A seller claims to offer Israel’s 2026 population registry, but checks show the 9.2 million records are authentic data dating back to 2005.
A vendor on a well-known leak forum claims to have breached Israel’s Population and Immigration Authority and is selling the entire national registry, 9.2 million records covering essentially the whole country. Ransomnews reviewed the sample the seller published, and the data checks out as genuine. It’s just not from 2026, or anywhere close to it.
The
A seller claims to offer Israel’s 2026 population registry, but checks show the 9.2 million records are authentic data dating back to 2005.
A vendor on a well-known leak forum claims to have breached Israel’s Population and Immigration Authority and is selling the entire national registry, 9.2 million records covering essentially the whole country. Ransomnews reviewed the sample the seller published, and the data checks out as genuine. It’s just not from 2026, or anywhere close to it.
The listing promises national ID numbers, addresses, phone numbers, birth and death dates, immigration dates, and family links for every person in the file, packaged as a 7.5 GB database.
To make it look convincing, the seller attached records supposedly belonging to the Netanyahu and Herzog families, including one person who died back in 1976 still appearing as a standard entry.
“To make the data look impressive, the seller attached a section matching records to well-known Israelis, presented as members of the Netanyahu and Herzog families, including a figure who died in 1976 and appears as a deceased record.” reads the report published by Ransomnews. “This is authenticity bait, and we have redacted it. It is worth noting for one reason: a registry that carries the long-deceased is a registry that behaves like a real civil register, and that detail matters when you try to work out how old this data is.”
That detail alone hints at how old this file actually is, a current registry wouldn’t be built around decades-dead public figures as its proof of authenticity.
Ransomnews’s technical checks back up that the data itself is real, even if the “2026” label isn’t. Israeli national ID numbers carry a mathematical check digit, so random numbers fail that test roughly nine times out of ten, and in the 100,000-record sample, all but three passed. Family-unit IDs also clustered together far more often than random chance would produce, the kind of pattern you only get when data comes out of a genuine household-structured government database.
Then comes the detail that undoes the entire “current” framing. Every date field in the sample, births, deaths, immigration dates, internal record updates, stops cold in 2005. Nobody in the file was born, died, immigrated, or had a record touched after that year, which is simply impossible for a live 2026 national registry.
“Here is the finding that undoes the headline. We checked the newest value in every date field in the sample. Birth dates stop at 2005. Aliyah dates stop at 2005. Death dates stop at 2005. The internal “record updated” field stops at 2005, and it ramps up year over year through the early 2000s and then falls off a cliff.” continues the report. “Nobody in this data was born, immigrated, died or had their record touched after 2005. A live 2026 registry would contain millions of people born in the last twenty years. There are none.”
That specific cutoff points to something with a long, ugly history. Back in 2006, an employee at Israel’s Ministry of Social Affairs copied the entire population registry and took it home, and the file eventually became a searchable tool known as “Agron 2006” that spread across file-sharing networks for years, leading to six arrests by Israel’s Justice Ministry in 2011. Same authority, same nine-million scale, same field structure, same 2005-into-2006 cutoff. It’s very hard to look at this listing and not see the same file resurfacing under a fresh coat of paint.
When Ransomnews challenged the seller directly about the outdated timestamps, he pushed back, insisting the published sample was only the oldest portion of the database and sent over what he said were the final rows to prove the rest was current. Those final rows, the actual tail end of the 9.22 million records, also stopped dead in 2005. He’d essentially handed over his own rebuttal evidence and it confirmed exactly what he was trying to disprove.
The seller, going by GordonFreeman, isn’t some throwaway account either. He’s a VIP member with a strong reputation built on dozens of threads, mostly recycled national databases from Ecuador, Venezuela, Panama, Spain, and Guatemala.
That pattern matters: a vendor whose whole catalogue is repackaged government data isn’t necessarily lying about possessing the file, he’s just misrepresenting when it was collected, and reputation built on volume tends to reward exactly that kind of relabeling.
None of this means people should shrug it off. A national ID number issued once never expires, and names, birthdates, and family relationships don’t age out of usefulness for identity theft or social engineering just because the file is twenty years old. The right response here isn’t panic about a fresh 2026 breach, since that framing is exactly what the seller wants people to believe, but old, permanent identifiers still recirculating is its own quieter, longer-lasting problem.
“Old breaches do not die, they get re-listed. The Israeli population registry is one of the most durable examples in the world, and its reappearance on a 2026 forum under a “current” label is a reminder that data with permanent identifiers has a very long tail. If you cover or respond to this, the two questions that matter are always the same: is the data real, and is it new. Here the answer is yes and no.” concludes the report. “The check digits, the household structure and the immigration demographics say the data is genuine. The hard wall at 2005 says it is not new.”
Note The July 2026 Dark Web Breach Incident Trend Report was compiled based on data breach cases posted on deep web and dark web forums. Due to the nature of some posts, it is difficult to fully verify their accuracy; some posts related to South Korea included AI-generated false data or cases where it could […]
Note The July 2026 Dark Web Breach Incident Trend Report was compiled based on data breach cases posted on deep web and dark web forums. Due to the nature of some posts, it is difficult to fully verify their accuracy; some posts related to South Korea included AI-generated false data or cases where it could […]
Yet another Israeli mass surveillance company:
Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it. That enables cops to keep tabs on any phones in the vicinity whether they’re owned by a suspect in a case or not. Cognyte’s contract with the state of Texas reveals that the simulator, called FalcoNet, can be concealed within the vehicles, hidden in a backpack for on-foot missions or attached to a helicopter. It’s the
Made by Israeli surveillance company Cognyte, the tech simulates a mobile phone tower, which forces nearby phones to connect to it. That enables cops to keep tabs on any phones in the vicinity whether they’re owned by a suspect in a case or not. Cognyte’s contract with the state of Texas reveals that the simulator, called FalcoNet, can be concealed within the vehicles, hidden in a backpack for on-foot missions or attached to a helicopter. It’s the same technology as the infamous Stingray, one of the original cell-site simulators made by defense giant L3Harris.
O IDCiber Threat Intelligence Center, por meio do monitoramento contínuo de fontes abertas, fóruns clandestinos e canais especializados, identificou a divulgação de uma alegada base de dados associada ao domínio governamental www.gov.il, anunciada por um ator de ameaça em 22/06/2025. Segundo a publicação analisada, o grupo afirma ter explorado uma vulnerabilidade de API e obtido acesso não autorizado a informações de aproximadamente 268.938 registros de cidadãos, contendo dados pessoais diversos
O IDCiber Threat Intelligence Center, por meio do monitoramento contínuo de fontes abertas, fóruns clandestinos e canais especializados, identificou a divulgação de uma alegada base de dados associada ao domínio governamental www.gov.il, anunciada por um ator de ameaça em 22/06/2025. Segundo a publicação analisada, o grupo afirma ter explorado uma vulnerabilidade de API e obtido acesso não autorizado a informações de aproximadamente 268.938 registros de cidadãos, contendo dados pessoais diversos. As evidências observadas incluem amostras de registros supostamente extraídos da base comprometida e disponibilizados em plataforma pública de compartilhamento de conteúdo. Em conformidade com as melhores práticas de proteção à privacidade, os dados pessoais identificáveis (PII) presentes nas amostras foram anonimizados nesta análise, não sendo reproduzidos nomes, documentos, telefones, endereços, e-mails, identificadores ou quaisquer informações que permitam a identificação direta de indivíduos.
IDCiber Threat Intelligence Center
A análise preliminar indica que o conjunto de informações alegadamente exposto contém categorias de dados de elevada sensibilidade, incluindo dados cadastrais, informações demográficas, informações de contato, dados de localização e outros atributos pessoais. Caso a autenticidade e atualidade da base sejam confirmadas pelas autoridades competentes, o incidente poderá representar riscos significativos de fraude, engenharia social, campanhas de phishing direcionado, roubo de identidade, comprometimento de contas e outras atividades criminosas. O anúncio também demonstra intenção de monetização dos dados por parte do ator de ameaça, que disponibilizou canal de contato para potenciais interessados na aquisição do conteúdo.
Até o momento da análise, as evidências observadas permitem confirmar a existência de uma publicação reivindicando a violação e exibindo amostras de registros, porém a validação integral da autenticidade, integridade, abrangência e origem dos dados requer investigação técnica complementar pelas entidades responsáveis. Considerando o potencial impacto sobre cidadãos e organizações governamentais, recomenda-se a realização de procedimentos de resposta a incidentes, validação dos dados expostos, revisão dos controles de acesso, análise de vulnerabilidades em APIs, monitoramento reforçado de credenciais e comunicação adequada às partes potencialmente afetadas.
IDCiber Threat Intelligence Center
Classificação do incidente: Vazamento de Dados (Data Breach)
FBI and Google disrupt NetNut after domains linked to its residential proxy network are seized, exposing abuse of 2 million TVs and streaming devices worldwide.
FBI and Google disrupt NetNut after domains linked to its residential proxy network are seized, exposing abuse of 2 million TVs and streaming devices worldwide.
Cyberbit is closing its Israeli operations and laying off local staff as the former Elbit Systems spin-off grows mainly in the US after buying RangeForce.
Cyberbit is closing its Israeli operations and laying off local staff as the former Elbit Systems spin-off grows mainly in the US after buying RangeForce.
The fragile ceasefire agreed between Israel and Hezbollah last month is holding.
But satellite imagery shows that at least 46 of 54 towns and villages within the Israel Defense Forces (IDF) “Yellow Line” in southern Lebanon have been heavily damaged or, in some cases, entirely flattened.
Much of the destruction and demolition has taken place in recent weeks.
Bellingcat’s satellite imagery analysis examined towns and villages identified on OpenStreetMap, a community-driven map database
The fragile ceasefire agreed between Israel and Hezbollah last month is holding.
But satellite imagery shows that at least 46 of 54 towns and villages within the Israel Defense Forces (IDF) “Yellow Line” in southern Lebanon have been heavily damaged or, in some cases, entirely flattened.
Much of the destruction and demolition has taken place in recent weeks.
Bellingcat’s satellite imagery analysis examined towns and villages identified on OpenStreetMap, a community-driven map database. Medium resolution PlanetScope satellite imagery covering each of the locations was provided by Planet Labs, a US company that recently restricted some of its imagery in the Middle East.
Bellingcat is sharing the annotated PlanetScope imagery for the dates of March 2 and May 8, 2026, showing the scale of damage that has occurred during roughly the first two months of the US-Israeli war against Iran.
The towns and villages detailed in the map are colour coded. Red shows locations that have suffered varying degrees of damage or destruction, while yellow shows locations that were damaged prior to the US-Israeli war with Iran. White shows locations that have not been significantly damaged at time of publication.
Scroll and zoom to see damage throughout southern Lebanon in each of the date tabs. The first image is from March 2, 2026, shortly after the US and Israel attacked Iran. The second image is from May 8, 2026, more than two months after the start of the war and amid a fragile ceasefire between Israel and Hezbollah. PlanetScope imagery via Planet Labs PBC.
Israel’s Defence Minister, Israel Katz, is reported to have stated that “all homes in Lebanese villages near the border will be destroyed — in accordance with the Rafah and Beit Hanoun model in Gaza”. The aim, Katz said, is to “remove, once and for all, the threats near the border”. Israel has adopted similar methods of flattening buildings and homes close to Israel’s border in Gaza.
The large-scale destruction in southern Lebanon has been reported by multiple outlets including the BBC, CNN, SkyNews and The New York Times. These reports have shared images from several towns and villages, but Bellingcat is publishing satellite imagery for the entirety of southern Lebanon. The changes between the two dates show the scale and pace of destruction.
Everything south of Lebanon’s Litani and Zahrani Rivers has been under evacuation orders issued by the IDF since early March, with regularupdateswarningresidents to leave ahead of airstrikes.
Much of the destruction within the “Yellow Line” appears to be from either controlled demolitions using explosives or construction vehicles. The IDF has shared numerousvideosshowing large-scaledemolitions conducted in the towns and villages in southern Lebanon, while videos shared elsewhere on social media show the aftermath — large parts of towns like Beit Lif or Kheim reduced to rubble.
One particularly large explosion took place in the small village of Qantara, where the IDF says it found two large tunnel systems built by Hezbollah.
The tunnels were detonated with 450 tonnes of explosives, leaving large parts of the village obliterated. Another video released by the IDF showed some of the few remaining buildings in the nearby village of Aadashit being demolished with explosives. The IDF claimed the buildings were “Hezbollah infrastructure”.
Before and after imagery from Planet Labs shows the villages of Qantara and Aadshit in southern Lebanon on March 2 and April 30, 2026. The April imagery shows the aftermath of two large demolitions conducted by the IDF. Large parts of both villages have also been demolished. The UNP 7-1 label details the position of a UN peacekeepers facility.
Bellingcat contacted the IDF for comment on the details in this story but did not receive a response before publication.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
The Israeli Air Force (IAF) has dropped 5,000 bombs on Iran since the United States and Israel launched an attack last week, according to a statement by the IAF on March 4.
Bellingcat has monitored weapons used in the first few days of the war, and strikes across the region, including those that caused civilian harm. Some weapons, such as the US Precision Strike Missile, have seen their first use in combat. A variant of the Tomahawk missile, previously unknown to the public, was also used.
The Israeli Air Force (IAF) has dropped 5,000 bombs on Iran since the United States and Israel launched an attack last week, according to a statement by the IAF on March 4.
On March 3, the IAF posted three images in threeseparateposts showing a bomb not publicly seen in Israeli service before. The Israel Air Force released these photos accompanied with claims they were of jets participating in the strikes on Iran. Experts told Bellingcat that this bomb appears to have an incendiary component, and may be one intended to destroy chemical or biological warfare agents.
Photo of an Israeli Air Force jet purportedly participating in strikes, equipped with two of these bombs (far left and far right). Source: Israeli Air Force.
The images appear to show 2,000-pound-class air-delivered bombs fitted with Joint Direct Attack Munition (JDAM) guidance kit with a red band around the nose. Red is commonly used to denote an incendiary, while yellow indicates high explosive effect.
Image of a bomb with the body of a MK 84 2,000-pound-bomb, but with a red band near the nose, and a US JDAM guidance kit. The image is cropped by Bellingcat to focus on the bomb. Source: Israeli Air Force.
We identified key details about the munition and shared the images with two weapons experts.
Apparent Similarities to the MK 84
Dr N.R. Jenzen-Jones, the director of Armament Research Services (ARES), a weapons intelligence consulting company, told Bellingcat these images show a 2,000-pound-class air-delivered bomb fitted with a Joint Direct Attack Munition (JDAM) guidance kit.
Frederic Gras, an Explosive Remnants of War (ERW) expert, also told Bellingcat that the bomb could be of the US MK 80 series, or an Israeli copy, and has a JDAM guidance kit.
Left: 2,000-pound bomb with red band and US JDAM guidance kit posted by the IAF. Right: Standard MK 84 2,000-pound bombs with US JDAM guidance kits. Sources: IAF and SrA Karalyn Degraffenreed/DVIDS.
The US JDAM bomb guidance kit is designed for use with bombs that use the MK 80 series bomb bodies, and the closely related BLU-109 “bunker buster” body.
The Open Source Munitions Portal added the munition to their website on March 3, describing it as “visually similar to a MK 84 general purpose aerial bomb”, while noting that “the marking scheme is distinctly different”. The War Zone also reported on these distinct markings, and possible munitions it could be.
Open Source Munitions Portal’s (OSMP) entry on the bomb, with an analyst note. The OSMP is jointly run by Airwars and ARES, and entries undergo a review by at least two experts. Source: Open Source Munitions Portal.
“The combination of yellow and red bands probably indicates both a high explosive and incendiary payload, which would be consistent with a 2,000-pound-class bomb of MK 84 form factor known as the BLU-119/B Crash Prompt Agent Defeat (CrashPAD),” Dr Jenzen-Jones told Bellingcat.
Frederic Gras, an Explosive Remnants of War (ERW) expert said that the US and Israel both use red markings to indicate an incendiary payload, or effect. The bomb could be a full incendiary payload, with the yellow band indicating a bursting charge, or it could be a bomb primarily with a high explosive component, and a secondary incendiary effect, Gras added.
Red Bands on Israeli Weapons
It’s not the first time the Israeli Air Forces has published weapon images with red bands marking the warhead or payload section of a munition. Shortly after the start of the Gaza War in 2023, the IAF posted a photo which included an Apache attack helicopter with a Hellfire missile with a red band. The IAF deleted the post and replaced it with a similar photo of an Apache without this missile.
Israeli Air Force AH-64 Apache with Hellfire missiles, including one with a red band. Source: Israeli Air Force.
Israeli munitions which are not incendiary have also been spotted with light red bands over the fuel tanks for munitions with jet engines, such as the Delilah cruise missile.
Designed To Target Chemical or Biological Weapon Stockpiles
The markings are consistent with the US-produced CrashPAD, but “given the possible CBW [chemical and biological warfare] threats Israel has long faced from Iran, it is entirely plausible that an Israeli analogue was developed,” Dr Jenzen-Jones told Bellingcat.
Dr Jenzen-Jones told Bellingcat that the CrashPAD is the only publicly known weapon of this type utilising a MK 84 bomb body although there are several programs producing similar munitions. A penetrating variant is known as the Shredder but it uses a modified BLU-109 bomb body, which is visually different from the MK 84 bomb body visible in the IAF photos.
CrashPAD has been in the US inventory for nearly two decades. “Chemical Agent Defeat weapons, such as Crashpad, are not illegal”, and they must undergo a legal review to ensure compliance with US domestic and international law, Michael Meier, former Senior Advisor to the Army Judge Advocate General for Law of War and current Adjunct Professor at Georgetown University Law Center, told Bellingcat.
“The express purpose for the reservation is that these weapons, such as Crashpad, are the only weapons that can effectively destroy certain targets such as biological weapons facilities, for which high heat would be required to eliminate bio-toxins,” Meier said. Dr Arthur van Coller, Professor of International Humanitarian Law at the STADIO Higher Education, told Bellingcat that “if the CrashPAD is used as designed, i.e. to target chemical or biological weapon stockpiles sufficiently removed from civilian populations, then its use is consistent with IHL [International Humanitarian Law] and treaty law, even under CCW [Certain Conventional Weapons], Protocol III.”
Dr Arthur van Coller also said that the “United States and Israel are State Parties to the CCW itself,” but only the US is also a party to Protocol III on incendiary weapons, albeit with reservations, which means that Israel “is not legally bound by Protocol III’s restrictions on incendiary weapons (including those applying to CrashPAD) under treaty law”. Iran is not a party to the CCW at all.
The US Defense Security Cooperation Agency, which publishes details of some major arms sales, does not mention any transfers of the CrashPAD. Bellingcat asked the Department of State if the CrashPAD or weapons with similar capabilities were transferred to Israel. Bellingcat also asked the Department of State if they assessed that Iran had a chemical weapons program. A State Department Spokesperson told Bellingcat that “The Trump administration backs Israel’s right to self-defense” and referred Bellingcat to the IDF for questions about procurement and munitions used.
The US Department of Defense did not respond to requests for comment by the time of publication.
Bellingcat asked the IDF what the bomb was, if it was supplied by the US, if it contained white phosphorus, thermobaric or fuel air explosives, and if the IDF assessed that Iran had a chemical weapons program. The IDF told Bellingcat that it “will not be able to provide details regarding the types of munitions it uses. With that said the IDF uses only legal weapons and ammunition.”
Bellingcat’s Carlos Gonzales contributed research to this article. Livio Spaini from Bellingcat’s Volunteer Community also contributed to this piece.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
US President Donald Trump said on January 2 that the US was “locked and loaded and ready to go”. Trump was talking aloud about intervening in Iran if it continued a violent crackdown on demonstrators who had taken to the streets over spiralling inflation and ongoing repression.
Thousands of Iranian’s were reported to have been killed by state security forces in just under a month. According to Amnesty International, the Islamic Revolutionary Guard Corps (IRGC), the Basij plainclothes militia
US President Donald Trump said on January 2 that the US was “locked and loaded and ready to go”. Trump was talking aloud about intervening in Iran if it continued a violent crackdown on demonstrators who had taken to the streets over spiralling inflation and ongoing repression.
On Saturday, February 28, the United States and Israel launched a large-scale attack against Iran, killing Supreme Leader Ayatollah Ali Khamenei and targeting military infrastructure throughout the country. President Trump initially told Iranians they should seize control of the government but on Tuesday this week said: “If you’re going to go out and protest, don’t do it yet. It’s very dangerous out there. A lot of bombs are being dropped.” Almost 800 Iranians have been killed in US and Israeli strikes so far, according to the Iranian Red Crescent.
While the US has released a list of military targets, including IRGC headquarters and missile systems, Bellingcat has reviewed strikes against another type of target inside the Islamic Republic — police stations.
Experts told the New York Times that strikes against these facilities may be part of an effort to motivate Iranians to challenge the regime, although satellite analysis alone doesn’t allow us to tell if it is the US, Israel or both nations who have targeted police stations.
Mapping Targeted Police Stations
Using medium-resolution PlanetScope satellite imagery from Planet Labs, Bellingcat has been able to locate at least 15 local police stations or similar buildings that were struck between March 1 and March 3. Videos and photos shared on social media also show the aftermath of some of these strikes.
Comparing the March 1 PlanetScope satellite imagery with imagery taken on March 3, it’s possible to make out visible signs of building destruction throughout Tehran. Some of these sites have already been widely-reported on, including the strike on Supreme Leader Ali Khamenei’s compound and official residence.
But Bellingcat reviewed damage to a number of smaller buildings throughout Tehran and cross-referenced the locations with data on Google Maps, Open Street Maps and Wikimapia where we found that several were listed as police stations. The majority of sites we identified are in dense urban areas.
Video shared by Iranian state broadcaster Tasnim News showed the aftermath of a strike on what it describes as a “diplomatic police station” near Ferdowsi Square — one of downtown Tehran’s main intersections. Another video taken at the same location shows at least two people on the ground with a large amount of damage to nearby buildings. Geolocation of the videos puts them at 35.7032, 51.4189, adjacent to a school and office buildings.
An annotated image from Google Earth showing where a police station was destroyed in an airstrike. Video from Iran’s Tasnim News shows buildings that match those in the satellite imagery.
Another video, geolocated by a volunteer with Geoconfirmed — a volunteer geolocation collective — shows a heavily damaged police station near Tehran’s Grand Bazaar. PlanetScope imagery from March 3 shows heavy damage to the area around the police station.
Photos and video from the Golestan Palace, a UNESCO World Heritage Site that sits adjacent to the police office, shows that it also sustained damage.
Iran’s Police and Law Enforcement
Iran’s security apparatus includes a network of police, plain clothes officers, civilian militia battalions known as Basij and the Islamic Revolutionary Guard Corps. During recent protests security forces were seen shooting protestors on the streets, and many of those killed showed signs of being shot in the head.
Iran has experienced several waves of anti-regime protests over the past 15 years, all of which have been put down by the authorities who have not shied away from using extreme violence to contain them.
Although the Financial Times reported speaking to a Tehran resident that said one of the police stations we identified, in the Gisha neighborhood, had hosted a branch of Iran’s morality police, it is thus far unclear from the satellite data whether any of the police stations had any particular role during the recent protests.
Trevor Ball, Logan Williams and Felix Matteo Lommerse contributed reporting to this piece for Bellingcat. Anisa Shabir and StéphanieLadel contributed from Bellingcat’s Volunteer Community.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
The United States and Israel launched an attack on Iran on Saturday morning, killing Supreme Leader Ayatollah Ali Khamenei as well as several senior regime figures and striking multiple sites across the country. Iran retaliated by firing at targets across the region, including Israel, Bahrain, Qatar, the UAE and other Gulf states. The conflict is ongoing despite no declaration of war by the US Congress. US President Donald Trump initially called for regime change in Iran but has since delivered
The United States and Israel launched an attack on Iran on Saturday morning, killing Supreme Leader Ayatollah Ali Khamenei as well as several senior regime figures and striking multiple sites across the country. Iran retaliated by firing at targets across the region, including Israel, Bahrain, Qatar, the UAE and other Gulf states. The conflict is ongoing despite no declaration of war by the US Congress. US President Donald Trump initially called for regime change in Iran but has since delivered a mixed message about the aims of “Operation Epic Fury”.
Israel has said it dropped more than 2,000 bombs in the first 30 hours of the war. While the US claims to have struck over 1,000 targets in the first 24 hours, with President Trump stating that “bombs will fall everywhere”. In response, Iran is reported to have launched at least 390 missiles and 830 drones in the first two days. Bellingcat has been monitoring strikes across the region, including those that caused civilian harm, and identified a wide variety of weapons have been used so far, including missiles and drones.
US-Made Weapons and Tomahawks Launched
The US reported that some of the first weapons they launched were Tomahawk missiles. Footage from the US McFaul also showed Tomahawks being launched.
Imagery of many other different munitions used by the US, Israel and Iran have appeared on social media.
This article covers some of the munitions Bellingcat has seen imagery of as the war enters its fourth day.
Many of the weapons used so far have also been deployed in other recent US conflicts, including the 12-day Israel-Iran war, and US strikes in Yemen and Venezuela.
The US is the major supplier of arms to allies in the region, including for Israel, Kuwait, Qatar, UAE, and Jordan.
On Sunday, the US Department Of Defence (DOD) published photos showing weapons being prepared for loading on aircrafts, including the MK-80 series of bombs like MK-82 500-pound bombs, and BLU-109 2,000-pound ‘bunker busters’ equipped with Joint Direct Attack Munition (JDAM) bomb guidance kits.
Left: Feb. 27. 500-pound bombs equipped with JDAM guidance kits. Right: Feb. 28. 2,000-pound BLU-109 ‘bunker busters’ equipped with JDAM guidance kits. Sources: US Navy/DVIDS and US NAVY/DVIDS.
Image of a Precision Strike Missile being fired in the first 24 hours of the war. Source: US CENTCOM.
Many of the weapons deployed by the US have also been used by Israel. This includes the MK-80 series of bombs, BLU-109 bombs and Joint Direct Attack Munition (JDAM) bomb guidance kits.
A Feb. 28. image shows an IAF F-15 equipped with a BLU-109 bomb with a JDAM guidance kit. Source: Israeli Air Force.
Israel also produces some of its own munitions, which they released video or photos of since the start of the conflict, including MK-83 1,000-pound bombs equipped with Israeli SPICE-1000 bomb guidance kits.
A Mar. 1. screenshot showing IAF personnel loading a MK-83 1,000 pound bomb equipped with a SPICE-1000 bomb guidance kit. Source: IAF.
Israel also produces RAMPAGE missiles, visible in the image below.
A Feb. 28. image showing an IAF F-16 with a RAMPAGE missile. Source: IAF.
On Sunday, the DOD said they had used the Low-cost Unmanned Combat Attack System (LUCAS) one-way attack drones in strikes. The LUCAS drone is a US copy of the Iranian Shahed one-way attack drone.
A video of a crashed LUCAS drone has subsequently appeared online, reportedly in Iraq.
While Bellingcat could not geolocate this video, then men seen in the footage can be heard speaking Arabic while US CENTCOM has said that this is the first time they have used this drone in combat.
Local Iraqi residents are taking the newly deployed, nearly intact American LUCAS drone for themselves. pic.twitter.com/fbx411iAYU
— Special Kherson Cat (@bayraktar_1love) March 2, 2026
A video shows a LUCAS drone that allegedly crashed in Iraq.
Iranian Attacks
Iran has retaliated by firing one-way attack drones, including Shahed variants, and missiles at Israel, and US-bases in various countries across the region, including UAE, Qatar, Kuwait, Jordan and Iraq.
A Feb. 28. video shows a Shahed drone hitting a residential tower in Bahrain.
Many missiles have a booster, a rocket motor that detaches from the missile after it is expended. These boosters fall to the ground under the flight path of the missile.
Bellingcat verified that Iranian missile boosters have fallen in nearby countries caught in the crossfire, including Qatar and Jordan (see below post geolocated to Al-Hashmi St. in Irbid, Jordan), while some Israeli boosters have reportedly fallen in Iraq.
A Feb. 28. post shows an Iranian ballistic missile booster that fell on Al-Hashmi St. in Irbid, Jordan.
Iranian Missiles Intercepted
The US and Israel, as well as several Gulf countries, have fired missiles, intended to destroy Iranian missiles or drones in the air before they reach their targets. Many Iranian weapons have been intercepted, but others have successfully hit, including in a strike on a US command post in Kuwait, killing six US troops.
Most ballistic missile interceptors are “hit-to-kill” where they are designed to destroy missiles by the impact. These interceptors have their own components that fall to the ground, as well as the debris from interceptions.
Feb. 28.Two photos showing the same remnants of a US-made Patriot Air Defense System PAC-3 CRI interceptor missile published by the UAE MOD. The UAE operates the Patriot system. Source: UAE Ministry of Defense.
A Sea of Unverified Images and Misidentification of Munitions
Many close-up images of munition debris have been posted on social media over recent days which are difficult to geolocate. While we have not been able to verify the location of these munitions, we used reverse image search tools to verify they had not been posted online prior to the current conflict. The munition remnants are also consistent with those used by the US, Israel and Iran. But as we cannot geolocate or chronolocate them yet, we cannot fully verify them. Many of these images have been posted with false claims about the object and who fired it.
Despite Bellingcat being unable to fully verify them, we are including a selection of them with accurate identifications, due to the likelihood that more images of these same objects will continue to appear online as the war continues.
One example of incorrectly identified munitions, is the below picture of an aircraft’s external fuel tank, or drop tank that was posted on Telegram on March 1 alongside the claim that it is an Israeli missile.
A Mar. 1. image shows a drop tank from an Israeli jet reportedly found in Anbar, Iraq. Source: NAYA.
Drop tanks are used on jets to extend the range and are jettisoned after use, resulting in these tanks falling to the ground. These tanks have been mistaken for missile parts in previous conflicts.
Despite Iran’s prevalent use of missiles, not all missile boosters are Iranian. On February 28 missile boosters from Israeli air-launched ballistic missiles were reportedly found just east of Tikrit, Iraq. The below image shows the booster from Israel’s Blue Sparrow series, and can be matched to images previously identified and posted on the likes of the Open Source Munitions Portal.
A Feb. 28. post shows an Israeli Blue Sparrow series missile booster, reportedly found in Duraji, Iraq.
Additionally, unexploded WDU-36/B warheads from Tomahawk missiles were reportedly found –, one in Kirkuk, Iraq and one found near Jablah, Syria. Tomahawk warheads and other remnants are frequently misidentified, often as drones.
Left: Feb. 28. Unexploded Tomahawk warhead reportedly found in Kirkuk, Iraq. Right: Mar. 2. Unexploded Tomahawk warhead reportedly found near Jablah, Syria. Sources: NAYA and Qalaat Al Mudiq.
These titanium cased warheads comprise a small part of the much larger Tomahawk missile, and have been found intact in numerous countries when the warhead has failed to explode, as seen in images shared on the Open Source Munitions Portal.
Unexploded Tomahawk warheads from strikes in other conflicts have also been identified by the Open Source Munitions Portal .
Remnants of an Israeli Arrow 2 interceptor missile were posted online, falsely identified as an Iranian missile, and were allegedly found in eastern Syria. These images could again be matched to those found from previous conflicts on the Open Source Munitions Portal.
An Iranian missile fell in Al-Shoula area, south of DeirEzzor eastern Syria!. pic.twitter.com/TsWVuda2nf
A Israeli Arrow 2 interceptor missile falsely identified as as an Iranian missile in a post on X.
An Ancient US Munition Used by Iran
One photo of a remnant reportedly found in Ahvaz, Iran, included a false claim that it was a US ATACMS missile. Bellingcat was able to confirm the image does not match ATACMS construction by comparing it to imagery of that munition. We have as yet been unable to confirm if it was indeed located in Ahvaz, Iran – although we were able to identify the munition.
An actuator section of a MIM-23 HAWK missile, falsely identified by the post above as an ATACMS missile.
The markings on the remnant include an “FSN” or federal stock number, that can be looked up to identify the item. The FSN was replaced by the national stock number (NSN) in 1974, meaning this missile was produced prior to 1974.
The markings on a actuator section of a MIM-23 HAWK missile.
Bellingcat looked up the FSN/NSN (1410002343266) which corresponds with the US manufactured MIM-23B HAWK, an air defence missile.
There are many other US, Israeli and Iranian munitions that may have been used in the current conflict, but images have not yet appeared on social media.
With fresh strikes carried out overnight/ early Tuesday and President Trump saying that “likely more” US troops will die, the conflict continues to escalate and shows no sign of ceasing in the days ahead. And despite the death of Ayatollah Ali Khamenei the Iranian regime has vowed revenge and continued strikes against Israel, the US and their Gulf allies.
Bellingcat’s Carlos Gonzales, Jake Godin and Felix Matteo Lommerse contributed research to this article. Anisa Shabir from Bellingcat’s Volunteer Community also contributed to this piece.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
To Our Partners and Customers
The following intelligence brief was sent to all SentinelOne partners and customers today:
Executive Summary
Recent U.S. and Israeli strikes against Iranian targets, followed by Iranian attacks on multiple regional locations, present a highly dynamic geopolitical situation with credible cyber threat implications. Iran has historically incorporated cyber operations into periods of regional escalation.
Given the rapid escalation of geopolitical tensions, we assess tha
The following intelligence brief was sent to all SentinelOne partners and customers today:
Executive Summary
Recent U.S. and Israeli strikes against Iranian targets, followed by Iranian attacks on multiple regional locations, present a highly dynamic geopolitical situation with credible cyber threat implications. Iran has historically incorporated cyber operations into periods of regional escalation.
Given the rapid escalation of geopolitical tensions, we assess that Iranian state-aligned cyber activity is likely to intensify in the near-term based on a long track record of leveraging cyber operations for asymmetric retaliation, coercive signaling, and strategic messaging. Prior campaigns, including destructive wiper malware, infrastructure disruption, and influence operations masquerading as ‘hacktivism’, demonstrate both capability and intent to operate in the cyber domain alongside kinetic action.
At the time of publication, SentinelOne has not attributed significant malicious cyber activity directly to these recent events. We have no indications that SentinelOne or our customers are being specifically targeted in connection with these developments.
This report outlines Iran’s historical cyber posture, relevant tactics and tradecraft, and our forward-looking assessment of potential cyber responses in the days and weeks following the airstrikes.
We assess with high confidence that organizations in Israel, the United States, and allied nations are likely to face direct or indirect targeting – particularly within government, critical infrastructure, defense, financial services, academic, and media sectors.
We recommend that all clients, especially those operating in, or supporting, U.S. and Israeli infrastructure, review their security posture and preparedness accordingly.
This assessment is current as of February 28, 2026 and reflects a rapidly evolving threat environment.
Iran’s Cyber Operations to Date
Iran presents a mature, well-resourced cyberthreat based on more than fifteen years of experience across a wide range of malicious cyber events.
Iran uses a diverse set of cyber tools to further state objectives, particularly preservation of the Iranian regime, including:
Espionage and credential theft via APT34, APT39, APT42, and MuddyWater, targeting a wide range of military, civilian, telecommunications, and academic institutions, particularly against regional targets (Israel, Middle East) and the United States
Disruptive and destructive campaigns, including the use of wiper malware
Targeted spearphishing and social engineering campaigns, supporting strategic intelligence collection across multiple industries
Fake hacktivist personas for plausible deniability and psychological impact (e.g., DarkBit, Cyber Av3ngers)
Coordinated disinformation and influence ops across Telegram, X, and compromised news outlets
Internet blackouts within Iran to control public opinion and narrative, while similarly countering the effect of foreign influence operations
Proxy ransomware and criminal fronts blurring lines between state and financially motivated actors
Iranian cyber actors previously aligned their operations with kinetic campaigns, often acting as a force multiplier for regional allies like Hamas or as a standalone tool of retaliation. The TTPs employed by Iranian hacktivists increasingly mirror those used by state-sponsored APTs, raising critical questions about capability sharing and formal command-and-control relationships within this environment.
Expected Iranian Cyber Response to Current Events
1 – Precision Espionage Operations
Expect escalated targeting of Israeli defense, government, and intelligence networks using spearphishing, credential harvesting, and deployment of custom malware. Historically, groups such as APT34 (OilRig) and APT42 (TA453) leveraged legitimate access to move laterally and exfiltrate strategic intelligence. Additionally, U.S. military and government organizations will likely be targeted in similar campaigns.
Anticipated Targets:
U.S. military and government organizations
Israeli defense entities and affiliated research organizations
U.S. and Israeli diplomatic infrastructure
Defense contractors and supply chain partners
Strategic allies and locations in theater
2 – Disruptive & Destructive Tactics
Iran has a well-documented history of using destructive malware and DDoS attacks to disrupt the critical infrastructure of its adversaries. We assess a high likelihood of similar tactics being deployed against U.S. and Israeli sectors, particularly utilities and public-facing systems.
Key techniques include:
Deployment of wipers via fake hacktivist personas or directly-attributed APT clusters
Exploitation of unpatched or poorly secured public-facing web services for defacement and initial access
Use of scheduled tasks and LOLBins to execute custom wiper malware with stealth and persistence
Anticipated Targets:
Transportation, Communication, Energy and Water utilities in U.S. and Israel
Telecom, alerting systems, and national broadcast infrastructure
Iranian-aligned actors are likely to amplify disinformation campaigns to shape public perception, particularly around civilian impact, military failure, and geopolitical instability. These efforts often run concurrently with real-world escalations and aim to degrade public trust in institutions.
Anticipated Themes:
Allegations of Israeli war crimes
U.S. and Israeli military losses
Fabricated claims of successful Iranian cyber retaliation
Disinformation on U.S.–Israel political division
Leaks of manipulated or stolen documents misattributed to Israeli insiders
Lack of support from the U.S. populace for ongoing strikes against Iran
4 – Probing Attacks on U.S. & Israeli Infrastructure
Iran has demonstrated readiness to expand attacks to Western infrastructure during periods of high tension. Recent examples include the exploitation of Unitronics PLCs at U.S. water treatment plants (late 2023), highlighting a shift toward ICS/OT targets. Such actions serve retaliatory and signaling purposes and are often designed to be low-impact yet high-visibility to maximize psychological effect.
Anticipated Targets:
U.S. defense industrial base, especially contractors supporting military action
Israeli military and key government organizations
Critical infrastructure (water, energy, transportation) in the U.S. and Israel
Regional partners (e.g., Jordan, UAE, Egypt, Saudi Arabia) aligned with U.S. and Israeli interests
Media and academic institutions reporting on the conflict
SentinelOne Detection & Monitoring Posture
SentinelOne research and detection teams have closely followed Iranian cyber actors for many years. We provide multiple layers of protection and are closely monitoring emerging threat intelligence to maximize coverage.
We extensively cover techniques known to be used by Iranian threat groups including:
PowerShell and script abuse
Proxy tools
Credential theft
Keylogger components
Wipers
Browser credential theft
DLL sideloading
Tunneling tools (ngrok/Cloudflared)
Scheduled task persistence
Remote access tool abuse
Active Directory reconnaissance
Destructive boot tampering
These protections are not Iran-specific but known to be effective in detecting their operations.
We are monitoring the situation closely and can ship new detections quickly through Platform Rules updates or Live Security Updates.
For maximum protection, we recommend:
Turning on Live Updates
Ensuring you’re opted-in to Emerging Threat Platform Rules
Activating Platform Detection Library rules listed in Appendix A
Recommendations
Increase Vigilance Against Phishing and Credential Abuse
Prioritize MFA enforcement and internal phishing detection
Monitor for abuse of VPN, email, and collaboration platforms
Monitor for suspicious activity involving legitimate user accounts and applications
Harden Critical Infrastructure and OT Environments
Patch and segment exposed ICS components, especially common HMI/PLC vendors
Scan all Internet-facing infrastructure, and patch any vulnerable Internet-facing services
Consider removing or restricting network access to any non-critical Internet-facing services, especially if they are not protected by MFA
Review DDoS mitigation playbooks and response procedures
Monitor for Influence Operations and Fake Leaks
Establish rapid communication response protocols for disinformation relevant to your organization
Be prepared for threat actors using “hacktivist” branding and Telegram/Telegram-style platforms for communication
Consider there are likely masquerade efforts and this requires a detailed assessment to determine true origin
Review and Test Incident Response Plans
Ensure IR and SOC teams maintain heightened alert status
Simulate data-wipe and ransomware scenarios
Simulate corporate social media hijacking scenarios and prepare for account pausing/access resets
Establish Clear Points of Contact
Ensure internal organization has direct POCs for support for security incidents
Communicate posture expectations and escalation paths internally
Monitor for activity associated with Iranian state-aligned threat actors
SentinelOne is proactively hunting for IOCs and TTPs associated with these groups. These threat hunts are being performed for all Wayfinder Threat Hunting customers. Any related hunt findings will be visible in the Wayfinder Threat Hunting dashboard.
Closing Note
This report is intended to support informed decision-making and proactive defensive measures amid a dynamic and escalating geopolitical conflict.
The cyber threat landscape associated with Iranian state-aligned actors is adaptive, and we assess that both targeting priorities and tactics may shift rapidly in response to real world developments, political statements, or perceived provocations.
We advise clients to treat this as a time-sensitive assessment and to revisit posture, incident response, and monitoring processes regularly.
Customers should consider activating Platform Detection Library rules to improve coverage. The following rules are known to be effective against Iranian cyber operations:
MuddyWater
Possible MuddyWater DLL Drop Consistent with Audio Driver Sideloading
Credential Dumping
Suspicious Task Creation for Credential Harvesting
To stay up to date on our latest investigations, join Bellingcat’s WhatsApp channel here
On the night of Jan. 7 this year, three 250-pound bombs smashed into an apartment block in the Al Tuffah neighbourhood of northern Gaza. Footage of the aftermath shows walls collapsed, rubble piled up and blackened household items scattered across the scene.
Although a ceasefire has been in effect since October, and a Board of Peace led by US President Donald Trump has been announced to begin phase two
To stay up to date on our latest investigations, join Bellingcat’s WhatsApp channel here
On the night of Jan. 7 this year, three 250-pound bombs smashed into an apartment block in the Al Tuffah neighbourhood of northern Gaza. Footage of the aftermath shows walls collapsed, rubble piled up and blackened household items scattered across the scene.
Although a ceasefire has been in effect since October, and a Board of Peace led by US President Donald Trump has been announced to begin phase two of that process, Israel has continued to conduct strikes within Gaza
The IDF claimed they targeted a senior Hamas operative in response to a violation of the ceasefire agreement in the Jan. 7 attack.
While the strike was an Israeli operation, among the debris were munition remnants of at least three US-made GBU-39 Small Diameter Bombs, including one that failed to explode.
However, human rights groups like Amnesty International and Human Rights Watch have said that US-made weapons have been used in Gaza in ways that have likely violated international law. Multiple international media reports have also identified individual instances of civilian harm likely caused by US weaponry deployed by Israel in Gaza.
A 2024 State Department report, completed during the administration of former President Joe Biden, even stated that due to Israel’s “significant reliance on US-made defence articles it is reasonable to assess” that they have been used in “instances inconsistent with its IHL [International Humanitarian Law] obligations or with established best practices for mitigating civilian harm” — although Israel says it operates within international law and seeks to mitigate civilian harm while aiming to dismantle Hamas’ military capabilities.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
Yet the full extent of civilian harm in Gaza caused by the use of US-produced weapons remains unclear.
Foreign media are not allowed into Gaza and the documentation of events there has relied heavily on social media footage and the work of local journalists, many of whom have been killed in Israeli air or ground strikes while carrying out their work.
Collating Incidents
Bellingcat has collated scores of incidents like the Jan. 7 strike in Al Tuffah where US-produced munitions have been found in the aftermath of Israeli strikes.
This analysis utilises publicly available media footage and identifies at least 79 specific cases, many of which caused death and damage to civilian infrastructure such as schools, homes and healthcare infrastructure.
While revealing, it is important to note that the data comes with some significant caveats and limitations that must be acknowledged before exploring it.
Gaza has been pummelled since the Hamas attacks of Oct. 7, 2023, when more than 1,200 Israelis were killed and hundreds more kidnapped.
In response, Israel is reported to have deployed 30,000 munitions into Gaza in the first seven weeks of the conflict alone. The Israeli Airforce has also bombed over 100 different targets in Gaza in a single day multipletimes.
This dataset – which details cases where US-made munition remnants have been found and evidence of their use published in media or posted to social media – therefore only captures a small fraction of the overall incidents over more than two years of war.
Furthermore, Israel and the US both produce some of the same munitions, such as the MK-80 series of bombs. The US supply of this series, especially the 2,000-pound MK-84 of which over 14,000 have reportedly been delivered since Oct. 7 2023, have been central to calls for the suspension of US arms transfers to Israel due to their destructive potential.
But because Israel also makes these bombs domestically the country of origin cannot be definitively identified without specific remnants that show either the lot number, indicating the manufacturer, or other identifying information.
Etched information on an unexploded MK-84 2000-pound bomb that was dropped by the Israeli Air Force on Sanaa Airport, Yemen and failed to explode. The lot number indicates that this bomb body was manufactured by General Dynamics Tactical Systems, a US based company, in 2017. Source: YEMAC
As a result a decision was made to try and track the use of three specific munitions that are made solely in the US and which Israel does not domestically produce. This, again, significantly reduced the number of incidents analysed.
The full dataset can be found here. The munition identifications were reviewed by Frederic Gras, an independent Explosive Remnants of War (ERW) Expert and Consultant.
Residents near the rubble of the Al Roya 2 tower which was hit in an Israeli attack in September 2024. Anadolu via Reuters Connect.
Despite all of the above caveats and limitations, the analysis recorded 79 geolocated incidents where remnants of these three models of US-made munitions were either found in the aftermath of a strike or were captured in visual imagery in the moments before impact.
Beyond the 79 cases analysed and included in the dataset, other US-made munitions were identified in a further 26 cases, although it was not possible to geolocate the remnants or strikes prior to publication. It may be possible to geolocate the outstanding incidents in time. Bellingcat is, therefore, including these incidents in the dataset but notes further work is required for them.
Many of the geolocations in the dataset were initially posted publicly by independent geolocators, or volunteers from the GeoConfirmed community, including Anno Nemo, Abu Location, fdov, Chris Osieck, Zvi Adler and Will Cobb. These geolocations were independently checked and verified by Bellingcat.
Subscribe to the Bellingcat newsletter
Subscribe to our newsletter for first access to our published content and events that our staff and contributors are involved with, including interviews and training workshops.
For the 79 incidents it was possible to geolocate, Bellingcat sought to compile reports of civilian harm. Yet given the lack of access afforded to international observers it was not possible to independently verify each of these reports of casualties or fatalities.
The reports, many of which cite health authorities in Gaza, detailed that at least 744 people were killed in these 79 strikes, including at least 78 women and 175 children. When reports offered a range for the number killed, or number of women and children killed, Bellingcat used the lower end of the estimate.
Israel rarely provides estimates for civilian casualties from their strikes. It has also claimed that the Gaza Ministry of Health has exaggerated death tolls after specific strikes. Analysing previous public reporting of each incident in the dataset, Bellingcat found that the IDF had claimed at least 69 people that were reported killed in these attacks were militants belonging to Hamas or other factions. In one strike, where at least 33 people were reported killed, the IDF claimed to have targeted “dozens” of Hamas members, releasing the names of 17 people they said were part of Hamas.
Bellingcat asked the IDF if they could provide a total for the number of people killed in the attacks listed in the dataset or for any specific strikes but they did not provide a figure. A spokesperson for the IDF provided information for eight strikes within the dataset that it said sought to hit “terrorist targets”. Bellingcat has noted this response beside each incident in the dataset.
The spokesperson added that Israel “strikes military targets and objectives in accordance with international law and takes all feasible measures to mitigate harm to civilians and civilian structures as much as possible.”
The Gaza Ministry of Health has reported that over 70,000 Palestinians have been killed in the conflict. While Israel has long disputed those casualty figures, Israeli media recently cited anonymous Israeli Defence Force (IDF) sources who said they believed them to be largely accurate. Israel has claimed to have killed about 25,000 militants in Gaza.
Attacks on Schools
Attacks on schools, mosques, shelters and residences are all included in the dataset. In total, 28 strikes on schools using US made munitions were identified. GBU-39 bomb remnants were found at the site of 20 of these strikes. Most of these took place before the ceasefire of January 2025.
For example, the Khadija school in Deir Al Balah was targeted in three rounds of airstrikes on July 27, 2024 that used both GBU-39 bombs and MK-80 series bombs equipped with JDAM kits. Satellite imagery before and after the strike showed significant damage to the facility.
Planet Imagery from before and after the July 27 2024 airstrikes on Khadija School Complex. The destruction of several buildings is visible. (Credit: Planet Labs PBC).
Video from the ground provided more detail, showing that the first round of airstrikes targeted five different areas of the school complex.
The unexploded bomb body of a GBU-39 was found inside the school, while the fuzewell from a GBU-39 bomb that exploded was photographed near the destroyed gate structure.
An evacuation notice was then reportedly issued, and two buildings on the eastern side of the complex were targeted with larger bombs, leveling the buildings there. An additional evacuation notice was reportedly issued before a third strike.
A video of the third strike shows at least six people, including a child, visible within approximately 55 meters of where a bomb equipped with a US-made JDAM kit hit one of the already collapsed buildings on the eastern side of the complex.
MK-80 series bomb shortly before impact in the third round of strikes at Khadija School. The buildings visible on the left in the previous graphic are both seen here already leveled. Source: Hamza via Telegram/Abu Ali Express
These three strikes killed at least 30 people, including 15 children and eight women, according to reports collated by Airwars. At least 100 were injured, according to the same reports. Most people were reportedly harmed in the initial strikes, according to the UN Office of the High Commissioner for Human Rights.
The United Nations reported at the end of February 2025 that 403 of 564 school buildings in Gaza had been “directly hit” in some manner, either by airstrikes or by other munitions. School buildings are often used as shelters. However, Israel has claimed in some instances that they were being used as Hamas command centres.
After the war resumed in March 2025, recorded strikes on schools generally appeared to use Israeli-made munitions. Only two strikes on schools since then were found to have used US made munitions – a May 2025 attack on the Fahmy Al Jarjawi school with at least three US-made GBU-39 bombs that killed 36 people, according to hospitals in Gaza, and a July 2025 strike on Cairo Basic School where five people were reported killed and where remnants of a Hellfire missile was found.
Part of a Hellfire missile rocket motor recovered after the strike at Cairo Basic School that reportedly killed five. Ali Jadallah / Anadolu via Reuters Connect.
While the dataset shows no other attacks on schools using US munitions after this period, it is important to note that there may have been other instances where US-made munitions were used in such circumstances but which were not recorded.
Strikes on Healthcare Facilities
Two strikes using US-made munitions to directly target medical facilities were identified in this analysis. A Hellfire missile was used in a June 2024 strike on a health clinic in Gaza City that killed Hani al-Jafarawi, the director of ambulance and emergency services in Gaza. However, the IDF claimed the strike had killed “the terrorist Muhammad Salah, who was responsible for projects and development in Hamas’ Weapons Manufacturing Headquarters”.
The Gaza Civil Defence Headquarters in Al Daraj, Gaza City, was also targeted with a US-made GBU-39 bomb in September 2024. The bomb penetrated multiple floors but failed to explode, causing injuries but no deaths.
Five instances of US-made munitions being used for strikes near medical facilities were also identified. Four of these strikes used Hellfire missiles to target tents within approximately 150 meters of the Al Aqsa Martyr’s Hospital Main Complex in Deir Al Balah.
Remnants of a Hellfire missile, including the control section, found after a November 2025 strike outside AlAqsa Martyr’s Hospital complex that reportedly killed three and wounded 26 others. Sources: Seraj TV, Lance Cpl. Paul Peterson/DVIDS, Captain Frank Spatt/DVIDS.
The fifth strike used a US JDAM likely attached to a MK-82 500-pound bomb to target the Al Aqsa Mosque across the street from the hospital, approximately 50 meters away from the main hospital complex. This strike killed 26 people, according to the Gaza Ministry of Health.
A US Marine Corps manual on Close Air Support states that a MK-82 bomb delivered within 425 meters is considered “danger close”, with a bomb delivered within 250 meters being 100 times more dangerous than the minimum “danger close” standard.
Evacuation Strike Notices
Twenty-sixstrikes were identified where US munitions were used to target buildings including homes, schools and mosques after an evacuation notice was issued by the IDF. In 23 of these strikes there was no reported harm. However, there was significant harm recorded in others even with evacuation notices.
Evacuation notices are notifications that provide advance warning of strikes and can be made on social media or sent to people’s phones. These notices often provide journalists on the ground time to set up cameras to record the incoming strikes. Such videos are occasionally of high enough quality to identify the bomb guidance kit attached as JDAMs kit as they fall, as can be seen in the video below.
لحظة قصف مسجد الألباني في مدينة خانيونس بصاروخين من طيران الحربي . The moment the Al-Albani Mosque in Khan Younis was bombed with two missiles by warplanes.
— عبدالله العطار abdallah alattar (@abdallahatar) August 1, 2025
By Sept. 17, 2025 Israel said it had destroyed 25 high-rise buildings in preparation for their assault on Gaza City. Bellingcat was able to identify that at least seven high-rise buildings in Gaza City, including Al Soussi Tower, Al Roya Tower, and Al Roya 2 Tower, were issued evacuation notices then destroyed using MK-80 series bombs with JDAM kits.
MK-80 series bombs with JDAM kits shortly before impact. Both strikes resulted in the total collapse of the towers. Source: Anadolu Agency via Reuters.
The Aybaki Mosque, built in the 13th century, was also hit with MK-80 series bombs with JDAM kit, which the IDF told Bellingcat was a strike targeting the “deputy commander of heavy machine guns unit in Hamas, Khaled Nabil Saleh Shabat”. The IDF has claimed that these tall buildings host Hamas infrastructure, including observation posts and prepared attack positions.
The public warnings posted by the IDF for buildings targeted in Gaza City in September 2025 alerted residents of specific blocks, as well as those in the target building and adjacent tents to leave and head south towards the IDF declared humanitarian zone.
Prior to strikes in Lebanon where the IDF issued evacuation notices, maps were publicly posted requesting civilians evacuate at least 500 meters away. However, a review of public posts by the IDF for evacuation notices in Gaza from September 2025 found no notices that provide a specific evacuation distance.
Bellingcat asked the IDF if the content of evacuation notices sent to people’s phones differ in content from those publicly posted and why evacuation notices in Gaza appeared to not provide a recommended evacuation distance like those issued by the IDF in Lebanon. The IDF told Bellingcat that they issue “clear and detailed advance warnings through multiple channels, including communications published by the IDF Arabic Spokesperson and enables the civilian population to evacuate before strike.”
The distance people are told to evacuate prior to strikes is important as fragments from bombs, or the buildings being targeted, can still kill or injure people hundreds of meters away.
After the airstrike targeting the Harmony Tower, a graphic video captured by the Anadolu Agency showed a group of people about 120 meters away had been either killed or injured by the strike, despite the evacuation notice.
US-made munitions have also been used in other IDF strikes, including one which reportedly killed the leader of Hamas’ Military Wing, Mohammed Deif. At least 90 people were reported killed in this attack and US-made JDAM remnants recovered. US munitions were also used in the September 2025 strike that reportedly killed Hamas Spokesman, “Abu Obayda” and at least six other people, where remnants of US-made GBU-39 bombs were found.
American-made munitions were also used alongside other unidentified munitions in the June 2024 IDF hostage rescue operation in Nuseirat, where 274 people were reportedly killed. These 274 deaths are not included in the 744 people reported killed in the incidents contained within the dataset due to the inability to identify the other weapons used in at least 13 strikes that occurred during the operation.
Bellingcat reached out to the IDF, the US Department of State, and the US Department of Defense before publishing this story. Bellingcat also asked the primary contractors for these munitions, Boeing and Lockheed Martin, about whether they track how their products are used in Gaza.
Boeing, which manufactures the GBU-39 bomb and JDAM bomb guidance kit did not respond. Neither did Lockheed Martin, which makes the AGM-114 “Hellfire” missile.
The Department of Defense declined to comment.
A spokesperson for the US Department of State said “The US Government is not able to make such determinations” when asked how many civilian deaths could be attributed to the use of US-made weapons in Gaza.
Bellingcat asked if the State Department held a different assessment than the NSM-20 which was introduced under President Biden and determined that it was reasonable to assess that US-made weapons were used by Israel in instances “inconsistent with its IHL obligations or with established best practices for mitigating civilian harm”. The spokesperson said “NSM-20 is no longer US policy.”
The State Department referred other questions about the use of the munitions highlighted in this article to the Israeli Defence Forces, who told Bellingcat that they do not detail the munitions they employ and that Hamas exploits “civilian infrastructure for terrorist purposes”.
Jake Godin and Carlos Gonzales contributed to this report.
Afton Briones, a member of Bellingcat’s Volunteer Community, contributed research to this piece.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here and Mastodon here.
In the early hours of June 13, Israeli missiles slammed into apartment buildings across the Iranian capital, Tehran.
By morning, it became apparent that nine men Israel said were closely associated with the country’s nuclear programme were dead.
Videos posted to social media showed buildings in flames and rescue workers sifting through rubble as they looked for survivors.
Dozens of civilians who lived in the same apartment blocks as those targeted also died in the strikes. In one inst
Videos posted to social media showed buildings in flames and rescue workers sifting through rubble as they looked for survivors.
Dozens of civilians who lived in the same apartment blocks as those targeted also died in the strikes. In one instance, a 14-storey residential tower completely collapsed.
But this was just the start, the opening shots of what Israel dubbed Operation Rising Lion – a 12-day operation targeting Iranian scientists, nuclear sites, security figures and military capabilities.
While Iran sought to fight back, launching missiles and drones at Israel, the damage and death toll inflicted by Israel was far greater.
On day 10 of the operation, the United States joined with Israel, carrying out strikes on nuclear sites at Fordow, Natanz and Isfahan.
Bellingcat worked with FRONTLINE (PBS), The Washington Post and Evident Media to piece together the events of the 12-day war to try and understand the true impact of the strikes on Iran’s nuclear programme. Iran maintains the programme is peaceful but Israel has long suspected that it is designed to develop nuclear weapons.
FRONTLINE filmmakers were given access to Iran, where they visited the sites of some of the strikes and spoke to neighbours and relatives of those who were killed as well as high-ranking Iranian officials.
The Washington Post also spoke to senior intelligence and military sources involved in Operation Rising Lion, and the filmmakers visited Vienna to speak with the International Atomic Energy Agency (IAEA), the organisation that has been responsible for monitoring Iran’s nuclear programme.
Bellingcat, alongside The Washington Post, analysed open source information such as satellite imagery, social media footage, local media coverage, death notices and cemetery records to understand how the attacks on Iranian scientists unfolded as well as analyse the civilian cost of the conflict.
Trevor Ball, Carlos Gonzales, Sebastian Vandermeersch and Eoghan Macguire reported for Bellingcat. Sebastian Walker and Adam Desiderio reported for PBS Frontline. Nilo Tabrizy and Jarrett Ley reported for The Washington Post.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Twitter here and Mastodon here.