/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

An obscure Indian firm provided hacking services to help spy on 10K+ email accounts over seven years, in one of the largest spy-for-hire operations ever exposed

LONDON/WASHINGTON (Reuters) - A little-known Indian IT firm offered its hacking services to help clients spy …

Reuters

Context & Ripple Effects

This 2020 Reuters exposé was the opening move in a multi-year unraveling of India's mercenary-hacking sector: the obscure IT firm behind the 10,000+ compromised mailboxes later surfaced in an investigation of hacking aimed at obtaining documents in legal cases, and the Bureau of Investigative Journalism traced the same industry serving corporate-intelligence clients targeting businesses, journalists, and politicians.

By 2023 the [[a:840686|New Yorker reported the industry operates with a tacit government alliance and touts its services publicly]], while Reuters itself was forced to temporarily pull its follow-up article under an Indian court order it now plans to appeal — making this story as much about press freedom and state tolerance as about one firm's client list.

First-order effects

  • The named firm's clients — corporate-intelligence buyers and litigants who used stolen emails and documents in legal disputes against 100+ US and European organizations — face exposure, and the firm itself loses the obscurity its seven-year operation depended on.
  • Reuters is directly affected: the reporting triggered an Indian court order forcing temporary removal of its follow-up article, putting the newsroom in a legal fight over the story.

Second-order effects

  • Rival hack-for-hire shops across India's hub, described by Livemint as targeting politicians, companies, and activists, now face investigative scrutiny that raises their client-acquisition and operational risk, while targets — law firms, multinationals, journalists — must treat litigation opponents as potential espionage customers.
  • The court-ordered removal gives the industry a censorship playbook: legal pressure in Indian courts can suppress reporting abroad, which Reuters' planned appeal will test.

Third-order effects

  • If the pattern holds, mercenary hacking in India hardens into a brazen, publicly marketed industry with tacit state cover — shifting the question from whether such firms exist to whether governments will tolerate an export-grade espionage market operating in the open.
  • Litigation emerges as a structural demand channel: when stolen documents are worth winning cases, corporate espionage stops being a fringe threat and becomes a routine risk inside legal systems.

The trend: Mercenary hacking is consolidating into a publicly marketed, litigation-driven industry in India, with tacit government tolerance setting the boundary of accountability.

Discussion

  • @jc_stubbs Jack Stubbs on x
    NEW: Little-known Indian cyber firm BellTroX InfoTech Services has been acting as an international hacking shop, helping clients spy on at least 10,000 email accounts belonging to politicians, investors, journalists and activists worldwide https://uk.reuters.com/...
  • @saffronsec Saher Naumaan on x
    Great investigation by @Reuters, @citizenlab, and many others into a huge hackers-for-hire operation out of India. Outsourcing these services through PIs & lawyers creates layers of obscurity and deniability, shielding the end client - who were the employers contracting BellTroX?…
  • @evan_greer Evan Greer on x
    NEW: @Reuters reveals for the first time the the hacking-for-hire firm that was paid to attack my organization @fightfortheftr and allied groups like @freepress at the height of the #netneutrality fight in 2017. https://www.reuters.com/...
  • @razhael Raphael Satter on x
    Over the past decade, an obscure Indian IT firm has quietly turned itself into an international hacking shop - helping a mysterious set of clients target upwards of 10,000 VIP email accounts worldwide. https://www.reuters.com/...
  • @nicole_hong Nicole Hong on x
    New: Federal prosecutors in Manhattan are investigating a sprawling hacker-for-hire operation that targeted the email accounts of journalists, government officials, environmental groups and more. w/@barrymeier @ronenbergman https://www.nytimes.com/...
  • @doctorvive Dr. Genevieve Guenther on x
    “Targets in the hacking campaign were American nonprofit groups that had been battling publicly with @exxonmobil for years over whether the oil company engaged in an effort to mislead the public about climate science, which the company has denied.” https://www.nytimes.com/...
  • @nytimes @nytimes on x
    Federal prosecutors in Manhattan are investigating a global hacker-for-hire operation that sent phishing emails to environmental groups, journalists and others, according to people briefed on the inquiry https://www.nytimes.com/...
  • @michaelemann Michael E. Mann on x
    Shocked...SHOCKED, that entrenched fossil fuel interests would engage in such illegal behavior! (not: https://www.theguardian.com/ ...) https://www.nytimes.com/...
  • @aimhonesty Fraser Perring on x
    Congratulations to @citizenlab for the work on ‘Dark Basin’ work - Uncovering a Massive Hack-For-Hire Operation. We worked tirelessly through 2017 and presented our evidence to law enforcement in 2017 https://citizenlab.ca/... See below emails to UK law enforcement @Wirecard http…
  • @lex_is Lex Gill on x
    Breaking — New report from @citizenlab uncovering Dark Basin, a hack-for-hire group that has targeted thousands of individuals on six continents. Targets include advocacy groups and journalists, elected and senior government officials, hedge funds, and multiple industries. https:…
  • @techjournalist Sean Kerner on x
    The depth of reporting and investigation that @citizenlab has conducted here is astounding and the attribution is solid too. “With high confidence, we link Dark Basin to BellTroX InfoTech Services ("BellTroX"), an India-based technology company." https://twitter.com/...
  • @donie Donie O'Sullivan on x
    Reuters: A little-known Indian IT firm offered its hacking services to help clients spy on more than 10,000 email accounts over a period of seven years. https://www.reuters.com/...
  • @muddywatersre @muddywatersre on x
    Just published - Reuters says we (MW) were targeted for hacking by clients of BellTroX, an Indian hacking for hire firm. Perhaps coincidentally, FT just published a story naming Wirecard $WDI.GY as a BellTroX hacking client 1/ cc: @_MarkusBraun https://www.reuters.com/...
  • @pankajontech Pankaj Mishra on x
    “I didn't help them access anything, I just helped them with downloading the mails and they provided me all the details,” said Sumit Gupta BellTroX's Gupta was charged in a 2015 hacking case in which two U.S. private investigators admitted to paying him to hack the accounts
  • @pankajontech Pankaj Mishra on x
    Indian cyber firm, BellTroX InfoTech Services, spied on politicians in Europe, gambling tycoons in the Bahamas, and well-known investors in the US including private equity giant KKR and short seller Muddy Waters https://www.reuters.com/...
  • @razhael Raphael Satter on x
    The scope and scale of the hacking is like nothing I've ever seen before. Researchers at @citizenlab - who have a report out today - have a write-up that gets into extraordinary detail about what this group did ... and how they were caught in the act: https://citizenlab.ca/...
  • @bing_chris Chris Bing on x
    More targets: judges in South Africa, politicians in Mexico during the 2018 election, and lawyers in Paris. https://www.reuters.com/... https://twitter.com/...
  • @jsrailton John Scott-Railton on x
    10. What BellTroX lacks in sophistication they make up for by being persistent. Some customers probably give them detailed dossiers to make convincing phishing. Also, they gave a hilarious cover story when @razhael @Bing_Chris @jc_stubbs called em up https://www.reuters.com/... h…
  • @bing_chris Chris Bing on x
    For background, see this detailed report by @citizenlab @jsrailton: https://twitter.com/... — Belltrox is a name you've never heard. But they're an important key 🔑 to solving potentially thousands of targeted hacks. We know they work for private investigators and intel firms. htt…
  • @patagorda Jasper Teulings on x
    BREAKING: environmentalists including @Greenpeace, @350.org and Rockefeller Family Fund targeted in large #hacking operation linked to @ExxonMobil “We determined that hiring hackers may be a relatively common practice for many private investigators,” https://www-nytimes-com.cdn.a…
  • @hal_pomeranz Hal Pomeranz on x
    “Because the shorteners created URLs with sequential shortcodes, we were able to enumerate them and identify almost 28,000 additional URLs...” It's small mistakes like this that blow your stuff up... https://twitter.com/...
  • @jsrailton John Scott-Railton on x
    4. EXHIBIT A.1: American environmental orgs doing the #ExxonKnew campaign. (which said @exxonmobil hid information about climate change for decades). A private email from targets was “leaked” and used in critical coverage. NYT has the full story: https://www.nytimes.com/... https…
  • @gcluley Graham Cluley on x
    Dark Basin: Uncovering a massive hack-for-hire operation that targeted thousands of individuals and hundreds of institutions on six continents https://citizenlab.ca/... https://twitter.com/...
  • @kevincollier Kevin Collier on x
    Very eager to see who (if anyone) DOJ charges after *someone* for hired this group to hack climate nonprofits (and plenty others). https://www.reuters.com/...
  • @marietjeschaake Marietje Schaake on x
    More evidence that toxic commercial hacking services need to be cracked down on. The accountability gap must be closed now! > Incredible work by @citizenlab once again. Hackers for hire target tens of thousands including parliamentarians and lawyers ↘️ https://twitter.com/...
  • @muzhunter Murray Hunter on x
    Wait, what? South African judges among those targeted for spying by an “obscure cyber firm” in India: https://www.reuters.com/... https://twitter.com/...
  • @junkscience Steve Milloy on x
    FBI investigating phishing emails sent to green groups. Is it too late for the FBI to look into @PeterGleick's email shenanigans against the @HeartlandInst? Gleick criminal referral: https://www.heartland.org/... https://www.nytimes.com/...
  • @citizenlab @citizenlab on x
    NEW REPORT: Dark Basin: Uncovering a Massive Hack-For-Hire Operation https://citizenlab.ca/...
  • @razhael Raphael Satter on x
    This piece doesn't name BellTroX but it should be read together with ours. It has disturbing details about the targeting of green groups who crossed swords with Exxon. https://www.nytimes.com/...
  • @jc_stubbs Jack Stubbs on x
    Researchers at @citizenlab have also spent more than 2 years tracking this activity and say they have high confidence that BellTroX employees were behind the campaign. Per @jsrailton: “This is one of the largest spy-for-hire operations ever exposed.” https://citizenlab.ca/...