Sign up here to receive Bellingcat’s biggest investigations by email as soon as they are published.
A sanctioned vessel that was previously reported to have transported weapons destined for Russian mercenaries has been traversing ports on the west coast of Africa since March, exhibiting what experts told Bellingcat was an unusual set of movements and behaviours.
Patria (IMO: 9159921) has been sanctioned by the US, Ukraine and Canada.
Support Bellingcat
Your donations directly co
Sign up here to receive Bellingcat’s biggest investigations by emailas soon as they are published.
A sanctioned vessel that was previously reported to have transported weapons destined for Russian mercenaries has been traversing ports on the west coast of Africa since March, exhibiting what experts told Bellingcat was an unusual set of movements and behaviours.
Patria (IMO: 9159921) has been sanctioned by the US, Ukraine and Canada.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
Radio France International (RFI) reported last year that it was one of two ships to deliver weapons to Conakry in Guinea that were intended for the Kremlin-controlled Africa Corps and their operations in Mali.
Satellite imagery and Automated Identification System (AIS) data from Lloyd’s List Intelligence shows Patria has shuttled between the Port of Douala in Cameroon and the Port of Owendo in Libreville, Gabon four times since March.
It has also twice stopped in anchorage off the coast of Lagos, Nigeria: first in March and then again at the time of publication. Analysis shows the vessel also spent time in anchorage off the coast of Equatorial Guinea.
The online news site, Modern Ghana, first reported Patria’s presence off the coast of Lagos in July after X-users @SONNAROW_OSINT and @RFNOSBlog picked up on Patria’s position.
It is not clear what Patria has delivered or picked up at these ports. Nor is it clear why it has spent so long going back and forth between them. But experts Bellingcat spoke to said the unusual patterns of behaviour raised numerous questions.
Charlie Brown, a former US Naval Officer and Senior Advisor at United Against Nuclear Iran said the combination of Patria’s repeated regional port calls, extended periods at anchor, and an apparent absence of a normal point-to-point trading cycle warranted scrutiny, especially as the ship is under sanction and is previously reported to have shipped arms.
Tracking the Patria
Patria is a cargo vessel that has a distinct shape and features. Its bridge is located on the bow and it has a bright red deck that contrasts with its blue hull and two yellow cranes.
At the end of the deck, the ship has a built-in ramp for vehicles (the Patria is a so-called roll on/roll off, or RoRo, vessel that is designed to transport wheeled vehicles). Its chimney is located next to the ramp.
Footage of the Patria, posted on Youtube on Jan 22, 2024. Credit: Hanro Shipping – Sakhalin Projects LLC / YouTube Channel @hanroship
This, in combination with the length of the ship (101 m), allowed Bellingcat to pick the vessel out in satellite imagery. AIS data helped us further track its long journey which began in the Sea of Japan, in Russia’s far-east, in January.
For the most part, we were able to match Patria’s AIS position with corresponding satellite imagery. We found no evidence of obvious spoofing incidents (where a ship intentionally broadcasts misleading AIS data) by the vessel during its months-long voyage, however, there were some instances where satellite images were not available and thus spoofing by the vessel cannot be completely ruled out.
AIS data indicates that Patria loaded at the Port of Olga in the Sea of Japan between Jan. 21 and 23. Patria can also be seen on satellite imagery on these dates.
AIS data indicates that Patria unloaded some cargo in the Port of Douala between Mar. 11 and 12. Again, the ship can also be seen in satellite imagery on these dates.
AIS data indicates Patria anchored off the coast of Lagos from Mar. 14 to 15.
A Sentinel-2 image from the 15th appears to show another ship next to Patria. AIS data indicates that this is JS Gratitude, a bunkering tanker. This close proximity suggests that Patria was refuelling.
AIS data and satellite imagery indicate Patria stayed at the Douala Anchorage from Apr. 6 to 14, before unloading at the Port of Douala between Apr. 14 and 18.
AIS data suggests Patria loaded in Libreville again between Apr. 22 and 26.
Port of Douala, Cameroon
AIS data, supported by satellite imagery, indicates Patria stayed at the Douala Anchorage for nearly a month from Apr. 27 to May 21 before unloading in Douala from May 21 to 27.
A third trip between the Port of Owendo, Libreville to Douala, Cameroon
AIS data indicates, after nearly a month’s wait in Douala anchorage, Patria again loaded at Owendo before returning to Douala to unload.
A fourth trip between the Port of Owendo, Libreville to Douala, Cameroon
AIS data indicates Patria again loaded at Owendo before returning to Douala to unload.
Lagos Anchorage, Nigeria
AIS data indicates, after a short visit to the Libreville anchorage, Patria anchored off the coast of Lagos where it remained at the time of publication.
We reviewed the draught of the ship at each port visit and found that the ship’s draught always dropped after a stay at the Port of Douala, suggesting it was unloading there.
A ship’s “draught” is the distance from the bottom of the hull (the keel) to the waterline. When loaded, a ship is heavier and sits lower in the water (e.g. a draught of six metres) than when it is unloaded (e.g. a draught of four metres).
Draught is the depth of a ship below the waterline.
In the period from March to July, the Patria made five port calls to Douala and each time the draught decreased. Conversely, it called four times at the Port of Owendo in Libreville, each time the draught increased, meaning the ship became heavier, suggesting it was loading.
The draught is self-reported by ships but usually when it arrives at ports this kind of data is checked – reporting accurate draught is also a safety issue for ships arriving and departing at ports.
Bellingcat asked the ship’s owners, managers and both ports if items were being transferred from Libreville to Douala but did not receive a response at time of publication.
Brown, the former US Naval Officer and now a Senior Advisor at United Against Nuclear Iran, said Patria’s movements were unusual.
“A sanctioned vessel linked to a prior military logistics shipment spending nearly six months operating between a small cluster of West African ports, Douala, and Owendo, without returning to a clear commercial trading pattern warrants scrutiny,” Brown told us.
“While innocent explanations such as mechanical issues, commercial disputes, lack of cargo, chartering delays, or prolonged maintenance are possible, the combination of repeated regional port calls, extended periods at anchor, and an apparent absence of a normal point-to-point trading cycle is atypical for a merchant vessel.”
He added that the current period of more than 30 days at the Lagos Anchorage, in particular, is noteworthy.
David Soud, Head of Research and Analysis at I.R Consilium also told Bellingcat that Patria’s prolonged Lagos Anchorage could have innocent explanations such as its need for ongoing repairs, or that its operators were out of money, but added that there could also be more calculated reasons and it was laying low for a while.
Bellingcat analysed AIS data from Lagos Anchorage and found that while there has been high congestion, no other RoRo or container vessel waited longer than 10 days to enter the port in the period that Patria has been at Lagos Anchorage. At time of writing, Patria has been in anchorage for more than 30 days.
Regarding the Patria’s apparent deliveries of cargo between Libreville in Gabon, and Douala in Cameroon, Soud told Bellingcat:
“Given the vessel’s history of transporting military equipment to African seaports for overland delivery to Russian and allied forces in the Sahel, it’s not out of the question that some form of supplies for Russian or other forces could be picked up in Gabon, whose government has developed a closer relationship with Moscow, to be discharged in Douala, which is the main entry point for goods going to Central African Republic.”
Bellingcat asked the Nigerian Ports Authority why Patria had been in anchorage for so long, whether it had applied to dock and whether the port was aware of its sanctioned status but did not receive a response at time of publication.
The ports of Douala in Cameroon and Owendo in Libreville, Gabon did not respond to Bellingcat’s requests for comment about the Patria’s visits and the cargo it was carrying.
Bellingcat also contacted the two companies connected to the vessel – Hanro Shipping and Sakhalin Shipping Company which are listed as the vessel’s owner and manager respectively in sanctions documents. We also contacted the company connected to JS Gratitude. We did not receive a response at time of publication.
Youri van der Weide, Galen Reich, Yörük Işık contributed to this report.
Cover image: Planet Lab image shows the Patria at the Port of Douala, Cameroon, on April 17, 2026. Credit: Planet Labs PBC.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
This investigation is a collaboration between Bellingcat and New Zealand news site The Press. You can read The Press’ piece here.
Content warning: This article discusses non-consensual sexually explicit content and child sexual abuse material.
In 2024, a former track and field coach in Boston, Massachusetts, was sentenced to five years in jail for attempting to trick and extort more than 100 women, including student-athletes he coached, into sending him intimate photos.
According to t
This investigation is a collaboration between Bellingcat and New Zealand news site The Press. You can read The Press’ piece here.
Content warning: This article discusses non-consensual sexually explicit content and child sexual abuse material.
In 2024, a former track and field coach in Boston, Massachusetts, was sentenced to five years in jail for attempting to trick and extort more than 100 women, including student-athletes he coached, into sending him intimate photos.
According to the 2021 criminal complaint, Steve Waithe stole photos from some of the student-athletes’ phones under the pretence of “filming their form” at practices and meets. He also approached some victims via fake online accounts, telling them he had found their images on a forum site called “leakedbb.com” (“LeakedBB”) and offering to help them remove these photos if they provided more images for “reference”.
Authorities said Waithe also hired and paid another man in October 2020 to hack into the Snapchat accounts of women he coached or had other relationships with in an effort to steal and distribute nude images online.
In one post, according to the US Attorney’s Office, Waithe wrote: “Does anyone want to trade nudes? I’m talking girls you actually know. Could be exes or whatever. I have quite a few and [am] down to trade over snap[chat] or something.”
Legal documents do not name the sites on which Waithe distributed these images, but Bellingcat found a cached version of a November 2020 post with that exact wording on LeakedBB – the same site he allegedly used to try to trick victims. Another cached LeakedBB thread posted a few months later shows the same user offering to trade nudes of athletes, including “a lot that I actually know”.
Screengrab from LeakedBB, showing a user asking to trade nudes of “girls you actually know”; redaction by Bellingcat
Such posts were not unusual on the site: multiple archived pages show the forum’s users either requesting Snapchat hacks or offering to help others hack Snapchat accounts, sometimes for a fee.
In the criminal case against Waithe, the ownership of LeakedBB is never discussed, but a Bellingcat investigation can reveal that payment streams, company records and website domain information appear to lead back to one individual: Jitendra Maharaj, a Christchurch-based former pilot and co-founder of a cryptocurrency start-up, Pay It Now (PIN), which reportedly billed itself as the “Stripe of crypto payments”.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
Our New Zealand publishing partner The Press sent an email to Maharaj on June 4 outlining our findings in detail and inviting him to respond. Maharaj did not reply to this.
However, by June 6, LeakedBB was down. As of publication, the website remains inaccessible.
The Press later received an email from a Christchurch-based lawyer representing Maharaj, who said their client was in Fiji for a family member’s funeral. The lawyer requested that we wait until his return on June 23.
When The Press visited his residence – a two-storey family home in Christchurch’s affluent Aidanfield suburb – on June 25, Maharaj said he did not know who was behind LeakedBB or operated it and that he was not sure if the website was down.
He said he did not respond to the email queries and had not spoken to his lawyers about them because “all the evidence against me just sounded really weird” and it seemed like there was “some kind of targeted attack out on me” based on “manufactured evidence or something that’s pointing me to this garbage”. However, he refused to comment on the record about most of the specific evidence linking him to the site and referred these questions to his lawyer.
He also claimed that he had been contacted by people “trying to harass me to get me to send them money”, but declined to provide details on the record.
Jitendra Maharaj at the entrance of his residence on June 25, 2026. Source: Iain McGregor/The Press
Despite a further extension of the deadline until July 6 – more than a month after we first reached out – Maharaj and his lawyer had not provided any statement directly addressing the specific evidence linking him to the site as of publication.
PIN, the company Maharaj co-founded, did not respond to The Press’ requests for comment. However, there is no suggestion that PIN has any knowledge of or involvement in LeakedBB.
Profiting Off ‘Leaks’
LeakedBB was set up in 2019 and built a sizeable following over the next seven years, averaging an estimated two million visits a month from March to May this year. The board statistics shown on LeakedBB’s homepage in May displayed 2.2 million registered users and more than 2.6 million posts.
Screengrab of the board’s statistics as of May 26, 2026; personal information redacted by Bellingcat
Google’s Transparency Report shows it received more than 95,000 individual requests for over 350,000 pages on LeakedBB to be delisted from search results. This resulted in Google de-listing more than 169,000 pages from its search results, according to the report.
Shortly after the site went offline, a Reddit post noting the outage and asking for alternatives trended in the “hot” section of a piracy subreddit, accumulating almost 700 votes in a week. In response to a question by one commenter asking what the site was, another person replied: “Not only did it have ‘onlyfans’ content, also amateur, asian, arabic, celebrity and other hacked phone/icloud content from other sites.”
This comment accurately summarised some of the content on the site. In LeakedBB’s early days, it had sections for other types of “leaked” content such as computer programmes and eBooks. But within months, the forum’s discussions were almost exclusively about pornographic images and videos that members claimed had been leaked – implying that it was non-consensual, hacked or stolen content.
The most popular section on the forum contained content that claimed to be from sites such as OnlyFans and Fansly, which, if shared without the original creators’ consent, would be a violation of their intellectual property.
Reba Rocket, co-owner and chief operating officer of Takedown Piracy, a company that helps both adult performers and private individuals remove non-consensually shared explicit media, said sites like LeakedBB cause financial harm to legitimate content creators.
“People would not shove a DVD into their coat pocket and walk out of the store – that’s something tangible that they know they’re doing something wrong, whereas watching something on the internet for free doesn’t have that same connected moral,” she said.
Other sections on LeakedBB featured threads requesting or promoting content that often appeared to show women who did not have anything to do with the adult industry, which the posts claimed were leaked, hacked or even obtained through blackmail.
One post advertised images of girls from 29 US states: “There’s names and Facebook information if you want that,” the member, “Master Leaker”, posted. “There’s also two girls that got blackmailed into sending more nudes as well!”
LeakedBB user advertising a large file of “girls from 29 different states”; personal information redacted by Bellingcat
In the “Requests” section, users shared clothed images of women or social media handles of potential victims, and asked if others had leaked content of them. In one recent post looking for a “Florida Milf”, a user wrote: “She may go by the name [redacted]. Looks like the daughter graduated from [redacted]. Anyone have content of her? Sex tapes?”
Some users also posted nude or intimate images of women they had found elsewhere, asking for help finding out their real identities. “Who is she?” or “Can anyone ID?” were some common questions in the posts.
Non-consensual intimate image sharing (NCII), colloquially referred to as “revenge porn”, is far from new. It is a known problem on Reddit, where, in 2022, a BBC investigation found “thousands” of such images being shared despite the platform’s attempts to crack down on the issue.
LeakedBB, however, seemed to take the opposite approach: instead of trying to moderate or prevent users from posting what appeared to be NCII, it sought to profit from and reward it.
Except for preview images, most of the content users shared in the “leaks” section was behind a paywall and could only be accessed with memberships costing up to US$99.99 or by redeeming credits.
The site rewarded members with credits for posting “leaked” content, as well as when other members spent credits to “unlock” their content. These credits could be used to access links that users could otherwise only view with a paid upgrade, or redeemed for cryptocurrency at varying rates (the most frequent contributors had the option to cash out the equivalent of up to $0.15 for each thread they posted).
There was also an annual Christmas contest, with last year’s total prizes worth over $4,000 in cryptocurrency for users who posted or liked the most threads.
Screengrab of a forum announcement on LeakedBB posted on Dec. 7, 2025.
Rocket said LeakedBB had “damaged many people”, including clients of her company. “Those specific clients are not in the adult industry,” she said, “but LeakedBB seemed more than happy to share their non-consensual content”.
The “leaks” were often posted with women’s purported real names, locations and social media accounts, as well as preview images showing their uncovered faces. One poster said sharing a woman’s social media details “adds to the experience”.
“For me, it makes my jerk-off sesh feel more personal, as if she’s an actual person I know rather than a moviestar/pornstar,” the post said.
Screengrab of a post where a LeakedBB user shared content of a woman, including her socials; personal information redacted by Bellingcat
There were more than 80 responses to this thread, mostly thanking the original poster for sharing the content. One of them, however, claimed to be the woman shown in the images: “Please remove this link. These photos were illegally stolen from me. This constitutes revenge porn and violates US law. Police are already involved. Not only is it illegal but just gross.”
Allison Mahoney, the founder and managing attorney at ALM Law in New York and Colorado, told Bellingcat she received calls about cases involving NCII “all the time”.
“It kind of amazes me, given the amount of media attention this has gotten over the years, that people are still engaging in this type of abuse so cavalierly,” said Mahoney, whose firm specialises in providing legal services for abuse survivors and children harmed in welfare systems.
Mahoney and Rocket agreed that sites sharing NCII often had real-world implications for victims, especially when images were posted alongside personal information, including names, contact information and professions.
“We have clients who … their children were kicked out of Catholic school, or they lost their mainstream job, or relationships ended, or families cut them off simply because content was posted online without their consent and viewed by others,” Rocket said.
Mahoney said online abuse can turn into offline abuse when victims have their personal information, like their name, profession and contact information, posted with their images. She has seen clients who had strangers show up at their homes or places of work, threatening their physical safety – a situation she said was “really terrifying”.
In July last year, LeakedBB closed a marketplace it had hosted for more than five years, which allowed users to sell leaks and services to each other. Lucifer NightStar, the administrator account on the site, said there were allegations of people selling “UA [underage] material”, which was “not something we want on [LeakedBB]”.
Screengrab of a post where Lucifer NightStar explained why the marketplace section had been shut down.
On one section of the forum, which was specifically for sharing content from other sites that hosted leaked pornographic content, LeakedBB had a disclaimer: “Please note that posting any content on any one below the legal age of 18 is against the law. We have a zero tolerance policy on such things and your account will immediately be banned / reported.”
But this warning did not appear on other sections of the forum, including those featuring threads of “amateur nudes” described as having been leaked. Some threads on the forum, which remained accessible shortly before the entire site was taken down, also described images of “young teens”.
While it is not known if those descriptions are accurate, in a recent post on Reddit a person asked for help taking down non-consensual photos they said were taken when they were a minor, hacked from Snapchat, and posted on LeakedBB, among other sites.
“I am in school to become a teacher and searched my name on google. If you go down a bit these websites come up,” they wrote. “I am so devastated and can’t believe this has happened to me.”
While speaking to The Press outside his residence on June 25, Maharaj said that when it came to publishing non-consensual pornography and child sexual abuse imagery, “It should be obvious anyone’s against that.”
Who Is Lucifer NightStar?
Lucifer NightStar was the username for the only account with the title of “Administrator” on the LeakedBB forum. This user posted FAQs for the site and almost every forum announcement throughout its history.
The URL of this account’s profile page shows the user ID (UID) of “1”. According to documentation for MyBB, a free and open source forum software that LeakedBB has credited for powering the site, the first user of the forum is assigned the UID “1” and has super administrator privileges – meaning their account cannot be deleted, banned or otherwise altered by regular administrators.
While the profile did not state the user’s location, it did show a local timestamp based on the user’s timezone settings, which matched GMT+12 – a timezone used in several countries in Oceania, including New Zealand and Fiji.
Lucifer NightStar’s recent posts generally avoid mentioning non-consensual intimate imagery, focusing on administrative updates and issues, troubleshooting and the annual Christmas contest. However, in the first few months of the forum’s existence, the user posted a thread with a “LeakedBB Exclusive” of “leaked Kiwi girls”.
One of Lucifer NightStar’s first posts on LeakedBB, sharing content described as “leaked Kiwi girls”.
In another discussion thread from 2020, Lucifer NightStar vouched for a user’s ability to “influence” another member’s ex-girlfriend to share nudes.
(Top) LeakedBB user offering their services to obtain nudes from another user’s ex-partner; (Below) A response from Lucifer NightStar vouching for this user being a “premium collector”. Personal information redacted by Bellingcat
Maharaj did not respond to The Press and Bellingcat’s question about whether he was Lucifer NightStar. However, one of the administrator’s posts led us to a clue pointing to Maharaj’s possible connection with LeakedBB.
Logica Ltd and MyBBplugins
In one post in May 2021, responding to a user reporting problems paying with Apple Pay, Lucifer NightStar shared a screenshot of what the payment screen should look like. A company name was visible in this image: “Logica LTD”.
Screenshot of a forum post by Lucifer NightStar on how to pay for a premium upgrade for LeakedBB using Apple Pay, showing the company name “Logica LTD”.
New Zealand company records show that Logica Limited was registered by Maharaj in February 2021, just months before this post. The company address is also in Christchurch, where Maharaj lives.
(Note: This is a different company from Logica Partners Limited, based in Auckland, which has no apparent connection with Maharaj or LeakedBB and is unrelated to this investigation.)
The records from the New Zealand Companies Office show that Maharaj has been the sole director of Logica Limited since its incorporation. He stated on his LinkedIn profile that he was self-employed as the CEO of Logica NZ from May 2020 to August 2021.
(Maharaj’s LinkedIn profile appears to have been deleted between June 13 and June 15, after The Press and Bellingcat’s initial enquiries and during the period his lawyer said he was in Fiji attending a family member’s funeral.)
Left: Screengrab of Jitendra’s work history from LinkedIn; right: Company registration information for Logica Limited (redaction by Bellingcat). Sources: LinkedIn, New Zealand Companies Office
But that was not the only connection to Logica Limited. On May 4, 2022, a YouTube user with the display name “LeakedBB” uploaded a video on how to pay for memberships on the site. This video was also embedded on LeakedBB’s homepage.
The video showed how users could pay by credit card. When they clicked to purchase a membership, LeakedBB would redirect them to another website to buy a digital avatar pack with a price corresponding to their selected membership tier.
After purchasing this “referral product”, users were encouraged to leave a comment and a positive rating to receive an “extra bonus month”. Archived versions of the website show view counts in the tens of thousands for some of these avatar packs.
The thumbnails of the “digital avatars” as well as their price and description, as shown in the video, were identical to those shown on the archived version of a site, logica.nz, which is recorded as Logica Limited’s website on OpenCorporates. This site also lists “Logica LTD” in its copyright information at the bottom of its landing page.
(Bellingcat last accessed a live version of the video on June 15. By July 1, we noticed that the video had been removed by the uploader.)
Left: YouTube video on how to purchase upgrades on LeakedBB. Right: Archived purchase screen of the same avatar pack on Logica.nz
In a forum thread on LeakedBB dedicated to explaining alternative ways to pay for membership, hundreds of users posted that they had just purchased the “Mystic Avatar Pack” or the “Pixel Avatar Pack” to gain access to the site. One user included screenshots of their purchase, showing the site URL to be “logica.nz”. Other users also stated that they had made the purchase on this website and were waiting to receive their upgrades.
Shared screenshot from a LeakedBB user who purchased a “Pixel Avatar” pack in exchange for membership, showing that they left a comment, like other users, on the purchase page on logica.nz. Personal information redacted by Bellingcat
This website’s landing page now displays only a note stating that it is under maintenance. However, according to archives captured by the Internet Archive, it was still selling “digital avatar packs” in March 2025.
This type of payment structure not only conceals the nature of the transaction from the payment processor (as non-consensual content violates most platforms’ terms of service), but it also hides the transactions for the user, as payments are not described as being made to “LeakedBB” on bank statements.
When asked about the links between LeakedBB and Logica Limited, Maharaj only told The Press at the doorstep interview on June 25 that “Logica was my company. I cannot say what happened there right now”.
According to the New Zealand Companies Register, Logica Limited is in good standing, with its most recent annual filing submitted by Maharaj in March 2026.
The Domain Name System (DNS) records of LeakedBB revealed another connection that seems to point back to Maharaj. Using online investigations tool DNSlytics, we viewed DNS records for the website and found that in 2020, the MX (mail exchange) record for LeakedBB.com was set to LeakedBB.net. An MX record is the mail server set up to accept emails for that domain. For LeakedBB.com, this was later changed to ProtonMail.
While the WHOIS ownership of LeakedBB.net is obscured, we found it on a list of sites that had DNS certificates issued by another site, mybbplugins.com. A DNS certificate is used to prove ownership of a domain and requires an administrator to validate that certificate.
According to WHOIS records from cyberthreat intelligence platform DomainTools, mybbplugins.com was publicly registered to Maharaj from December 2011 to February 2019, after which the registrant information was redacted.
The same site also issued a DNS certificate for a domain bearing Maharaj’s name (jitendramaharaj.com) as well as two domains that include part of his first name, jit-pay.cc and thejitshow.com. DNS certificates for these domains were issued between 2016 and 2021, according to free Certificate Transparency monitoring site crt.sh. Both “leakedbb” and the domain names linked to Maharaj’s name (i.e. “jitendramaharaj”, “jit-pay” and “thejitshow”) were also used as subdomains for mybbplugins.com, records from DomainTools show.
Another link appeared when we inspected the code of the oldest saved archive of the payment screen on LeakedBB, from November 2019, which showed a ProtonMail address associated with the PayPal form at the time with a string of seven digits as the username.
This string of seven digits is an exact match for what appears to be part of a Fiji-based phone number listed on WHOIS records for websites registered to Maharaj’s name including mybbplugins.com, from 2008 to 2011. It is unclear whether Maharaj was using this phone number in 2019, by the time LeakedBB was set up, and a different Fiji-based phone number was used with his name when the registration for mybbplugins.com was renewed in 2016.
Top: The archived HTML code for LeakedBB’s payment page, with a ProtonMail email linked to its PayPal account. Bottom: The WHOIS domain registry for mybbplugins.com, registered to Maharaj in 2011, with a phone number matching the digits to the ProtonMail email. Graphic: Galen Reich
Explore some of the links between Maharaj and LeakedBB:
Graphic: Galen Reich
From MyBB to LeakedBB
Bellingcat also found several other apparent connections between Maharaj and other applications hosting adult content.
An account with the username “Jitendra M.” has been posting on the MyBB community forum since 2008, with the account ID originally using the username “Darkmew”. An archived capture of this account’s profile information showed a date of birth and a location in Fiji.
This date of birth matches the one listed on a Facebook profile Bellingcat found under Maharaj’s name. His LinkedIn profile also shows that prior to moving to Christchurch, he worked in Nadi, Fiji, and he has listed addresses in the city for some of the domains registered to his name, as well as an email with a Fijian domain. This user also mentions that they are a pilot.
Jitendra M.’s profile bears a “former staff” label, indicating that he used to work for MyBB. A previous commit (save) of a file containing details of MyBB team members shows that the full name associated with this account’s user ID and username was “Jitendra Maharaj”, and his website was listed as jitendra-maharaj.com.
Archived versions of this site show photos and details that match those from Maharaj’s public social media profiles and interviews. For example, a 2011 capture shows that he mentioned being a pilot at a company called Pacific Sun. Pacific Sun was later rebranded as Fiji Link, and Maharaj’s LinkedIn profile, before it was deleted, stated that he worked for Fiji Link from 2009 to 2015. A blog post on the site also refers to mybbplugins.com as the author’s “newest endeavour”.
Left: Archived profile of “Darkmew”’s profile on MyBB; Right: Screengrab of information from a Facebook profile under Maharaj’s name, which has either been made private or deleted as of publication.
Very shortly after joining the MyBB community forum in Feb 2008, Jitendra M. asked about using MyBB for “warez” (an internet slang term for pirated digital content) and/or adult content. He stated that he was “interested in using it for a [sic] adult forum”.
During this time, he also posted asking about streaming videos from a server and how to use a PayPal account without a credit card for “people putting money into my account for services I provide”. In late 2008, Jitendra M. purchased a web domain, reaperscrypt.info, which Wayback Machine archives show hosted pornographic content while it was online in 2009. This domain was publicly registered to Maharaj from November 2008 to January 2010.
In 2013, he posted about selling the mybbplugins.com domain. However, as previously mentioned, Maharaj’s name was still publicly registered as the owner of the domain until February 2019, when registration data was redacted.
Top: Post by Jitendra M. about using MyBB for warez and adult sites using MyBB; Bottom: Post about selling mybbplugins.com
Bellingcat was able to view Facebook and Instagram accounts under Maharaj’s name and showing his profile picture in early May. These accounts painted a picture of a family man, with his public photos mainly showing his wife and children. His Facebook account had been either deleted or made private by May, and his Instagram account, while still active, has not been updated since 2013.
Archives of an X account using the same username as Maharaj’s Facebook and Instagram accounts also show several posts from November 2019 promoting LeakedBB.
Archived tweets from an account, using the same username as what appeared to be Maharaj’s former Facebook and Instagram accounts, which posted links to LeakedBB in November 2019. Personal information redacted by Bellingcat
The “Darkmew” username that Jitendra M. originally used was also used for a GitHub account which hosts a repository described as the “official repository for Pay it Now – PIN Token”. This account, which now redirects to an account with the username “JitMaharaj”, has also forked (or copied) two apps created by other people: one to create a subscription platform “like onlyfans.com” that uses cryptocurrency for payments; the other designed to scrape and report illicit content from LeakedBB.
Screengrabs from the “JitMaharaj” GitHub account, which forked repositories for an application designed to create a platform “like ‘onlyfans.com’, and another to report illicit content from LeakedBB.
These forked repositories were among 38 visible on JitMaharaj’s account on June 17, but by July 1 – after a June 22 query from The Press asking Maharaj whether he owned this account – there were only 25 repositories listed on this account. The two repositories mentioned above were among those removed.
Maharaj did not respond to questions about whether he owned any of the accounts or domains mentioned in this section.
‘Hiding Behind Screens’
Mahoney said that successfully removing clients’ images from platforms like LeakedBB was a time-consuming task. “Some sites, usually the sites hosted overseas, will just ignore the request and won’t take them down,” she said.
In the US, which accounted for almost half (40 percent) of LeakedBB’s web traffic in May, the Take it Down Act recently came into effect. The new federal law requires platforms to quickly remove non-consensually shared intimate imagery when it is reported.
However, there has been little discussion of the law on LeakedBB. One user asked in the “Help” forum how this act would affect the site and its members back in October 2025, but Lucifer NightStar never responded to this post.
LeakedBB user asking about the Take It Down Act
Rocket said having content removed for her US-based clients could be difficult when the platforms were based overseas: “A lot of it depends on where the platform is hosted, who runs their ad network and who is monetising – who their payment processors are,” she said.
LeakedBB accepted cryptocurrency payments through NOWPayments, a cryptocurrency payments gateway based in the Netherlands and Estonia. The purchase page for its subscription plans, which allowed users to gain unrestricted access to the site, redirected to a NOWPayments purchase screen to transfer cryptocurrency to LeakedBB.
In response to questions from Bellingcat, NOWPayments confirmed that LeakedBB’s activities violated its terms of service. The payments provider said it had deactivated LeakedBB’s account and blacklisted the platform immediately, as of June 4.
LeakedBB did have a form for people to request that their content be taken down under the Digital Millennium Copyright Act (DMCA), a US copyright law. However, this required victims to submit personal information such as a physical address and a business email address, and stated that it would reject requests that used email addresses from free services like Google and ProtonMail. Such details appear to go beyond those required for DMCA takedown requests on other sites: for example, Google only requires a first and last name, and an email address from any domain.
In one Reddit thread discussing the difficulty of removing content from LeakedBB under the DMCA, someone commented: “Some of this seems fairly standard, some of it seems like it’s designed to make people not request a takedown for fear of doxing [sic] themselves.”
On the page to submit DMCA takedown requests, LeakedBB also stated that successful requests would lead to them removing content hosted on their servers, but not links to third-party hosting providers – which is how a large portion of the content was made available to the website’s users.
In New Zealand, where Maharaj is based, posting intimate imagery without consent is illegal under the Harmful Digital Communications Act. People face up to two years imprisonment or a fine up to NZ$50,000 (US$29,200), while for a company, the fine can be as high as NZ$200,000.
Netsafe is the only approved body in the country that handles complaints under this act. The agency’s chief online safety officer Sean Lyons told The Press that the law was quite novel and other jurisdictions were “envious” when it was enacted – it was able to respond to generative AI technology that didn’t exist when it was written, and gave New Zealand courts powers to issue takedown orders, even in other countries.
Still, Lyons said the law had its limitations: it was mostly intended for use where one individual was harming another, and if the responsible party was overseas, the law’s efficacy largely relied on responsible platforms doing the right thing.
“There are times when within our process, we will have contacted platforms or hosts and they will have said, ‘Who the heck are you?’…[Or] ‘We know what we’re doing, we are quite comfortable with what we are doing, and we don’t give a stuff about what it is that you are telling us, or about New Zealand law, or about the harm.’”
Mahoney and Rocket agreed that current laws were limited in their effectiveness against sites like LeakedBB.
“The fact of the matter is there are places where … until there is an enforceable international law, that content is going to be available forever, which means there is a risk of it being shared forever,” Rocket said.
Mahoney said image-based abusers have also become more sophisticated over time: “Technology is advancing, and the law is always playing catch-up,” she said.
But she suggested that identifying those responsible for the abuse could have a deterrent effect: “The anonymity that people have hiding behind screens really contributes to this and emboldens people to act in ways that are very abusive to people.
“If people understand that there’s a risk that their identity and their bad behaviour will be revealed, the hope is that it will curtail some of this and dissuade people from engaging in this type of conduct, which is so, so harmful to the victims.”
If you are a victim or know anyone who is affected by image-based abuse, resources and support are available through StopNCII.org.
Galen Reich and Melissa Zhu from Bellingcat and Michael Wright from The Press contributed to this article.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
Warning: Includes graphic descriptions of animal harm and images of animal parts from the outset.
A Bellingcat investigation has uncovered a Myanmar-based wildlife trafficker who has operated openly across social media for at least six years, claiming to have sold tiger bones, rhino horn, elephant skin and other products from protected and endangered species to customers in Myanmar, China and Thailand.
By analysing hundreds of adverts and customer conversations, Bellingcat traced more than
Warning: Includes graphic descriptions of animal harm and images of animal parts from the outset.
A Bellingcat investigation has uncovered a Myanmar-based wildlife trafficker who has operated openly across social media for at least six years, claiming to have sold tiger bones, rhino horn, elephant skin and other products from protected and endangered species to customers in Myanmar, China and Thailand.
By analysing hundreds of adverts and customer conversations, Bellingcat traced more than US$21,000 in sales, identified cross-border shipments linked to multiple payment accounts, and geolocated the dealer’s home address. The seller frequently used graphic images to convince buyers that his wildlife products were genuine, sharing footage of animals before and after they were killed as proof of authenticity.
Following this investigation, Meta removed 10 Facebook accounts, WeChat suspended three accounts and revoked their payment functions, TikTok and YouTube each removed one account, and authorities in Myanmar and Thailand said they would examine the findings further.
On December 21 2022, a Facebook account shared a reel of a tiger cub lying unconscious beneath the caption: “Time for winemaking”, followed by several laughing face emojis. Four days later, the same account shared another reel, this time of an adult tiger lying motionless on an orange plastic sheet as a man approaches with a knife.
Two separate videos posted to Facebook by the account known as MB.
The account behind both videos belongs to Mei Ba (hereafter MB), a self-described Traditional Chinese Medicine (TCM) doctor based in Myanmar. In TCM, plants and animal products are used to prepare remedies based on established medicinal formulas. These remedies can take many forms, including herbal teas, simmered concoctions, ingredients steeped in wine, and pills. TCM is also sometimes associated with pseudoscientific beliefs, such as the idea that consuming an animal’s organ can nourish the corresponding organ in the human body.
A Bellingcat investigation has found that MB frequently advertises the trafficked parts of critically endangered and vulnerable species to customers in Myanmar, Thailand and China. An analysis of social media posts published by MB over six years found references to sales involving parts of bears, elephants, leopards, musk deer, otters, pangolins, rhinos, seahorses and tigers, all of which are protected species.
Screenshot of MB’s TikTok profile where he identifies himself as a TCM Doctor. Bottom: English translation by Bellingcat.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
For at least six years, MB has used ten different Facebook accounts under versions of his name to advertise animal parts and products for sale, including those derived from vulnerable and protected species.
MB has advertised tiger body parts and products, including skins and wine made from bones. Myanmar’s wild tiger population was last estimated at a minimum of 22 animals (in a 2019 study published before the civil war). Licensed tiger farms, described as being similar to zoos, also operate in the country. However, Myanmar law prohibits the killing of any tiger, wild or captive.
Bellingcat has also identified adverts offering leopard body parts, including skin, bones and gallbladders, as well as a product described as a “whip”, a euphemism for a penis. Many of the adverts explicitly stated that the body parts came from wild animals. The Indochinese leopard is classified as critically endangered, with fewer than 800 mature individuals believed to remain in the wild across mainland South-East Asia.
Products as advertised by MB on Facebook. Left: wild leopard skin, Dec 2024; top right: wild leopard bones, Dec 2025; bottom right: leopard gallbladder, Dec 2022. Descriptions added by Bellingcat.
MB has advertised body parts and other products derived from Asian elephants, an endangered species, including skin sold in pieces and powdered form, as well as their genitals.
One of MB’s more graphic posts showed a recently killed and butchered moon bear – a type of Asian black bear which is classified as a vulnerable species. MB has also advertised various bear body parts for sale, including paws, heads, gallbladders, bile and fat.
Whole rhino horns, as well as bracelets and medicinal products made from rhino horn, have been advertised by MB. Although rhinos have been extinct in Myanmar since the 1980s, the country remains a known transit route for rhino products moving from India to China and elsewhere in South-East Asia, suggesting the items advertised by MB originated outside Myanmar.
Rhino products as advertised by MB on Facebook. Labels added by Bellingcat.
Under Myanmar law, anyone convicted of killing, possessing or trading a “completely protected species,” or its parts, faces a minimum prison sentence of three years and a fine under a conservation law introduced in 2018. Completely protected species advertised by MB include Asiatic black bears, elephants, leopards and rhinos.
Bellingcat contacted multiple Myanmar government authorities for comment regarding MB’s wildlife trade. The Myanmar embassy in London confirmed receipt of Bellingcat’s request and said it would consult the relevant authorities in Myanmar.
Convincing Customers
Counterfeits are common in the illegal wildlife trade. Buffalo horn is often carved to resemble rhino horn, while cattle penises are passed off as tiger parts. Much of MB’s promotional strategy therefore focuses on persuading buyers that his products are genuine.
To market rhino horn, MB has posted images of the items on scales or held up against a light, which he claims demonstrates the texture of genuine horn. For tiger bones, in one post he said that a patch of skin would be left attached to demonstrate their authenticity.
MB has also posted videos of recent leopard and tiger kills. He has shared footage of live tigers in cages followed by images of the same animals being butchered for their skins, bones, skulls, claws and fangs.
Video of a live tiger in a cage, posted by MB on Facebook on Nov, 14 2022. Translation of the accompanying text: “What the hell are you huffing about? Just wait, your turn is coming [Smug emoji]”.
Bellingcat only analysed open source evidence, including social posts, customer conversations, visible transactions and shipping receipts. Therefore, the authenticity and composition of the wildlife products advertised or sold could not be independently verified.
Nevertheless, given the volume and graphic nature of these posts, MB’s ability to operate on Facebook for at least six years raises questions about why his accounts remained active up until Bellingcat contacted Meta.
Evading Platform Moderation
For years, MB has openly advertised his business on Facebook, posting hundreds of adverts across ten profiles and various groups. He often uses coded language, including Chinese-language euphemisms in his comments.
For example, he uses “eraser” (橡皮) to refer to “elephant skin” (象皮), a Mandarin homophone with characters that are also visually similar, shown below.
Screenshot of a Facebook advert posted by MB on Oct, 30 2024. Post refers to elephant skin as “eraser” and includes an elephant emoji. Annotations by Bellingcat.
MB also uses pinyin, the phonetic system for spelling Mandarin Chinese words using Latin letters. For example, in one post, he abbreviates the pinyin word for “rhino” (xīniú) as “X”, advertising “X horn powder”, and uses “Y” (pinyin: yào) as shorthand for “medicine”. He also frequently uses animal emojis, including tiger, elephant, rhino, deer and bear, to refer to products derived from those animals without naming them directly.
Clockwise from top left, the emojis and text refer to products including rhino meat strips, African elephant skin, tiger bone paste (twice), wild deer antler and bear gallbladder.
Asked why MB had been able to operate for so long without being banned and how it detects common evasion tactics such as coded language, Meta responded: “Bad actors constantly evolve their tactics to avoid enforcement, which is why we partner with groups and invest in tools and technology to detect and remove violating content.”
Cross-Border Trade
To map the scale of MB’s business, Bellingcat analysed more than 500 screenshots of customer conversations spanning May 2021 to May 2026. Originally taking place on Facebook, Viber and WeChat, these exchanges were later reposted by MB on Facebook.
Often blurred or cropped, the material appears to have been shared as part of a strategy to present MB as a trusted seller who reliably delivers to customers. However, given the content frequently included shipping labels with names and addresses, product descriptions, and price discussions, Bellingcat was able to trace part of MB’s customer base and income. Notably, only content MB chose to repost was available for analysis, meaning the findings represent only a sample of his overall activity.
Across the dataset, Bellingcat identified more than 150 transactions totalling US$21,000. The United Nations estimated Myanmar’s annual per capita income at between $300 and $430 in 2023.
Bellingcat analysis of MB’s digital footprint showing revenue earned per species by MB. Currency in US$. Trade values are estimated based on yearly average black market exchange rates.
Based on delivery records, Bellingcat identified 119 deliveries within Myanmar, 27 to mainland China, and nine to Thailand. Within Myanmar, shipments were most often sent to shared pickup points in cities or towns, whereas those to China were more frequently sent directly to individual addresses.
Shipments within Myanmar most often involved small quantities of powders or medicines, such as 3 to 7 g of rhino horn powder or 5 g of bear gall bladder. By contrast, deliveries to China more often included whole animal parts such as rhino horn or tiger bones, or larger quantities of products, including 500 g to 1 kg of elephant skin powder or 10 to 40 bottles of medicine.
Map of number of recorded sales to regions in Myanmar, China and Thailand, based on Bellingcat’s analysis of MB’s digital footprint between 2021 and 2026.
MB’s highest-value recorded transaction was to a customer in Yiyang, Hunan Province, China and involved two tiger femur bones weighing just over 2.5 kg. Sold in July 2022, the bones fetched 23,500 Chinese Yuan (US$3,494). The customer was asked to provide a screenshot as proof of payment. MB later reposted this on Facebook, alongside a photograph of the bones wrapped in cling film and a shipping label for Deppon Logistics attached.
Bellingcat contacted Deppon Logistics for comment, sharing the image and tracking number shown below, but received no response at the time of publication.
Screenshot of a customer conversation in which MB offers several tiger femur bones for sale. Bottom: Photograph of the wrapped bones, showing a courier label and tracking number, posted on Facebook on July, 8 2022.
Under Chinese law, buying, transporting, or selling protected or endangered species can, in the most serious cases, carry prison sentences of more than 10 years. Asian elephants and wild tigers are listed as “Class 1” protected animals. A permit system does exist for the use of captive-bred tigers, although it remains controversial.
Under the Convention on International Trade in Endangered Species of Wild Fauna and Flora (CITES) Appendix I, international trade in any endangered species, including Asian elephants and tigers, as well as their derivatives such as skin powder, scales and bones, is prohibited. China, Myanmar and Thailand are all parties to the treaty.
Bellingcat contacted the General Administration of Customs of China for comment on MB’s wildlife sales to China but did not receive a response at the time of publication.
Bellingcat also found evidence of nine deliveries to Thailand, including a tiger penis and several TCM powders said to contain dog, yak and seahorse, all species regulated by Thai law and protected under CITES.
The Thai Natural Resources and Environmental Crime Division told Bellingcat that it already monitors packages falsely declared as traditional medicine but found to contain protected wildlife parts or ingredients derived from them. Following Bellingcat’s findings on MB’s activities, the division said it would investigate further.
A large proportion of MB’s exports to all three countries were bottles of TCM powders or tablets. For example, a “kidney replenishing medicine” was purported to contain deer, dog, gecko, praying mantis, seahorse and yak, while a “prostate medicine” was said to include deer, seahorse and dog.
Under Chinese law, all packaged TCMs must carry labels clearly displaying the manufacturer’s name, full ingredient list, production and expiry dates, and information on side effects and safety. None of these details were present on MB’s labels.
A shipment of “Elephant Treasure Digestive Medicine”, described by MB as containing rare and valuable ingredients and bearing the image of an elephant on the label. The ingredient list states only “skin powder”. Posted on Facebook in October 2025.
Multiple banks accounts
Over six years of reposted conversations with customers, Bellingcat observed MB requesting payments to at least 15 different accounts, including seven via WeChat Pay, two via Alipay and six via third-party bank accounts, which MB described as belonging to friends or family.
For example, in May 2022, a customer purchased 1kg of elephant skin powder to be shipped to Chiuchow, Guangdong Province, China. MB told the customer his WeChat account could not currently receive the payment and instructed them to send the funds to his “sis” [female associate], shown below.
Screenshots of a WeChat conversation between MB and a customer, reposted by MB on 29 May 2022. English translation by Bellingcat.
Both WeChat Pay and Alipay’s terms and conditions prohibit the use of their services to receive payments for illegal activities.
After being contacted by Bellingcat, WeChat suspended three accounts, revoking all payment functions and removing associated content.
Alipay did not respond to Bellingcat’s request for comment.
Identifying MB
MB’s brazen online activities include operating at least ten Facebook profiles, two TikTok accounts, one WeChat account and one YouTube channel. He is the sole administrator of a Facebook group with nearly 1,000 members. Across these platforms, he has amassed some 12,000 followers.
While using variations of “Mei Ba” (MB) across most of these accounts, he also uses the Chinese name “Mei Xiangfu” on his personal WeChat account. The name “May Kyin Phu” also appears alongside payment QR codes when customers are asked to transfer funds. Below is a QR code for Myanmar’s largest bank, KBZ, which includes what appears to be MB’s legal name: U May Kyin Phu, with “U” used as an honorific equivalent to Mr.
Screenshot from a WeChat conversation with a customer showing MB’s ID photograph and a bank QR code displaying the name “May Kyin Phu”. Reposted by MB to Facebook on Dec, 23 2024.
Since 2019, MB has used the same ID photo as his profile picture across multiple platforms, as well as his wedding photo as his TikTok profile picture and Facebook banner image. His wife, identified in the wedding photo and in other images posted by MB, has also been found advertising vulnerable and protected species via her Facebook account.
With more than 3,100 followers, she frequently reposts MB’s adverts while also sharing screenshots of conversations with customers. For example, in one WeChat exchange later reposted to Facebook, she discusses the cash sale of five “real” tiger penises.
From MB’s posts, Bellingcat geolocated a house in Lashio, eastern Myanmar, used to photograph animal parts for sale in his advertisements. MB has posted content from this property since 2020.
In the images below, what MB describes as “leopard gallbladders” can be seen hanging from a balcony, revealing the layout of the property’s backyard and the rooftops of adjacent buildings. Although Lashio is not covered by Street View, the distinctive roof visible in MB’s images matched with user-uploaded photographs on Google Maps.
Geolocation of photographs posted by MB to Facebook in Dec 2022, matching rooftops in Lashio, Myanmar, with Google Earth imagery from Sept 2022.
Bellingcat contacted both MB and his wife for comment on the findings of this report. Both were reached via WeChat and appear to have received the request, but did not reply at the time of publication.
Data visuals by Galen Reich, Graphics by Merel Zoet, Editor, Claire Press.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
A “river of blood” was how one survivor described the scene in western Myanmar. “I saw shooting. I saw mass killing.” Another told the UN High Commissioner for Human Rights (UNHRC) how 20 relatives, including three children, had been killed in the 2024 attack on Htan Shauk Khan village.
Human Rights Watch (HRW) said earlier this month that the Arakan Army (AA) “may have killed at least 170 Rohingya men, women, and children” in Hoyyar Siri (known as Htan Shauk Khan in Burmese) in Buthidaung To
A “river of blood” was how one survivor described the scene in western Myanmar. “I saw shooting. I saw mass killing.” Another told the UN High Commissioner for Human Rights (UNHRC) how 20 relatives, including three children, had been killed in the 2024 attack on Htan Shauk Khan village.
Human Rights Watch (HRW) said earlier this month that the Arakan Army (AA) “may have killed at least 170 Rohingya men, women, and children” in Hoyyar Siri (known as Htan Shauk Khan in Burmese) in Buthidaung Township. It described the May 2, 2024, attack as a “massacre”.
Buthidaung is one of the two townships in Rakhine State that is home to the majority of the Rohingya, a mainly Muslim ethnic minority in the predominantly Buddhist Myanmar.
At least 40 villages in Buthindaung were burned down in April and May 2024 amid clashes between the AA, an ethnic armed group fighting Myanmar’s military junta for control of Rakhine, and junta forces battling to retain their hold of the township.
Both sides committed abuses against civilians during the clashes, according to HRW. The military junta’s forced conscription of Rohingya to fight on its behalf has also intensified violence against them.
The military and Rohingya armed groups began arson attacks in Buthidaung township in April 2024. By mid-May the AA had captured all junta bases, according to the think tank, the Australian Strategic Policy Institute. The destruction of Buthidaung has previously been documented by Bellingcat.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
The AA has denied accusations that it massacred civilians in Buthidaung, claiming that those killed were junta soldiers and Rohingya militants.
Bellingcat emailed the United League of Arakan, AA’s political wing, about the alleged attack on civilians but did not receive a response at the time of publication. The United League of Arakan’s humanitarian office responded to Bellingcat after publication disputing the Human Rights Watch report and the allegation that Arakan Army personnel massacred Muslim civilians. Instead describing that the village became part of an intense military confrontation involving several armed groups, rather than a one-sided assault. Myanmar’s Ministry of Defence also did not respond to our questions.
Evidence of civilian harm in Myanmar is slow to emerge and difficult to obtain due to the military’s strict control of the region and the tight grip of armed groups such as the AA in areas they control.
“The mass killing could only be confirmed more than a year later,” the recent HRW report said, “when survivors eventually crossed into Bangladesh and found their way to the Rohingya refugee camps in Cox’s Bazar.”
Aerial imagery shows that Htan Shauk Khan was almost entirely destroyed in May 2024.
False-colour infrared map from Copernicus on Planet Insights Browser shows exposed ground in grey or tan, indicative of possible damage, in the village.
Erasing Homes
A new investigation by Bellingcat has identified 115 villages in Rakhine State, similar to Htan Shauk Khan, as partially or completely destroyed since the February 2021 military coup that overthrew Myanmar’s democratically elected government.
The data points to a pattern of violence that leaves civilian areas uninhabitable and in some cases, erases them completely.
Several buildings were set on fire when the junta allegedly dropped a
bomb on the Muslim village of Zu La on Nov. 3, 2024. The fire was captured nearby on
NASA FIRMS.
Satellite imagery indicates that it was attacked again on Dec. 9, 2024. Visible smoke can be seen
rising from the village.
Zu La is located in Maungdaw Township. Along with neighbouring Buthidaung, Maungdaw is home to
the majority
of Myanmar’s persecuted Rohingya.
Zu La, and the neighbouring village of Gone Nar, previously faced violence during the 2017
Rohingya genocide.
Satellite imagery from that year shows them completely burned to the ground.
They show signs of reconstruction after 2017.
But repeated attacks in 2024 destroyed the villages again.
Neither of the villages appears on the latest maps from 2024. These are produced by the United
Nations mapping unit, based on Myanmar government maps.
Steve Ross, Senior Fellow at the US nonprofit Stimson Center who is leading the ‘Crisis in
Myanmar’s Rakhine State’ project, told Bellingcat this is part of the military’s broader
campaign to deny the existence of the Rohingya and erase identity in Rakhine.
Bellingcat contacted the Myanmar government but had received no response by the time of
publication.
Villages in Mungdaw are inured to cycles of violence. Ywar Haung, a village south of Zu La, has
stood barren since 2017.
So has Kan Kya, where the military built the Border Guard Police Battalion No. 5 (BGP5).
All four villages are among the growing number of Rakhine’s lost settlements.
Six of the 10 villages we found partially or totally destroyed in Maungdaw in 2024 aren’t marked
on the UN’s township map.
Removing more villages from the map remains a possibility, Ross said. However, following this
April’s elections, which critics dismissed as a sham,
the military is eager to restore international credibility and avoid actions that might be seen
as provocative, the expert told Bellingcat.
The AA announced the capture of Maungdaw when it
seized BGP5 on Dec. 8, 2024.
And with that the armed group gained full
control of Myanmar’s entire border with Bangladesh.
Shortly afterwards, the AA took control of the strategically important Ann Township in central
Rakhine.
The armed group announced it had captured the headquarters of the Western Regional Military
Command on Dec. 18, 2024.
It shared a video of the headquarters and nearby
military installations burning.
Local residents in and around the township were trapped,
displaced or forced to
flee their homes due to the months-long fight for Ann.
According to reports, the military
entered Pyaung Chaung village and burned it down on Oct. 31, 2024.
Satellite imagery from Nov. 1, 2024, shows large-scale damage in the village. There were reports that the
military warned residents to evacuate the village a week before the attack.
Ross believes that the military’s intention has been to try to make Rakhine as ungovernable as
possible if the AA gains full control of the state.
Nearby villages of Yat Thar Ywar Thit
and Pyaung Thay show similar evidence of destruction.
Sittwe
city, the capital of Rakhine State, has become a focal area of fighting since late 2025.
The city is in Sittwe township, one of the three townships still under junta control.
Su Mon Thant, Asia-Pacific analyst at Armed Conflict Location and Event Data Project (ACLED),
said capturing Sittwe would be highly symbolic for the AA as no non-state actor has yet taken
control of a state capital in the country.
The AA already controls areas along an India-backed transport corridor in Myanmar that includes
a port in Sittwe.
Sittwe is surrounded by water on three sides. Capturing it would be challenging, with the
military maintaining naval superiority and building defences in and around the city to deter a
potential AA offensive, Ross said.
On Dec. 27, 2024, the AA attacked the Kyauk
Tan checkpoint near Sittwe on the highway linking the capital to Yangon, the largest city to the
south of Rakhine.
There are many villages near the checkpoint.
Like Taw Kan
where, according to local reports,
junta forces carried out an arson attack that destroyed 80 houses on Jan. 15, 2024.
Bellingcat found at least 13 villages near the checkpoint that had been destroyed, with only a
few remaining structures. All but one of them were attacked in 2024-2025.
Less than 4km from the checkpoint is Yar Tan
which appears intact in a March 2024 Google Earth image
but several buildings look destroyed in high-resolution satellite image on Google Earth from
March 2025.
Trenches and military outposts began appearing near the village around Nov-Dec 2024.
They grew as the months passed. However, due to a lack of updated high-resolution satellite
images, we cannot tell whether these are currently in use or to what extent.
There are also villages that appear to have been replaced with defensive structures. For
example, Kan Pyin Ywar Haung, for which the latest available high-resolution satellite image
shows trenches on both sides.
Although such structures are clearly visible in high-resolution satellite imagery, lower-quality
images can also help indicate whether a village was replaced with fortifications.
Kan Pyin Ywar Thit, located just south of Kan Pyin Ywar Haung, appears to have been completely
destroyed; however, the same criss-crossing lines are not visible across the village.
Similar fortifications appear in other villages.
Defence infrastructure has replaced villages on the outskirts of Sittwe, making it more difficult
for AA to advance towards the city, said Ross.
Bellingcat also found at least 10 villages partially or totally destroyed in Kyaukpyu Township
since fighting intensified in February 2025.
Kyaukpyu,
which has abundant oil, natural gas and marine resources, is also home to a junta naval base
Nearly all the villages we found to be destroyed or damaged are within a 10km radius of the
naval base.
In early March this year, clashes
took place between the AA and the military near Say Maw village, located less than 5km from the
base.
NASA FIRMS detected fire in the village and the surrounding areas on March 23, 2026.
The latest high resolution satellite image on Planet from April 2026 shows flattened buildings in
the village.
A month earlier Saing Chon Dwein village, also less than 5km from the base, was reportedly
burned down by the military.
The fire was caught on a Feb. 9, 2026 lower resolution satellite image
with burnt areas distinguishable the next day.
Like Sittwe, Kyaukpyu is surrounded by water, making it difficult for the Arakan Army, which
lacks naval capabilities, to seize control. “AA has some advanced drones reportedly, but these
areas also have jamming technology,” said Thant.
Methodology
The data was compiled using news reports, including social media channels, ACLED, satellite imagery and NASA FIRMS. The names of the villages were corroborated using the UN’s Myanmar Information Management Unit (MIMU), news reports and Planet Labs.
We only included areas where the destruction was clearly visible in high-resolution satellite imagery or significant enough to be detected in mid-resolution images. Our data is not exhaustive and the true number of affected villages is likely to be higher.
While it is difficult to ascertain whether the villages we found damaged or destroyed showed signs of reconstruction, at least five of them appear to show some buildings rebuilt in latest available satellite imagery.
Military Control Is Slipping
Last month, in the first election since Myanmar’s 2021 coup, the pro-military parliament chose junta chief Min Aung Hlaing to be the next president.
Subscribe to the Bellingcat newsletter
Subscribe to our newsletter for first access to our published content and events that our staff and contributors are involved with, including interviews and training workshops.
According to research group Data for Myanmar, at least 65 townships were excluded from voting, including the 14 in the AA’s control. In Rakhine’s 17 townships, voting was held in only three still under junta control – Kyaukpyu, Sittwe and Manaung.
The AA resumed attacks against the junta in Rakhine in November 2023, ending a year-long ceasefire.
Data published by the Armed Conflict Location and Event Data Project (ACLED) and analysed by Bellingcat reveals a sharp increase in the military’s air and drone strikes in Rakhine. After the AA resumed its offensive, strikes rose from 30 in 2023 to 461 in 2024. By the end of 2024, the AA had captured all but three townships in the state.
Bellingcat found that strikes were then concentrated in the townships where the junta is fighting to maintain control. They decreased in 13 townships captured by the AA and remained unchanged in one during 2025. By contrast, attacks increased in Kyaukpyu and Sittwe, yet to be captured by the AA. Data for Manaung is unavailable.
ACLED’s data comes from multiple sources, including news reports and social media. While the data is not exhaustive, a broad trend can be identified. You can read further details and caveats about the data here.
Su Mon Thant, Asia-Pacific analyst at ACLED,explained that the military conducts clearance operations to prevent the AA from using villages as buffers or shelters – a tactic employed across the country. “At the same time, it’s a warning sign for other villages,” she said, adding that when one village is set ablaze, it sends a signal to other villages not to “accept, shelter or harbor” armed groups. Thant also noted that people are displaced when their village is destroyed, eroding support for armed groups as locals suffer the consequences of the fighting.
The AA has vowed to take control of all of Rakhine by 2027 and success may bring a geopolitical shift in the region. The armed group’s control over Kyaukpyu and Sittwe will give it significant leverage, with both India and China having infrastructure projects in the townships, Steve Ross of the Stimson Center told Bellingcat.
But neither side can control the state without further alleviation of civilian suffering, Ross said. According to UNHRC data, there are almost half a million internally displaced people (IDPs) in Rakhine as of March 30, 2026.
Estimated total IDPs in March-April of each year. Data prior to 2022 is unavailable. Source: United Nations Human Rights Council. Chart: Created on Datawrapper, edited on Adobe Illustrator by Pooja Chaudhuri/Bellingcat
In Sittwe township alone, about 120,000 Rohingya have been displaced by communal conflict since 2012.
“People displaced from other parts of Rakhine State during the war are in Sittwe, hundreds of thousands of civilians,” said Thant, adding that neither side can control the capital without significant loss of life.
There are also 1 million Rohingya refugees in Bangladesh. The futures of both the refugees and IDPs remain uncertain.
“Nobody can go home yet at this stage,” said Thant.
Editor’s note: This article was updated on July 6, 2026 to include response from representatives of the United League of Arakan.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit hereand YouTube here.
The video posted by a state branch of India’s ruling Bharatiya Janata Party (BJP) showed Assam chief minister Himanta Biswa Sarma shooting an image of two men in Muslim skull caps. “Foreigner-free Assam”, read one caption across the video. “Why did you not go to Pakistan?” said another.
Screenshots of the now-deleted video shared by BJP on Feb. 7 showing Assam Chief Minister Himanta Biswa Sarma shooting an AI-generated version of INC leader Gaurav Gogoi (in a white skull cap) and another uni
The video posted by a state branch of India’s ruling Bharatiya Janata Party (BJP) showed Assam chief minister Himanta Biswa Sarma shooting an image of two men in Muslim skull caps. “Foreigner-free Assam”, read one caption across the video. “Why did you not go to Pakistan?” said another.
Screenshots of the now-deleted video shared by BJP on Feb. 7 showing Assam Chief Minister Himanta Biswa Sarma shooting an AI-generated version of INC leader Gaurav Gogoi (in a white skull cap) and another unidentified, bearded man. Source: BJP4Assam/X
One of the men in the photo that Sarma was portrayed as shooting was Gaurav Gogoi, a leader of the Indian National Congress (INC), the BJP’s main competitor in Assam for the state’s upcoming legislative elections next month.
Gogoi has stated that he is Hindu but enjoys visiting different religious sites and observing their norms. He has been photographed wearing traditional Muslim attire during religious occasions such as Eid.
But the image of him in the video shared by BJP Assam, wearing a casual singlet with a skull cap, was not one of those occasions.
Bellingcat has seen several dozen videos posted by the BJP that use generative artificial intelligence (AI) alongside anti-Muslim and anti-Bangladeshi messaging in the border states of Assam and West Bengal in December last year, ahead of legislative elections scheduled in both states for April.
Left: Original photo shared by Gogoi on Jun. 17, 2025. Right: An image shared by BJP Assam that was edited with AI to show Gogoi with a skull cap, beard and Quran. Source: gauravgogoiasm/Facebook, BJP4Bengal/Facebook
Bellingcat analysed 499 social media posts containing photos and videos shared on Facebook, Instagram and X by the BJP’s official accounts in the two states for this time period, finding 194 posts that appeared to meet the United Nations’ definition of hate speech: discriminating against persons or communities based on inherent characteristics such as religion and national origin. Of these, 31 (about one in six of the hateful posts) contained the obvious use of AI-generated imagery.
Chart: Galen Reich
These appear to be part of a larger pattern of politicians and parties globally using generative AI to amplify hateful or divisive content, particularly ahead of major political events such as elections.
Ahead of the New York City mayoral race last year, Andrew Cuomo’s official X account shared, then deleted, an AI-generated video depicting Mamdani eating rice with his hands and a Black man in a keffiyeh shoplifting. In Italy, several opposition parties complained to a communications watchdog after deputy prime minister Matteo Salvini’s League party published a series of AI-generated images depicting men of colour attacking women or police officers. And in the UK, videos by an AI-generated rapper funded by the far-right Advance UK party, with lyrics targeting Muslims, were viewed millions of times.
A Campaign of Hate
Both Assam and West Bengal share a border with Bangladesh. BJP, the world’s largest political party, is currently in power in Assam, where legislative elections are scheduled on Apr. 9. West Bengal, which goes to the polls on Apr. 23, is governed by the Trinamool Congress (TMC).
Map: Pooja Chaudhuri. Source: Goran tek-en, CC BY-SA 4.0, via Wikimedia Commons
US-based international affairs expert Mohammed Zeeshan told Bellingcat that the “dehumanising and debasing” terminology used in India to refer to alleged illegal Bangladeshi immigrants, including by senior ministers, has caused resentment towards India in Bangladesh.
“The situation, in fact, was so bad that Hasina herself had subtly warned the Modi government in public statements that Indian domestic rhetoric was endangering Bangladeshi Hindus, who bore the brunt of that resentment,” Zeeshan said.
Zobaida Nasreen, a professor of anthropology at Dhaka University, said that anti-Muslim rhetoric intensified by BJP leaders reinforces the belief in Bangladesh that Muslims and Bengalis are being collectively targeted in India.
“Viral videos containing this message tend to spread quickly across Bangladeshi media and social platforms especially on Facebook, enhancing perceptions of hostility and triggering anti-India sentiment or nationalist backlash,” she added.
In December, the month our dataset was collected, Dipu Das, a Hindu garment worker, was beaten to death at an anti-India protest in Bangladesh over allegations that he had made derogatory remarks about Islam.
And while the administration led by Bangladesh’s newly elected leader Tarique Rahman has sought to reset strained ties, most of the hateful social media posts we saw posted by the BJP in December attacked Bangladeshi Muslims and/or Bengali-origin Muslims in India, showing how tensions between the two countries continue to influence political messaging in India’s border states.
Bellingcat’s analysis included a total of 202 posts by BJP Assam and 297 by BJP’s West Bengal branch on their official accounts. We also looked at posts shared by BJP’s main opponent parties – 194 from INC in Assam and 357 from the TMC in West Bengal – during the same time period in December.
This included all visual social media posts (containing photos or videos) by each party in December, except those that did not appear to contain any overt political messaging, such as those simply commemorating public holidays. We only counted each photo or video once, regardless of how many platforms it was shared across.
Although all of the major parties contesting in the Assam and West Bengal state elections appeared to use AI-generated imagery in some of their posts, there appeared to be a particularly high concentration of hateful messaging in the ones posted by the BJP’s accounts.
In Assam, we identified 28 posts by BJP using apparently AI-generated imagery, of which 24 carried hateful messaging. Of the 194 INC posts we looked at from December, 41 appeared to feature AI-generated imagery, but none of these appeared to carry hateful messaging.
In West Bengal, we found 14 BJP posts that contained clear indicators of AI-generated imagery, seven of which were hateful. We also identified 15 posts by the incumbent TMC that appeared to feature AI imagery, but none of these appeared to meet the definition of hate speech.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
When contacted for comment, BJP Assam spokesperson Rupam Goswami did not directly respond to questions on the party’s general use of AI but said they did not post any AI-generated photos of Gogoi. “BJP does not stoop so low,” he told Bellingcat.
As for the “point blank” shooting video, Goswami initially said the person responsible had been punished and removed from the party. However, when asked about Sarma saying that he would re-post the video with those he was depicted shooting labelled as “Bangladeshis”, Goswami said, “[Bangladeshis] need to be completely suppressed.”
BJP West Bengal did not respond to multiple requests for comment by Bellingcat via phone and email.
It is important to note that as generative AI technology improves, it can be increasingly difficult to detect AI-generated imagery. Our manual count of AI-generated imagery only included posts that had obvious signs of generative AI such as unnaturally smooth textures and multiple people with the same faces. It is therefore possible that there were other images in our dataset where generative AI was used more subtly.
However, Joyojeet Pal, Professor of Information at the University of Michigan, told Bellingcat that the quality of these visuals, or whether they looked real, was not the priority.
“What politicians in India have understood is that the sociocultural drivers of misinformation are most important for elections, so they harp on about things to the extent that they have started to not care about form over substance. It looks bad? It doesn’t matter,” he said.
More important to voters, according to Pal, was whether they already believed in the narrative contained in the videos, which generative AI could help create more quickly: “AI is helping cement polarised opinions by giving you the kind of content you have already decided you want to engage with.”
When asked about INC’s use of AI, party spokesperson Aman Wadud said that it was obvious that some of the videos they posted were made with AI and that there was no intention to mislead.
“AI can be both destructive and creative. We are using it in a creative manner, we are not using it in a destructive manner. We don’t violate people’s dignity, we don’t falsely accuse people,” he said.
TMC did not respond to Bellingcat’s multiple requests for comment via phone and email by publication time.
Portraying Bengali Muslims as ‘Foreigners’
The largest category of hateful messaging Bellingcat observed in the BJP’s posts targeted Bangladeshi or Bengali-origin Muslims, referring to them as “infiltrators” or “foreigners”. We counted 66 such posts by the BJP’s Assam and West Bengal branches from December, of which eight appeared to contain obvious AI-generated imagery.
One video referencing this theme shows AI-generated visuals of protests against “illegal infiltration” in Assam, with the caption urging people to “wake up” or the country would “turn into Bangladesh”.
A different one uses real footage from past violence in Assam mixed in with images of Muslim men. A song playing in the background accuses them of taking over “Assamese land” and shows AI images of “Assamese” people, i.e. those not in stereotypical Muslim clothing, crying.
An AI-generated image of a crying man in non-Muslim clothing and a traditional Assamese scarf on his shoulders. Source: BJP4Assam/X
Both videos use religious markers to draw a distinction between “infiltrators” – men in skull caps or lungis associated with Bengal-origin Muslims – and “citizens” in non-Muslim attire.
Clothing is often used by the Hindu far-right as a visual shorthand for identity and a deepening religious divide. In 2019, Prime Minister Narendra Modi said of protests against a controversial citizenship law that those responsible for violence could be “identified by their clothes”.
In the hateful posts seen by Bellingcat, both real and AI-generated images of opposition figures – particularly Gogoi – were shown alongside messaging that suggested that they supported “foreigners” or “infiltrators”.
The Center for the Study of Organized Hate (CSOH) also noted, in a 2025 report on AI-generated imagery and Islomophobia in India, that Hindu far-right politicians and media outlets have invoked and reinforced the trope of Muslims as “infiltrators” for years.
“AI-generated images on these themes reinforce associations between Muslim identity and illegality, reinforcing xenophobic and Islamophobic stereotypes. In doing so, they play a powerful role in justifying exclusionary policies and normalising discrimination against Muslims,” the report said.
‘Save Hindus’
Zenith Khan, a data analyst who worked on the CSOH report, noted that AI-generated propaganda was often tightly knit with current political moments, and its impact depended on “timing it right” especially when “people are emotionally charged”.
The violence against the minority Hindu community in Bangladesh has been used by the BJP to raise concerns over the safety of Hindus in India.
Days after Das’ lynching, the Assam state branch of BJP posted a video with an image of his face – except that it was manipulated with AI to show tears streaming from his eyes. “Save Hindus”, said the text accompanying the video.
Posts by BJP’s West Bengal unit also seemed to frame Muslims as criminals or threats. A video, styled after the TV show “Stranger Things”, raised alarms over an “upside down” version of the state under the current government.
A man is depicted being chased by men in skull caps. Arrows label them as “Ralib,” “Galib,” and “Chalib” – a play on Muslim names ending in “-lib” – in case the skull caps left any ambiguity about their Muslim portrayal.
“Stranger Things” themed post that depicts Hindus under threat from Muslims in West Bengal. Source: BJP4Bengal/X
INC filed a police complaint in September last year against the BJP for sharing AI videos targeting Gogoi and the Muslim community, as well as another complaint in relation to the video of Sarma portrayed as shooting two men “point blank” in February.
INC Assam spokesperson Wadud said that no action had been taken on the party’s police complaints as far as he knew.
Disinformation researcher Bharat Nayak told Bellingcat that it has always been tech platforms’ responsibility to control new types of content.
“The goal post can’t shift. This has always been a tech problem,” he said.
When this responsibility is shrugged off, Nayak added, the result is a lack of accountability. “If you’re using old videos from other countries as new, you will have people countering you. But AI-generated videos can be shared without context just to spread hate – like showing people in skull caps – and the ‘when, where, how’ questions vanish.”
Both Meta – which owns Facebook and Instagram – and X have policies against hateful conduct.
Meta also announced in 2024 that it would start adding “AI info” labels to more content detected as AI-generated, while some X users spotted a similar feature introduced on the platform last month. Only five of INC’s AI visuals that we identified – and none of those by TMC or the BJP – had a disclaimer that said “AI-generated”.
Bellingcat reached out to Meta and X for comment on whether the posts we identified breached their terms of use regarding hateful conduct or labelling AI-generated posts. A Meta spokesperson said they were reviewing the flagged content and “will take appropriate action on any violations of our policies”. As of publication, X had not responded.
Kalim Ahmed from Bellingcat’s Discord Community contributed research to this piece.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
A Bellingcat investigation has identified nine Facebook groups with a combined membership of more than 70,000 people, in which coded language has helped illegal wildlife dealers evade bans on the platform for years. Facebook says it prohibits any form of animal trading on its platform.
Investigating the operators behind all nine groups, Bellingcat identified six Facebook profiles that led back to a single broker in Jakarta, Indonesia. This investigation was carried out in partnership with Mon
A Bellingcat investigation has identified nine Facebook groups with a combined membership of more than 70,000 people, in which coded language has helped illegal wildlife dealers evade bans on the platform for years. Facebook says it prohibits any form of animal trading on its platform.
Investigating the operators behind all nine groups, Bellingcat identified six Facebook profiles that led back to a single broker in Jakarta, Indonesia. This investigation was carried out in partnership with Mongabay. You can read their report in English here and in Bahasa Indonesia here.
In an open Facebook group, brazenly titled “West Bogor Animal Selling and Trading Forum,” one member posts an advert for a vulnerable rhinoceros hornbill.
Screenshots of an online advertisement for a rhinoceros hornbill chick, a protected and vulnerable species, posted on Facebook on July 11, 2025.
Commenting on the advert, another member warns: “Just be careful not to get caught.”
Screenshot of a Facebook conversation, translated from Bahasa Indonesia and posted in July 2025. Annotated by Bellingcat.
“That’s the risk,” replies the seller.
Under Indonesian law, the capture, trade, or possession of a rhinoceros hornbill is punishable by up to five years’ imprisonment or a fine of up to Rp100 million (US$6,000). (According to Statistics Indonesia, the average monthly wage in August 2025 was just over Rp3 million or US$180.)
Meta also states that the buying and selling of animals on its platforms is prohibited. However, in this group, along with eight others identified by Bellingcat, animals have been traded in plain sight for years, including wild and protected species. Three of the nine groups have been live on Facebook for at least five years. Four have been active for 12 months or more, and the remaining two were created in 2025.
Screenshots of tortoises, monkeys, and owls for sale, posted in Facebook adverts in October 2025.
In one of the most active groups, West Bogor Animal Selling and Trading Forum, more than 200 adverts were posted in a single week. Of these, 18 advertised vulnerable species, including these two infant silvery gibbons.
Screenshots of two infant silvery gibbons advertised on Facebook on May 10, 2025.
Otters were also frequently posted in the group. Popular in the Southeast Asian pet trade, most otter species are protected due to declining numbers in the wild. However, because many of the adverts were for infants, it was not always possible to determine which otter species was being sold, and therefore whether it was protected.
“Using Codes So The Group Stays Safe”
Despite Facebook’s total ban on animal trading, including pets, in the group titled: Civet/Pet Buying and Selling in the Greater Jakarta Area, members were instructed in the “About” tab to “prioritise using codes so the group stays safe from being banned.”
Screenshot of the group’s About description. Translated and annotated by Bellingcat.
Alphanumeric codes were used to discuss animal prices in eight of the nine groups identified by Bellingcat. According to the Indonesian news outlet Jateng Today, the use of pricing codes, intended to circumvent Facebook’s automated moderation systems, is not uncommon among animal traders on the platform.
Such codes use the letters A, B, and C to denote different Indonesian rupiah denominations. A stands for a Rp100,000 note (about US$6), while B represents a Rp50,000 note (about US$3). An accompanying number specifies the quantity, so A3 indicates three Rp100,000 notes.
Screenshot of a conversation on Facebook discussing the price of animals. Blurring by Bellingcat.
In the post below, one member asks, “A2 dapet apa?” – “What does A2 (Rp 200,000; US$12) get you?”
Screenshot from the Facebook group ‘Buying and Selling civets/pets in the Greater Jakarta area,’ posted on Facebook, August 6, 2024.
The post received 69 replies, with members offering everything from otters to owls, civets and geckos.
The term “Wc” – a common shorthand in animal trading groups for “wild-caught” – was also frequently used across all nine groups. Under Indonesian law, even if a species is not listed as vulnerable or protected, capturing and selling wild animals without a permit is illegal.
Asked whether its moderation systems could detect cost codes (as text or embedded in images) or key terms such as WC (when found next to images of animals), Meta responded:
“Bad actors constantly evolve their tactics to avoid enforcement, which is why we partner with groups like the World Wildlife Fund and invest in tools and technology to detect and remove violating content.”
The Operators
While investigating the operators behind all nine groups, Bellingcat identified six Facebook profiles that led back to one individual broker based in Jakarta.
By navigating to the “People” tab in one of the groups, a list of admins and moderators appears, including an account referenced below as AB. Despite AB’s profile being locked, a search with the term “wa.” (WhatsApp’s click-to-chat feature) returned dozens of animal adverts alongside a phone number.
Screenshot of AB’s Facebook post including a phone number. Posted June 11, 2025.
Using the phone number to search for AB’s historic posts, six out of the nine groups under investigation were found to have adverts for vulnerable species, including this advert for a binturong.
Screenshot of an advert for a “Bintu” short for binturong. Posted by AB, September 2024.
Listed as vulnerable by the International Union for Conservation of Nature (IUCN), keeping a binturong, let alone trading it commercially, is prohibited under Indonesian law.
AB has also advertised this “Celepuk Wc”, a wild-caught scops owl, seen below. Although the species itself is not protected, selling a wild-caught owl in Indonesia without a permit (which are tightly regulated) violates Indonesian law.
Owls for sale, posted by AB. Left: Labelled “Wc” for wild-caught. Right: “BC” for bred in captivity.
By following the phone number shared by AB, five more Facebook profiles were uncovered. The six profiles frequently shared similar adverts, often within days of each other, for the same species, sometimes featuring a similar interior background, and always listing the same telephone number.
Six different accounts posting similar-looking animal adverts, while all using the same contact phone number.
Late last year, one of the accounts referenced below as W, posted this wreathed hornbill, a protected species in Indonesia.
Screenshot of an advert for a wreathed hornbill. Posted by Waa, November 2025.
Of the six profiles, only one, named Azie Soka Smithh has ever posted personal data, including a profile picture of a man with a child.
An advert for a civet, posted by Azie Soka Smithh and tagging the same phone number as used by the other five accounts.
Further investigation into Azie Soka Smithh confirmed their presence on other platforms, including Telegram and Instagram. However, their full legal name remained unknown. While searching for visual clues to their location, it became apparent that the vast majority of images had been tightly cropped, revealing little about their whereabouts – except for a handful of images that appeared to have been taken at the same location: a pet shop.
In the adverts shown below, a poster can be seen on the wall behind the cage displaying the shop name Station Sato Exotic and a phone number. Of all the images seemingly taken in the same shop, none featured species protected under Indonesian law. However, the long-tailed macaque shown below is considered endangered according to IUCN due to declining numbers in the wild.
Adverts posted by two different accounts but with the same shop name and phone number visible in the background. The right image features a long-tailed macaque.
A Google search for the shop’s name and number returned a Google Maps listing for Station Sato Exotic. A man named “beni” had left a five-star rating as well as several dozen photos and videos of the pet shop’s interior, including one that appeared to show a man sitting next to an identical poster as seen in the animal adverts.
Screenshot of Beni’s Google review, including (right) a video of a man sitting beside a poster for Station Sato Exotic. Posted July 2021.
According to beni’s Google account, his full name is Beni Abdul Hamid (translated from Arabic). His bio reads: “We sell various kinds of accessories, cages, animal feed, etc” (translated from Bahasa Indonesia).
Of the 16 photos and 25 videos posted by Beni, several showed a left hand holding animals up to the camera, with a distinctive mole visible on the wrist. A seemingly identical mole appeared in several of the adverts posted by the six Facebook accounts sharing the same phone number. Notably, the mole and wrist were not seen holding species protected under Indonesian law. However, the long-tailed macaque shown below is considered endangered according to IUCN.
A distinctive mole appears in multiple animal adverts posted by (left) Beni on Google Listings, (centre) AB on Facebook and (right) another of the six accounts using the shared phone number. The centre and right images feature a long-tailed macaque.
Upon visiting Station Sato Exotic, our partners at Mongabay confirmed that Google reviewer Beni Abdul Hamid was in fact the owner. His son, Jordan Bastian, who was present on the day, told their reporter he now manages the shop on his father’s behalf.
Bastian confirmed that it was his wrist and mole in the adverts and that he had taken all of the photos inside the shop. However, he said he was not behind any of the six Facebook accounts and that they were most likely run by a local broker. He explained that his business relies on a network of brokers operating on Facebook and WhatsApp. He sends them photos of the animals he has for sale, and they handle sourcing and organising everything with the buyer in exchange for a cut of the profits.
“I’m a broker. I’m involved in marketing the animals, so I provide the photos,” said Bastian. “I don’t want to know about the buyer.”
When shown the Facebook account for Azie Soka Smithh, Bastian confirmed that the man in the profile picture was a local broker, but one who seldom visited the shop.
Station Sato Exotic Pet Shop also has an online presence on Tokopedia, a major Indonesian marketplace. The platform’s guidelines prohibit the sale of endangered species, but are not clear regarding the sale of other animals, including pets.
Of Station Sato Exotic’s 71 current listings, the large majority have been miscategorised. Animals are listed as tools, toys, aquarium decorations and books. They are also miscategorised as other species; for example, birds and squirrels have been listed as hamsters or reptiles.
One advert features a vulnerable cuckoo species, the Sunda Coucal. Endemic to Java and numbering fewer than 10,000, this bird has been listed as vulnerable since 1994.
Screenshot of Station Sato Exotic’s Tokopedia page promoting the sale of a vulnerable cuckoo species. The page reports that four birds have already been sold.
Asked whether he had sold many animals via Tokopedia, Bastian said his account had been blocked after he was banned for selling squirrels. When shown the advert above for the Sunda Coucal, he said he was surprised to learn it was classified as vulnerable. Tokopedia did not respond to requests for comment regarding an advert for a vulnerable species appearing on their platform.
On the sale of protected or vulnerable species more broadly, Bastian admitted he had in the past, but has since stopped, describing “the risk is big” and saying he prefers to “play it safe.”
After contacting the local authorities for comment, three officers from the West Java Natural Resources Conservation Agency (BBKSDA) made a surprise visit to Station Sato Exotic, due to the shop having previously been reported for selling protected species. Head of Conservation Stephanus Hanny said that upon arrival, “We went inside and checked every animal… We did not find any protected species.” He added that even the sale of non-protected wildlife requires a permit, which the shop does not currently hold. However, since it’s not a criminal offence, Hanny said they could only issue the owners with a warning.
Bellingcat also contacted the phone number associated with Azie Soka Smithh. The person replied, confirming they managed all six accounts but denied selling any animals, including protected and vulnerable species. “I’m just a hobbyist. An animal lover,” they said.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
Given that the account had been found advertising vulnerable and protected species for sale, the Indonesian Director General of Forestry Law Enforcement, Dwi Januanto Nugroho, said authorities would investigate. Asked how their team of investigators was adapting to the illegal wildlife trade growing online, Nugroho replied:
“Criminal behaviour continues to reproduce itself in order to survive. In fact, it can evolve faster than the law enforcement system itself. In response …cyber patrols and desk analysis via the operations room will continue to be intensified, while we further optimise support from volunteer networks, working partners, and public participation.”
After contacting Meta, all six accounts, including Azie Soka Smithh, and all nine groups, totalling 70,000 members, were shut down. Meta confirmed: “We removed the Facebook groups and profiles in question for violating our Restricted Goods and Services Policy.”
Merel Zoet and Claire Press contributed to this report.
Bellingcat is a non-profit and the ability to carry out our work depends on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here and Mastodon here.
A shipwreck in India, an ammunition seizure in Senegal, and a raid on an oil tanker in Malaysia – all three incidents involve ageing vessels, operating with false papers and one recurring figure: Captain Suniel Kumar Sharma.
For over a decade, Sharma has been condemned by the governments of Dominica, Guyana, Samoa, the Federated States of Micronesia and Eswatini, as well as the UN International Maritime Organisation (IMO), for issuing fraudulent paperwork to vessels, including false flag cert
A shipwreck in India, an ammunition seizure in Senegal, and a raid on an oil tanker in Malaysia – all three incidents involve ageing vessels, operating with false papers and one recurring figure: Captain Suniel Kumar Sharma.
In a recent interview with the Financial Times, Sharma said his most prominent flag registry, the International Maritime Safety Agency of Guyana (IMSAG), was no longer operational. However, a Bellingcat investigation has found certificates issued by IMSAG as recently as December 2025. In the same interview, Sharma denied setting up any more registries. Yet Bellingcat has found evidence of a newly launched website linked to Sharma offering flag registration in Nicaragua.
The Basra Star became a local tourist attraction during the five years it lay rusting on the beach. Instagram post, December 2025.
The insurance report states Basra Star was sailing under a Samoan flag and its classification society (the company that certifies the vessel as seaworthy) was Ascent Navals.
Two years before MT Basra Star ran aground, the Samoan government and the IMO issued a warning about a fraudulent company called Ascent Navals, and its director, Captain Suniel Kumar Sharma, for appearing to operate on behalf of Samoa, but without official authorisation.
Bellingcat contacted the vessel’s owners, Shat Al Arab Marine Supply LLC, the insurance surveyors, Uday Bhogate & Associates, and Ascent Navals and its director, Suniel Kumar Sharma. None responded to requests for comment.
Nearly two years after Basra Star was shipwrecked, another ageing vessel, Eolika (IMO 8214968), was found operating under a false flag while laden with illicit cargo. At the port of Dakar, Senegalese customs officers boarded the 39-year-old cargo ship and discovered three concealed containers of ammunition, reportedly worth US$5.2 million. Eolika was flying a false Guyana flag.
In an open letter, the IMO, together with the Guyana authorities, denounced the flag under which Eolika was sailing as false. They warned of a fraudulent company, the International Maritime Safety Agency of Guyana (IMSAG), for flagging vessels without authorisation from any flag state. Guyana’s police force said it would investigate “this rogue enterprise led by Captain Suniel Kumar”, together with Interpol.
There is no suggestion that Sharma or IMSAG took part in the transport of illicit goods. The IMO warning was issued in response to IMSAG supplying false paperwork, which then enables vessels to operate without oversight. Flying a false flag for a registry that doesn’t exist voids any insurance, risks crew safety and threatens environmental harm, as seen with the Basra Star.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
Nora (left) and Rcelebra (right) moored together during an unauthorised ship-to-ship transfer off Penang. Source: MMEA/Facebook
Both captains and 53 members of the crew were detained. The cargo of crude oil was valued at more than RM512 million (US$130 million), according to the MMEA.
53 crew members were arrested, according to MMEA. Source: MMEA/Facebook
However, within days, both tankers were released. Fined the maximum penalty of RM300,000 (US$76,000) for an unauthorised ship-to-ship transfer, the MMEA acted to enforce Malaysia’s environmental and maritime safety laws, but not International and UN sanctions. Asked if this was within its remit, the MMEA did not respond to our request.
There is no indication that Sharma or IMSAG knowingly issued flags to criminal actors. But by providing false paperwork, the IMO warn that fraudulent flag registries are enabling high-risk vessels to continue operating.
The promise of investment and the signing of an MoU
Crucial to understanding how IMSAG has continued to operate as a fraudulent registry for so long is that it was once legitimate.
Back in 2021,Guyanan media described how IMSAG was making investments of US$35 million, creating hundreds of jobs, and constructing a state-of-the-art training facility – all presented as a way to grow Guyana’s maritime industry.
Sharma (centre) and his wife (centre-right) pose with Guyanese officials after announcing a US$35M investment in Guyana’s maritime industry, March 2021. Source: Ministry of Public Works/Facebook.
Screenshot of Guyana’s official notice terminating all relations with Sharma. Source: MARAD.
Whilst the MoU was in effect, IMSAG had served as Guyana’s official international ship registry. The domain imsag.org was used to register and flag vessels on its behalf. But after the MoU was terminated, instead of shutting the company down, IMSAG continued to operate without Guyana’s authorisation. A redacted version of the MoU is still live and being promoted on IMSAG’s website.
Screenshot from imsag.org, January, 2026. The yellow box added by Bellingcat highlights the continued promotion of the MoU, which Guyana terminated in 2021.
In a recent interview with the Financial Times, Sharma confirmed he had set up a ship registry in Guyana, but said it had been “discontinued” after the authorities withdrew consent. He also said the domain imsag.org was “not operational just informative”.
Bellingcat recently downloaded 230 vessel certificates for 87 ships from imsag.org, including the sanctioned tanker recently seized by the Malaysian authorities, Nora.
Nora is still broadcasting the call sign ‘8RKK9’ as shown in this certificate issued by IMSAG.
Counter to Sharma’s claims that IMSAG was no longer operational, all 230 certificates found by Bellingcat were issued well after the MoU was terminated in March 2021, including some as recently as December 2025. Of the 87 certified vessels 63 were oil tankers, with an average age of 24 years. Diana 1 (IMO 9212229), for example – a 26-year-old oil tanker last seen in Libya – was issued a certificate by IMSAG on June 26 2025.
According to Equasis data, Diana 1 hopped to a false Guyana flag on July 1 2025.
Screenshot of Equasis data for Diana 1 showing flag as Guyana False.
Neither Sharma nor IMSAG responded to our request for comment regarding our findings that IMSAG had continued issuing certificates as recently as December 2025, despite Guyana having terminated the MoU and withdrawn its authorisation.
For a full list of the 87 vessels, including certificates and details of our methods, click below to expand:
See full certificate list and methodology
The table below lists all 87 vessels and 230 certificates that Bellingcat found records for on imsag.org. Hover over each certificate for details, or click to see an archived screenshot. Each vessel’s flag history has been pulled from the maritime database Equasis to compare when the vessels switched to the Guyana flag and when they were issued a certificate from IMSAG.
Methods:
The IMSAG website allowed users to search using either a “Certificate Number” or an “Official Number.” The search returned information about a vessel, including the dates on which certificates were issued. While these certificate numbers were not publicly disclosed, Bellingcat found a seafarer certificate via a Google search for “site:imsag.org filetype:pdf”, which locates PDFs hosted on IMSAG’s website. By changing the URL to look for ship certificates instead, imsag.org returned a vessel certificate for the oil tanker, Tranquilus.
Bellingcat then tested sequential variations of certificate and official numbers, returning 230 certificates issued by IMSAG. As not all certificate numbers were sequential, this index represents only a partial view of IMSAG’s recent activity.
Expanding Operations in Nicaragua
In Sharma’s interview with the Financial Times, he denied he was setting up any more registries and said he had left the maritime sector entirely. Yet Bellingcat has found evidence of a new registry with links to Sharma that appears to be offering flag registration in Nicaragua.
In July 2025, the domain niataregister.com was launched, promoting the Nicaragua International Aquatica Transportation Administration (NIATA).
The website is active. Bellingcat found a certificate issued as recently as February 2 for the sanctioned tanker and member of the shadow fleet, Al Jafzia (IMO 9171498, sanctioned under the name Chil 1).
Screenshot of a vessel certificate issued for Al Jafzia, February, 2026.
Despite multiple requests, the Nicaraguan authorities did not respond to our questions as to whether they had heard of NIATA or had any official partnership with the company.
According to the IMO’s GISIS database, Nicaragua has not approved any organisation to issue flags on its behalf. The IMO also confirmed directly to Bellingcat that Nicaragua had provided no further information beyond what was visible in GISIS at the time of publication.
Bellingcat downloaded all publicly available forms from NIATA’s website. Analysing document metadata revealed the creator of the documents as ‘Oceaniek Technologies’.
Screenshots: (left) form downloaded from the NIATA website, December 2025; (right) form metadata showing author as Oceaniek Technologies.
Navigating to the Oceaniek Technologies homepage (shown below), under the headline ‘Our Products’ 11 companies were promoted in a looping carousel up until August of last year. It now features only five, spanning a wide range of industries, including a cricket league, a hospital and streaming services.
Top – Oceanik Technologies homepage. Bottom – four of the 11 companies promoted up until August of last year. Shown left to right: IMSAG, a cricket league, streaming services, and a hospital. Screenshots captured August, 2025.
The managing director of Oceanik Technologies, according to his own LinkedIn, is Suniel Sharma. Sharma has also been photographed by local Indian media, cited as the “MD of Oceanik Technologies”.
Screenshot of Sharma’s LinkedIn profile from December 19 2025.
Also among the 11 companies promoted up until August of last year were the Nautilus Times and Nautilus Register.
Screenshots taken August, 2025.
Promoting vessel classification services, Nautilus Register, appears as an entity of interest in OpenSanctions due to its ties with several sanctioned vessels, including members of the shadow fleet. Sharma’s own LinkedIn lists him as the Director General of the Nautilus Register.
Screenshot of Sharma’s LinkedIn profile, dated 19 Dec.
Bellingcat confirmed nautilusregister.net is still active, issuing classification certificates as recently as January 2026 (shown below). The IMO told Bellingcat that Nautilus Register is not listed as a recognised organisation in their database, GISIS.
Certificate issued January 13 2026, via nautilusregister.net. Metadata contained within the PDF listed Sharma as the author.
A search for the second company, Nautilus Times, led to a website offering dozens of training courses, from cadetship to firefighting, as well as competency training.
Competency training is a requirement for all seafarers. Crew members may attend a course in any jurisdiction, but it’s then up to the flag state (the country in which the vessel is registered) as to whether that training is recognised.
According to the Nautilus Times website, a crew member can enrol in any one of six jurisdictions, as shown below, including Guyana and Nicaragua.
Screenshot of the Nautilus Times website offering competency training fees for six jurisdictions, highlighted by a yellow box. Annotations by Bellingcat.
After contacting all six jurisdictions, the official Maritime Administration Department (MARAD) of Guyana confirmed that Nautilus Times was not authorised to issue certificates to seafarers on their behalf. They reiterated that they had no relationship with Nautilus Times or Sharma. St Maarten has previously said that it does not have an international flag registry and therefore does not issue competency certificates. No other jurisdictions replied to our request.
Bellingcat contacted both the Nautilus Times and Sharma to ask why the site was advertising courses on behalf of Guyana and St Maarten without their authorisation. Neither replied to our request for comment.
Finally, two more companies embedded in the carousel on Oceaniek Technologies’ homepage, but deleted after August 2025, were the MSTA Registry and Aruba Maritime.
Screenshots of two of the 11 companies promoted in a carousel embedded on Oceanik Technologies’ homepage. Captured August 2025.
Subscribe to the Bellingcat newsletter
Subscribe to our newsletter for first access to our published content and events that our staff and contributors are involved with, including interviews and training workshops.
Neither Oceaniek Technologies nor Sharma responded to our request for comment regarding the nature of these companies’ connection to Oceaniek Technologies.
Merel Zoet and Claire Press contributed to this report.
Bellingcat is a non-profit and the ability to carry out our work depends on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here and Mastodon here.