An obscure Indian firm provided hacking services to help spy on 10K+ email accounts over seven years, in one of the largest spy-for-hire operations ever exposed
New report from @citizenlab uncovering Dark Basin, a hack-for-hire group that has targeted thousands of individuals on six continents. Targets include advocacy groups and journalists, elected and senior government officials, hedge funds, and multiple industries. https://twitter.com/... Sean Kerner / @techjournalist : The depth of reporting and investigation that @citizenlab has conducted here is astounding and the attribution is solid too. “With high confidence, we link Dark Basin to BellTroXInfoTech Services ("BellTroX"), an India-based technology company." https://twitter.com/... Donie O'Sullivan / @donie : A little-known Indian IT firm offered its hacking services to help clients spy on more than 10,000 email accounts over a period of seven years. https://www.reuters.com/... @muddywatersre : Just published - Reuters says we (MW) were targeted for hacking by clients of BellTroX, an Indian hacking for hire firm. Perhaps coincidentally, FT just published a story naming Wirecard $WDI.GY as a BellTroX hacking client 1/ cc: @_MarkusBraun https://www.reuters.com/... Pankaj Mishra / @pankajontech : “I didn't help them access anything, I just helped them with downloading the mails and they provided me all the details,” said Sumit Gupta BellTroX's Gupta was charged in a 2015 hacking case in which two U.S. private investigators admitted to paying him to hack the accounts Pankaj Mishra / @pankajontech : Indian cyber firm, BellTroX InfoTech Services, spied on politicians in Europe, gambling tycoons in the Bahamas, and well-known investors in the US including private equity giant KKR and short seller Muddy Waters https://www.reuters.com/... Jasper Teulings / @patagorda : BREAKING: environmentalists including @Greenpeace, @350.org and Rockefeller Family Fund targeted in large #hacking operation linked to @ExxonMobil “We determined that hiring hackers may be a relatively common practice for many private investigators,” https://www-nytimes-com.cdn.ampproject. org/ ... John Scott-Railton / @jsrailton : 4. EXHIBIT A.1: American environmental orgs doing the #ExxonKnew campaign. (which said @exxonmobil hid information about climate change for decades). A private email from targets was “leaked” and used in critical coverage. NYT has the full story: https://www.nytimes.com/... https://twitter.com/... Steve Milloy / @junkscience : FBI investigating phishing emails sent to green groups. Is it too late for the FBI to look into @PeterGleick's email shenanigans against the @HeartlandInst? Gleick criminal referral: https://www.heartland.org/... https://www.nytimes.com/... Raphael Satter / @razhael : This piece doesn't name BellTroX but it should be read together with ours. It has disturbing details about the targeting of green groups who crossed swords with Exxon. https://www.nytimes.com/... Raphael Satter / @razhael : The scope and scale of the hacking is like nothing I've ever seen before. Researchers at @citizenlab - who have a report out today - have a write-up that gets into extraordinary detail about what this group did ... and how they were caught in the act: https://citizenlab.ca/... Chris Bing / @bing_chris : For background, see this detailed report by @citizenlab @jsrailton: https://twitter.com/... — Belltrox is a name you've never heard. But they're an important key 🔑 to solving potentially thousands of targeted hacks. We know they work for private investigators and intel firms. https://twitter.com/... Hal Pomeranz / @hal_pomeranz : “Because the shorteners created URLs with sequential shortcodes, we were able to enumerate them and identify almost 28,000 additional URLs...” It's small mistakes like this that blow your stuff up... https://twitter.com/... Marietje Schaake / @marietjeschaake : More evidence that toxic commercial hacking services need to be cracked down on. The accountability gap must be closed now! > Incredible work by @citizenlab once again. Hackers for hire target tens of thousands including parliamentarians and lawyers ↘️ https://twitter.com/... @citizenlab : NEW REPORT: Dark Basin: Uncovering a Massive Hack-For-Hire Operation https://citizenlab.ca/... Jack Stubbs / @jc_stubbs : Researchers at @citizenlab have also spent more than 2 years tracking this activity and say they have high confidence that BellTroX employees were behind the campaign. Per @jsrailton: “This is one of the largest spy-for-hire operations ever exposed.” https://citizenlab.ca/... Murray Hunter / @muzhunter : Wait, what? South African judges among those targeted for spying by an “obscure cyber firm” in India: https://www.reuters.com/... https://twitter.com/... Chris Bing / @bing_chris : More targets: judges in South Africa, politicians in Mexico during the 2018 election, and lawyers in Paris. https://www.reuters.com/... https://twitter.com/... John Scott-Railton / @jsrailton : 10. What BellTroX lacks in sophistication they make up for by being persistent. Some customers probably give them detailed dossiers to make convincing phishing. Also, they gave a hilarious cover story when @razhael @Bing_Chris @jc_stubbs called em up https://www.reuters.com/... https://twitter.com/... Kevin Collier / @kevincollier : Very eager to see who (if anyone) DOJ charges after *someone* for hired this group to hack climate nonprofits (and plenty others). https://www.reuters.com/... Graham Cluley / @gcluley : Dark Basin: Uncovering a massive hack-for-hire operation that targeted thousands of individuals and hundreds of institutions on six continents https://citizenlab.ca/... https://twitter.com/...
Reuters
Context & Ripple Effects
Citizen Lab's attribution closes the loop on an operation that had been visible only through its phishing traces: Dark Basin's seven-year campaign against more than 10,000 email accounts now has a named operator, BellTroX InfoTech Services, and named client interests — including hacking campaigns aimed at short seller Muddy Waters and services used by Wirecard. Sumit Gupta's earlier appearance in a 2015 US case involving private investigators who admitted paying him shows this was not BellTroX's first brush with exposure.
Advocacy groups, journalists, elected officials, and hedge funds across six continents — including environmental groups now under FBI investigation for related phishing emails — learn their inboxes were compromised for years by a commercial vendor rather than a state actor.
BellTroX moves from obscure Delhi contractor to named defendant-in-waiting: with Citizen Lab's high-confidence attribution and Gupta's prior US hacking case on record, DOJ and law-enforcement attention shifts from the anonymous phishers to an identifiable company.
Second-order effects
Corporate-intelligence intermediaries who resell BellTroX's capabilities — the private investigators and due-diligence firms that connect clients like Wirecard to hackers — face the same attribution risk, pushing buyers toward deniable offshore suppliers or in-house capability.
Short sellers and litigation adversaries such as Muddy Waters must assume opposing counsel or corporate rivals can buy intrusion-as-a-service cheaply, raising demand for hardened communications and counter-forensics inside activist finance.
Third-order effects
If the pattern holds, hack-for-hire consolidates into an identifiable national industry — one that later reporting describes as operating openly alongside a tacit government alliance — forcing regulators and platforms to treat commercial spyware vendors as a distinct policy problem, separate from both nation-state APTs and ordinary cybercrime.
The trend: Commercial espionage is industrializing into an outsourced Indian hack-for-hire market where attribution, once impossible, is becoming the main constraint on clients and vendors alike.
It's a surreal experience to be the target of a sophisticated phishing operation. even more surreal to have the firm that targeted you exposed years later. more surreal still to know an ISP very likely paid for it, but that might be impossible to prove https://www.reuters.com/...
Exposed: a sprawling hacking-for-hire operation that for years targeted the emails of government officials, journalists, banks and environmental activists, some of them involved in the climate-change campaign against Exxon Mobil https://www.nytimes.com/... W/@nicole_hong, @barrym…
Who are Dark Basin?: Outing the cybermercenaries who attacked Net Neutrality and anti-Exxon activists. https://twitter.com/... 7/ https://twitter.com/...
When you fight greedy corporations and powerful politicians trying to take away people's basic rights int he digital age, you're bound to make some enemies. https://www.reuters.com/... Want to help us keep us going as a thorn in the side of evil doers? https://donate.fightforthef…
NEW: @Reuters reveals for the first time the the hacking-for-hire firm that was paid to attack my organization @fightfortheftr and allied groups like @freepress at the height of the #netneutrality fight in 2017. https://www.reuters.com/...
Jaw-dropping stuff: Targeted organizations included the Rockefeller Family Fund, the Climate Investigations Center and Greenpeace, with phishing emails tailored to the organizations' work on Exxon and climate change, the report said. https://www.nytimes.com/...
Environmentalists leading effort to have ExxonMobil prosecuted for concealing climate change risk, a potential existential challenge to the company, became the target of a sophisticated hacking campaign, anonymous attackers impersonated their colleagues https://www.nytimes.com/..…
For years, researchers have tracked a group of hackers-for-hire that targeted US-based Net Neutrality and anti-Exxon campaigners. Now @citizenlab has identified the cybermercenaries behind these “Dark Basin” attacks: @BellTrox, a New Delhi company. https://citizenlab.ca/... 1/ ht…
Citizen Lab researchers disclose huge hack-for-hire operation targeting thousands of people from govt, business, & media across six continents. The campaign, linked to an Indian IT firm, “extensively targeted” U.S. nonprofits like anti-Exxon activists. https://citizenlab.ca/...
NEW: Little-known Indian cyber firm BellTroX InfoTech Services has been acting as an international hacking shop, helping clients spy on at least 10,000 email accounts belonging to politicians, investors, journalists and activists worldwide https://uk.reuters.com/...
Great investigation by @Reuters, @citizenlab, and many others into a huge hackers-for-hire operation out of India. Outsourcing these services through PIs & lawyers creates layers of obscurity and deniability, shielding the end client - who were the employers contracting BellTroX?…
Over the past decade, an obscure Indian IT firm has quietly turned itself into an international hacking shop - helping a mysterious set of clients target upwards of 10,000 VIP email accounts worldwide. https://www.reuters.com/...
New: Federal prosecutors in Manhattan are investigating a sprawling hacker-for-hire operation that targeted the email accounts of journalists, government officials, environmental groups and more. w/@barrymeier @ronenbergman https://www.nytimes.com/...
“Targets in the hacking campaign were American nonprofit groups that had been battling publicly with @exxonmobil for years over whether the oil company engaged in an effort to mislead the public about climate science, which the company has denied.” https://www.nytimes.com/...
Federal prosecutors in Manhattan are investigating a global hacker-for-hire operation that sent phishing emails to environmental groups, journalists and others, according to people briefed on the inquiry https://www.nytimes.com/...
Shocked...SHOCKED, that entrenched fossil fuel interests would engage in such illegal behavior! (not: https://www.theguardian.com/ ...) https://www.nytimes.com/...
Congratulations to @citizenlab for the work on ‘Dark Basin’ work - Uncovering a Massive Hack-For-Hire Operation. We worked tirelessly through 2017 and presented our evidence to law enforcement in 2017 https://citizenlab.ca/... See below emails to UK law enforcement @Wirecard http…
Breaking — New report from @citizenlab uncovering Dark Basin, a hack-for-hire group that has targeted thousands of individuals on six continents. Targets include advocacy groups and journalists, elected and senior government officials, hedge funds, and multiple industries. https:…
The depth of reporting and investigation that @citizenlab has conducted here is astounding and the attribution is solid too. “With high confidence, we link Dark Basin to BellTroX InfoTech Services ("BellTroX"), an India-based technology company." https://twitter.com/...
Reuters: A little-known Indian IT firm offered its hacking services to help clients spy on more than 10,000 email accounts over a period of seven years. https://www.reuters.com/...
Just published - Reuters says we (MW) were targeted for hacking by clients of BellTroX, an Indian hacking for hire firm. Perhaps coincidentally, FT just published a story naming Wirecard $WDI.GY as a BellTroX hacking client 1/ cc: @_MarkusBraun https://www.reuters.com/...
“I didn't help them access anything, I just helped them with downloading the mails and they provided me all the details,” said Sumit Gupta BellTroX's Gupta was charged in a 2015 hacking case in which two U.S. private investigators admitted to paying him to hack the accounts
Indian cyber firm, BellTroX InfoTech Services, spied on politicians in Europe, gambling tycoons in the Bahamas, and well-known investors in the US including private equity giant KKR and short seller Muddy Waters https://www.reuters.com/...
BREAKING: environmentalists including @Greenpeace, @350.org and Rockefeller Family Fund targeted in large #hacking operation linked to @ExxonMobil “We determined that hiring hackers may be a relatively common practice for many private investigators,” https://www-nytimes-com.cdn.a…
4. EXHIBIT A.1: American environmental orgs doing the #ExxonKnew campaign. (which said @exxonmobil hid information about climate change for decades). A private email from targets was “leaked” and used in critical coverage. NYT has the full story: https://www.nytimes.com/... https…
FBI investigating phishing emails sent to green groups. Is it too late for the FBI to look into @PeterGleick's email shenanigans against the @HeartlandInst? Gleick criminal referral: https://www.heartland.org/... https://www.nytimes.com/...
This piece doesn't name BellTroX but it should be read together with ours. It has disturbing details about the targeting of green groups who crossed swords with Exxon. https://www.nytimes.com/...
The scope and scale of the hacking is like nothing I've ever seen before. Researchers at @citizenlab - who have a report out today - have a write-up that gets into extraordinary detail about what this group did ... and how they were caught in the act: https://citizenlab.ca/...
For background, see this detailed report by @citizenlab @jsrailton: https://twitter.com/... — Belltrox is a name you've never heard. But they're an important key 🔑 to solving potentially thousands of targeted hacks. We know they work for private investigators and intel firms. htt…
“Because the shorteners created URLs with sequential shortcodes, we were able to enumerate them and identify almost 28,000 additional URLs...” It's small mistakes like this that blow your stuff up... https://twitter.com/...
More evidence that toxic commercial hacking services need to be cracked down on. The accountability gap must be closed now! > Incredible work by @citizenlab once again. Hackers for hire target tens of thousands including parliamentarians and lawyers ↘️ https://twitter.com/...
Researchers at @citizenlab have also spent more than 2 years tracking this activity and say they have high confidence that BellTroX employees were behind the campaign. Per @jsrailton: “This is one of the largest spy-for-hire operations ever exposed.” https://citizenlab.ca/...
Wait, what? South African judges among those targeted for spying by an “obscure cyber firm” in India: https://www.reuters.com/... https://twitter.com/...
More targets: judges in South Africa, politicians in Mexico during the 2018 election, and lawyers in Paris. https://www.reuters.com/... https://twitter.com/...
10. What BellTroX lacks in sophistication they make up for by being persistent. Some customers probably give them detailed dossiers to make convincing phishing. Also, they gave a hilarious cover story when @razhael @Bing_Chris @jc_stubbs called em up https://www.reuters.com/... h…
Very eager to see who (if anyone) DOJ charges after *someone* for hired this group to hack climate nonprofits (and plenty others). https://www.reuters.com/...
Dark Basin: Uncovering a massive hack-for-hire operation that targeted thousands of individuals and hundreds of institutions on six continents https://citizenlab.ca/... https://twitter.com/...