Appin was an Indian
cyber espionage company founded in 2003 by brothers Rajat and Anuj Khare. It initially started as a cybersecurity training firm, but by 2010, the company had begun providing hacking services for governments and corporate clients that was reported to have stolen secrets from executives, politicians, military officials and wealthy elites worldwide. ''
Reuters
Reuters ( ) is a news agency owned by Thomson Reuters. It employs around 2,500 journalists and 600 photojournalists in about 200 locations worldwide writing in 16 languages. Reuters is one of the largest news agencies in the world.
The agency ...
'', ''
The New Yorker
''The New Yorker'' is an American magazine featuring journalism, commentary, criticism, essays, fiction, satire, cartoons, and poetry. It was founded on February 21, 1925, by Harold Ross and his wife Jane Grant, a reporter for ''The New York T ...
'', ''
Wired
Wired may refer to:
Arts, entertainment, and media Music
* ''Wired'' (Jeff Beck album), 1976
* ''Wired'' (Hugh Cornwell album), 1993
* ''Wired'' (Mallory Knox album), 2017
* "Wired", a song by Prism from their album '' Beat Street''
* "Wired ...
'', ''
SRF Investigativ'', and ''
Intelligence Online'' have reported on Appin's
hack-for-hire operations and Rajat Khare's extensive efforts to suppress coverage through civil and criminal actions.
Appin created the model that is still used by the Indian hack-for-hire industry.
History
In December 2003, Rajat Khare along with high school friends conceived Appin to offer technology training workshops to university students. By 2005, now joined by Anuj, an entrepreneur and former motivational speaker, the company had an office in western
New Delhi
New Delhi (; ) is the Capital city, capital of India and a part of the Delhi, National Capital Territory of Delhi (NCT). New Delhi is the seat of all three branches of the Government of India, hosting the Rashtrapati Bhavan, New Parliament ...
. Appin began as a digital security consultancy that provided cybersecurity classes to help Indian organizations defend themselves online. This drew the attention of Indian government officials, who were navigating internet-era intelligence challenges and seeking ways to hack into computers and emails.
Shortly thereafter, Appin established a subsidiary called Appin Software Security also known as the Appin Security Group to conduct surveillance activities for the Indian government. Employees signed
non-disclosure agreement
A non-disclosure agreement (NDA), also known as a confidentiality agreement (CA), confidential disclosure agreement (CDA), proprietary information agreement (PIA), or secrecy agreement (SA), is a legal contract or part of a contract between at le ...
s and were shipped to military-controlled facilities, where they worked away from their colleagues in the wider company.Their targets included Pakistan, China, and
Khalistani separatists from India's
Punjab
Punjab (; ; also romanised as Panjāb or Panj-Āb) is a geopolitical, cultural, and historical region in South Asia. It is located in the northwestern part of the Indian subcontinent, comprising areas of modern-day eastern Pakistan and no ...
state.
By 2009, the company's clients had included the
Research and Analysis Wing
The Research and Analysis Wing (R&AW) is the foreign intelligence agency of the Republic of India. The agency's primary function is gathering foreign intelligence, counter-terrorism, counter-proliferation, advising Indian policymakers, and a ...
(RAW), the
Intelligence Bureau, the
Indian Armed Forces
The Indian Armed Forces are the armed forces, military forces of the India, Republic of India. It consists of three professional uniformed services: the Indian Army, the Indian Navy, and the Indian Air Force.—— Additionally, the Indian Ar ...
, the
Ministry of Home Affairs
An interior ministry or ministry of the interior (also called ministry of home affairs or ministry of internal affairs) is a government department that is responsible for domestic policy, public security and law enforcement.
In some states, the i ...
, and the
Central Bureau of Investigation
The Central Bureau of Investigation (CBI) is the domestic crime investigating agency of India. It operates under the jurisdiction of the Ministry of Personnel, Public Grievances and Pensions. Originally set up to investigate bribery and gover ...
(CBI). Appin claimed their solutions were used by government intelligence agencies to monitor hostile individuals, marketed software for analyzing call metadata, and explored importing Israeli cell phone interception devices. For the fiscal year ending in 2009, the company earned nearly $1 million in revenue and a profit of about $170,000, with a projected tenfold increase in revenue over the next 36 months.
The company also made extra money by discreetly reselling material it had hacked for one Indian agency to another. This practice of double-dipping was eventually uncovered, prompting several outraged Indian intelligence agencies to terminate their contracts with Appin. Facing dwindling opportunities in intelligence work, Appin shifted its focus to hacking and phishing for the private sector.
In 2010, Rajat Khare sent bulk emails to private intelligence firms across Europe offering hacking-for-hire services.
Around 2011, the mercenaries began operating a digital dashboard dubbed "My Commando" for spy services, resembling an e-commerce platform with a menu of hacking options. Customers logged in to request Appin to hack emails, computers, or phones, track the operation's progress like a delivery, and later download the stolen data.
More than 70 global clients hired Appin to hack hundreds of targets through "My Commando."
Among the system's early users were Israeli private detectives Aviram Halevi and Tamir Mor, who accessed it in late 2011. That year, Mor ordered hacks on more than 40 targets, including Malaysian politician
Mohamed Azmin Ali
Mohamed Azmin bin Ali ( Jawi: محمد عزمين بن علي; born 25 August 1964) is a Malaysian politician who has served as the State Leader of the Opposition of Selangor and Member of the Selangor State Legislative Assembly (MLA) for Hul ...
, Russian oligarch
Boris Berezovsky, and his lawyers. Berezovsky was found dead in 2013 after losing a multibillion-dollar case the previous year. Around the same time, another user hired Appin to hack 30 targets, including a Rwandan
dissident
A dissident is a person who actively challenges an established political or religious system, doctrine, belief, policy, or institution. In a religious context, the word has been used since the 18th century, and in the political sense since the 2 ...
and the wife of another wealthy Russian going through a divorce.
The targets also included Kristi Rogers—the wife of Representative
Mike Rogers, who was the Chairman of the
U.S. House Intelligence Committee at the time. Less well-known individuals, such as a landscape architect in
New Jersey
New Jersey is a U.S. state, state located in both the Mid-Atlantic States, Mid-Atlantic and Northeastern United States, Northeastern regions of the United States. Located at the geographic hub of the urban area, heavily urbanized Northeas ...
and a
Native American tribal member, were also targeted using the system. Other victims of Appin included
human rights activists
A human rights defender or human rights activist is a person who, individually or with others, acts to promote or protect human rights. They can be journalists, environmentalists, whistleblowers, trade unionists, lawyers, teachers, housing campai ...
, such as those associated with the
Oslo Freedom Forum
Oslo Freedom Forum (OFF) is a series of global conferences run by the New York–based non-profit Human Rights Foundation under the slogan "Challenging Power". OFF was founded in 2009 as a one-time event and has taken place annually ever since. ...
, along with governmental and private organizations.
Starting on 5 January 2012, a cyberattack targeted Peter Hargitay, a Zurich-based
FIFA
The Fédération Internationale de Football Association (), more commonly known by its acronym FIFA ( ), is the international self-regulatory governing body of association football, beach soccer, and futsal. It was founded on 21 May 1904 to o ...
insider and consultant for Australia's 2022 World Cup bid. Hargitay and his son hired an expert who traced the hack to a server linked to Rajat Khare. The attack was part of an extensive hacking operation targeting numerous individuals for smear campaigns. This was tied to Qatar's web of espionage to secure the
2022 FIFA World Cup
The 2022 FIFA World Cup was the 22nd FIFA World Cup, the quadrennial world championship for national football teams organized by FIFA. It took place in Qatar from 20 November to 18 December 2022, after the country was awarded the hosting ri ...
hosting rights.
Hack-for-hire companies founded by Appin alumni were also implicated in the campaign.
Also in 2012, a German private investigator paid Appin $3,000 to hack an email during an inheritance feud involving a wealthy businessman.
That same year, an Indian cybersecurity consultant traced an attempted hack on a client to Appin and discovered compromising material on its servers. In the Dominican Republic, authorities raided a local newspaper publisher in 2012 and formally accused him of collaborating with Khare to hack emails and extract information from the nation's elite for his digital newspaper. The publisher later admitted that in 2011, he paid Appin between $5,000 and $10,000 a month to spy on over 200 prominent
Dominicans
Dominicans () also known as Quisqueyans () are an ethnic group, ethno-nationality, national people, a people of shared ancestry and culture, who have ancestral roots in the Dominican Republic.
The Dominican ethnic group was born out of a fusio ...
—including then-President
Leonel Fernández
Leonel Antonio Fernández Reyna () (born 26 December 1953) is a Dominican lawyer, academic, and was the 50th and 52nd President of the Dominican Republic from 1996 to 2000 and from 2004 to 2012. From 2016 until 2020, he was the President of th ...
.
In 2012, after analyzing a hack and leak targeting a Native American tribal member, the
FBI
The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and Federal law enforcement in the United States, its principal federal law enforcement ag ...
linked multiple cases to a single perpetrator. Collaborating with Swiss authorities, the FBI identified the perpetrator as Appin and shared that they had human intelligence through a confidential source.
In February 2013, the
Chicago Mercantile Exchange
The Chicago Mercantile Exchange (CME) (often called "the Chicago Merc", or "the Merc") is an American derivatives marketplace based in Chicago and located at 20 S. Wacker Drive. The CME was founded in 1898 as the Chicago Butter and Egg Board ...
filed a complaint with the
World Intellectual Property Organization
The World Intellectual Property Organization (WIPO; (OMPI)) is one of the 15 specialized agencies of the United Nations (UN). Pursuant to the 1967 Convention Establishing the World Intellectual Property Organization, WIPO was created to pr ...
regarding a phishing attack that used a suspicious domain to steal investment information.
In March of that year, after
Telenor
Telenor ASA ( or ) is a Norwegian majority state-owned multinational telecommunications company headquartered at Fornebu in Bærum, close to Oslo. It is one of the world's largest mobile telecommunications companies with operations worldwi ...
filed a criminal case with Norwegian police
Kripos
The National Criminal Investigation Service (, previously ''Kriminalpolitisentralen''), commonly known as Kripos, is a special agency of the Norwegian Police Service. Based at Bryn in Oslo and established in 1959, it is a national unit that wo ...
over a hack stealing 66,000 emails from its leadership and legal advisor, the infosec community obtained evidence that allowed them to access Appin's unsecured servers and link the group to several high-profile cyberattacks that had been directed at more than a dozen countries.
Notably, Norman Shark publicly linked the Telenor hack to Appin.
Appin's industrial-scale random attacks drew global attention,
and by 2013, they had become well known among security researchers, who referred to them using various monikers to describe their pattern of activity, including Operation Hangover by
Shadowserver Foundation and Norman Shark,
Monsoon by
Forcepoint, and Viceroy Tiger by
CrowdStrike
CrowdStrike Holdings, Inc. is an American cybersecurity technology company based in Austin, Texas. It provides endpoint security, threat intelligence, and cyberattack response services.
The company has been involved in investigations of seve ...
. From 2013 onward, Google spent a decade monitoring Appin-linked hackers who targeted tens of thousands of email accounts on its platform.
Due to the unusually high volume worked by the hackers, Google had to expand its systems and procedures to keep up with them. Security researchers have been cautious in their public statements linking Appin to the hacking and
phishing
Phishing is a form of social engineering and a scam where attackers deceive people into revealing sensitive information or installing malware such as viruses, worms, adware, or ransomware. Phishing attacks have become increasingly sophisticate ...
incidents to avoid legal trouble; however, privately, they remain confident in the connection.
Since 2012, Appin and its CEO Rajat Khare have been under criminal investigations in multiple countries. Swiss authorities linked Appin and Rajat Khare to a criminal complaint filed by the Hargitays for intrusion into their systems, while Norwegian investigators connected Appin to the
Telenor
Telenor ASA ( or ) is a Norwegian majority state-owned multinational telecommunications company headquartered at Fornebu in Bærum, close to Oslo. It is one of the world's largest mobile telecommunications companies with operations worldwi ...
hack. In 2016, the person who had hired a private detective to access the email of her fellow Native American tribal member pleaded guilty in federal court. Later, in mid-2020, that detective confessed in an affidavit that he had hired Appin to carry out the email heist. Similarly, Aviram Halevi, who hired Appin to hack at least three dozen people in 2011, admitted to employing them to steal emails from a Korean businessman.
In 2021, the
State Bank of India
State Bank of India (SBI) is an Indian Multinational corporation, multinational Public sector undertakings in India, public sector bank and financial service body headquartered in Mumbai. It is the largest bank in India with a 23% market shar ...
filed a criminal complaint with the Central Bureau of Investigation, Appin's former client, accusing Rajat Khare and others of embezzling ₹8.06 billion ($97 million) from loans to
Educomp, where Khare was a director.
Controversies
Appin and co-founder Rajat Khare have systematically pressured news sources in multiple countries, including France, Luxembourg, Switzerland, the United Kingdom, and India, to remove references in articles to the company and Khare.
On 2 November 2022, Swiss media outlet ''
SRF Investigativ'' published an investigative piece about Qatar's elaborate and extensive espionage operation to secure the
2022 FIFA World Cup
The 2022 FIFA World Cup was the 22nd FIFA World Cup, the quadrennial world championship for national football teams organized by FIFA. It took place in Qatar from 20 November to 18 December 2022, after the country was awarded the hosting ri ...
hosting rights. The operation, which was dubbed Project Merciless, involved hacking emails and phones of
FIFA
The Fédération Internationale de Football Association (), more commonly known by its acronym FIFA ( ), is the international self-regulatory governing body of association football, beach soccer, and futsal. It was founded on 21 May 1904 to o ...
officials and critics of Qatar's corruption and
poor human rights record. It also targeted their friends and family members to run smear campaigns and influence FIFA policy.
In November 2022, a lower court in Geneva ordered the publication to provisionally remove Rajat Khare's name and photo from the article. When contacted by RSF, Khare's Swiss lawyer, Nicolas Capt, stated that Khare has taken civil and criminal action in Switzerland and other countries to protect his honor.
On 1 June 2023, The ''
New Yorker
New Yorker may refer to:
* A resident of New York:
** A resident of New York City and its suburbs
*** List of people from New York City
** A resident of the New York (state), State of New York
*** Demographics of New York (state)
* ''The New Yor ...
'' published an article titled, "A Confession Exposes India's Secret Hacking Industry." The article primarily focused on firms founded by Appin alumni, such as BellTroX Infotech Services and CyberRoot Risk Advisory, which have targeted climate activists, investors, lawsuit defendants, and organizations on a global scale and still remain operational. Appin first sued the U.S. magazine in India, and later, Rajat Khare filed a lawsuit against it in Switzerland. The New Yorker refused to take down their article, stating that they fully stand behind the piece, which is an accurate and fair account of a matter of legitimate public interest. They further stated that they will continue to defend the right to publish important reporting without fear or favor.
On 16 November 2023, ''
Reuters
Reuters ( ) is a news agency owned by Thomson Reuters. It employs around 2,500 journalists and 600 photojournalists in about 200 locations worldwide writing in 16 languages. Reuters is one of the largest news agencies in the world.
The agency ...
'' published an explosive article about the company and its cofounder Rajat Khare titled, "How an Indian Startup Hacked the World." Drawing on hundreds of interviews and thousands of vetted documents, ''Reuters'' found that Appin "grew from an educational startup to a hack-for-hire powerhouse that stole secrets from executives, politicians, military officials and wealthy elites around the globe." The report was based on Appin's activities for nearly two decades, including company records, law enforcement files, and input from former employees, clients, and security professionals. The raw material spanning 2005 to 2022 was authenticated by ''Reuters'' and further verified by U.S. cybersecurity firm
SentinelOne.
Appin sued ''Reuters'', claiming the news agency had engaged in a "defamatory campaign."
It obtained an injunction from a Delhi court and, on 4 December 2023, ''Reuters'' temporarily removed its article. Reuters said that it stood by its reporting.
An archived version of the ''Reuters'' article hosted on the
Wayback Machine
The Wayback Machine is a digital archive of the World Wide Web founded by Internet Archive, an American nonprofit organization based in San Francisco, California. Launched for public access in 2001, the service allows users to go "back in ...
was likewise removed following demands from lawyers representing Appin co-founder Rajat Khare. Appin further sent demands to
Meta Platforms
Meta Platforms, Inc. is an American multinational technology company headquartered in Menlo Park, California. Meta owns and operates several prominent social media platforms and communication services, including Facebook, Instagram, Threads ...
,
LinkedIn
LinkedIn () is an American business and employment-oriented Social networking service, social network. It was launched on May 5, 2003 by Reid Hoffman and Eric Ly. Since December 2016, LinkedIn has been a wholly owned subsidiary of Microsoft. ...
and
Naukri.com to block accounts associated with the authors of the ''Reuters'' story.
In February 2024,
''Wired'' reported that lawyers for Appin and a related entity called the
Association for Appin Training Centers
have filed lawsuits and made legal threats against more than a dozen news organizations. Appin sent emails demanding news site ''
Techdirt
Techdirt is an American Internet blog that reports on technology's legal challenges and related business and economic policy issues, in context of the digital revolution. It focuses on intellectual property, patent, information privacy and copyr ...
'' and the organization
MuckRock
MuckRock is a United States–based 501(c)(3) non-profit organization which assists anyone in filing governmental requests for information through the Freedom of Information Act (FOIA) and other public record laws around the United States, then ...
which hosted some of the information ''Reuters'' relied on. The two sites denied that the injunction was binding on them.
Other sites, such as the
''Lawfare'' blog, removed material based on the ''Reuters'' article.
The
Electronic Frontier Foundation
The Electronic Frontier Foundation (EFF) is an American international non-profit digital rights group based in San Francisco, California. It was founded in 1990 to promote Internet civil liberties.
It provides funds for legal defense in court, ...
(EFF) announced that they responded on behalf of ''Techdirt'' and MuckRock to legal threats made by Appin Training Centers. One of the arguments the EFF made in their letter to Appin is that the Indian court's order is unenforceable in U.S. courts because it conflicts with the
First Amendment
First most commonly refers to:
* First, the ordinal form of the number 1
First or 1st may also refer to:
Acronyms
* Faint Images of the Radio Sky at Twenty-Centimeters, an astronomical survey carried out by the Very Large Array
* Far Infrared a ...
and
Section 230
In the United States, Section 230 is a section of the Communications Act of 1934 that was enacted as part of the Communications Decency Act of 1996, which is Title V of the Telecommunications Act of 1996, and generally provides immunity for on ...
of the
Communications Decency Act
The Communications Decency Act of 1996 (CDA) was the United States Congress's first notable attempt to regulate pornographic material on the Internet. In the 1997 landmark case '' Reno v. ACLU'', the United States Supreme Court unanimously stru ...
(47 U.S.C. § 230), as reinforced by the
SPEECH Act
In the philosophy of language and linguistics, a speech act is something expressed by an individual that not only presents information but performs an action as well. For example, the phrase "I would like the mashed potatoes; could you please pas ...
(28 U.S.C. § 4102). The EFF also urged recipients of Indian gag orders to carefully evaluate their legitimacy.
The ''
Reuters
Reuters ( ) is a news agency owned by Thomson Reuters. It employs around 2,500 journalists and 600 photojournalists in about 200 locations worldwide writing in 16 languages. Reuters is one of the largest news agencies in the world.
The agency ...
'' article was restored in October 2024, after the Delhi court rescinded its injunction on 3 October 2024, noting "the plaintiff has not been able to show any
prima facie
''Prima facie'' (; ) is a Latin expression meaning "at first sight", or "based on first impression". The literal translation would be "at first face" or "at first appearance", from the feminine forms of ' ("first") and ' ("face"), both in the a ...
case to make interference in the process of journalism". The article is back online at its original location.
On 21 November 2024,
Reporters Without Borders
Reporters Without Borders (RWB; ; RSF) is an international non-profit and non-governmental organisation, non-governmental organization headquartered in Paris, which focuses on safeguarding the right to freedom of information. It describes its a ...
(RSF) reported that works from at least 15 different media outlets had been modified or withdrawn as a result of a
strategic lawsuit against public participation
Strategic lawsuits against public participation (also known as SLAPP suits or intimidation lawsuits), or strategic litigation against public participation, are lawsuits intended to censor, intimidate, and silence critics by burdening them with ...
or a legal notice from Rajat Khare or Appin Training Centers, while posts praising Khare on self-published sites flooded the internet. Additionally, an ''Intelligence Online'' article
was the subject of what
Reporters Without Borders
Reporters Without Borders (RWB; ; RSF) is an international non-profit and non-governmental organisation, non-governmental organization headquartered in Paris, which focuses on safeguarding the right to freedom of information. It describes its a ...
described as an "abusive DMCA takedown request".
Legacy
Following Norman Shark's public attribution of the
Telenor
Telenor ASA ( or ) is a Norwegian majority state-owned multinational telecommunications company headquartered at Fornebu in Bærum, close to Oslo. It is one of the world's largest mobile telecommunications companies with operations worldwi ...
hack to Appin,
the company faced increasing scrutiny, and the group began scaling back its online presence.
Around that time, former Appin employees branched out, founding similar hack-for-hire firms.
Two such companies—BellTroX InfoTech Services led by Sumit Gupta and CyberRoot Risk Advisory
—started collaborating with Appin, sharing staff and computer infrastructure for their hacking operations.
Their activities were identified using a database of over 80,000 phishing emails sent to 13,000 targets from 2013 to 2020.
This database was vetted by six expert groups, with each group independently confirming recognized hacking activity.
Further analysis by
Mandiant
Mandiant, Inc. is an American cybersecurity firm and a subsidiary of Google. Mandiant received attention in February 2013 when it released a report directly implicating China in cyber espionage. In December 2013, Mandiant was acquired by FireE ...
, LinkedIn, Google,
and court records revealed that the hacking was carried out by three Appin-linked companies with an intermingling of resources among them.
This network of mercenaries charged clients anywhere from a few thousand to millions of dollars,
while paying workers just $370 per month.
The hackers targeted attorneys and their clients—including companies, advocacy groups, media organizations, and business executives—seeking to undermine the legal process. Notably, media reports have linked Appin alumnus Sumit Gupta to criminal cases, former Israeli policeman Aviram Azari,
Dark Basin
Dark Basin is a hack-for-hire group, discovered in 2017 by Citizen Lab. They are suspected to have acted on the behalf of companies such as Wirecard and ExxonMobil. Dark Basin is believed to be run by Indian company BellTroX InfoTech Services.
...
, and the wider network of Indian hackers.
Appin Technology rebranded multiple times before adopting the name Sunkissed Organic Farms in 2017. Its subsidiaries also underwent rebranding. In 2015, Appin Software Security—which billed private eyes for the hacking work—became Adaptive Control Security Global Corporate (ACSG).
Rajat Khare resigned as director of Appin Technology in 2016 and now resides in Switzerland. The multinational criminal investigations into him and Appin ultimately proved abortive due to jurisdictional challenges.
After the Swiss criminal investigation into his hacking of the Hargitays was closed, in the fall of 2020, Khare purchased a villa in Switzerland for 13.5 million
Swiss franc
The Swiss franc, or simply the franc, is the currency and legal tender of Switzerland and Liechtenstein. It is also legal tender in the Italian exclave of Campione d'Italia which is surrounded by Swiss territory. The Swiss National Bank (SNB) iss ...
s from the daughter of a Ukrainian oligarch. He now portrays himself as a renowned start-up investor.
In September 2023, The Economic Times reported that Rajat and Shweta Khare had purchased a plot in Delhi for ₹760 million (about $9.1 million). Together, they run Boundary Holding, a Luxembourg-based venture capital firm.
Rajat Khare's family controls companies founded under the Appin name, as well as the renamed Indian firms, including ACSG, which officially claims to provide confidential computer security services to governments.
See also
*
Dark Basin
Dark Basin is a hack-for-hire group, discovered in 2017 by Citizen Lab. They are suspected to have acted on the behalf of companies such as Wirecard and ExxonMobil. Dark Basin is believed to be run by Indian company BellTroX InfoTech Services.
...
References
{{Hacking in the 2010s
Hacker groups
Cybercrime in India
Private intelligence agencies
Censorship in India
Strategic lawsuits against public participation
Hacking in the 2010s
Information technology companies of New Delhi
Indian companies established in 2003
Defunct companies of India
Corporate scandals
Technology companies established in 2003