Remember Appin? It’s the Indian “hack for hire” company that got so upset about Reuters’ giant investigation — which detailed how Appin grew into a “leading cyberespionage firm” that “stole secrets from executives, politicians, military officials and wealthy elites around the globe” — that it convinced an Indian court to make Reuters take the story down. Then, when we wrote about them forcing Reuters to take down the article, they demanded we take down our article as well, claiming that we violated a court order (to which we were not a party) by republishing some of the Reuters article (which we did not even do).
Depressingly, plenty of other publications — including the vaunted Lawfare — simply caved to these specious demands. We refused to do so, with the help of EFF, who sent a letter on our behalf explaining why we (and our friends at MuckRock) would not abide by this ridiculous legal threat. We never heard from them again. Eventually, Reuters convinced the court in India to overturn its ruling and put the article back online (bizarrely, Lawfare’s version is still redacted two years after the Reuters article came back online).
But Appin and its original boss Rajat Khare have continued to threaten and bully journalists, media websites, and tech websites, for any kind of reporting on Khare or Appin’s questionable history. Even the Behind the Bastards podcast pulled down episodes about Khare, even after they were titled “We Can’t Put This Guy’s Name in the Title, But Trust Us, He Sucks” and started out with host Robert Evans admitting he expected them to get legal demands to remove the episode pretty quickly.
This week, Senators Ron Wyden and Sheldon Whitehouse, along with Rep. Pat Harrigan, sent a letter to Commerce Secretary Howard Lutnick, asking him to add Appin and several related companies (CyberRoot, BellTroX, Adaptive Control Security Global Corporate, ABP Holdings, and “Sunkissed Organic Farms” — yes really) to the Commerce Department’s Bureau of Industry and Security (BIS) “Entity List” — the tool that effectively cuts foreign entities deemed national security threats off from American technology and American business partners. It’s the same designation BIS used against NSO Group in 2021.
This is notable, in part, because the senders are bipartisan (Harrigan is a Republican while Wyden and Whitehouse are Democrats). This issue shouldn’t be partisan, though it’s a bit odd they couldn’t get a GOP Senator to sign on as well, especially given how frequently GOP Senators whine about claims of foreign censorship. I guess it’s not so important when that censorship is actually real and not part of a culture war.
Also, the Entity List is a kind of “nuclear option” and one that I’ve been worried this Commerce Department will abuse. After all, we’ve already seen this administration totally abuse the “supply chain risk” designation against Anthropic for not being willing to takedown some guardrails. You could totally see it making use of the Entity List (for which there is little due process) to cut off foreign companies that someone in Trump’s orbit is mad about.
But this isn’t that. This seems like an entity that has zero redeeming qualities and is just doing serious damage around the globe, while then suppressing (or attempting to suppress!) the speech of anyone who publicly talks about what they’re doing.
So while I’m always a little nervous about how this administration would use something like the Entity List, this seems like a legitimate situation where it makes sense.
Being put on the Entity List would cut Appin off from a variety of American technology tools and business partners, greatly increasing its cost of doing business. Though, it wouldn’t necessarily stop Appin’s SLAPP happy speech suppression campaigns. The Entity List is an export control tools, so would restrict the flow of American tech to these Indian entities. But it doesn’t bar American companies from providing services. Thus, they could likely still hire proud speech suppressors from the law firm of Clare Locke (as they have in the past) to try to scare the media into silence.
And, of course, they can still seek out judges elsewhere (as they did to suppress the Reuters story) where there are fewer free speech protections.
So, yes, getting Appin on the Entity List would make the hacking part a bit more difficult (just as it limited NSO’s business), but to deal with the speech suppression, Congress should finally get around to passing a federal anti-SLAPP law.
The letter lays out both halves of the problem: the espionage itself — including targeting of US law firms and work allegedly done at the behest of the Qatari government — and the global lawfare campaign the hackers ran afterward to keep Americans from reading about any of it:
Several India-based cyber-mercenary groups have spent more than fifteen years conducting targeted espionage against U.S. citizens, businesses and the lawyers representing them. Compounding this security threat, these cyber mercenaries and their associates have engaged in an aggressive campaign of global lawfare to censor investigative reporting by prominent American media organizations. This coordinated effort effectively allows foreign entities to use foreign courts to keep the American public in the dark about cyber threats to their own country and undermines the fundamental constitutional rights of U.S. citizens.
These hackers have systematically subverted the U.S. legal and financial sectors, targeting private equity firms, pharmaceutical companies, and more than 1,000 attorneys across major U.S. law firms to manipulate ongoing litigation. The threat is further heightened by evidence that these groups have operated at the behest of the Qatari government, targeting opponents of Qatar’s World Cup bid and even the family of a former Republican Chairman of the House Permanent Select Committee on Intelligence. While one of these operatives has been indicted by the Department of Justice, the foreign hackers continue to operate with impunity.
Simultaneously, these actors have mounted an aggressive censorship campaign to suppress public awareness of their illicit activities, directly threatening American free speech and press freedom. Executives connected to one hack-for-hire group secured an Indian court order enforcing a global takedown of an investigative report by Reuters, including a copy of the report hosted by the Internet Archive. To force further censorship, these foreign hackers have launched ongoing lawsuits against major American media institutions and technology companies, including Google, Meta, Microsoft, and The New Yorker.
While those companies named at the end there are all large, with big legal departments who can fend off SLAPP suits, not everyone else can, which is probably why so many smaller outfits (though not us!) have given in to censorial demands from Appin and related companies.
I do wonder whether Appin’s legal bullies will now demand we take down this article — one about a letter from two sitting senators and a member of Congress, published on an American website, describing a censorship campaign aimed at American publishers. If they do, I wonder if they’ll also throw in any extraneous claims to deny as well, such as about unmentioned “conspiracy to or complicity in murder.”