple governments to surveil journalists, dissidents, human rights lawyers, and political opponents. In November 2021, the U.S. Commerce Department placed NSO Group and another Israeli company, Candiru, on the Entity List, citing their tools' use in "transnational repression" activities. This marked the first time the U.S. brought a commercial spyware company under the export control framework, signaling an expansion of regulatory logic from focusing solely on state actors to encompassing commercial cyberattack tool vendors. The European Parliament subsequently launched a dedicated investigation into spyware abuse.
Impact on the Global Cybersecurity Ecosystem
The Persistent Challenge of Industrialization
The root cause behind the hack-for-hire industry's persistence is sustained market demand. As long as clients are willing to pay for illegally obtained information, suppliers will take the risk. Simply banning a few companies may only cause the business to migrate or rebrand. Genuine governance requires simultaneous action on three fronts: the demand side, cross-border law enforcement cooperation, and technical defense.
On the demand side, the primary buyers of hack-for-hire services tend to be companies and individuals involved in high-stakes business competition or complex litigation. In some cases, prominent law firms and corporate investigation companies have acted as intermediaries, "laundering" client requests before passing them to hacking groups — forming a gray subcontracting chain from legitimate commercial institutions to illegal cyberattacks. Cracking down on the intermediary links in this chain — the middlemen and end clients who knowingly commission illegal hacking services — is equally crucial for curbing the industry's scale.
Practical Enterprise Defense Guide
Companies and high-value individuals who may be targeted need to establish multi-layered defense systems:
- Strengthen authentication: Broadly deploy multi-factor authentication (MFA), prioritizing phishing-resistant hardware keys
- Raise security awareness: Conduct regular, targeted anti-phishing training
- Monitor anomalous access: Deploy account behavior monitoring systems to detect signs of credential compromise early
- Combine legal and technical measures: When involved in significant litigation, remain vigilant against the opposing party obtaining information through illegal means
Regarding authentication, it's important to emphasize that not all MFA solutions are equally secure. SMS-based verification codes are vulnerable to SIM swapping attacks, while push notification-based MFA can be defeated by "MFA fatigue attacks" — where attackers repeatedly send authentication requests until the user accidentally approves one. FIDO2-standard hardware security keys (such as YubiKey) are considered the strongest anti-phishing authentication solution currently available, because they require the physical device to cryptographically bind to a specific website domain. Even if a user clicks on a phishing link, the key will not send credentials to the spoofed site, fundamentally blocking credential phishing attacks. After Google deployed hardware keys for all employees in 2017, the company achieved a record of zero successful internal phishing attacks.
Long-Term Governance Challenges
This bipartisan joint appeal reflects that the hack-for-hire industry has evolved from a fringe gray area into a serious issue touching on national security and judicial integrity. While banning specific companies may not eradicate the entire supply chain, it sends a clear signal — using cyberattacks to manipulate judicial proceedings and business competition now carries an increasingly high legal and political price.
Looking ahead, building an effective governance framework that balances cross-border law enforcement cooperation, industry standards, and technical defense will be a long-term challenge for all nations. Currently, the international community primarily relies on the Budapest Convention (also known as the Convention on Cybercrime) as the legal framework for cross-border cooperation. The convention has over 60 signatory states, but key countries including India, China, and Russia have not joined. The United Nations Cybercrime Convention passed in 2024 attempts to bridge this gap, but the broad definition of "cybercrime" in its provisions has raised concerns among human rights organizations. On the practical level, agencies like the FBI and Europol have achieved some results through joint operations — such as the 2023 global law enforcement action against the Genesis Market dark web marketplace — but effective action against hack-for-hire companies based in countries with limited law enforcement cooperation remains a formidable challenge. Building a global cybercrime governance system that balances enforcement efficiency, privacy protection, and national sovereignty still has a long way to go.
Key Takeaways
Related articles

Type.com Review: A Deep Dive into the Team AI Collaboration Shared Workspace
Type.com integrates Claude, Codex, and other AI models into a team collaboration platform with shared knowledge, automation, and custom apps. Read our in-depth review of its features, use cases, and competitive edge.

OTP.com Review: One API to Unify SMS, WhatsApp, Email, and Telegram OTP Delivery
In-depth review of OTP.com: a single API unifying SMS, WhatsApp, Email, and Telegram OTP channels to cut integration costs and boost delivery rates for developers.

Pluno Review: An AI Chrome Extension That Proactively Discovers Automation Opportunities
Pluno is an AI Chrome extension that proactively discovers and executes automation tasks. No manual workflow setup needed — it observes user behavior, identifies repetitive tasks, and proposes automation solutions.