The hack-for-hire market has grown large enough to attract tools typically associated with industrial policy and sanctions. A bipartisan group of U.S. lawmakers has called on the Department of Commerce to add BellTroX, CyberRoot, and Sunkissed Organic Farms, formerly known as Appin, to the Entity List.
According to the lawmakers, the firms are allegedly linked to intrusion and espionage operations targeting American targets. Inclusion on the list would make accessing U.S. software, cloud services, and other technologies significantly harder. The companies in question are not currently formally listed; the request is directed at the government.
Mercenary hacking meets sanctions
The move is significant because it acknowledges that Western commercial infrastructure can serve as leverage against private cyber operators. Even a firm selling intrusions relies on hosting, software licenses, development tools, and financial services.
Cybersecurity is thus increasingly resembling traditional geopolitics: attribution, accountability, and access to technology supply chains are turning into instruments of deterrence.



