What HappenedIn mid-2026, an emerging cybercriminal group known as ExfilSquad launched a high-profile extortion campaign targeting prominent UK organisations across the public sector, education, and law enforcement, as well as other firms worldwide.Unlike traditional ransomware groups, ExfilSquad does not deploy encryptors or destructive malware. Instead, they operate as a pure data extortion group, stealing data and threatening to publish it on their onion-based Data Leak Site (DLS) if a ransom
In mid-2026, an emerging cybercriminal group known as ExfilSquad launched a high-profile extortion campaign targeting prominent UK organisations across the public sector, education, and law enforcement, as well as other firms worldwide.
Unlike traditional ransomware groups, ExfilSquad does not deploy encryptors or destructive malware. Instead, they operate as a pure data extortion group, stealing data and threatening to publish it on their onion-based Data Leak Site (DLS) if a ransom is not paid.
Several prominent UK entities have confirmed breaches linked to the group:
UK Department for Education (DfE): Approximately 600,000 records stolen from its Help Portal containing parent and staff contact details (names, emails, phone numbers, job titles), plus around 7,000 records from the Turing Portal.
Police National Legal Database (PNLD): Stole 1.9 GB of data (around 135,000 records) containing contact information for over 100,000 serving police officers, staff, and criminal justice professionals, alongside around 21,000 "Ask the Police" public inquiry records.
Newcastle University: Approximately 440,000 records compromised containing applicant and student contact information, personally identifiable information (PII), and admissions database records caused by a technical configuration flaw connecting to an admissions system.
Analysis of the details left on the data leak site revealed that ExfilSquad's primary attack vector involves exploiting misconfigurations in cloud portals, customer relationship management (CRM) platforms, internal case management systems, as well as Microsoft Power Pages data tables left publicly accessible without proper authentication.
To force compliance and prove their claims are real, ExfilSquad uploaded multi-gigabyte torrent files for each victim to their TOR leak site. Resecurity noted that ExfilSquad assigns a distinct Torrent Tracker and initial Web Seed per victim.
Analyst Comment
While ExfilSquad is a new group, they appear to be already experienced at running these types of attacks, suggesting they have a history of cybercrime. Plus, ExfilSquad’s recent campaign highlights the growing trend of transitioning from file-encrypting ransomware to extortion driven entirely by cloud and SaaS misconfigurations. Organisations that have invested in defending against endpoint-based threats are often leaving critical business application interfaces exposed.
SaaS platforms continue to be primary targets of English-speaking cybercrime communities. In recent years, customers of major SaaS providers, such as Salesloft, Salesforce, and Snowflake have all been extorted. Microsoft Power Pages portals, CRM databases, and customer support helpdesks frequently hold vast repositories of sensitive contact data and interaction histories. When internet-facing API endpoints or data table permissions are left unauthenticated or unpatched, cybercriminals can systematically scrape massive volumes of data without ever needing to drop a payload or escalate privileges internally.
ExfilSquad’s reliance on torrent distribution further amplifies reputational and operational damage. While gangs like LockBit, Clop, and Akira have previously utilised torrents, ExfilSquad’s operational twist of assigning unique Torrent Trackers and dedicated Web Seeds to individual victims ensures that leaked files distribute rapidly across P2P networks, making it extremely difficult to perform a takedown.
While ExfilSquad’s breaches have largely compromised contact directories and administrative support records, the real-world risks remain significant. Exposing work emails, names, and organisational structures for over 100,000 police officers and civil servants poses distinct social engineering, spear-phishing, and physical security concerns that impacted institutions will have to manage long after the breach occurs.
Defensive Takeaways
Audit Microsoft Power Pages and Public SaaS Tables: Regularly review public data table permissions, web API settings, and unauthenticated browser views across Microsoft Power Pages, CRMs, and customer support portals to ensure backend data tables are not exposed to the public internet.
Harden CRM and Case Management Integrations: Treat external-facing admissions portals, helpdesks, and case management systems as high-risk platforms. Implement strict access controls, conduct routine configuration audits, and enforce proper API token security.
Deploy External Attack Surface Management (EASM): Utilise continuous external attack surface scanning to detect newly exposed web endpoints, misconfigured database connectors, and publicly exposed storage buckets before malicious actors locate them.
Incorporate Pure Extortion into Incident Response Plans: Security teams must adapt incident response playbooks for data-theft-only scenarios. Organisations may seek to establish protocols for monitoring peer-to-peer (P2P) networks and managing public disclosures when stolen data is distributed via torrents.
What HappenedOn 7 August 2026, the UK Information Commissioner's Office (ICO) disclosed that between July 2021 and June 2023, the ACRO Criminal Records Office suffered three separate compromises involving its customer portal website (acro.police.uk).ACRO is a national police unit providing public services such as issuing Police Certificates, International Child Protection Certificates, and processing Subject Access Requests.In March 2023, ACRO was notified about an SQL injection attack that repo
On 7 August 2026, the UK Information Commissioner's Office (ICO) disclosed that between July 2021 and June 2023, the ACRO Criminal Records Office suffered three separate compromises involving its customer portal website (acro.police.uk).
ACRO is a national police unit providing public services such as issuing Police Certificates, International Child Protection Certificates, and processing Subject Access Requests.
In March 2023, ACRO was notified about an SQL injection attack that reportedly exposed 15 sets of credentials, the majority of which belonged to its employees.
A subsequent forensic investigation uncovered long-term threat actor activity within the website's environment, spanning from 9 July 2021 to 22 June 2023.
The website was built on the Kentico CMS and was running version 12.0.0 between September 2019 and March 2023. This version had multiple known vulnerabilities at the time of the incident, but suffered from ambiguity around who was accountable for patching led to missed hotfixes and updates.
Between 15 and 16 February 2023, an unknown threat actor staged personal data for exfiltration, which included Police Certificate Applications, Subject Access Request (SAR) forms, and International Child Protection Certificate forms.
Due to insufficient log retention, ACRO could not definitively determine if the data was successfully exfiltrated. A maximum of 10,920 data subjects had their data staged, but ACRO ultimately notified 84,048 data subjects on a precautionary basis in April 2023.
Notably, on 23 February 2023, the ICO learned that ACRO's Trend Micro antivirus software detected and quarantined four attempts to install the well-known credential harvesting tool Mimikatz. However, because ACRO operated without a documented patching policy and lacked a structured process for analyzing security alerts, these warnings were never reviewed or acted upon.
Analyst Comment
The Information Commissioner's Office (ICO) reprimand against the ACRO underscores the persistent issue within many organisations of a breakdown in basic IT governance and accountability. The fact that a threat actor was able to operate within the environment for nearly two years highlights systemic failures in both vulnerability management and security monitoring. Running an outdated content management system with known vulnerabilities for several years is a critical oversight. The ambiguity surrounding patching responsibilities created a dangerous blind spot that adversaries successfully exploited.
Further, the failure to act on critical security alerts is also a classic breakdown in the incident response chain. While the deployed Trend Micro antivirus successfully detected and quarantined a known threat, the alerts were ultimately ignored. Security tools are only as effective as the teams monitoring and responding to them. Without a structured review process, even the most sophisticated detection capabilities fall flat.
It is important to note, however, that while private sector organisations will receive a hefty fine for data protection offences, public sector organisations like ACRO receive a public reprimand from the ICO rather than receive a fine that confiscates public funds.
At the time of writing, the data has not yet appeared on any cybercrime forums or underground chat channels. The use of an open source tool like Mimikatz combined with SQL injection attacks indicates a likely opportunistic adversary rather than a stealthy cyber-espionage operation. However, both cybercriminal and nation state groups are known for opportunistic attacks. Current attribution for who or what was responsible this breach remains uncertain from an open source intelligence (OSINT) perspective.
On a positive note, the ICO highlighted that ACRO’s network segmentation effectively prevented the threat actor from pivoting from the compromised web environment into core policing systems. This containment significantly reduced the scale of harm and demonstrates the immense value of architectural defense-in-depth strategies. Following the breach, ACRO has migrated its portal to the Salesforce Experience Cloud for automated patching and hotfixes and implemented a Security Information and Event Management (SIEM) system to improve visibility.
Defensive Takeaways
Establish Clear Accountability for Patching: Organisations must have a documented patching policy with clearly defined ownership, especially for public-facing web applications and Content Management Systems (CMS). Ambiguity in IT governance directly leads to unpatched vulnerabilities which then get exploited.
Implement Structured Alert Monitoring: Deploying antivirus or Endpoint Detection and Response (EDR) solutions alone is insufficient if alerts are not actively monitored and investigated. It is recommended to establish either structured internal processes or an outsourced 24/7 Managed Detection and Response (MDR) or SOC service to review and respond to critical security alerts promptly.
Maintain Robust Network Segmentation: Ensure that public-facing web infrastructure is strictly segmented from internal corporate networks and core operational systems. As demonstrated in this incident, strict segmentation is a crucial control for stopping an attacker's lateral movement.
Ensure Adequate Log Retention: Insufficient logging severely hinders incident response and forensic investigations. Implement comprehensive logging policies and utilise a SIEM to aggregate logs, ensuring they are retained long enough to accurately determine the scope of data exfiltration during a compromise.
A usage policy for Flock license plate reader cameras tells police not to talk about the cameras:
When cops use Flock to arrest someone in Wapello County, Iowa, they don’t want them to know. A usage policy for the automated license plate reader cameras in the county tells police, in no uncertain terms, to keep them a secret: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE,” the policy document reads. “DO NOT MENTION ALPR USAGE IN YOUR REPORT OR COMPLAINT UNLESS ABSOLUTELY NECESSARY.”
A usage policy for Flock license plate reader cameras tells police not to talk about the cameras:
When cops use Flock to arrest someone in Wapello County, Iowa, they don’t want them to know. A usage policy for the automated license plate reader cameras in the county tells police, in no uncertain terms, to keep them a secret: “DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE,” the policy document reads. “DO NOT MENTION ALPR USAGE IN YOUR REPORT OR COMPLAINT UNLESS ABSOLUTELY NECESSARY.”
This reminds me of IMSI-catchers (Stingray was the most popular) a couple of decades ago. Police would go to even more extremes to hide their usage.
What HappenedNew data published by the City of London Police in June 2026 reveals that courier fraud losses exceeded £21 million in 2025, with individuals aged over 70 being heavily targeted. The highest concentration of these offenses was recorded in London and the Home Counties.Cybercriminals and fraud syndicates are actively evolving their operational tactics, increasingly pivoting to messaging platforms like WhatsApp to contact their victims and remotely paying for third-party courier servic
New data published by the City of London Police in June 2026 reveals that courier fraud losses exceeded £21 million in 2025, with individuals aged over 70 being heavily targeted. The highest concentration of these offenses was recorded in London and the Home Counties.
Cybercriminals and fraud syndicates are actively evolving their operational tactics, increasingly pivoting to messaging platforms like WhatsApp to contact their victims and remotely paying for third-party courier services to facilitate physical collections.
UK law enforcement also highlighted a dangerous shift in 2025 toward high-value physical goods. Victims are being systematically manipulated into visiting multiple jewellers over an extended period to purchase gold and expensive jewellery, which they then hand directly to fraud couriers.
Recent operational crackdowns by UK Regional Organised Crime Units (ROCUs) showcase the nationwide scale of these networks:
North West ROCU Operations (July 2026): Police executed coordinated search warrants in Huddersfield and Manchester, arresting two men (aged 21 and 25) on suspicion of Conspiracy to Defraud and Money Laundering. In this specific series, the suspects impersonated bank fraud departments, convinced a victim her card was compromised, sent a courier to collect it, and immediately exploit the physical card to make numerous fraudulent transactions.
North East ROCU (NEROCU) Sentencing (June 2026): A complex, cross-country courier fraud operation spanning March to May 2022 concluded with a prison sentence for a primary operative. The network targeted 14 separate victims, convincing them to hand over physical bank cards and PIN numbers under the guise of an internal "investigation" by their bank's fraud department. The group scammed a total of £56,000, which was then rapidly laundered through the high street purchase of smartphones, designer clothing, and luxury jewellery.
Analyst Comment
Courier fraud is effectively a hybrid cyber-physical social engineering campaign. While the final phase relies on a physical courier arriving at a victim’s doorstep, the initial approach relies heavily on psychological manipulation and email, message, or phone call-based deception.
This type of fraud is notable as it follows a structured cybercriminal playbook that bypasses detection systems and takes advantage of the vulnerable in society. The victim is instructed to bypass normal banking security controls by withdrawing cash, disclosing sensitive credentials (like PINs), or purchasing high-value physical commodities like gold or luxury jewellery. This makes it difficult to proactively detect and prevent.
The other concerning factor is the couriers themselves. According to reports, they can be an unwitting third-party courier service that is paid to go to the victim's home to collect the assets. Online services enable cybercriminals to organise these pickups remotely, lowering their risk of being caught.
The £21 million sizeable loss metric from 2025 shows how profitable this low-tech, high manipulation vector remains. The recent shift to targeting gold and luxury jewellery is a deliberate evasion tactic against traditional anti-money laundering (AML) and banking fraud detection algorithms. While banks have grown adept at flagging unusual rapid bank transfers, they cannot easily stop an account holder from physically withdrawing funds or using a card over several days at different brick-and-mortar luxury retailers. This tactic serves as a highly liquid physical laundering pipeline for these syndicates that remains a challenge to prevent.
Defensive Takeaways
Implement Bank Transfer and Purchase Outlier Alerts: Financial institutions can focus on further behavioural monitoring for elderly demographics, looking specifically for sudden, consecutive high-value transactions at physical luxury retail or jewellery establishments and flag patterns on unusual activity for review.
Public Awareness on Cross-Media Scams: Security awareness campaigns must make it clear that legitimate institutions, specifically the Police and Banking Fraud teams, will never send a courier to a residential address to collect cash, PIN numbers, bank cards, or purchased items.
Vetting of Courier Logistics: Commercial courier services are increasingly being abused as infrastructure by these threat groups. Logistics firms must implement logging and analysis systems to detect unusual residential pickups booked via suspicious accounts and forged identities.
What HappenedNemesis Dark Web Drug Dealers ArrestedOn 14 May 2026, two Cambridgeshire drug dealers were sentenced after being arrested in July 2024 by the Eastern Region Special Operations Unit (ERSOU).ERSOU officers recovered Royal Mail parcel labels, order lists, Gorgonites-branded packaging, and a USB memory stick containing login credentials for multiple dark web marketplace accounts.The dealers reportedly used the dark web to supply heroin, cocaine, and amphetamine to hundreds of users acro
On 14 May 2026, two Cambridgeshire drug dealers were sentenced after being arrested in July 2024 by the Eastern Region Special Operations Unit (ERSOU).
ERSOU officers recovered Royal Mail parcel labels, order lists, Gorgonites-branded packaging, and a USB memory stick containing login credentials for multiple dark web marketplace accounts.
The dealers reportedly used the dark web to supply heroin, cocaine, and amphetamine to hundreds of users across the UK.
The drug deals were initially arranged via a Telegram channel under the handle Gorgonites, which was linked to at least 570 individual sales on Nemesis Market since September 2023.
AEGIS Dark Web Drug Market Seizure
On 17 March 2026, the London Metropolitan Police’s Cyber Crime Unit announced the seizure of AEGIS Marketplace.
In June 2025, the Met Cyber Crime Unit became aware of AEGIS Marketplace, which was a site where individual sellers could market drugs for sale to users who could make purchases using cryptocurrency.
By March 2026, the website had 30 active sellers and was estimated to have generated 10,000 drug sales in ten months, leading to an estimated annual turnover of almost £2 million.
Officers from the Met managed to infiltrate the site, retrieving server data that led to the identification of administrators, sellers and customers.
Online Killers Marketplace (OKM) Admins Arrested
On 19 January 2026, two suspects were arrested in Romania as part of an ERSOU investigation into a bogus ‘harm-for-hire’ website which offered services including murder.
The arrests were connected to a dark web scam website called Online Killers Marketplace (OKM), which purported to facilitate criminal activities including the hiring of hitmen and extortion.
ERSOU noted that even though none of the services OKM offered were genuine, successful prosecutions have previously been pursued by police forces of individuals attempting to use it to cause harm to others.
The investigation led to the seizure of US crypto currency worth at least $600,000, as well as cash which included almost €50,000 Euros, and around £48,000 worth of Romanian Leu.
Analyst Comment
The anonymity and connectivity of encrypted messaging apps, the Tor network, cryptocurrency, and online marketplaces makes it nearly impossible to prevent such crime. However, law enforcement can achieve strategic containment by targeting specific infrastructure for seizure and individuals for arrest. These activities support the overall strategy for national law enforcement agencies is to deter criminals from being active in their country.
Telegram is increasingly used as a front-end service for all sorts of cybercrime activities. As seen in the Nemesis investigation, the dealers operated a Telegram channel under the handle Gorgonites to coordinate and funnel buyers toward more secure transactions. It is an easy-to-use mobile application that makes access to such illicit services simple for buyers. It is more accessible than having to download the Tor browser and use a desktop or laptop browser. Many of these illicit services also would not exist without cryptocurrency. The ability to send funds via peer-to-peer networks and obfuscate transactions continues to be the main enabling factor for most cybercrime operations.
Interestingly, the sole administrator of Nemesis Market was sanctioned in March 2025 by the US Treasury OFAC department. The admin was an Iran-based individual named Behrouz Parsarad. Prior to its takedown by law enforcement in March 2024, Nemesis had over 30,000 active users and 1,000 vendors and facilitated the sale of nearly $30 million USD worth of drugs around the world between 2021 and 2024.
Defensive Takeaways
Blockchain Analytics:While cryptocurrency provides a layer of perceived anonymity for illicit markets it also leaves a permanent, public ledger. Law enforcement and threat intelligence firms, such as TRM Labs and Chainalysis, can leverage blockchain analytics to follow the money and deanonymise the administrators. By mapping transaction inputs and outputs, investigators can trace mixed funds, identify exchanges used to cash out into fiat currency, and map the financial infrastructure of a marketplace.
Breach Data Pivoting: To catch these cybercriminals, threat intelligence analysts can use historical breach data repositories to pivot from a known dark web alias or leaked credential to find a real-world identity. If an administrator used the same password or a variation of a username on a compromised gaming forum ten years ago, that footprint can blow their operational security (OPSEC).
Profile Scraping: Dark web vendors and market admins often leave massive digital footprints across forums, marketplaces, and messaging apps like Telegram. Continuous profile scraping can be achieve via automated bots to collect vendor profiles, feedback ratings, PGP keys, styles of writing (stylometry), and active hours. By aggregating this data over time, defenders can create a comprehensive profile of a target and identify them.
Dark Web Market Sock Puppet Accounts: Law enforcement and threat intelligence analysts can deploy sock puppets accounts, which are undercover, synthetic personas, into these dark web ecosystems. These accounts are kept for long periods of time and actively posting in an attempt to build trust within the cybercrime underground. Investigators can use them to buy products, interact with admins, and gain access to private vendor portals or escrow systems to support evidence gathering for a takedown.
Infrastructure Analysis: As dark web markets rely on servers, hosting providers, DNS, and Tor is is possible to analyse these attributes and look for configuration mistakes. This can include exposed IP addresses, trackable X509 certificates, or open port banners that reveal the true location of a hidden service. Once a server's true IP is uncovered, law enforcement can issue subpoenas to hosting providers or execute physical raids to seize the hardware and unmask administrators, vendors, and buyer databases.
What HappenedOfficers from the Dedicated Card and Payment Crime Unit (DCPCU), jointly run by the London Met Police and City of London Police, secured the conviction of a man who used an SMS Blaster device to send fraudulent text messages as part of an organised criminal operation in London.The conviction relates to an investigation that previously led to the sentencing of Ruichen Xiong in July 2025, who was apprehended while driving a vehicle in North London as the device was in operation. Duri
Officers from the Dedicated Card and Payment Crime Unit (DCPCU), jointly run by the London Met Police and City of London Police, secured the conviction of a man who used an SMS Blaster device to send fraudulent text messages as part of an organised criminal operation in London.
The conviction relates to an investigation that previously led to the sentencing of Ruichen Xiong in July 2025, who was apprehended while driving a vehicle in North London as the device was in operation. During that incident, officers in the vicinity received fraudulent text messages purporting to be from HMRC.
Ruichen Xiong was a student from China who drove around London using the SMS Blaster between 22 and 27 March 2025, sending messages to tens of thousands of potential victims.
Following Xiong’s arrest and subsequent conviction, enquiries identified another individual called Di Li who was a key organiser. Li facilitated Xiong’s involvement by arranging access to the device, assisting with obtaining a vehicle, and supporting his day-to-day living costs.
Xiong had accrued significant gambling debts after arriving in the UK as a student. To pay off his debts, Li instructed that he could repay what he owed by driving routes in a car with the SMS Blaster.
On 20 August 2025, officers searched Li’s home address, where digital evidence was recovered showing communications between Li and Xiong relating to the deployment of the SMS blaster. Li was arrested on 1 September 2025 and charged with offences linked to the operation.
At the court trial, Li’s defence was that the device was intended for “advertising” purposes and described himself as a middleman acting on behalf of an individual based in China. He maintained that he had been merely attempting to help Xiong repay his debts.
Analyst Comment
An SMS Blaster acts as a portable mobile phone mast that forces nearby mobile devices to connect to it by silently downgrading it to 2G while they try to connect to 5G or LTE. By doing so, criminals can bypass safeguards designed to block malicious senders and harmful links, enabling them to deliver fraudulent messages directly to victims nearby without needing their phone numbers. The SMS Blaster allow an operator to customise all aspects of the messages, so they can make it look like it has come from a genuine organisation like HMRC, the UK tax authority.
SMS Blasters are a relatively new technology for scammers. Police in the UK only encountered them for the first time in 2025, but they have been used in other parts of the world. SMS Blaster are also a type of IMSI catcher that mirrors the capability of law enforcement tools such as a Stingray.
When used in busy metropolitan areas, they allow criminals to easily send out SMS phishing messages to hundreds of people at a time. These SMS messages typically have a malicious link that host scam websites that trick victims into entering their personal details. These details can then used by fraudsters to make payments, steal funds, or resell it to others.
This report also highlights the concerning trend of organised cybercrime gangs from China are actively hunting for individuals who are financially vulnerable (like students with gambling debts) to conduct high-risk in-person operations.
Defensive Takeaways
Block and Report: If you receive a suspicious text message, do not engage with it. Instead, forward it to 7726, a free reporting service, and block the number.
Move Away from SMS: If your organisation relies on SMS for One-Time Passcodes (OTPs), this threat highlights that the SMS sender ID can be perfectly spoofed locally. Organisations should migrate to authenticator apps, hardware tokens, or application push notifications to avoid spoofing.
Proactive Takedown Programs: Since the attack relies on hosting malicious links to harvest credentials, defenders can perform proactive domain monitoring. Detecting and taking down lookalike domains immediately minimises the impact.
What HappenedOn 3 June 2026, the City of London Police issued a warning stating Report Fraud has seen a significant increase in cases mentioning the retailer, reflecting how criminals are targeting well-known brands.Report Fraud, which is run by the City of London Police, warned that cybercriminals are using leaked credentials from historical data breaches to hijack Argos user accounts.Once on the account, the fraudsters order and then collect the goods in-person at a physical store. In some ins
On 3 June 2026, the City of London Police issued a warning stating Report Fraud has seen a significant increase in cases mentioning the retailer, reflecting how criminals are targeting well-known brands.
Report Fraud, which is run by the City of London Police, warned that cybercriminals are using leaked credentials from historical data breaches to hijack Argos user accounts.
Once on the account, the fraudsters order and then collect the goods in-person at a physical store. In some instances, the goods are paid for using payment details not connected to the victim of the compromised account.
Notably, the goods from fraudulent orders are often claimed via Click & Collect option that Argos allows, enabling the threat actors to retrieve goods in store.
In May, Report Fraud received 652 reports which mention Argos, a 323% increase compared to April, when 154 reports mentioning the retailer were made. Since the start of 2026, there have been 1,175 reports mentioning the retailer, with May seeing the highest number to date.
This alert is also not the first raised about Argos. On 18 November 2025, the East Midlands Cyber Resilience Center issued a warning about Argos and Currys accounts getting compromised and unauthorised purchases being made. In some instances, particularly with Currys, the Buy Now Pay Later (BNPL) option was used, leaving the account holder with finance plans in their names.
Analyst Comment
For both everyday UK consumers and UK retail risk teams, these alerts provide several layered insights. Retailers have spent years optimising Click & Collect to be as frictionless as possible to compete with online shopping giants like Amazon. However, this alert shows how Click & Collect can be a security liability. As Argos allows quick collections, criminals can buy an item online and pick it up at a local store before the real account owner notices an order confirmation email.
The police alerts also note that the items may even be paid for using payment details not connected to the victim.Criminals are mixing stolen accounts with stolen credit cards. This is likely due to an established Argos account with a multi-year history buying expensive items would look pretty normal to a fraud detection engines.
The combination of an Account Takeover (ATO) and Buy Now Pay Later (BNPL) fraud creates a difficult scenario for retailers, credit providers, and consumers. The regulatory and reputational fallout for a retailer under the rules of the UK Financial Conduct Authority (FCA) could be severe. If a retailer's poor account security allows fraudsters to easily spin up a finance plan in a victim's name, the FCA will view this as a systemic failure to protect consumers, resulting in massive fines.
These attacks are possible due to the practice of Argos users who are reusing the same previously leaked password across multiple accounts, plus users not having multi-factor authentication (MFA) turned on in their account settings.
Campaigns like this can trigger a reputational hit to retailers as victims often do not suffer silently. They take to social media to share stories and the public narrative can shift to being about a retailer who is complicit in disrupting innocent people's financial lives.
Defensive Takeaways
User Account Hygiene Best Practices: Standard practices such as rotating passwords, using complex password, using a different password per service, using a password manager, using passkeys, and turning on MFA would all help mitigate this type of threat for users.
Credit Monitoring: If a user suspects their account has been compromised, they should consider using a credit monitoring service to help prevent unauthorised loans taken out in their name.
Cancel and Replace Payment Cards: If a user suspects their payment card data has been stolen, then they should contact their financial institution and have it cancelled and replaced.
Implement Click-and-Collect Controls: Retailers with click-and-click options should introduce controls such as requiring ID of the account owner or a single-use QR code or PIN via SMS/Email at the point of collection for high-value items to prevent this type of fraud.
Detecting Credential Stuff Attacks: If the cybercriminals were using credential stuffing attacks, then retailers should be able to detect unauthorised password guessing attempts against their online portals. It is recommended to use IP context analysis and perform source IP correlation. If one IP address tagged as a proxy or VPN is observed attempting to login to dozens of accounts simultaneously, then there’s an issue.
Leverage Stripe’s FT3 framework: If your organisation or team is tasked with combating fraud, then categorising these scammers TTPs is crucial. That’s why Stripe has developed the Fraud Tools, Tactics, and Techniques (FT3) framework. It’s designed to help security teams understand the landscape, spot gaps, develop detections, improve incident response, and foster collaboration.
We’ve taken one small step towards robot police officers: a drone capable of disarming a suspect:
In a June 22 video posted on the Sacramento County Sheriff’s Office’s Instagram page, an officer wearing goggles can be seen operating a drone to retrieve a knife from an armed suspect hiding inside a cluttered house. “After not responding to negotiators, a drone was deployed inside the residence,” the post says. “Drone pilots located the suspect hiding in a corner of a garage” and then used a high-
We’ve taken one small step towards robot police officers: a drone capable of disarming a suspect:
In a June 22 video posted on the Sacramento County Sheriff’s Office’s Instagram page, an officer wearing goggles can be seen operating a drone to retrieve a knife from an armed suspect hiding inside a cluttered house. “After not responding to negotiators, a drone was deployed inside the residence,” the post says. “Drone pilots located the suspect hiding in a corner of a garage” and then used a high-powered magnet attached to the drone to grab the knife out of the suspect’s hand. In the video which is soundtracked by the “Mission: Impossible” theme song—the intercepted knife can be seen spinning around in the air as the drone carries it back to the deputies.
We know that ICE wants to deploy eyeglasses with facial recognition that can identify people in real time.
Turns out Meta is prototyping the feature with a Pentagon supplier. (Alternate news story.)
What HappenedOn 5 May 2026, new data revealed that British romance scam victims were defrauded of a staggering £102 million last year, representing a 29% surge in reported cases.The figures come from information gathered by Report Fraud (f.k.a ActionFraud), which is a City of London Police-run service that logged 10,784 romance scam reports in 2025.According to the data, cybercriminals are reportedly pocketing roughly £280,000 everyday by exploiting online relationships, with individual losses
On 5 May 2026, new data revealed that British romance scam victims were defrauded of a staggering £102 million last year, representing a 29% surge in reported cases.
The figures come from information gathered by Report Fraud (f.k.a ActionFraud), which is a City of London Police-run service that logged 10,784 romance scam reports in 2025.
According to the data, cybercriminals are reportedly pocketing roughly £280,000 everyday by exploiting online relationships, with individual losses averaging £9,500 and in extreme cases, reaching up to £1 million per victim.
This wave of scam victims is part of the growing trend where scammers blend emotional manipulation with fake cryptocurrency investment schemes, heavily weaponising AI-generated profiles, and focusing on lonely victims aged 55 to 74.
Analyst Comment
When analysing fraud statistics, it is important to remember that underreporting is very common, with many victims staying silent out of shame. Therefore, this is likely only a fraction of the real figures and the problem is likely much worse than we know. The data we do have, however, still reveals there is essentially an army of digital scammers routinely bleeding UK citizens dry, using not much more than a Midjourney AI subscription, a ChatGPT script, face-swapping services, and an entirely fictitious character with an emotional backstory.
Losing £102 million in a single year to fake internet characters is a truly wild national milestone. The fact that reports surged by nearly a third (29%) proves that in our society, emotional vulnerability is being monetised at industrial scale. We aren’t just looking at a clumsy email from a Nigerian prince anymore. This is industrial-grade social engineering. Scammers are playing the long game, spending months "love-bombing" victims before dropping the inevitable bombshell that they need a quick bank transfer to cover a “medical emergency” or an unmissable cryptocurrency investment opportunity.
In March 2026, the UK Government took some action against this threat and sanctioned Xinbi, a Chinese-language cryptocurrency marketplace accused of enabling large-scale online fraud and human exploitation. Xinbi reportedly processed more than $19.9 billion in transactions between 2021 and 2025, highlighting how much money the scam industry is generating globally.
Until we treat the underground scam economy with the same significance we treat ransomware or nation state attacks, the UK will continue to be one of the world's most lucrative money spinners for heartless cybercriminals.
Defensive Takeaways
Enforce the "Face-to-Face" Financial Boundary: If you are advising family members (especially those in vulnerable demographics), establish an unshakeable, non-negotiable rule: if you have not looked a person in their physical eyeballs, you do not send them money, gift cards, or cryptocurrency.
Teach Others Digital Sanity Checks: Teach your friends and family the art of basic digital literacy. Run profile images through reverse-image search tools (Google Lens or TinEye) and consciously flag the platform migration trap. Scammers desperately want to move targets off monitored apps like Tinder or Bumble and onto unmoderated WhatsApp or Telegram channels as fast as possible to avoid automated dating app ban filters.
Learn From the Mistakes of Others: To find examples of victims falling for these scams, the UK Financial Ombudsman Service’s database of decisions can act as a useful resource. The decision details can help you understand how these scams work, how much money individuals can lose, and the rate at which UK banks offer refunds or compensation. More examples can be found in my talk on this topic here.
Leverage Stripe’s FT3 Framework: If your organisation or team is tasked with combating fraud, then categorising these scammers TTPs is crucial. That’s why Stripe has developed the Fraud Tools, Tactics, and Techniques (FT3) framework. It’s designed to help security teams understand the landscape, spot gaps, develop detections, improve incident response, and foster collaboration.
Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS) attacks over the past six months. KrebsOnSecurity publicly named the suspect in February 2026 after the accused launched a volley of DDoS, doxing and swatting campaigns against this author and a security researcher. He now faces criminal h
Canadian authorities on Wednesday arrested a 23-year-old Ottawa man on suspicion of building and operating Kimwolf, a fast spreading Internet-of-Things botnet that enslaved millions of devices for use in a series of massive distributed denial-of-service (DDoS) attacks over the past six months. KrebsOnSecurity publicly named the suspect in February 2026 after the accused launched a volley of DDoS, doxing and swatting campaigns against this author and a security researcher. He now faces criminal hacking charges in both Canada and the United States.
A criminal complaint unsealed today in an Alaska district court charges Jacob Butler, a.k.a. “Dort,” of Ottawa, Canada with operating the Kimwolf DDoS botnet. A statement from the Department of Justice says the complaint against Butler was unsealed following the defendant’s arrest in Canada by the Ontario Provincial Police pursuant to a U.S. extradition warrant. Butler is currently in Canadian custody awaiting an initial court hearing scheduled for early next week.
The government said Kimwolf targeted infected devices which were traditionally “firewalled” from the rest of the internet, such as digital photo frames and web cameras. The infected systems were then rented to other cybercriminals, or forced to participate in record-smashing DDoS attacks, as well as assaults that affected Internet address ranges for the Department of Defense. Consequently, the DoD’s Defense Criminal Investigative Service is investigating the case, with assistance from the FBI field office in Anchorage.
“KimWolf was tied to DDoS attacks which were measured at nearly 30 Terabits per second, a record in recorded DDoS attack volume,” the Justice Department statement reads. “These attacks resulted in financial losses which, for some victims, exceeded one million dollars. The KimWolf botnet is alleged to have issued over 25,000 attack commands.”
On March 19, U.S. authorities joined international law enforcement partners in seizing the technical infrastructure for Kimwolf and three other large DDoS botnets — named Aisuru, JackSkid and Mossad — that were all competing for the same pool of vulnerable devices.
On February 28, KrebsOnSecurity identified Butler as the Kimwolf botmaster after digging through his various email addresses, registrations on the cybercrime forums, and posts to public Telegram and Discord servers. However, Dort continued to threaten and harass researchers who helped track down his real-life identity and dramatically slow the spread of his botnet.
Dort claimed responsibility for at least two swatting attacks targeting the founder of Synthient, a security startup that helped to secure a widespread critical security weakness that Kimwolf was using to spread faster and more effectively than any other IoT botnet out there. Synthient was among many technology companies thanked by the Justice Department today, and Synthient’s founder Ben Brundage told KrebsOnSecurity he’s relieved Butler is in custody.
“Hopefully this will end the harassment,” Brundage said.
An excerpt from the criminal complaint against Butler, detailing how he ordered a swatting attack against Ben Brundage, the founder of the security firm Synthient.
The government says investigators connected Butler to the administration of the KimWolf botnet through IP address, online account information, transaction records, and online messaging application records obtained through the issuance of legal process. The criminal complaint against Butler (PDF) shows he did little to separate his real-life and cybercriminal identities (something we demonstrated in our February unmasking of Dort).
In April, the Justice Department joined authorities across Europe in seizing domain names tied to nearly four-dozen DDoS-for-hire services, although because of a bureaucratic mix-up the list of seized domains has remain sealed until today. The DOJ said at least one of those services collaborated with Butler’s Kimwolf botnet.
A statement from the Ontario Provincial Police said a search warrant was executed on March 19 at Butler’s address in Ottawa, where they seized multiple devices. As a result of that investigation, Butler was arrested and charged this week with unauthorized user of computer; possession of device to obtain unauthorized use of computer system or to commit mischief; and mischief in relation to computer data. He is scheduled to remain in custody until a hearing on May 26.
In the United States, Butler is facing one count of aiding and abetting computer intrusion. If extradited, tried and convicted in a U.S. court, Butler could face up to 10 years in prison, although that maximum sentence would likely be heavily tempered by considerations in the U.S. Sentencing Guidelines, which make allowances for mitigating factors such as youth, lack of criminal history and level of cooperation with investigators.
Bellingcat has identified at least 80 police stations or infrastructure related to law enforcement agencies and the Basij paramilitary group that has been damaged or destroyed in the first three weeks of the United States and Israel’s war against Iran. Experts told Bellingcat that both countries aim to degrade the Iranian regime’s “repressive capacity”.
Combined, the US and Israel have conducted thousands of strikes during the course of the 2026 war in Iran. Targets range from Islamic Revolut
Bellingcat has identified at least 80 police stations or infrastructure related to law enforcement agencies and the Basij paramilitary group that has been damaged or destroyed in the first three weeks of the United States and Israel’s war against Iran. Experts told Bellingcat that bothcountries aim to degrade the Iranian regime’s “repressive capacity”.
Combined, the US and Israel have conductedthousands of strikes during the course of the 2026 war in Iran. Targets range from Islamic Revolutionary Guard Corps (IRGC) sites, Navy vessels to Iranian weapons manufacturers.
In early March, a Bellingcat analysis using satellite imagery and available photos and videos identified police stations as another apparent target, with at least 15 damaged or destroyed in the capital, Tehran.
We also identified multiple strikes against police infrastructure in the country’s north and west; these areas were targeted by the Israel Defence Forces according to a map released by the IDF on March 31.
“We are providing the brave people of Iran with the conditions to take their destiny into their own hands,” declared the Israeli Ministry of Foreign Affairs official X account, along with a photo of a destroyed police station.
اینجا کلانتری ۱۲۱ سلیمانیه در خیابان نبرد تهران بود.
ما شرایطی را برای مردم شجاع ایران فراهم میکنیم تا سرنوشت خود را در دست بگیرند. pic.twitter.com/VSm6YVvIwZ
In all, the majority of strikes Bellingcat analysed focused on police stations (30 incidents) and command centers or headquarters (29 incidents). Locations also include sites related to Basij, a plainclothes paramilitary organisation (9) affiliated with the IRGC that were “involved in the deadly crackdown” of protests in January 2026, others are associated with special forces (3) and traffic (2) or diplomatic (2) police compounds.
Due to commercial satellite companies limiting access to imagery over Iran and neighbouring countries we relied on Sentinel-2 imagery data to help verify the incidents, as well as videos and photos, some of which were also verified by independent geolocators and contributors to the Geoconfirmed volunteer community and confirmed by Bellingcat researchers.
Location data was partly determined using open source mapping data either from Wikimapia, OpenStreetMap or Google Maps. When video footage or photos were available for incidents reportedly targeting police stations, the location was verified with geolocation and satellite imagery analysis using either Planet Labs medium resolution PlanetScope data (restricted to imagery collected by March 9) or low resolution Sentinel-2 data.
Some locations were discovered utilising location data taken from OpenStreetMap using Overpass Turbo and comparing that with available Sentinel-2 data throughout Iran.
Map showing geolocated incidents in Iran. Click the markers to view the coordinates, sources, and verification notes. Map: Bellingcat/Miguel Ramalho
A Problem of Scale
Israel has released multiplevideos showing the targeting of bases and checkpoints belonging to the Basij. In mid-March, the IDF announced the killing of the paramilitary group’s commander, Gholamreza Soleimani.
Targeting the Basij is part of Israel’s and the US’ agenda “to degrade the regime’s repressive capacity,” Ali Vaez, the director of International Crisis Group Iran Project, told Bellingcat. Police stations are “not involved in repression in the way that crowd control police or Basij centers are”, so targeting them “appears more aimed at preventing the Islamic Republic from being able to maintain control internally,” he said.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
Vaez told Bellingcat that, when considered alongside the broader range of targets, including industrial factories, the widespread targeting of police stations is part of a strategy “to make Iran ungovernable for the existing regime or whatever comes after”.
Vaez was skeptical about the short term effects: “It’s a problem of scale. Iran is such a large country, even if you are able to completely destroy, not just degrade, the capacity of the regime in policing, oppressing, etc – it really requires not just maybe weeks but maybe months if not years.”
The Risk of Civilian Casualties
As of April 7, the Iranian Human Rights Activists News Agency estimates there’ve been more than 1,700 civilian fatalities during the war.
Several police stations are situated in densely populated urban areas such as Tehran. Stations are used by civilians for various reasons including renewing driving licences, so if these buildings are targeted “during working hours and not in the middle of the night then risk is higher for these people,” Vaez said.
Map showing geolocated incidents in Tehran. Click the markers to view the coordinates, sources, and verification notes.Map: Bellingcat/Miguel Ramalho
A recent joint Airwars, Center for Civilians in Conflict and Human Rights Activists in Iran report detailing the first month of civilian casualties included a section on the worsening situation for detainees in Iranian prisons — including police stations that have been targeted.
“I was detained in the holding cell of [Police Station 148] for ten days, along with four other activists. Now it looks like nothing is left of that station but ruins. I can’t even recognize where the detention area was. I keep wondering what happened to the people who were being held there during the attack. – Activist, told HRA upon seeing photos of the police station after recent US/Israeli airstrikes.”
Footage shared and geolocated by the BBC’s Shayan Sardarizadeh showed Police Station 148 damaged after an apparent strike in mid-March.
The main building of Tehran’s 148 police station and its courtyard, located on Enghelab Street, has been severely damaged in air strikes conducted on Friday.
The adjacent Hamoon Theatre also sustained some damage.
One destroyed police station identified by Bellingcat in the city of Mahabad in northwestern Iran led to apparent damage to an Iranian Red Crescent Society building located next door. According to Iran’s Tasnim News agency (an IRGC-affiliated media outlet sanctioned by the EU, the US and Canada), one Red Crescent employee was injured in the attack.
The police station adjacent to the Red Crescent building isn’t identified on any mapping services, though there are reports “Police Station 11” was targeted the same day.
Annotated Google Earth image showing the location of a destroyed police station and partially destroyed Red Crescent building in Mahabad, West Azerbaijan Province, Iran. A video shared on Telegram by mamlekate on March 6 shows the view of the destruction from the ground. Buildings behind the destroyed police station match with those seen in the Google Earth imagery.
Israel has also targeted checkpoints operated by Basij members.
Bellingcat examined two cases showing Israeli strikes on checkpoints while civilians were passing. In one video, a strike hits a checkpoint as five motorbikes and a vehicle go by.
View of a Basij checkpoint in Tehran targeted by the IDF. Immediately before the explosion is visible in the video, there are five motorbikes and a car next to the checkpoint. Source: YouTube/IDF
In another IDF video, a yellow bus is immediately adjacent to the checkpoint when it is hit. It is unclear how many people were on the bus at the time of the strike or if anyone was injured.
View of a Basij checkpoint in Tehran targeted by the IDF. Immediately before the explosion, there is a yellow bus visible next to the targeted checkpoint. Source: IDF
“I have been watching the reporting on these Basij strikes and the use of the Mikholit in particular in open urban areas. It is IDF standard—using precision munitions and even sometimes “low collateral” munitions but in a reckless manner that still puts the civilian population at risk,” Wes J. Bryant, a defence and national security analyst formerly with the Pentagon’s Civilian Protection Center of Excellence told Bellingcat.
Questions Over Legality
International Humanitarian Lawdefines civilians as “persons who are not members of the armed forces”. Police officers fall under that definition, according to Adil Haque, Professor of Law at Rutgers University and Executive Editor at Just Security. “As a rule, police are civilians and may not be attacked unless they take a direct part in hostilities,” Haque told Bellingcat. National security analyst Bryant agreed, adding that targeting police “does not stand up to legal scrutiny”.
Subscribe to the Bellingcat newsletter
Subscribe to our newsletter for first access to our published content and events that our staff and contributors are involved with, including interviews and training workshops.
In an email to Bellingcat, the IDF noted “that the police form part of Iran’s internal security apparatus, which also forms part of Iran’s armed forces, under Iran’s own domestic legislation. In every strike, the IDF takes feasible precautions in order to mitigate incidental harm to civilians and civilian objects to the extent possible under the circumstances.”
Police are indeed “part of the country’s armed forces. By that logic, anything with a flag on it is a legitimate target,” Ali Vaez, the director of International Crisis Group Iran Project, said.
Although Basij is a paramilitary group, any strikes against it would require precautions to minimise harm to civilians, Haque told Bellingcat. “Since the hostilities almost entirely involve aerial bombardment, the concrete and direct military advantage anticipated from strikes on Basij members who qualify as combatants is extremely low, so significant harm to nearby civilians would be disproportionate and illegal,” he said.
When asked about potential civilian casualties in the checkpoint strikes, the IDF told Bellingcat that since the Basij are subordinate to the IRGC and are therefore part of the armed forces, they are regarded as lawful military targets. Regarding the checkpoint strikes specifically, they stated “precision munitions and surveillance means were used in the strikes, as part of the precautions taken under the circumstances to mitigate expected incidental harm”.
Bellingcat reached out to US Central Command (CENTCOM) to ask if the US had any role in the police station strikes identified but received no official comment at the time of publication.
Miguel Ramalho and Felix Matteo Lommerse contributed to this report.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
According to a new law, the Hong Kong police can demand that you reveal the encryption keys protecting your computer, phone, hard drives, etc.—even if you are just transiting the airport.
In a security alert dated March 26, the U.S. Consulate General said that, on March 23, 2026, Hong Kong authorities changed the rules governing enforcement of the National Security Law. Under the revised framework, police can require individuals to provide passwords or other assistance to access personal electro
According to a new law, the Hong Kong police can demand that you reveal the encryption keys protecting your computer, phone, hard drives, etc.—even if you are just transiting the airport.
In a security alert dated March 26, the U.S. Consulate General said that, on March 23, 2026, Hong Kong authorities changed the rules governing enforcement of the National Security Law. Under the revised framework, police can require individuals to provide passwords or other assistance to access personal electronic devices, including cellphones and laptops.
The consulate warned that refusal to comply is now a criminal offense. It also said authorities have expanded powers to take and keep personal electronic devices as evidence if they claim the devices are linked to national security offenses.
An elusive hacker who went by the handle “UNKN” and ran the early Russian ransomware groups GandCrab and REvil now has a name and a face. Authorities in Germany say 31-year-old Russian Daniil Maksimovich Shchukin headed both cybercrime gangs and helped carry out at least 130 acts of computer sabotage and extortion against victims across the country between 2019 and 2021.
Shchukin was named as UNKN (a.k.a. UNKNOWN) in an advisory published by the German Federal Criminal Police (the “Bundeskrimina
An elusive hacker who went by the handle “UNKN” and ran the early Russian ransomware groups GandCrab and REvil now has a name and a face. Authorities in Germany say 31-year-old Russian Daniil Maksimovich Shchukin headed both cybercrime gangs and helped carry out at least 130 acts of computer sabotage and extortion against victims across the country between 2019 and 2021.
Shchukin was named as UNKN (a.k.a. UNKNOWN) in an advisory published by the German Federal Criminal Police (the “Bundeskriminalamt” or BKA for short). The BKA said Shchukin and another Russian — 43-year-old Anatoly Sergeevitsch Kravchuk — extorted nearly $2 million euros across two dozen cyberattacks that caused more than 35 million euros in total economic damage.
Daniil Maksimovich SHCHUKIN, a.k.a. UNKN, and Anatoly Sergeevitsch Karvchuk, alleged leaders of the GandCrab and REvil ransomware groups.
Germany’s BKA said Shchukin acted as the head of one of the largest worldwide operating ransomware groups GandCrab and REvil, which pioneered the practice of double extortion — charging victims once for a key needed to unlock hacked systems, and a separate payment in exchange for a promise not to publish stolen data.
Shchukin’s name appeared in a Feb. 2023 filing (PDF) from the U.S. Justice Department seeking the seizure of various cryptocurrency accounts associated with proceeds from the REvil ransomware gang’s activities. The government said the digital wallet tied to Shchukin contained more than $317,000 in ill-gotten cryptocurrency.
The GandCrab ransomware affiliate program first surfaced in January 2018, and paid enterprising hackers huge shares of the profits just for hacking into user accounts at major corporations. The GandCrab team would then try to expand that access, often siphoning vast amounts of sensitive and internal documents in the process. The malware’s curators shipped five major revisions to the GandCrab code, each corresponding with sneaky new features and bug fixes aimed at thwarting the efforts of computer security firms to stymie the spread of the malware.
On May 31, 2019, the GandCrab team announced the group was shutting down after extorting more than $2 billion from victims. “We are a living proof that you can do evil and get off scot-free,” GandCrab’s farewell address famously quipped. “We have proved that one can make a lifetime of money in one year. We have proved that you can become number one by general admission, not in your own conceit.”
The REvil ransomware affiliate program materialized around the same as GandCrab’s demise, fronted by a user named UNKNOWN who announced on a Russian cybercrime forum that he’d deposited $1 million in the forum’s escrow to show he meant business. By this time, many cybersecurity experts had concluded REvil was little more than a reorganization of GandCrab.
UNKNOWN also gave an interview to Dmitry Smilyanets, a former malicious hacker hired by Recorded Future, wherein UNKNOWN described a rags-to-riches tale unencumbered by ethics and morals.
“As a child, I scrounged through the trash heaps and smoked cigarette butts,” UNKNOWN told Recorded Future. “I walked 10 km one way to the school. I wore the same clothes for six months. In my youth, in a communal apartment, I didn’t eat for two or even three days. Now I am a millionaire.”
As described in The Ransomware Hunting Team by Renee Dudley and Daniel Golden, UNKNOWN and REvil reinvested significant earnings into improving their success and mirroring practices of legitimate businesses. The authors wrote:
“Just as a real-world manufacturer might hire other companies to handle logistics or web design, ransomware developers increasingly outsourced tasks beyond their purview, focusing instead on improving the quality of their ransomware. The higher quality ransomware—which, in many cases, the Hunting Team could not break—resulted in more and higher pay-outs from victims. The monumental payments enabled gangs to reinvest in their enterprises. They hired more specialists, and their success accelerated.”
“Criminals raced to join the booming ransomware economy. Underworld ancillary service providers sprouted or pivoted from other criminal work to meet developers’ demand for customized support. Partnering with gangs like GandCrab, ‘cryptor’ providers ensured ransomware could not be detected by standard anti-malware scanners. ‘Initial access brokerages’ specialized in stealing credentials and finding vulnerabilities in target networks, selling that access to ransomware operators and affiliates. Bitcoin “tumblers” offered discounts to gangs that used them as a preferred vendor for laundering ransom payments. Some contractors were open to working with any gang, while others entered exclusive partnerships.”
REvil would evolve into a feared “big-game-hunting” machine capable of extracting hefty extortion payments from victims, largely going after organizations with more than $100 million in annual revenues and fat new cyber insurance policies that were known to pay out.
Over the July 4, 2021 weekend in the United States, REvil hacked into and extorted Kaseya, a company that handled IT operations for more than 1,500 businesses, nonprofits and government agencies. The FBI would later announce they’d infiltrated the ransomware group’s servers prior to the Kaseya hack but couldn’t tip their hand at the time. REvil never recovered from that core compromise, or from the FBI’s release of a free decryption key for REvil victims who couldn’t or didn’t pay.
Shchukin is from Krasnodar, Russia and is thought to reside there, the BKA said.
“Based on the investigations so far, it is assumed that the wanted person is abroad, presumably in Russia,” the BKA advised. “Travel behaviour cannot be ruled out.”
There is little that connects Shchukin to UNKNOWN’s various accounts on the Russian crime forums. But a review of the Russian crime forums indexed by the cyber intelligence firm Intel 471 shows there is plenty connecting Shchukin to a hacker identity called “Ger0in” who operated large botnets and sold “installs” — allowing other cybercriminals to rapidly deploy malware of their choice to thousands of PCs in one go. However, Ger0in was only active between 2010 and 2011, well before UNKNOWN’s appearance as the REvil front man.
A review of the mugshots released by the BKA at the image comparison site Pimeyes found a match on this birthday celebration from 2023, which features a young man named Daniel wearing the same fancy watch as in the BKA photos.
Images from Daniil Shchukin’s birthday party celebration in Krasnodar in 2023.
Update, April 6, 12:06 p.m. ET: A reader forwarded this English-dubbed audio recording from a ccc.de (37C3) conference talk in Germany from 2023 that previously outed Shchukin as the REvil leader (Shchuckin is mentioned at around 24:25).
This investigation is part of a collaboration between Bellingcat, Evident Media and CalMatters. You can watch Evident’s investigative video here, and read CalMatters’ report here.
In early January 2025, a gardener named Ernesto Campos was pulled over by Border Patrol agents in the city of Bakersfield, California.
The agents were a long way from home: Bakersfield is over 240 miles (386km) from the US border with Mexico.
They were there as part of Operation Return to Sender, a Border Pa
This investigation is part of a collaboration between Bellingcat, Evident Media and CalMatters. You can watch Evident’s investigative video here, and read CalMatters’ report here.
In early January 2025, a gardener named Ernesto Campos was pulled over by Border Patrol agents in the city of Bakersfield, California.
The agents were a long way from home: Bakersfield is over 240 miles (386km) from the US border with Mexico.
They were there as part of Operation Return to Sender, a Border Patrol surge in the city that acted as a portent of what was to come across the US in 2025.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
Video footage shows one agent threatening to break Campos’ car window as they believed he was transporting an undocumented individual.
Campos filmed the agents, who he said slashed his tyres before arresting him and a passenger. The agents’ faces later appeared on local news reports detailing the incident.
Ten months later, two of the agents visible in footage recorded by Campos were filmed in Chicago as Border Patrol agents descended on the city for what was dubbed “Operation Midway Blitz”.
An image from court documents shows a Border Patrol agent unholstering his gun at an incident in Evanston, Illinois.
A federal judge in Illinois said in November that the use of force by federal agents in Chicago – including the use of tear gas and other less lethal munitions on multiple occasions – “shocks the conscience”.
A restraining order issued by that Illinois judge was vacated on appeal earlier this month. But what took place on the streets of Chicago also happened in other locations, with some of the same agents involved.
Bellingcat has worked with our partners at Evident Media and CalMatters to analyse over 85 hours of social media and bodycam footage, as well as court documents and incident reports, to try to unpack the actions of Border Patrol agents across the country.
With agents often masked and badge or identification numbers not always visible, understanding exactly who has enforced the immigration surges of the past year has been difficult. This, in turn, has made public questioning and accountability around use-of-force incidents challenging.
Subscribe to the Bellingcat newsletter
Subscribe to our newsletter for first access to our published content and events that our staff and contributors are involved with, including interviews and training workshops.
Nonetheless, we observed over 25 agents who appeared in more than one city, either by recognising their faces or matching badge numbers that were visible on their vests or arm patches. Many were seen alongside former Border Patrol Commander at Large, Gregory Bovino, on at least one occasion.
But this is likely just a fraction of the agents who moved around the country to take part in Border Patrol surges in cities like Los Angeles, Chicago and Minneapolis. When speaking to reporters in January, Border Czar Tom Homan said he had spoken to some agents who had “been in theatre for eight months”. Many wore masks in the videos viewed by Bellingcat, and it was not always possible to identify number patches from social media or bodycam footage alone.
Although some of the agents we logged appeared on neighbourhood walkabouts or in footage where little happened, others could be seen using force on multiple occasions. For this story, we have focused on the actions of five agents whom we have been able to identify and who appear to have repeatedly used force in at least two, but often more, locations. We have decided to name those we have been able to identify just as we would name any officer involved in incidents like those detailed. But these were by no means the only agents whom we saw using force across one or multiple cities.
The footage we analysed also appears to show a steady escalation of violence and confrontational incidents as 2025 progressed, culminating in widespread use-of-force incidents in Chicago and Minneapolis, where two people, Renee Good and Alex Pretti, were killed by Immigration and Customs Enforcement (ICE) and Border Patrol agents, respectively, in early 2026.
Agents on the Move
While former Border Patrol Commander at Large Gregory Bovino is no longer in a national role, some of the agents observed and documented for this report appear to have travelled from his El Centro sector over the past year.
These included agent Timothy Donahue and Georgy Simeon, who were filmed by Ernesto Campos in Bakersfield. Donahue was the agent who was subsequently pictured pointing his gun at citizens just outside Chicago after a traffic incident (Donahue stated in his incident report that his car was rammed by an activist – something also described in Illinois federal judge Sara Ellis’ opinion – although Donahue’s report made no mention of punching a man in the face or unholstering his weapon). It was Simeon, meanwhile, who was filmed slamming a man to the ground after grabbing him by the throat.
Donahue was also spotted in social media footage in Los Angeles in June last year pushing a citizen who was blocking his vehicle, as well as grabbing a man on an immigration raid inside a car wash.
The Chicago publication, Unraveled Press, previously reported that Donahue was the owner of a social media account that made seemingly racist and sexist posts. Bellingcat and others have checked this account and found that an old profile picture showed an image of Donahue. Bodycam footage from outside a detention centre near Chicago also showed Donahue tackle a journalist from Unraveled without apparent warning.
Footage from Donahue’s own bodycam on Oct. 3 also appears to show him compiling an incident report with ChatGPT. The possibility of CBP agents using ChatGPT to compile incident reports was addressed by Judge Ellis in her ruling issuing a restraining order in November. She wrote that using ChatGPT to write reports “undermines their credibility and may explain the inaccuracy of some reports filed by CBP officers”.
The evidence doesn’t enable us to determine if Donahue used ChatGPT to compile the Oct. 31 incident report in which he did not mention he punched a man and unholstered his gun.
Bodycam footage released with court documents shows a Border Patrol agent using ChatGPT to compile an incident report.
Our reporting partners CalMatters emailed and called Donahue prior to publication. The email received no response. Donahue answered his cellphone but said, “never, ever call my cellphone again,” and hung up.
Simeon did not respond to emailed questions prior to publication, and calls to a number listed under his name went unanswered.
The Department of Homeland Security (DHS) did not respond to questions posed about the actions of Donahue and Simeon detailed in this report or the agency’s use-of-force policies. They also did not respond to questions about whether it was permissible for agents to use generative AI platforms like ChatGPT to compile incident reports.
While the actions of Donahue and Simeon made news reports in various cities, the pair were far from alone in having their actions filmed and documented across the country.
Kristopher Hewson, a supervisory agent based out of Bovino’s El Centro sector, was seen on bodycam footage in Chicago spraying an individual who was being held down by agents with what he detailed in his incident report as oleoresin capsicum (OC), also known as pepper spray, from what appears to be just a few inches away. The individual was on the ground and had one hand behind his back, but agents could be heard asking for his other hand during the incident. Hewson said in his incident report (see here and here) that the individual had been resisting arrest, but he also stated that he deployed the pepper spray from two feet away. Bodycam footage (see below) showed the canister beside the individual’s head right after a burst of spray can be heard.
Bodycam footage shows an individual being held down before pepper spray is released while he remains on the ground. Annotations after 15 seconds made by Bellingcat.
Hewson, who wore a mask but was identifiable in several videos by the C-29 ID number on his uniform, was later spotted in Minneapolis. He also said his name during one incident that allowed us to find other bodycam footage releases that belonged to him. In one video, his mask slipped, which allowed us to compare his face to images on his social media accounts.
Court testimony revealed that he was present in Los Angeles during a Border Patrol surge in the city in the summer of 2025. He was also seen alongside Bovino on numerous occasions, including in Chicago, where Bovino can be heard greeting him by saying, “Hey, Hewson”, in one video captured by the filmmaker Jeff Perlman.
In bodycam footage from Chicago a man can be heard saying that the person Hewson pepper-sprayed was his son, who was just 15 years old. This appears to be backed up by an incident report showing the individual’s date of birth. A short time later, Hewson can be heard shouting “get back or you will be gassed” at a group of protesters immediately before deploying tear gas towards them. As he throws the canister, a person can be heard shouting, “You’re not de-escalating shit, bro”. Hewson stated in his incident report (see here and here) that he gave a warning that CS gas was coming, but he did not detail how that warning was virtually instantaneous.
All of these actions came two weeks after a judge issued a temporary restraining order on Oct. 9, preventing agents from using chemical agents on protesters and journalists unless there was an imminent threat of physical danger to federal forces. While that order was lifted in March 2026, it was still in force during the incidents detailed in this story.
Hewson was seen in Minneapolis in early 2026 alongside Bovino. He was captured on footage marching towards and tackling a Target employee, a teenage US citizen, who was directing insults at agents. A melee ensued at the front door of the Target store before two people were handcuffed and taken away by agents. Hewson’s C-29 number was visible as he led one of the men away. Both of those arrested were later released.
Hewson was questioned as part of a preliminary injunction hearing in Chicago, where, among other things, he stated (pages 183 and 184) that protesters have the right to shout and even swear at officers as long as they aren’t impeding their ability to carry out their work. He also said during questioning that tear gas “doesn’t harm people” (page 189). Multiple individuals who were impacted by the release of gas and chemical irritants in Chicago stated otherwise in incidents detailed in Judge Ellis’ ruling.
When reached on the phone by CalMatters, Hewson said he could not comment. DHS did not respond to questions posed about the actions of Hewson detailed in this report or the agency’s use-of-force policies.
El Paso Agents
Hewson was present and visible in footage when ex-Border Patrol Commander at Large Bovino appeared to push and manhandle a protester who crossed his path on Nicollet Avenue in Minneapolis.
Also beside Bovino and Hewson that day were two officers based out of El Paso bearing the ID numbers EZ-2 and EZ-17. Both of these agents are seen wearing vests of the Border Patrol Tactical Division (BORTAC), a specialised unit that, according to the CBP, has a selection process “designed to mirror aspects of the US Special Operations Forces’ selection courses”.
Bellingcat and Evident Media previously reported how EZ-17 fired less lethal munitions at protesters from close range a day after Renee Good was shot and killed by an Immigration and Customs Enforcement (ICE) officer in Minneapolis.
EZ-17 was accompanied during that incident by EZ-2, who could be seen spraying a chemical irritant in the face of a man who appeared to have thrown a snowball at him. EZ-2 was also seen throwing two female protesters to the ground outside Roosevelt High School in Minneapolis on Jan. 7.
Both EZ-17 and EZ-2 were present in Chicago. EZ-17 was seen passing a tear gas canister to Bovino at an incident in the city’s Little Village neighbourhood on Oct. 23.
The Chicago publication, Unraveled, previously identified EZ-17 as Edgar Vazquez and EZ-2 as Michael Sveum. Bellingcat was able to corroborate these identifications using similar techniques. Firstly, for Vazquez we compared images on his Facebook page with footage from EZ-2’s bodycam, which showed Vazquez inside a vehicle without a mask.
Ernesto Vazquez photo taken from Facebook (left) and image taken from bodycam footage in Chicago (right). Source: CBP via Loevy.com
EZ-2 was identified in a similar manner. Bodycam footage from EZ-2 showed him looking at his phone. On the lockscreen was a picture of a man smiling and wearing a blue jacket. That same picture was posted on Sveum’s social media accounts and appeared to have been taken at an ultramarathon event whose organisers posted Sveum’s name alongside that same image.
Bodycam footage (left) shows a lockscreen with a picture of a man that matches images seen on archived posts from the social media accounts of Michael Sveum.
When reached by phone by CalMatters reporters, Vazquez said that he could not comment. Sveum hung up immediately after CalMatters’ reporter introduced himself. DHS did not respond to questions posed about the actions of Vazquez or Sveum detailed in this report or the agency’s use-of-force policies.
Dozens of other incidents where agents appeared to escalate rather than de-escalate situations, as well as use force or less lethal munitions, were logged as part of this investigation. This included agents pointing guns at protesters (see here and here) as well as using violent force and less lethal munitions on protesters, journalists and bystanders.
Bovino himself appeared to instigate confrontations with people, such as in Chicago, when he can be seen throwing a man to the ground before agents pounce on him, although he stated during his Illinois deposition that he did not think such actions represented a use-of-force incident.
The former Border Patrol Commander at Large told CalMatters that he could not speak to the media without DHS approval prior to publication of this story. Requests sent to DHS to speak with Bovino went unanswered.
‘Unusual and Beyond the Pale’
According to John Roth, a former DHS Inspector General, and Steve Burnell, a former DHS General Counsel, the events of the past year, involving masked agents descending on select cities, have eroded trust and credibility in DHS and law enforcement.
While both agreed that there had to be professional immigration enforcement operations, they said that has to be done in a way that is responsible and ensures accountability when lines are crossed.
“This is sort of a scary Orwellian thing”, Roth said. “I don’t think the public understands how unusual and beyond the pale it is to have these roving sort of groups of masked agents, out there handling the public.”
Burnell said that the inability to identify agents carrying out their work as enforcement officers was a particular concern: “At the end of the day, ICE and everybody at DHS are public servants. They’re supposed to be working for the public. And, you know, if somebody is working for you, you should have a right to know who they are, and you should have a right to hold them accountable and protest what they’re doing.”
Roth and Burnell both served under President Barack Obama and during President Donald Trump’s first term. The pair have testified to Congress in recent months, raising the alarm about what they see as a dismantling of accountability at DHS. Prominent members of the US government, including President Trump, have offered repeated support to Border Patrol agents, even after the death of protesters such as Renee Good.
Our partners at Evident and CalMatters showed Roth and Burnell some of the footage described in this report. While they refrained from commenting on individual incidents, Roth described the footage generally as “difficult to watch”.
“The question I’d ask. Have [agents] inserted themselves into something that requires them to use force,” said Roth. “In which case that would be a violation of DHS policy,” he added, referring to use-of-force policies that detail how law enforcement officers may use force when no “reasonably, safe and feasible alternative appears to exist”.
“It’s actually DHS policy that you [are required] to attempt to de-escalate when that’s possible. I mean, they don’t have a duty to retreat, but they do have a duty not to insert themselves into a place where use of force is necessary,” Roth said.
Burnell described a lot of what has happened over the past year as a type of “dominance display”.
“It’s there to send a message. And that is not de-escalatory. It’s the opposite,” he said.
Bellingcat, CalMatters and Evident Media jointly sought to contact DHS as well as all of the agents mentioned in this story prior to publication.
We asked DHS whether any of the incidents detailed in this report violated DHS use-of-force policies or whether those policies had been updated under the current administration.
We also asked if DHS was taking any action or providing further training to agents to ensure the public’s constitutional rights are respected during immigration enforcement operations carried out by Border Patrol.
DHS did not respond before publication.
Youri van der Weide, Kolina Koltai and Eoghan Macguire from Bellingcat, as well as Sergio Olmos from CalMatters and Kevin Clancy from Evident Media, contributed reporting to this piece.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
To stay up to date on our latest investigations, join Bellingcat’s WhatsApp channel here.
Federal agents have frequently used so-called “less-lethal” weapons against protesters, including impact projectiles, tear gas and pepper spray, since the Trump administration’s nationwide immigration raids began last year.
The use of less-lethal weapons (LLWs) has been controversial. While designed to incapacitate or control a person without causing death or permanent injury, they can cause serious
To stay up to date on our latest investigations, join Bellingcat’s WhatsApp channel here.
Federal agents have frequently used so-called “less-lethal” weapons against protesters, including impact projectiles, tear gas and pepper spray, since the Trump administration’s nationwide immigration raids began last year.
Earlier this month, two protesters in California were reportedly blinded after US federal agents fired less-lethal rounds at their faces from close range. These incidents were part of a wave of violent clashes between agents from the Department of Homeland Security (DHS) and protesters across the country after the deadly shooting of US citizen Renee Good by an Immigration and Customs Enforcement (ICE) agent in Minneapolis.
Federal agents armed with less-lethal weapons in Minneapolis on Friday, Jan. 9, 2026. Source: Cristina Matuozzi/Sipa USA via Reuters Connect
In protests in Minneapolis immediately following Good’s death, one Customs and Border Patrol (CBP) officer was captured on camera firing a 40mm less-lethal launcher five times in less than five minutes, with several of these shots appearing to target protesters’ faces, which is against CBP’s own use-of-force policy.
A Bellingcat investigation of DHS incidents in October 2025 also found about 30 incidents that appeared to violate a temporary restraining order (TRO) issued by an Illinois judge restricting how DHS agents could use LLWs.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
It is not always obvious whether the use of a LLW is authorised or not, as DHS component agencies such as ICE and CBP have varying guidance on factors such as the level of resistance an individual needs to show before a certain type of force can be used, as well as how specific types of less-lethal weapons and munitions can be used.
While CBP’s use-of-force policy as of January 2021 is available on its website, ICE does not include specific guidance on less-lethal weapons in its 2023 “Firearms and Use of Force” Directive, and does not appear to have any publicly available policy that outlines this guidance.
DHS did not respond by publication time to Bellingcat’s request for the most recent DHS, CBP and ICE use-of-force policies, or to questions about what less-lethal weapons were authorised for use by the department and its component agencies.
The DHS use-of-force policy, updated in February 2023, states that the department’s law enforcement officers and agents may use force, including LLWs, “only when no reasonably effective, safe and feasible alternative appears to exist”. It also says agents may only use a level of force that is “objectively reasonable in light of the facts and circumstances” that they face at the time.
DHS has repeatedlydefended its use of riot-control weapons in protests across the country, stating that it was “taking reasonable and constitutional measures to uphold the rule of law and protect [its] officers”.
Here’s how to identify some of the less-lethal weapons that DHS agents, including those from ICE and CBP, have been seen using during recent immigration operations.
Compressed Air Launchers or ‘PepperBall Guns’
Left: A Border Patrol Agent in Chicago carrying an orange TAC-SF series PepperBall gun in Illinois on Oct. 24, 2025. Right: Agent aiming a Pepperball gun at someone filming them in Illinois on Oct. 19, 2025. Source: Youtube / @BlockClubChicago and Tiktok / @ericcervantes25
Compressed air, or pneumatic launchers, are essentially paintball guns that fire 0.68mm balls which break on impact. Often, this releases a powdered chemical irritant such as oleoresin capsicum (OC) or PavaPowder – the same compounds typically found in pepper spray.
Compressed air launchers can also be used with other projectiles, such as “marking” projectiles that use paint to mark an individual for later arrest, and projectiles intended to break glass.
These weapons are often referred to as “PepperBall” guns, named after the leading brand PepperBall. However, DHS agents have also been seen carrying compressed air launchers from different brands, such as the FN303, produced by FN America.
Many compressed air launchers resemble standard paintball guns, with a distinct hopper or loader, which holds the ball projectiles, mounted to the top. They also have a compressed air tank that might be mounted to the side, bottom, or inside the buttstock (or back) of the weapon.
Many compressed air launchers, and less-lethal weapons in general, have very bright colours such as orange to distinguish them from lethal weapons.
The TAC-SF PepperBall gun features a compressed air tank and a top-mounted EL-2 hopper, which has a distinctive shape. Graphic: Justin Baird for Bellingcat
The PepperBall TAC-SA Pro’s hopper is a slightly different shape from the TAC-SF, but serves the same purpose. Graphic: Justin Baird for Bellingcat
PepperBall VKS Pro features a compressed air tank located inside the buttstock and a magazine rather than a top-mounted hopper. Graphic: Justin Baird for Bellingcat
However, some compressed air launchers require closer scrutiny to distinguish them from firearms.
For example, federal agents have been seen carrying FN303 compressed air launchers in videos of immigration enforcement activities. This weapon may resemble a rifle or other firearm, as it is usually all-black and, unlike the TAC-SF series PepperBall guns, lacks a visible hopper.
Left: Agent holding an FN303 in California on June 11, 2025. Right: Federal Agent aiming a FN303 compressed air launcher at someone filming them in Illinois on Oct. 7, 2025. Source: TikTok / @anthony.depice and TikTok / @krisvvec
If closer examination is possible, this weapon can be identified by its distinct features, including a circular magazine, side-mounted compressed air tank and a hose connecting the firearm to the air tank.
The FN303’s air tank is mounted on the side and connected to the firearm by a hose. Graphic: Justin Baird for Bellingcat
The January 2021 CBP Use of Force Policy places several restrictions on the use of compressed air launchers, including that they should not be used against small children, the elderly, visibly pregnant women, or people operating a vehicle. It also states that PepperBall guns should not be used within 3 feet “unless the use of deadly force is reasonable and necessary”. When using the FN303, the minimum distance is increased to 10 feet.
The CBP Use of Force Policy says that the intentional targeting of areas where there is a “substantial risk of serious bodily injury or death is considered a use of deadly force.” Agents are instructed not to target “the head, neck, spine, or groin of the intended subject, unless the use of deadly force is reasonable”. PepperBall and FN America provide similar warnings about avoiding vital areas to prevent serious injury or death.
According to a 2021 report by the US Office of Inspector General, CBP requires its agents to recertify their training to use PepperBall guns and FN303s every year, but ICE does not.
40mm Launchers
Left: CBP agent “EZ-17” with a B&T GL06 40mm launcher and a belt with a variety of Defense Technology 40mm less lethal munitions, including one Direct Impact OC round and two Direct Impact CS rounds in Illinois on Oct. 24, 2025. Centre: EZ-17 firing a B&T GL06 launcher at a man in Minneapolis on Jan. 7, 2026. Right: A federal agent with a B&T GL06 in Illinois on Oct. 24, 2025. Source: YouTube / Block Club Chicago, X / Dymanh, Facebook / Draco Nesquik
DHS agents also use 40mm launchers to fire “Less-Lethal Specialist Impact and Chemical Munitions (LLSI-CM)”. These launchers resemble military grenade launchers, but are used to fire less-lethal ammunition, including “sponge” rounds that can disperse chemical irritants on impact.
The B&T GL06 (pictured) and other 40mm launchers have a visibly wider barrel than compressed air launchers or standard firearms. Graphic: Justin Baird for Bellingcat
There are various less-lethal munitions available for 40mm launchers, including those whose primary function is “pain compliance” through the force of impact, chemical irritants or a combination of both.
Videos of clashes between Border Patrol agents and protesters show these launchers being used with combination rounds designed to hit the target for pain compliance while also delivering a chemical irritant such as OC or CS.
Direct Impact munitions by Defense Technology have distinctive rounded sponge foam noses and colours that indicate their chemical fill. Graphic: Justin Baird for Bellingcat
Other munitions dispense chemical irritants or smoke after being launched. For example, in the protests immediately following Good’s death, a Border Patrol agent was seen firing a 40mm munition that released multiple projectiles emitting chemical irritants in a single shot, consistent with the “SKAT Shell” by Defense Technology.
The SKAT Shell by Defense Technology (left) fires multiple projectiles, while the company’s SPEDE-Heat shell launches a single projectile. Graphic: Justin Baird for Bellingcat
Defense Technology’s technical specifications for its 40mm Direct Impact Rounds, which agents have been seen armed with, state that the munitions are considered less-lethal when fired at a minimum safe range of 5 feet and at the large muscle groups of the buttocks, thigh and knees, which “provide sufficient pain stimulus, while greatly reducing serious or life-threatening injuries”.
A DHS Office of Inspector General Report in 2021 noted varying guidance on the use of 40mm launchers among the department’s component agencies: “ICE’s use of force policy indicates that the 40MM launcher is deadly force when fired at someone, while the CBP use of force policy only directs officers not to target a person’s head or neck.”
CBP’s 2021 use-of-force policy states that agents should “not intentionally target the head, neck, groin, spine, or female breast”, and that anyone in custody who has been subject to such munitions should be seen by a medical professional “as soon as practicable”.
As of publication, DHS had not replied to Bellingcat’s questions about whether the department had an internal policy or provided training to staff on the minimum safe distance for 40mm less-lethal launchers as recommended by the manufacturers.
Hand-Thrown Munitions
Top Left: Border Patrol Commander of Operations At Large Greg Bovino with two Triple-Chaser CS Grenades on his vest in Minneapolis on Jan. 8, 2026. Top Right: Person holding a used Pocket Tactical Green Smoke grenade in Minneapolis, Jan. 21, 2026. Bottom Left: Top third of a Triple-Chaser Grenade in Illinois, Oct. 25, 2025. Bottom Right: Used Riot Control CS Grenade in Minneapolis, Jan. 23, 2026. Source: Nick Sortor, Rollofthedice, Bluesky / Unraveled Press, Andrew Hazzard
DHS agents have also been seen throwing some less-lethal munitions, such as flash-bangs, smoke and “tear gas” grenades or canisters by hand.
These munitions activate a short delay after the grenade is employed. When they activate, flash-bangs or “stun” grenades emit a bright flash of light and a loud sound that is designed to disorient targets. Both smoke grenades and tear gas (also known as “CS gas” or “OC gas”) emit thick smoke, but the former just impedes visibility, whereas the latter also contains chemical irritants that sting the eyes.
The shape and general construction, colour, and any text can help identify these munitions.
Less-lethal munitions typically feature the manufacturer’s logo, the model name of the munition, and the model or part number. The text and manufacturer logo are typically colour-coded to indicate the type of payload the munition has, with blue indicating CS, orange indicating OC, yellow indicating smoke, green indicating a marking composition and black indicating munitions with no chemical payload.
The “Triple-Chaser” grenade by Defense Technology (left) has three distinct segments that separate after the grenade is thrown, with each emitting smoke or chemical irritants, while other chemical grenades by the same company have a single smooth body (right). Graphic: Justin Baird for Bellingcat
A 2021 analysis by Bellingcat and Newsy found that Defense Technology and Combined Tactical Systems, the two manufacturers which produce most of the less-lethal munitions used by federal agents, both list the model numbers of their products online. Publicly available price lists for Defense Technology and Combined Tactical Systems can also be used to identify specific munitions by their model numbers.
CBP’s 2021 use-of-force policy states that hand-thrown munitions are subject to the same restrictions for use as munition launcher-fired impact and chemical munitions.
Chemical Irritant Sprays
Left: DHS agent using a chemical irritant spray on a protester in Minneapolis on Nov. 25, 2025. Centre: CBP Agent spraying Alex Pretti with what appears to be OC spray moments before he is killed in Minneapolis on Jan. 24, 2026. Right: Federal Agent with a SABRE MK-9 spray threatening to spray a journalist if they do not move back in Minneapolis on Dec. 11, 2025. Source: Reddit / I_May_Have_Weed, TikTok/ShitboxHyundai, Instagram / Status Coup
DHS agents have also been using handheld chemical irritant sprays, often colloquially referred to as “pepper spray” or “mace”.
These sprays come in a variety of sizes and concentrations containing CS, OC, or both. Sprays used by law enforcement usually have a canister size designated “MK-” followed by a number, with higher numbers indicating larger canister sizes. The concentration of chemical irritants contained in the spray is also indicated on the canister.
The .2% MK-9 OC Spray by Defense Technology (left). The MK-9 produced by various companies with various concentrations has been seen often used by federal agents on protestors (right). Graphic: Justin Baird for Bellingcat
The effectiveness of OC sprays is determined by the concentration of major capsaicinoids, which are the active compounds in OC that cause irritation. These sprays are also affected by the type of aerosol dispersion, or stream, used. Different types of streams increase or decrease the range of the spray as well as the coverage area.
Civilian and law enforcement sprays range from 0.18 percent to 1.33 percent major capsaicinoids, according to SABRE, a producer of law enforcement and civilian sprays. Civilian sprays in the US can have the same major capsaicinoid content as law enforcement sprays, but are restricted to smaller-sized canisters.
Subscribe to the Bellingcat newsletter
Subscribe to our newsletter for first access to our published content and events that our staff and contributors are involved with, including interviews and training workshops.
Defense Technology sprays have different colour bands to indicate the percentage of major capsaicinoids in the spray for OC. If the spray is CS, the CS concentration is standardised at 2 percent. The company uses a white band for .2 percent, yellow band for .4 percent, orange band for .7 percent, red band for 1.3 percent and a grey band for sprays containing either CS or a combination of OC and CS.
SABRE sells a variety of concentrations and sprays as law enforcement products, including 0.33 percent, 0.67 percent, and 1.33 percent major capsaicinoid concentrations of OC, as well as CS, and combination CS and OC sprays. The specific concentrations of SABRE sprays and the type of stream can also be identified by the text on the canister.
One Air Force Research Laboratory study found that some sprays may pose a significant risk of severe eye damage due to pressure injuries resulting from large aerosol droplets hitting the eye.
Defense Technology’s technical specifications recommend a minimum distance of between 3 and 6 feet, depending on the specific spray. SABRE does not publicly provide their minimum safe deployment distances, but a Mesa Police Department document lists a minimum distance of six feet for the SABRE Red MK-9. CBP’s 2021 use-of-force policy does not provide any minimum use distances.
CBP’s 2021 use-of-force policy states that OC Spray may only be used on individuals offering “active resistance”, and that it should not be used on “small children; visibly pregnant; and operators of motor vehicles”.
Electronic Control Weapons
Left: Federal Agent pointing an Axon Taser 10 at a bystander who was filming an arrest in Los Angeles in June 2025. Right: DHS Agent with an Axon Taser 10 during an arrest in California on June 24, 2025. Source: Instagram / @dianaluespeciales, Instagram / Joe Knows Ventura
ECWs can deliver a shock upon direct contact or launch probes that embed in the targeted person, incapacitating them.
A shock on contact, or a “drive-stun” feature, delivers localised pain while in direct contact. When properly deployed, the probes send signals to the body that cause muscles to contract. A person’s body “locking up” from muscle contractions is an indicator that an ECW has been deployed. ECWs may be capable of using either or both methods. ECWs are typically painted a combination of black and bright yellow, but this varies between models. The bright colour of parts of tasers is a common feature to help distinguish an ECW from handguns used by federal agents. When viewed from the front, a circular gun barrel is visible on handguns, while ECWs feature multiple circular probes or rectangular covers on the cartridge. ECWs also usually have flashlights and lasers, although handguns may also be equipped with these features. Some ECWs may make audible sounds when armed or deployed.
The Axon TASER 10. Graphic: Justin Baird for Bellingcat
Axon, the predominant manufacturer of ECWs, produces several models including the TASER 10 and TASER 7. Axon provides a policy guide on recommended use of its TASER models to law enforcement agencies, which recommends targeting below the neck from behind, or the lower torso from the front. It recommends avoiding sensitive areas including the head, face, throat, chest and groin.
Axon also recommends against using ECWs against small children, the elderly, pregnant people, very thin people and individuals in positions of increased risks such as running, operating a motor vehicle, or in an elevated position “unless the situation justifies an increased risk”.
CBP’s 2021 use-of-force policy, in addition to restricting the use of ECWs against small children, the elderly, visibly pregnant women, and people operating a vehicle, states that they should not be used against someone who is running or handcuffed. However, the policy does state that there may be an exception to the rule against using ECWs on a running person if an agent has a “reasonable belief that the subject presents an imminent threat of injury” to an agent or another person. This threat, according to the policy, must “outweigh the risk of injury to the subject that might occur as a result of an uncontrolled fall while the subject is running”.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here and Mastodon here.
This investigation is part of a collaboration between Bellingcat and Evident Media. You can watch Evident’s video here.
The fatal shooting of Renee Nicole Good by Immigration and Customs Enforcement (ICE) agent Jonathan Ross in Minneapolis on Jan. 7 sparked nationwide protests, with often violent clashes breaking out between protesters and federal agents. Some of the most intense protests took place in Minneapolis itself, with an agent using a less-lethal launcher in ways that experts told B
This investigation is part of a collaboration between Bellingcat and Evident Media. You can watch Evident’s video here.
The fatal shooting of Renee Nicole Good by Immigration and Customs Enforcement (ICE) agent Jonathan Ross in Minneapolis on Jan. 7 sparked nationwide protests, with often violent clashes breaking out between protesters and federal agents. Some of the most intense protests took place in Minneapolis itself, with an agent using a less-lethal launcher in ways that experts told Bellingcat were “punitive” and “questionable at best”.
This agent, an elite Border Patrol officer who was masked but identifiable through the uniform number patch EZ-17, was captured on camera firing his B&T GL06 40mm less-lethal launcher at protesters five times in five minutes as he travelled down a street adjacent to where Good was killed.
EZ-17 on the streets of Minneapolis on Jan. 8. Source: Michael Nigro/Sipa USA via Reuters Connect
While “less-lethal” weapons are not designed to kill, they can still result in serious injuries and even death when misused. In California, a protester said he was permanently blinded in one eye after he was shot with a less-lethal weapon at a protest on Jan. 13. Footage shows a DHS officer firing a PepperBall gun at his face at close range, causing him to bleed.
Last year, a judge in Illinois ordered an injunction limiting federal agents’ use of force in the state due to what she described as aggressive use of force against peaceful protesters that “shocks the conscience”. However, Bellingcat found multiple examples of force and riot control weapons being used during immigration raids and in apparent violation of that order in the weeks immediately after.
Experts told Bellingcat that most of the less-lethal shots fired by EZ-17 after arriving at the site of Good’s shooting with Border Patrol Commander Gregory Bovino on Jan. 7, also appear to breach CBP’s use-of-force policy.
Bellingcat analysed videos from news outlets and social media and mapped out all five shots the agent fired.
Five shots EZ-17 fired in five minutes near the location of Good’s shooting, numbered by the order they occurred with approximate locations. The general path of travel of EZ-17 and the location of where Renee Good was shot and killed is marked. Sources: Status Coup News, Dymanh and Google Earth. Graphic: Evident Media / Jennifer Smart
Four of these shots appeared to be aimed directly at protesters’ faces at close range, while a fifth was fired from a distance towards a crowd after tear gas had already been deployed. A sixth shot, captured at another location on the same day, also shows EZ-17 firing a shot from the same launcher at someone at head-level.
As of publication, DHS had not responded to Bellingcat’s requests for comment.
The Agent
In footage captured by independent news outlet Mercado Media, EZ-17 is seen inside the crime scene tape perimeter, standing near Bovino, with eight 40mm munitions on his belt.
EZ-17 with eight visible munitions on his belt, including a 40mm CS “Muzzle Blast” (red box), and three sponge-nosed direct impact munitions (blue box) approximately 30 minutes before he fires his first shot. Annotations by Bellingcat. Source: Mercado Media @ 36:28Annotations by Bellingcat
These included three sponge-nose impact rounds, which are designed for “pain compliance” through the direct force of impact, and five cylindrical munitions that can be filled with different payloads and chemical irritants. “BLAST” in blue text is visible on one munition, indicating a “Muzzle Blast” munition with a CS gas fill – commonly known as tear gas. At least three additional 40mm munitions are visible in his plate carrier.
Another video by independent news network Status Coup News showed uninterrupted footage capturing five shots from the time the agent exited the crime scene perimeter (at 5:02) shortly before firing the first shot, to when he left in a truck with other agents (9:23) immediately after firing the fifth shot.
The back of EZ-17’s vest shows that he belongs to CBP’s Border Patrol Tactical Unit (BORTAC). BORTAC is a specialised and highly trained unit that, according to the CBP, has a selection process “designed to mirror aspects of the US Special Operations Forces’ selection courses”.
The patch on the back of EZ-17’s vest (centre) shows that he belongs to BORTAC. Source: Status Coup News
Members of BORTAC have regularly accompanied Bovino as he leads Trump’s immigration raids, including EZ-17 and EZ-2, another CBP agent that was frequently seen beside EZ-17 in the footage from Jan. 7. Both agents have continued to accompany Bovino on raids in Minnesota in subsequent days.
Five shots EZ-17 fired in five minutes near the location of Good’s shooting, numbered by the order they occurred. Sources: Status Coup News and Dymanh
First Shot
In the Status Coup Media video, EZ-17, and three other CBP agents, including EZ-2, can be seen leaving the crime scene tape perimeter set up after Good’s death, pushing protesters who are physically blocking them. Snowballs are thrown at the CBP agents.
EZ-17’s belt is visible after he and EZ-2 push a man who was physically blocking them to the ground, seconds before EZ-17 fires his first shot, at 5:15. Source: Status Coup News
EZ-17 initially aims at the man he had pushed to the ground, but then turns and aims at the face of another nearby protester who did not appear to be involved in any previous physical contact with the agents. As EZ-17 aims at the face of this protester, the man raises his arms to shield himself before EZ-17 fires.
EZ-17 fires his first shot, at 5:19. Source: Status Coup News.Blurring by Bellingcat
The large cloud of chemical irritant appears to disperse from the barrel immediately on firing for this shot as well as the next three shots EZ-17 fires.
This is consistent with the “Muzzle Blast” 40mm munitions produced by Defense Technology, which were seen in images of the agent’s belt. Defense Technology says in its product specifications for 40mm “Muzzle Blast” munitions that these rounds provide “instantaneous emission” of a chemical agent in the immediate area (30 feet) of the person shooting them.
Second Shot
Seconds later, after EZ-17 is hit by a snowball, he turns and fires towards the face of a man who is filming in the direction the snowball came from. It is unclear if this man is the intended target or someone else in the crowd behind him.
EZ-17 firing the second shot. This shot can be heard and partially seen at 5:37 in the Status Coup News video. Left: Screenshot before firing. Centre and Right: Screenshots taken after firing. Source: Dymanh/TikTok at 0:22
Third Shot
The third shot is at a man who was seen on video throwing a snowball that hits EZ-2.
Man throwing snowballs at CBP agents after the second shot. Source: Mercado Media; annotation by Bellingcat
Vexor exclusively produces various types of OC spray, and does not list any chemical irritant sprays that do not contain OC on its website.
Top: EZ-2 visibly deploys at least two streams of OC spray at the man. Bottom: EZ-2 is seen leaving the crime scene tape perimeter earlier with a “Vexor Professional” branded canister. Vexor manufactures various OC spray products. Source: Status Coup News. Annotations by Bellingcat
The man slowly walks closer to the agents, saying that he has been maced. EZ-17 pushes the man, then aims at the man’s face and fires.
The seals that keep the chemical irritant inside the 40mm canister before it is fired can be seen hitting the man in this shot, with the smoke surrounding his face.
Seals from the 40mm Muzzle Blast munition. Source: Dymanh Chhoun. Annotations by Bellingcat
Fourth Shot
After the third shot, an unmarked white CBP truck turns off the street and tries to drive down an alley. Protestors begin physically blocking the vehicle, throwing snowballs and other objects at it. The windshield gets cracked, and the back window gets broken. EZ-17 and EZ-2 physically push the protesters blocking the truck out of the way, with EZ-2 also deploying what appears to be a canister of OC spray.
EZ-17 is seen firing his fourth shot at a person who was banging on the truck windows at 9:02. Source: Status Coup News
University of St. Thomas School of Law professor Rachel Moran, who reviewed the videos at Bellingcat’s request, said that of the six shots we identified as being fired by EZ-17 this one appeared to be “the most reasonably related to carrying out the duty of helping the vehicle evacuate” as the person targeted was “still pounding aggressively” on the vehicle when EZ-17 fired the shot.
Fifth Shot
After EZ-17’s fourth shot, EZ-2 deploys a tear gas grenade, and the CBP truck moves down the alley, away from protesters.
EZ-2 deploying a tear gas grenade at 9:09. Source: Status Coup News
EZ-17 can be seen reloading next to EZ-2, who is holding a canister that appears to be OC spray, and another CBP agent holding a PepperBall gun.
EZ-17 (in red box) reloading the 40mm launcher at 9:18. Source: Status Coup News. Annotations by Bellingcat
The CBP agent with the PepperBall gun appears to cross over to the other side of the truck, and EZ-2 appears to begin to enter the vehicle.
CBP agent with PepperBall gun (yellow box) walking to the opposite side of the truck, EZ-2 standing in front of EZ-17 (red box) at 9:20. Source: Status Coup News. Annotations by Bellingcat
As soon as the back right door on the truck closes, gas from the muzzle can be seen from where EZ-17 was standing.
Visible gas exiting the muzzle at 9:22. Source: Status Coup News
This fifth shot appears to be “skip-fired” or aimed towards the ground before ricocheting upwards, at close range, resulting in three visible projectiles going towards the crowd of people, narrowly missing some.
Although the footage is blurry with the tear gas from the grenade EZ-2 threw still clouding the air, EZ-17 appears to be the only agent who could have fired this: EZ-2 was not armed with a projectile launcher, and PepperBall guns like the one carried by the other CBP agent do not have munitions that release multiple projectiles with a single shot.
Three different projectiles visible after the muzzle gas, at 9:22. Source: Status Coup News
Chemical irritant smoke was seen being released by the projectiles from this last shot as it travelled through the air.
One projectile visibly emits chemical irritants as it travels through the air, at 9:23. Source: Status Coup News
The multiple projectiles are consistent with the 40mm “SKAT Shell” by Defense Technology, which ejects four separate submunitions upon firing, each dispensing chemical irritants. In one of the videos, a SKAT Shell is seen in EZ-17’s belt.
EZ-17’s belt before firing the second shot, with a visible SKAT-SHELL SAF-SMOKE to the right of the direct impact munitions on his belt. Source: Dymanh/TikTok at 0:21
This video showed EZ-17 again firing his B&T GL06, apparently towards someone’s head, this time someone who threw a snowball at a CBP agent.
EZ-17 after firing his B&T GL06 launcher at a high school student’s face. Source: Matthew Moore/Facebook
‘Punitive and Unlawful’
Patrick Wilcken, Amnesty International’s Researcher on Military, Security and Policing issues, said that while the overall situation shown in the videos was tense, with “verbal abuse, some shoving/throwing of snowballs and the attempted obstruction of a vehicle”, there did not seem to be any substantial physical threat to the agents that would have justified the use of less-lethal weapons.
Wilcken, who reviewed the videos of all six shots fired by EZ-17 at Bellingcat’s request, said the actions of agents shown in these videos – pursuing fleeing protesters and in some instances firing at protesters who appeared to be trying to protect themselves – were “punitive and unlawful”.
CBP’s use-of-force policy states that weapons such as 40mm launchers are only authorised for use against subjects offering “active” or “assaultive” resistance. Similarly, DHS’ use-of-force policy guidance says agents may use force “only when no reasonably effective, safe and feasible alternative appears to exist”, and may only use the level of force “objectively reasonable in light of the facts and circumstances” that they face at the time force is applied.
“Officers should only resort to less lethal weapons when faced by a serious physical violence posing a threat to themselves or others that is not possible to diffuse in any other way,” Wilcken said. “They must exercise force with restraint, to the minimum extent possible while respecting and enabling the right to peaceful assembly.”
University of St. Thomas School of Law professor Rachel Moran agreed that whether the use of less-lethal weapons is justified largely depends on the level of threat or aggression the agent faces from the person targeted. Although she said the fourth shot could be justified in helping the CBP vehicle evacuate, Moran said the justification for the other shots was “questionable at best” based on the footage.
For example, Moran noted that although the man in the third shot had thrown a snowball at another officer, any threat had dissipated by the time EZ-17 shot him because the man had already run away and clearly had his hands up with nothing in them. “The shot appears to be more retaliatory than defensive”, she said.
Similarly, for the incident at Roosevelt High School, Moran noted that EZ-17 did not appear to be in any danger from the snowball, as the person who threw it was already retreating before the agent fired.
Moran said that if EZ-17 was carrying a B&T GL06 40mm launcher, he did appear to violate CBP policy by directly aiming at people’s faces.
The weapon used by EZ-17 is visible as he points it towards a protester. Source: Status Coup News. Blurring by Bellingcat
CBP’s use-of-force policy states that agents using munitions launchers, including 40mm launchers “shall not intentionally target the head, neck, groin, spine, or female breast”. However, Bellingcat’s analysis of the six shots fired by EZ-17 showed that he appeared to be aiming at the head of targets in five of these cases.
Travis Norton, a retired police lieutenant and use-of-force consultant, told Bellingcat that standard training and manufacturer guidance for 40mm launchers recommended aiming at “large muscle groups of the lower body” while avoiding “prohibited target areas” like the head, neck, chest, spine and groin. This helps to reduce the risk of significant injury, Norton said.
Norton said that 40mm launchers are not intended for random or area fire: “Their use is limited to clearly identified individuals who are engaging in violent or dangerous behaviour and cannot be safely addressed by other means.”
Although he declined to comment on specific incidents based solely on video footage, Norton said that skip-firing – which was used in the fifth shot identified by Bellingcat, and the only shot where a person did not appear to be targeted at head-level – was generally not a standard or recommended practice in most law-enforcement training programs.
“Because ground conditions, angles, and projectile behaviour are unpredictable, skip-firing reduces accuracy and control and increases the risk of unintended injury,” Norton said.
Pooja Chaudhuri contributed research to this piece.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here and Mastodon here.
To stay up to date on our latest investigations, join Bellingcat’s WhatsApp channel here
On Jan. 7 Renee Good, a 37-year-old mother of three, was shot and killed by a federal agent on Portland Avenue in Minneapolis, Minnesota. The incident was captured on several separate videos and spread rapidly on social media. The videos were soon accompanied by competing analysis and narratives as to what had happened.
Bellingcat looked at five videos filmed during the incident, including one apparent
To stay up to date on our latest investigations, join Bellingcat’s WhatsApp channel here
On Jan. 7 Renee Good, a 37-year-old mother of three, was shot and killed by a federal agent on Portland Avenue in Minneapolis, Minnesota. The incident was captured on several separate videos and spread rapidly on social media. The videos were soon accompanied by competing analysis and narratives as to what had happened.
Bellingcat looked at five videos filmed during the incident, including one apparently from the phone of Jonathan Ross, the ICE agent who shot and killed Good.
While each video alone provides valuable information, the five together provide a fuller picture of the situation as it unfolded.
Synced Overview
One of the ways to visualise the full incident was by tracking the movements of the key players on an overview map, which Bellingcat did shortly after the incident on Jan. 7.
Using eyewitness video shared by Daniel Suitor on Bluesky we tracked the movements of federal agents at the scene – including Ross as he moved around the street. The video also captured the position and movements of Good’s vehicle before, during and after the shots were fired.
We’ve also updated our animated map of the positions of agents and vehicles during the incident here with new footage published by @cnn.com that shows the shooter closer to a white SUV prior to the shootingbsky.app/profile/bell…
Another video, filmed by a bystander and later shared by the Minnesota Reformer, shows a closer view of Ross’ movements in the moments immediately before the shooting.
In the video, Ross can be seen with his phone in his left hand filming Good before he pulls his gun out of its holster with his right hand. Roughly one second elapses before he fires the first round through Good’s front window. Two more shots follow.
A still from that same video captures Ross as he walks past in the seconds after the shooting. A camera app appears open on his phone.
A still image in a video published by the Minnesota Reformer. A video app can be seen open in the federal agent’s phone.
Agent’s Phone
On Jan. 9, a video filmed by Ross was published on X by a conservative news outlet called Alpha News.
By syncing this video up with the other four available videos, it was possible to observe more of what occurred, including from Ross’ rough perspective. However, it is important to note that Ross was holding the phone slightly away from his body, so what appears in the video would be marginally different to what would have been his line of sight.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
In the footage, Good can be seen backing up before veering to the right as Ross and the camera move to her left. It is not clear from this footage exactly how close the car came to Ross, as the cellphone points up and away as the vehicle moves forward. Someone can be heard saying “whoa” before gunshots are heard.
An angle captured from down the street (middle lower right in the synchronised video below and in full view here) – which some have suggested shows Ross being hit by the vehicle – does appear to show the vehicle pass close to the agent as he fires. However, the close-up video shared by the Minnesota Reformer (middle top and in full view here) shows Ross moving out of the way and to the side of the vehicle as he fires.
Another video published by CNN (middle lower left) shows a head-on view of the incident from surveillance footage.
New footage from the ICE agent’s phone who shot at Renee Nicole Good in Minneapolis has emerged, posted by AlphaNews on X. We’ve placed that footage in a synced timeline with the other currently available footage.
Almost one week after the incident, protests have been held in Minneapolis and other cities in the US.
US President, Donald Trump, and Department of Homeland Security, Kristi Noem, initially said that Good had tried to run over an ICE officer after blocking the road, labelling her a “domestic terrorist”. However, the Democratic mayor of Minneapolis, Jacob Frey, said that version of events was “garbage” and disproven by the video footage.
On Monday Jan. 12, Noem, told FOX News that more ICE agents would be sent to Minnesota.
Individual links to each of the five videos detailed above can be found here, here, here, here and here.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here and Mastodon here.