An obscure Indian firm provided hacking services to help spy on 10K+ email accounts over seven years, in one of the largest spy-for-hire operations ever exposed
By 2023 the [[a:840686|New Yorker reported the industry operates with a tacit government alliance and touts its services publicly]], while Reuters itself was forced to temporarily pull its follow-up article under an Indian court order it now plans to appeal — making this story as much about press freedom and state tolerance as about one firm's client list.
First-order effects
The named firm's clients — corporate-intelligence buyers and litigants who used stolen emails and documents in legal disputes against 100+ US and European organizations — face exposure, and the firm itself loses the obscurity its seven-year operation depended on.
Reuters is directly affected: the reporting triggered an Indian court order forcing temporary removal of its follow-up article, putting the newsroom in a legal fight over the story.
Second-order effects
Rival hack-for-hire shops across India's hub, described by Livemint as targeting politicians, companies, and activists, now face investigative scrutiny that raises their client-acquisition and operational risk, while targets — law firms, multinationals, journalists — must treat litigation opponents as potential espionage customers.
The court-ordered removal gives the industry a censorship playbook: legal pressure in Indian courts can suppress reporting abroad, which Reuters' planned appeal will test.
Third-order effects
If the pattern holds, mercenary hacking in India hardens into a brazen, publicly marketed industry with tacit state cover — shifting the question from whether such firms exist to whether governments will tolerate an export-grade espionage market operating in the open.
Litigation emerges as a structural demand channel: when stolen documents are worth winning cases, corporate espionage stops being a fringe threat and becomes a routine risk inside legal systems.
The trend: Mercenary hacking is consolidating into a publicly marketed, litigation-driven industry in India, with tacit government tolerance setting the boundary of accountability.
NEW: Little-known Indian cyber firm BellTroX InfoTech Services has been acting as an international hacking shop, helping clients spy on at least 10,000 email accounts belonging to politicians, investors, journalists and activists worldwide https://uk.reuters.com/...
Great investigation by @Reuters, @citizenlab, and many others into a huge hackers-for-hire operation out of India. Outsourcing these services through PIs & lawyers creates layers of obscurity and deniability, shielding the end client - who were the employers contracting BellTroX?…
NEW: @Reuters reveals for the first time the the hacking-for-hire firm that was paid to attack my organization @fightfortheftr and allied groups like @freepress at the height of the #netneutrality fight in 2017. https://www.reuters.com/...
Over the past decade, an obscure Indian IT firm has quietly turned itself into an international hacking shop - helping a mysterious set of clients target upwards of 10,000 VIP email accounts worldwide. https://www.reuters.com/...
New: Federal prosecutors in Manhattan are investigating a sprawling hacker-for-hire operation that targeted the email accounts of journalists, government officials, environmental groups and more. w/@barrymeier @ronenbergman https://www.nytimes.com/...
“Targets in the hacking campaign were American nonprofit groups that had been battling publicly with @exxonmobil for years over whether the oil company engaged in an effort to mislead the public about climate science, which the company has denied.” https://www.nytimes.com/...
Federal prosecutors in Manhattan are investigating a global hacker-for-hire operation that sent phishing emails to environmental groups, journalists and others, according to people briefed on the inquiry https://www.nytimes.com/...
Shocked...SHOCKED, that entrenched fossil fuel interests would engage in such illegal behavior! (not: https://www.theguardian.com/ ...) https://www.nytimes.com/...
Congratulations to @citizenlab for the work on ‘Dark Basin’ work - Uncovering a Massive Hack-For-Hire Operation. We worked tirelessly through 2017 and presented our evidence to law enforcement in 2017 https://citizenlab.ca/... See below emails to UK law enforcement @Wirecard http…
Breaking — New report from @citizenlab uncovering Dark Basin, a hack-for-hire group that has targeted thousands of individuals on six continents. Targets include advocacy groups and journalists, elected and senior government officials, hedge funds, and multiple industries. https:…
The depth of reporting and investigation that @citizenlab has conducted here is astounding and the attribution is solid too. “With high confidence, we link Dark Basin to BellTroX InfoTech Services ("BellTroX"), an India-based technology company." https://twitter.com/...
Reuters: A little-known Indian IT firm offered its hacking services to help clients spy on more than 10,000 email accounts over a period of seven years. https://www.reuters.com/...
Just published - Reuters says we (MW) were targeted for hacking by clients of BellTroX, an Indian hacking for hire firm. Perhaps coincidentally, FT just published a story naming Wirecard $WDI.GY as a BellTroX hacking client 1/ cc: @_MarkusBraun https://www.reuters.com/...
“I didn't help them access anything, I just helped them with downloading the mails and they provided me all the details,” said Sumit Gupta BellTroX's Gupta was charged in a 2015 hacking case in which two U.S. private investigators admitted to paying him to hack the accounts
Indian cyber firm, BellTroX InfoTech Services, spied on politicians in Europe, gambling tycoons in the Bahamas, and well-known investors in the US including private equity giant KKR and short seller Muddy Waters https://www.reuters.com/...
The scope and scale of the hacking is like nothing I've ever seen before. Researchers at @citizenlab - who have a report out today - have a write-up that gets into extraordinary detail about what this group did ... and how they were caught in the act: https://citizenlab.ca/...
More targets: judges in South Africa, politicians in Mexico during the 2018 election, and lawyers in Paris. https://www.reuters.com/... https://twitter.com/...
10. What BellTroX lacks in sophistication they make up for by being persistent. Some customers probably give them detailed dossiers to make convincing phishing. Also, they gave a hilarious cover story when @razhael @Bing_Chris @jc_stubbs called em up https://www.reuters.com/... h…
For background, see this detailed report by @citizenlab @jsrailton: https://twitter.com/... — Belltrox is a name you've never heard. But they're an important key 🔑 to solving potentially thousands of targeted hacks. We know they work for private investigators and intel firms. htt…
BREAKING: environmentalists including @Greenpeace, @350.org and Rockefeller Family Fund targeted in large #hacking operation linked to @ExxonMobil “We determined that hiring hackers may be a relatively common practice for many private investigators,” https://www-nytimes-com.cdn.a…
“Because the shorteners created URLs with sequential shortcodes, we were able to enumerate them and identify almost 28,000 additional URLs...” It's small mistakes like this that blow your stuff up... https://twitter.com/...
4. EXHIBIT A.1: American environmental orgs doing the #ExxonKnew campaign. (which said @exxonmobil hid information about climate change for decades). A private email from targets was “leaked” and used in critical coverage. NYT has the full story: https://www.nytimes.com/... https…
Dark Basin: Uncovering a massive hack-for-hire operation that targeted thousands of individuals and hundreds of institutions on six continents https://citizenlab.ca/... https://twitter.com/...
Very eager to see who (if anyone) DOJ charges after *someone* for hired this group to hack climate nonprofits (and plenty others). https://www.reuters.com/...
More evidence that toxic commercial hacking services need to be cracked down on. The accountability gap must be closed now! > Incredible work by @citizenlab once again. Hackers for hire target tens of thousands including parliamentarians and lawyers ↘️ https://twitter.com/...
Wait, what? South African judges among those targeted for spying by an “obscure cyber firm” in India: https://www.reuters.com/... https://twitter.com/...
FBI investigating phishing emails sent to green groups. Is it too late for the FBI to look into @PeterGleick's email shenanigans against the @HeartlandInst? Gleick criminal referral: https://www.heartland.org/... https://www.nytimes.com/...
This piece doesn't name BellTroX but it should be read together with ours. It has disturbing details about the targeting of green groups who crossed swords with Exxon. https://www.nytimes.com/...
Researchers at @citizenlab have also spent more than 2 years tracking this activity and say they have high confidence that BellTroX employees were behind the campaign. Per @jsrailton: “This is one of the largest spy-for-hire operations ever exposed.” https://citizenlab.ca/...