Skip to content

Product1 publisher2 min readPublished

Wyden, Whitehouse and Harrigan hand Commerce six names for the Entity List

A designation would restrict what American vendors can ship to Appin, and because the Entity List covers exports and not services, the law firms and foreign courts the company has used against reporters stay available.

The Product Desk · Product desk

Photograph accompanying Wyden, Whitehouse and Harrigan hand Commerce six names for the Entity List
Photo: yahoo.com

What happened

  • Senators Ron Wyden and Sheldon Whitehouse and Rep. Pat Harrigan wrote to Commerce Secretary Howard Lutnick asking him to add the Indian hack-for-hire firm Appin and related companies to the BIS Entity List.
  • The related companies named are CyberRoot, BellTroX, Adaptive Control Security Global Corporate, ABP Holdings, and Sunkissed Organic Farms.
  • BIS last used this designation on a surveillance vendor when it listed NSO Group in 2021.
  • Appin previously persuaded an Indian court to order Reuters to pull its investigation, and Reuters later got that ruling overturned and the story restored.
  • The Behind the Bastards podcast pulled its episodes about Appin's original boss Rajat Khare, which had been titled "We Can't Put This Guy's Name in the Title, But Trust Us, He Sucks".

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • constraint The remedy reaches Appin's suppliers; its lawyers sit outside it. Publishers sitting on takedown demands get nothing from a listing that they can use when the next letter arrives.
  • decision For American vendors, a listing would turn a reputational judgment about hack-for-hire work into a screening task against six specific corporate names, some of which do not look like security companies at all.
  • cost On Techdirt's reading the bill lands on the listed entities, whose cost of doing business rises as American tools and partners become unavailable to them, and not on the outlets that already redacted their reporting.
  • precedent Techdirt argues that a defensible listing normalises an indefensible one, because the Entity List comes with little due process and this Commerce Department has already aimed a supply chain risk designation at Anthropic over guardrails.

Two years after Reuters got an Indian court to reverse itself and put its Appin investigation back online, Lawfare's copy of that reporting is still redacted [8]. Whoever pulled it was not obviously wrong. Techdirt says it refused the same demand with the help of EFF, which sent a letter on behalf of Techdirt and MuckRock, and that it never heard from Appin again [9].

The letter to Commerce Secretary Howard Lutnick asks for an export control [1]. The Entity List restricts the flow of American technology to the named entities, and Techdirt notes it does not bar American companies from selling them services [11]. Appin has hired the law firm Clare Locke before, and Techdirt expects it could do so again [12]. Courts outside the United States also stay available, which is how the Reuters story was suppressed in the first place [7][15].

Six entities are named in all, Appin plus five others [16]. A listing converts a judgment call about who your customer actually is into a name match, and the names include a holding company and an organic farm [2].

BIS used this designation against NSO Group in 2021 [5]. Techdirt says a listing would cut Appin off from a variety of American technology tools and business partners and greatly increase its cost of doing business [13]. The company being described here is the one Reuters called a "leading cyberespionage firm" that "stole secrets from executives, politicians, military officials and wealthy elites around the globe" [6].

Techdirt is not comfortable with the tool it is backing. It calls the Entity List a kind of nuclear option with little due process, and points to this administration's use of a supply chain risk designation against Anthropic after the company would not take down some guardrails [14].

Two tests tell you what a designation would do for your organisation. First, whether it restricts something your counterparty buys from you. Second, whether it restricts the instrument your counterparty uses against you. For an American vendor with Appin somewhere down a reseller chain, the first becomes a live compliance question the day the names are published [4]. For an editor holding a takedown demand, both stay negative, because the instrument is a law firm and a foreign judge, and export controls reach neither [11][15].

The bipartisan framing carries some weight here, since Harrigan is a Republican and Wyden and Whitehouse are Democrats [3]. Techdirt's account ends with the letter going out this week and records no answer from Commerce [17].

What to watch

  • Whether Lutnick's department acts on the request, and whether all six named entities survive into whatever BIS publishes.
  • Whether a Republican senator signs on, since the current letter carries one House Republican and two Senate Democrats.
  • Whether Lawfare restores its redacted version now that the request is public.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories