Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

The 2023 headline “Shadowy Hack-for-Hire Group Behind Sprawling Web of Global Cyberattacks” appears to refer to Appin, a New Delhi-based operation. But the underlying SentinelOne report is not available in the sources reviewed here, and Dark Reading removed its story after SentinelOne temporarily took the report offline. That means the headline alone does not establish Appin’s targets, tools, clients, attack count or operations. Separate investigations do document how hack-for-hire services can work—and why their activity can put journalists, activists, businesses and other account holders at risk.

What is a hack-for-hire group?

Google’s Threat Analysis Group (TAG) uses “hack-for-hire” for operators who carry out attacks themselves for paying clients, often to gain access to accounts or extract data. That differs from a commercial surveillance vendor, which generally sells a tool or capability for a customer to operate. The distinction matters: in the first model, the provider conducts the intrusion; in the second, the buyer uses the product.

The client may be difficult to identify because intermediaries can stand between the customer and the operator. TAG’s 2022 research describes a varied market that included actors associated with India, Russia and the United Arab Emirates (UAE). Those examples show that the market is not one organization with one target profile, and they do not establish Appin’s identity, clients or activity.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What is known about Appin?

The exact-title result from Dark Reading in 2023 characterized its story as concerning a New Delhi-based Appin operation and said the story was removed after SentinelOne temporarily took its report offline. The report’s underlying Appin-specific findings are not available here. As a result, claims about Appin’s alleged victims, methods, scale, clients or links to particular incidents cannot be independently established from that result.

Other sources provide context about the broader Indian hack-for-hire market, not proof of Appin’s specific conduct. The Bureau of Investigative Journalism’s 2022 reporting recounted undercover contact with suspected Indian operators and attributed claims about work to a source. Those are investigative reporting and attributed allegations, not judicial findings or Appin-specific technical evidence.

How do documented hack-for-hire attacks work?

Google TAG’s 2022 reporting describes methods it observed in examples involving other actors. A 2019 academic study examined a sample of hack-for-hire services. These findings illustrate techniques used in the wider ecosystem; neither source establishes that Appin used them.

Stage or technique What the sources documented Scope
Phishing and credential theft TAG described fake account notifications and other credential lures. In one Russia-related example, emails linked to attacker-controlled pages and impersonated webmail notifications or government organizations. TAG’s observations about the groups it studied, not Appin.
Other lures and mailbox access In a UAE-related example, TAG described password-reset lures, phishing emails, a custom kit and mailbox collection after account access. TAG’s observations about a separate example, not Appin.
Persistence after access In its Russia-related example, TAG observed persistence through an OAuth token granted to a legitimate mail app or an app password used for IMAP access. A specific observed method; it should not be generalized to every operator or account compromise.
Social engineering in a study sample A 2019 academic study found that the services it examined predominantly relied on targeted phishing email. Some used spoofed login pages to capture credentials and SMS codes. A historically and methodologically bounded sample, not a current industry-wide measurement.

The same 2019 study reported that only five services in its sample delivered on promises to attack the researchers’ fabricated victim personas. Two-factor authentication remained an obstacle in the study’s tests. Neither result is a current success rate for the market, and neither says anything specific about Appin.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who can be targeted, and how broad can the impact be?

TAG says hack-for-hire targets can include activists, journalists, nongovernmental organizations, companies and other individuals. Its examples include broad and sometimes opportunistic targeting, rather than a single universal victim profile.

Citizen Lab’s 2020 investigation of the separate operation Dark Basin reported that it targeted “thousands of individuals and hundreds of institutions on six continents.” Citizen Lab assessed that Dark Basin likely conducted commercial espionage for clients involved in disputes and public events. Its findings illustrate the potential reach and consequences of the market; Dark Basin is not another name for Appin.

A separate campaign shows that the concern has continued in recent years. Access Now’s 2026 report describes spear-phishing attacks against Egyptian journalists and government critics in 2023–2024. Access Now and Lookout characterized the likely actor as a hack-for-hire group with Asian ties. This is a distinct campaign and does not establish a connection to Appin.

How can you reduce the risk of account compromise?

Google TAG recommends that people at elevated risk use Advanced Protection, enable Enhanced Safe Browsing and keep their devices updated. These are defensive steps, not a guarantee against every kind of intrusion.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Use Advanced Protection if you face elevated targeting risk. Google TAG specifically recommends it for high-risk users.
  2. Turn on Enhanced Safe Browsing. TAG includes this among its recommendations for reducing exposure to malicious links and content.
  3. Keep your devices updated. Install available operating-system and browser updates so devices receive current security fixes.
  4. Review your account’s security and recovery settings. Check the current instructions from your email provider and review connected apps and account access.
  5. If you suspect account access, change the password and follow your provider’s recovery guidance. In the cases TAG observed, changing the account password revoked associated persistent OAuth tokens or app passwords. That observation concerns those mechanisms; it should not be treated as proof that a password change alone will remove every form of persistence.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the evidence does—and does not—support

There is well-documented evidence that hack-for-hire is a broader market in which operators can conduct phishing and credential-theft campaigns for clients, with targets ranging from civil society to businesses. There are also detailed investigations of separate operations, including Dark Basin, and reporting about suspected Indian operators.

That context cannot fill the gap in the Appin-specific account behind the 2023 headline. Without the SentinelOne report or equivalent direct evidence, the claims implied by “sprawling web of global cyberattacks” remain unverified here. The available material supports explaining the market and its risks, but not treating those headline particulars as established facts.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.