Visualização normal

Antes de ontemStream principal
  • ✇ASEC BLOG
  • Ransom & Dark Web Issues Week 1, September 2026 ATCP
    ASEC Blog publishes Ransom & Dark Web Issues Week 1, September 2026           ZaWoo Data Extortion Attacks Against Multiple Organizations Worldwide Black X Ransomware Attack on a South Korean Automotive Parts Manufacturer Internal Data of a South Korean Asset Management and Investment Firm Offered for Sale
     

Ransom & Dark Web Issues Week 1, September 2026

Por:ATCP
2 de Setembro de 2026, 12:00
ASEC Blog publishes Ransom & Dark Web Issues Week 1, September 2026           ZaWoo Data Extortion Attacks Against Multiple Organizations Worldwide Black X Ransomware Attack on a South Korean Automotive Parts Manufacturer Internal Data of a South Korean Asset Management and Investment Firm Offered for Sale
  • ✇bellingcat
  • Investigating a Murder: Public Records Uncover New Clues in Chinatown Cold Case Peter Barth
    Sign up here to receive Bellingcat’s biggest investigations by email as soon as they are published. Illustration by Oisín Mac Con Iomaire On a June night in 1996, in a basement apartment in Boston’s Chinatown, a killer put a pistol to the back of a young man’s head and pulled the trigger. The victim’s body was wrapped in quilts, lowered into the trunk of a car and driven about 20 miles southwest of the city, where it was dumped in the woods. It lay undiscovered through two New England winte
     

Investigating a Murder: Public Records Uncover New Clues in Chinatown Cold Case

31 de Agosto de 2026, 09:58

Sign up here to receive Bellingcat’s biggest investigations by email as soon as they are published.

Illustration by Oisín Mac Con Iomaire

On a June night in 1996, in a basement apartment in Boston’s Chinatown, a killer put a pistol to the back of a young man’s head and pulled the trigger. The victim’s body was wrapped in quilts, lowered into the trunk of a car and driven about 20 miles southwest of the city, where it was dumped in the woods. It lay undiscovered through two New England winters until a dog walked home carrying a human bone. 

For three decades, authorities did not release the victim’s name to the public. He is listed in the National Missing and Unidentified Persons System (NamUs) as #UP12385, one of 202 unidentified people recorded in the state of Massachusetts. The circumstances of his discovery are reduced to five words: “Skeletal remains found in woods.” The case remains unsolved.

Bellingcat spent more than a year investigating in an effort to put a name to the victim. Using open sources, including freedom-of-information requests and newspaper archives, as well as interviews with investigators who worked on the case, we pieced together the story of the man’s life and death in an era before the internet kept a digital record. In total, we submitted 27 public records requests to 18 local, state and federal law enforcement agencies. We also contacted more than two dozen investigators, prosecutors, crime victims, journalists, experts and community groups connected to the case, though most said they did not recall the 30-year-old murder. 

We learned that authorities identified the victim as Fu Chun Wang, a 26-year-old undocumented Chinese immigrant who did not speak English. We also learned of a sweeping investigation into Chinese organised crime in New England in the late 1990s. Authorities suspected Wang was a member of the Fukienese Flying Dragons, a gang the FBI described at the time as a “violent offshoot” of the larger Flying Dragons crime ring.

Fu Chun Wang’s mugshot. Source: Released by Sharon Police Department

Based in New York’s Chinatown, the Fukienese Flying Dragons were active across much of the East Coast. The gang trafficked migrants, extorted and robbed businesses, kidnapped for ransom and murdered rivals. Authorities believed Wang belonged to the Boston faction of the group, which was suspected of carrying out home invasions targeting Asian and Asian-American restaurant owners and staff across New England in 1996. 

Heavily redacted FBI documents and correspondence between local and state authorities show that a federal operation investigating the home invasions uncovered information about Wang’s murder and other crimes. The operation, whose name is redacted, was led by the US Attorney for the District of New Hampshire.

Authorities suspected that the Boston-based members of the Fukienese Flying Dragons were also involved in prostitution, illegal gambling and kidnappings in multiple states. Investigators examined possible ties between the gang and a suspect in one of Boston’s deadliest mass killings: the 1991 Chinatown Massacre

According to these newly released files, investigators received information that Wang had been murdered by members of his own gang shortly after Boston Police arrested and charged him for using credit cards stolen in one of the home invasions. While some gang members were identified as suspects and investigated, none were ever charged and convicted for the murder.

A Dog with a Bone

On April 10, 1998, a resident in Sharon, an affluent suburb southwest of Boston, called the police. Their black Labrador retriever had returned from the woods carrying a large bone. Four days later, testing by the coroner’s office in Boston determined it was a human femur likely belonging to an adult male. Police searched the woods, where a detective uncovered more bones near a bundle of quilts. Inside, they found a decomposed skeleton. 

A coroner ruled that the victim was a man in his twenties or thirties who was possibly Asian or Native American. He had long black hair with blonde streaks. There were at least two overlapping bullet holes in the back of his skull. Local media reported at the time that the victim had been shot “execution style”. A single, corroded .380 calibre shell casing was found inside the quilt. The victim was wearing a green-and-white striped rugby shirt, denim jeans and white leather sneakers on the night he died. Loose change, a pocket knife and a tarnished set of keys were found nearby on the forest floor. 

Blurred
Crime scene photos showing remains found in the woods, near the intersection of Walpole Street and Bluff Head Road, in April 1998. Source: Sharon Police Department

A botanist from Harvard University determined the body had likely been in the woods for at least 18 months. Experts from The Smithsonian Institution told police that forensic facial reconstruction would be “of questionable value” due to the damage caused by the gunshot injuries. 

Before his murder, open source records of Wang’s life amounted to a few scattered data points: interactions with authorities, apartment rentals, a loan application and a hospitalisation following a car accident. 

Police reports after his death show investigators pieced together a patchy collection of biographical data. He was from a family of five in Dongshan, a village in the southeastern Chinese province of Fujian, and was likely born into poverty. During his autopsy, it was noted that his teeth showed signs he had been “undernourished” as a child. He moved to the US to work in the restaurant industry and eventually joined a gang. 

A January 1994 Immigration and Naturalisation Service (INS) record containing Wang’s fingerprints. Source: Released by Sharon Police Department

Wang migrated at a time when thousands of Fujianese were arriving in the US every month in search of a better life. Like many migrants at the time, he entered the country without documentation. By 1994, when Wang met with immigration authorities in Boston, he gave his address as an apartment on East Broadway in New York’s Chinatown. Two years later, he was issued an employment authorisation card. Boston Police would learn from the Immigration and Naturalisation Service (INS) that Wang had been granted political asylum.

Search results on Ancestry.com suggest that prior to living in Massachusetts, Wang had also lived in Virginia and Vermont. Records from the Sharon Police Department corroborate these findings. In Virginia, police learned that he worked in restaurants and had applied for a loan to buy a car, a 1994 green Mitsubishi Mirage. 

In Vermont, Wang worked at a Chinese restaurant called Men-at-Wok until he was injured in a car accident in May 1996. After he was reported missing a month later, his car sat unclaimed in an auto body shop in Vermont until a bank sought to reclaim it.

Wang’s INS employment authorisation card. Source: Released by Sharon Police Department

Unclaimed checking and savings accounts at Fleet National Bank are listed under Wang’s name and the Quincy address in the Massachusetts unclaimed property database. The amount of money in these accounts is not publicly available, but the presence of unclaimed funds in his name, along with his abandoned car, are some of the many indicators that he met with foul play.

‘We’ll Kill Your Family’

In the summer of 1996, Chinese restaurant owners and their staff in suburban Boston and New Hampshire were terrorised by a wave of violent home invasions and robberies. Police described the suspects as “an organised group of Asian individuals”.

Composite sketches of two suspects in a July 1996 home invasion in Merrimack, NH based on witness descriptions. Source: Merrimack Police Department

The modus operandi was often the same. In the early morning hours, young men barged into rooming houses while Chinese restaurant workers slept. Sometimes they robbed the business owners’ homes. Armed with guns and knives, the intruders tied up their victims before stealing cash and valuables. One woman who was attacked at knifepoint told police an assailant threatened: “Shut up or I will kill you”. In another case, a victim was stabbed.

The assailants were described as young men or teenagers. In several cases, victims reported that they spoke Fuzhou, also known as Foochow, a language originating from eastern Fujian Province. 

Jim Keating, a retired Sharon Police detective, told Bellingcat that many Asian gang extortions and robberies in the Boston area at the time were not reported. “They were all afraid of these guys, because they said, ‘We’ll come back and we’ll kill your family.’ And they would.”

In the span of a few months in 1996, similar robberies occurred in the Massachusetts towns of Bedford and Westborough, as well as Malden, a city about 10 kilometres north of Boston. These were followed by home invasions in the bordering state of New Hampshire, in Wolfeboro, Merrimack, Lebanon and Manchester. It is unclear if the home invasions and robberies were connected, but Bellingcat’s review of historic newspaper clippings and newly released police documents suggest that at least one other gang may have been responsible for some of the crimes. 

In response to the crime spree, local, state and federal law enforcement agencies coordinated investigative efforts. Bellingcat obtained files detailing a federal operation led by the US Attorney for the District of New Hampshire. It included agents from the FBI, INS, Drug Enforcement Administration, Bureau of Alcohol, Tobacco, Firearms and Explosives, Customs Service, Border Patrol and Royal Canadian Mounted Police, along with officers from state, county, and local law enforcement agencies in New England.

Local media coverage of the home invasions in 1996. Source: Janet Wilson, The Boston Globe

Ben Leong, a retired Boston Police detective, said Asian gangs committing robberies, extortion and home invasions against restaurant owners and their staff were common in the 1990s. He said many of these crimes went unreported for cultural reasons, over fears of gang retaliation, and because victims did not trust law enforcement.

“Back then there were many factions of gangs,” he said. “The gang members were recruited throughout the country, nationally and internationally. Law enforcement was always playing catch up to identify the prevalent groups, and the individual members and leaders committing illegal activity.” 

Leong, who is president of the International Organisation of Asian Crime Investigators and Specialists (IOACIS), said authorities had a better understanding of gang culture in Boston by around 1996 when local, state and federal agencies began sharing information.

Murdered in Chinatown

On June 9, 1996, one day after a home invasion in Wolfeboro, New Hampshire, Boston police were called to a Macy’s department store when a man tried to use credit cards stolen in the robbery to buy jewellery and electronics. He was arrested and booked on charges of receiving stolen property. The man was Fu Chun Wang.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

In Sharon Police records, Wang was described as “very depressed” and “possibly suicidal”. He told a Boston Police detective that he urgently needed to send $1,000 to his family in China. Other records said his father was ill and needed money. Files found on Judyrecords.com, a free database that purports to include more than 770 million US court case records, show that Wang was arraigned and a court appointed a defence attorney to him. He was bailed out after pleading not guilty. 

Less than two weeks later, on June 21, Wang was reported missing to the Quincy Police Department in Massachusetts. The police report said Wang was last seen in Boston’s Chinatown on June 13, two days after he left jail. Police records indicate that a female friend of Wang’s had asked an attorney to file the missing persons report. The attorney who reported him missing told Bellingcat that he did not remember Wang. 

The Sharon Police Department’s murder case file notes that within weeks of finding the human remains in the woods, they received information from Boston Police and the FBI that “Wang was murdered in Chinatown” in June 1996 and “his body [was] never found”. 

Investigator’s handwritten notes about Wang’s case. Source: Sharon Police Department

Not all documents were released to Bellingcat, and some names were redacted. Fragmentary notes and witness statements provide the only clues to Wang’s final days. In handwritten records, Sharon Police said a man who was described as the “head of [an] Asian gang in Boston” had Wang killed over the New Hampshire breaking-and-entering incident.

A note in the Sharon Police file described a witness to Wang’s murder as a “Flying Dra” and a “NY gangster”. Retired detective Jim Keating confirmed to Bellingcat that Wang, along with his associates and killer, were suspected members of the Fukienese Flying Dragons. He said he believed Wang was murdered because he posed a risk to the gang following his arrest.

Investigator’s notes describing a witness as a gang member. Source: Sharon Police Department

Documents released by the Merrimack Police Department and Sharon Police Department said that an inmate in New York who, in 1997, was serving a 25-year sentence for attempted kidnapping, offered to share information about Wang’s murder with the FBI in return “for a reduction (sentence)”. The inmate implicated the gang in at least two 1996 New Hampshire home invasions and also gave authorities information about the murder.

The account is heavily redacted but includes a note that the US Attorney for New Hampshire was making arrangements to interview the man. Police in New Hampshire said they believed the inmate “was truthful in his statements and has knowledge about the murder of Mr Wang”. Keating confirmed to Bellingcat that he and investigators from other law enforcement agencies traveled to New York to interview the man. He said the inmate, a suspected member of the Fukienese Flying Dragons, gave a statement on Wang’s murder. 

Keating said that investigators had learned of a dispute on the night of the murder between Wang and the gang’s leader. He said Wang had planned to run an illegal gambling operation at an apartment, which the gang boss was using as a prostitution venue. This led to an argument at another location, and when Wang left for the apartment the boss followed him. 

But Keating said that based on the information gathered throughout the investigation, he believes the primary motive for Wang’s murder was his arrest over the use of credit cards stolen in the Wolfeboro home invasion. With that arrest, Wang presented a risk to the rest of the gang because investigators could tie them to the home invasions. “Wang broke the basic rules by taking something that was identifiable and using it, and that’s what the whole damn thing was about,” Keating said.

Crime scene photos of the basement unit on Oxford Place in Boston’s Chinatown where Wang was murdered. Source: Sharon Police Department

Keating told Bellingcat that the crime scene had been damaged by flooding after the murder. He said he used a power saw to cut off the bottom of a door in the unit and that lab testing revealed the presence of Wang’s blood. 

Investigators also worked to confirm Wang’s identity by testing the DNA of the remains found in the woods. In a 1999 case summary written by a Massachusetts State Police Trooper, it was noted that the FBI was attempting to locate Wang’s parents through police in China.

Three months later, the FBI’s Hong Kong office sent a communique to Boston confirming that the Chinese Ministry of Public Security and Interpol had located Wang’s parents. Wang’s mother, it said, was willing to provide a DNA sample for comparison. 

The FBI communique is the final document in the newly released files that details the efforts to confirm Wang’s identity with DNA. However, Keating told Bellingcat that a DNA sample was obtained from Wang’s mother in China. It was brought back to the US for testing and confirmed to be a match, he said. “I don’t know when the DNA was collected or who did it. But I know that they did that,” Keating said. “There is no question about who he was.” 

Bellingcat contacted both the Norfolk and the Suffolk County District Attorneys to confirm the DNA match, but did not receive a response to questions about DNA testing or the victim’s identity. Other former law enforcement officers named in the files released to Bellingcat have not responded to requests for comment. 

One document included in the murder file references discussions between homicide investigators and the FBI about charging Wang’s killer with home invasion offences. The note discusses the potential to have a witness testify against Wang’s suspected killer. It is unknown whether he was ever charged. 

The Shooter

The man authorities suspected of shooting Wang, or ordering his killing, was described in the documents as the head of the Fukienese Flying Dragons in Boston. Police said he was an undocumented immigrant from Fujian Province who ran a sex trafficking ring. 

A redacted note in the Sharon Police Department murder file references Wang’s suspected killer as “a player” in the Chinatown Massacre, an infamous 1991 case in which five men were shot dead in a basement gambling parlour in Boston. In another note in the case file, investigators wrote that he was “thought to be a federal informant”. 

The name of the gang boss was redacted in the police file released to Bellingcat.

Keating said Wang’s identity was confirmed by DNA and that blood evidence, corroborated by witness statements, placed his killing in the Boston Chinatown apartment. The retired Sharon detective said at that point, the Boston Police Department and the Suffolk County District Attorney’s Office should have, respectively, taken over the investigation and prosecution of the case. 

The Boston Police Department did not respond to questions from Bellingcat. It does not include the killing in its list of unsolved homicides. 

The Suffolk County District Attorney’s Office said it did not have records for Wang’s murder. “Unfortunately, after a thorough search with assistance from our homicide unit, no responsive records could be located,” it said.

In response to Bellingcat’s original public records request, the Norfolk County District Attorney’s office, which covers Sharon, said the files were exempt from public disclosure because they pertained to “an active and ongoing criminal investigation”.

A spokesman for the office said last week that the circumstances surrounding the remains of an adult male discovered in Sharon in April 1998 “remain under investigation” by a state police detective assigned to the Norfolk District Attorney’s Unsolved Case Unit. 

The FBI confirmed that the agency assisted state and local partners in an operation investigating home invasions in the late 1990s but did not answer questions about Wang’s murder or his suspected killer. “Given that we’re not the lead, we’ll refer you to Massachusetts State Police,” a spokeswoman said.

Massachusetts State Police referred questions to the Suffolk and Norfolk County District Attorney’s offices.

It remains a mystery why Wang’s killer was never charged and prosecuted for his murder. “They got away with so much. Blatantly got away with so much,” Keating said of the gang. “Killing people for these guys was like … these guys were all expendable.”

The Norfolk District Attorney’s Office encouraged anyone with any information about the case to contact the Massachusetts State Police Tip Line or the Sharon Police Department.


Melissa Zhu contributed research to this article.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Investigating a Murder: Public Records Uncover New Clues in Chinatown Cold Case appeared first on bellingcat.

  • ✇bellingcat
  • Satellite Imagery Documents New Border Patrol Road Construction in Big Bend National Park Logan Williams
    Sign up here to receive Bellingcat’s biggest investigations by email as soon as they are published. Satellite images obtained and analysed by Bellingcat show over five miles of new road constructed in Big Bend National Park in southwestern Texas, part of a US Customs and Border Protection (CBP) “Smart Wall” installation, which includes roads, barriers, lighting and cameras.  The project was paused earlier this week after pushback from local residents, politicians and environmental groups.
     

Satellite Imagery Documents New Border Patrol Road Construction in Big Bend National Park

20 de Agosto de 2026, 17:50

Sign up here to receive Bellingcat’s biggest investigations by email as soon as they are published.

Satellite images obtained and analysed by Bellingcat show over five miles of new road constructed in Big Bend National Park in southwestern Texas, part of a US Customs and Border Protection (CBP) “Smart Wall” installation, which includes roads, barriers, lighting and cameras. 

The project was paused earlier this week after pushback from local residents, politicians and environmental groups.

The roads have been built adjacent to the Rio Grande, through the river’s floodplain and riparian forest, and include construction adjacent to Cottonwood Campground, Santa Elena Canyon, and Mariscal Canyon in the National Park.

Planet Labs satellite imagery captured on August 15 and August 19 shows new roads cleared through the riparian forest around the Rio Grande in Big Bend National Park.

The map above traces the new road construction in yellow. An unannotated version of the satellite image showing the new road can be found here while a before image of the same area where no road is visible can be seen here.

The new road extends to Cottonwood Campground, one of four campgrounds in Big Bend National Park. 

The road can be seen crossing the riparian forest and smaller drainages before joining the campground access road. Imagery also appears to show bright yellow construction equipment staging in the campground area, where bulldozers were previously seen.

Planet Labs satellite imagery captured on August 19 shows a new road near Cottonwood Campground in Big Bend National Park. Hover to compare to Planet satellite imagery from September 2022. Note that the removal of cottonwood trees in the campground is unrelated to CBP construction activity.

In the southernmost part of Big Bend National Park, additional new road construction is also visible near Mariscal Canyon and connecting to Talley Road. 

CBP planning documents indicate that this section of the border will receive a four-to-six foot tall vehicle barrier in addition to the “smart wall” lighting and camera systems. Talley Road currently provides access to riverside backcountry campsites and hiking and boating access to Mariscal Canyon on the Rio Grande.

Planet Labs satellite imagery captured on August 18 shows a new road near Mariscal Canyon in the southernmost part of Big Bend National Park.

The map above traces the new road construction in yellow. An unannotated version of the satellite image showing the new road can be found here. A before image of the same area where no road is visible can be seen here.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

CBP Commissioner Rodney Scott described the construction activities as “survey and design work” in an August 13 statement. He also stated that CBP is “building one new access road, improving existing roads, installing detection technology, and placing vehicle barriers in limited, strategic locations.”

However, by August 17 Scott had announced a “pause” of construction activities in the face of  bipartisan criticism of the project’s impact to the environment, recreation access, and the local economy

The Big Bend Border Patrol Sector sees the fewest migrant apprehensions of any part of the US southern border, according to CBP’s own data.


Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Satellite Imagery Documents New Border Patrol Road Construction in Big Bend National Park appeared first on bellingcat.

  • ✇bellingcat
  • Will Ronaldo Cry​? World Cup Fans Bet Billions Through Prediction Markets Miguel Ramalho
    Cristiano Ronaldo during Portugal’s losing game against Spain earlier this month. Source: Imagn Images via Reuters Connect Football fans wagered more than US $14 billion on the FIFA World Cup through prediction markets Polymarket and Kalshi, a Bellingcat analysis has found. Support Bellingcat Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world. Donate On the crypto-based Polymarket, which provid
     

Will Ronaldo Cry​? World Cup Fans Bet Billions Through Prediction Markets

30 de Julho de 2026, 08:17
Cristiano Ronaldo during Portugal’s losing game against Spain earlier this month. Source: Imagn Images via Reuters Connect

Football fans wagered more than US $14 billion on the FIFA World Cup through prediction markets Polymarket and Kalshi, a Bellingcat analysis has found.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

On the crypto-based Polymarket, which provides more information about individual trading accounts than its rival American site Kalshi, we also found that just 1% of users collected the vast majority of winnings during the tournament.

Users traded on almost 60,000 outcomes across both sites during the competition, betting on everything from the sponsor of the Golden Boot winner to whether Cristiano Ronaldo would shed a tear during a Portugal match. 

The World Cup, held in the US, Canada and Mexico over June and July, was forecast to be the biggest betting event in history, with a predicted $50 billion in wagers. 

Unlike traditional sports betting sites, prediction markets resemble stock exchanges where users trade, via an order book, on whether a real-world event will happen. Prices fluctuate based on what the market believes the probability of that event is. The sites charge fees on each sports trade.  

With 48 teams playing 104 games, the World Cup was slated to be the biggest gambling event of all time. Source: Polymarket

The prediction market industry has faced criticism over its vulnerability to insider trading, potential market manipulation and concerns about fueling unregulated gambling. The Wall Street Journal also reported in May that a small number of individuals using algorithmic trading models were taking home an outsized share of winnings.

This would appear to align with Bellingcat’s World Cup analysis, where a small percentage of accounts made most of the winnings. However, the level of detail we were able to obtain did not allow us to see accounts that had utilised algorithmic methods.

Both Polymarket and Kalshi make events and volume data available for programmatic extraction – making it useful for open source analysis. Bellingcat’s data analysis examined all 104 matches as well as the World Cup winner event that was hosted on each platform.

On Polymarket, users traded a total of $10 billion ($5.7 billion on individual games and $4.3 billion on which country would win). The largest game on Polymarket was the Spain vs Argentina final ($212 million), followed by the France vs Spain semi-final ($165 million) and the England vs Argentina semi-final ($142 million). 

On Kalshi, users traded a total of more than $4.3 billion ($4.1 billion on the games and $200 million on the winner).

Bellingcat’s analysis also found that 1% of Polymarket trading accounts collected 86% of all winnings during the World Cup, and the bottom 50% of winners shared just 0.1% of profits. The typical winning account on Polymarket made $21, while the typical losing account lost $32 (measured by the median, which is less affected by a handful of exceptionally large wins and losses). More than 12% of traders (14,500) who bet on two or more games lost every bet. The Polymarket account that won the most across all games made a profit of more than $13 million, while the biggest loser lost $11.6 million.

We were unable to run the same win-loss analysis for Kalshi because trading account overviews are not publicly available.

The top teams, by trading volume, across both sites were Argentina ($1.068 billion), Spain ($876 million) and France ($836 million). The top players were Argentina’s Lionel Messi ($40 million), France’s Kylian Mbappé ($36 million) and Norway’s Erling Haaland ($16 million).

How We Calculated the Volume

Polymarket displays the actual traded volume on its site, the total US dollar amount of shares bought and sold since the market started.

Kalshi does not display the traded volume. Instead, it shows the notional volume, which counts every contract traded at the maximum payout value of $1. This means that a token bought for $0.20 will be presented as $1 extra in a user’s displayed volume. This makes the total monetary volume appear higher on Kalshi’s website. To achieve a fair comparison between both platforms, we implemented a heuristic to reconstruct Kalshi’s markets’ volume. We used the daily average price for each market over their duration and multiplied it by the number of contracts traded on that day, the sum of which gives us the values used in this piece. We applied this formula for the more than 21,000 World Cup markets. 


Data scraping was supported by Oxylabs’ Project 4β.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Will Ronaldo Cry​? World Cup Fans Bet Billions Through Prediction Markets appeared first on bellingcat.

  • ✇ASEC BLOG
  • June 2026 Security Issues in Korean & Global Financial Sector ATCP
    Statistics on Malware Distributed to the Financial Sector In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third attack stage, indicating that multi-stage […]
     

June 2026 Security Issues in Korean & Global Financial Sector

Por:ATCP
15 de Julho de 2026, 12:00
Statistics on Malware Distributed to the Financial Sector In the June threat analysis for the financial sector, phishing was the most prevalent attack method in Attack Stage 1, while droppers/downloaders (distribution tools that download additional malware) were the most prevalent in Attack Stage 2. Infostealers were identified in the third attack stage, indicating that multi-stage […]
  • ✇bellingcat
  • Identifying the Crypto Entrepreneur Linked to Popular Forum Trading in ‘Leaked’ Nudes of Women Kolina Koltai
    This investigation is a collaboration between Bellingcat and New Zealand news site The Press. You can read The Press’ piece here.  Content warning: This article discusses non-consensual sexually explicit content and child sexual abuse material. In 2024, a former track and field coach in Boston, Massachusetts, was sentenced to five years in jail for attempting to trick and extort more than 100 women, including student-athletes he coached, into sending him intimate photos.  According to t
     

Identifying the Crypto Entrepreneur Linked to Popular Forum Trading in ‘Leaked’ Nudes of Women

16 de Julho de 2026, 13:00

This investigation is a collaboration between Bellingcat and New Zealand news site The Press. You can read The Press’ piece here

Content warning: This article discusses non-consensual sexually explicit content and child sexual abuse material.

In 2024, a former track and field coach in Boston, Massachusetts, was sentenced to five years in jail for attempting to trick and extort more than 100 women, including student-athletes he coached, into sending him intimate photos. 

According to the 2021 criminal complaint, Steve Waithe stole photos from some of the student-athletes’ phones under the pretence of “filming their form” at practices and meets. He also approached some victims via fake online accounts, telling them he had found their images on a forum site called “leakedbb.com” (“LeakedBB”) and offering to help them remove these photos if they provided more images for “reference”. 

Authorities said Waithe also hired and paid another man in October 2020 to hack into the Snapchat accounts of women he coached or had other relationships with in an effort to steal and distribute nude images online. 

In one post, according to the US Attorney’s Office, Waithe wrote: “Does anyone want to trade nudes? I’m talking girls you actually know. Could be exes or whatever. I have quite a few and [am] down to trade over snap[chat] or something.” 

Legal documents do not name the sites on which Waithe distributed these images, but Bellingcat found a cached version of a November 2020 post with that exact wording on LeakedBB – the same site he allegedly used to try to trick victims. Another cached LeakedBB thread posted a few months later shows the same user offering to trade nudes of athletes, including “a lot that I actually know”.

Screengrab from LeakedBB, showing a user asking to trade nudes of “girls you actually know”; redaction by Bellingcat

Such posts were not unusual on the site: multiple archived pages show the forum’s users either requesting Snapchat hacks or offering to help others hack Snapchat accounts, sometimes for a fee. 

In the criminal case against Waithe, the ownership of LeakedBB is never discussed, but a Bellingcat investigation can reveal that payment streams, company records and website domain information appear to lead back to one individual: Jitendra Maharaj, a Christchurch-based former pilot and co-founder of a cryptocurrency start-up, Pay It Now (PIN), which reportedly billed itself as the “Stripe of crypto payments”. 

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Our New Zealand publishing partner The Press sent an email to Maharaj on June 4 outlining our findings in detail and inviting him to respond. Maharaj did not reply to this. 

However, by June 6, LeakedBB was down. As of publication, the website remains inaccessible. 

The Press later received an email from a Christchurch-based lawyer representing Maharaj, who said their client was in Fiji for a family member’s funeral. The lawyer requested that we wait until his return on June 23. 

When The Press visited his residence – a two-storey family home in Christchurch’s affluent Aidanfield suburb – on June 25, Maharaj said he did not know who was behind LeakedBB or operated it and that he was not sure if the website was down. 

He said he did not respond to the email queries and had not spoken to his lawyers about them because “all the evidence against me just sounded really weird” and it seemed like there was “some kind of targeted attack out on me” based on “manufactured evidence or something that’s pointing me to this garbage”. However, he refused to comment on the record about most of the specific evidence linking him to the site and referred these questions to his lawyer. 

He also claimed that he had been contacted by people “trying to harass me to get me to send them money”, but declined to provide details on the record.

Jitendra Maharaj at the entrance of his residence on June 25, 2026. Source: Iain McGregor/The Press

Despite a further extension of the deadline until July 6 – more than a month after we first reached out – Maharaj and his lawyer had not provided any statement directly addressing the specific evidence linking him to the site as of publication. 

PIN, the company Maharaj co-founded, did not respond to The Press’ requests for comment. However, there is no suggestion that PIN has any knowledge of or involvement in LeakedBB.

Profiting Off ‘Leaks’

LeakedBB was set up in 2019 and built a sizeable following over the next seven years, averaging an estimated two million visits a month from March to May this year. The board statistics shown on LeakedBB’s homepage in May displayed 2.2 million registered users and more than 2.6 million posts.

Screengrab of the board’s statistics as of May 26, 2026; personal information redacted by Bellingcat

Google’s Transparency Report shows it received more than 95,000 individual requests for over 350,000 pages on LeakedBB to be delisted from search results. This resulted in Google de-listing more than 169,000 pages from its search results, according to the report. 

Shortly after the site went offline, a Reddit post noting the outage and asking for alternatives trended in the “hot” section of a piracy subreddit, accumulating almost 700 votes in a week. In response to a question by one commenter asking what the site was, another person replied: “Not only did it have ‘onlyfans’ content, also amateur, asian, arabic, celebrity and other hacked phone/icloud content from other sites.”

This comment accurately summarised some of the content on the site. In LeakedBB’s early days, it had sections for other types of “leaked” content such as computer programmes and eBooks. But within months, the forum’s discussions were almost exclusively about pornographic images and videos that members claimed had been leaked – implying that it was non-consensual, hacked or stolen content.

The most popular section on the forum contained content that claimed to be from sites such as OnlyFans and Fansly, which, if shared without the original creators’ consent, would be a violation of their intellectual property

Reba Rocket, co-owner and chief operating officer of Takedown Piracy, a company that helps both adult performers and private individuals remove non-consensually shared explicit media, said sites like LeakedBB cause financial harm to legitimate content creators.

“People would not shove a DVD into their coat pocket and walk out of the store – that’s something tangible that they know they’re doing something wrong, whereas watching something on the internet for free doesn’t have that same connected moral,” she said. 

Other sections on LeakedBB featured threads requesting or promoting content that often appeared to show women who did not have anything to do with the adult industry, which the posts claimed were leaked, hacked or even obtained through blackmail. 

One post advertised images of girls from 29 US states: “There’s names and Facebook information if you want that,” the member, “Master Leaker”, posted. “There’s also two girls that got blackmailed into sending more nudes as well!”

LeakedBB user advertising a large file of “girls from 29 different states”; personal information redacted by Bellingcat

In the “Requests” section, users shared clothed images of women or social media handles of potential victims, and asked if others had leaked content of them. In one recent post looking for a “Florida Milf”, a user wrote: “She may go by the name [redacted]. Looks like the daughter graduated from [redacted]. Anyone have content of her? Sex tapes?” 

Some users also posted nude or intimate images of women they had found elsewhere, asking for help finding out their real identities. “Who is she?” or “Can anyone ID?” were some common questions in the posts. 

Non-consensual intimate image sharing (NCII), colloquially referred to as “revenge porn”, is far from new. It is a known problem on Reddit, where, in 2022, a BBC investigation found “thousands” of such images being shared despite the platform’s attempts to crack down on the issue. 

LeakedBB, however, seemed to take the opposite approach: instead of trying to moderate or prevent users from posting what appeared to be NCII, it sought to profit from and reward it. 

Except for preview images, most of the content users shared in the “leaks” section was behind a paywall and could only be accessed with memberships costing up to US$99.99 or by redeeming credits. 

The site rewarded members with credits for posting “leaked” content, as well as when other members spent credits to “unlock” their content. These credits could be used to access links that users could otherwise only view with a paid upgrade, or redeemed for cryptocurrency at varying rates (the most frequent contributors had the option to cash out the equivalent of up to $0.15 for each thread they posted). 

There was also an annual Christmas contest, with last year’s total prizes worth over $4,000 in cryptocurrency for users who posted or liked the most threads.

Screengrab of a forum announcement on LeakedBB posted on Dec. 7, 2025.

Rocket said LeakedBB had “damaged many people”, including clients of her company. “Those specific clients are not in the adult industry,” she said, “but LeakedBB seemed more than happy to share their non-consensual content”. 

The “leaks” were often posted with women’s purported real names, locations and social media accounts, as well as preview images showing their uncovered faces. One poster said sharing a woman’s social media details “adds to the experience”. 

“For me, it makes my jerk-off sesh feel more personal, as if she’s an actual person I know rather than a moviestar/pornstar,” the post said.

Screengrab of a post where a LeakedBB user shared content of a woman, including her socials; personal information redacted by Bellingcat

There were more than 80 responses to this thread, mostly thanking the original poster for sharing the content. One of them, however, claimed to be the woman shown in the images: “Please remove this link. These photos were illegally stolen from me. This constitutes revenge porn and violates US law. Police are already involved. Not only is it illegal but just gross.”

Allison Mahoney, the founder and managing attorney at ALM Law in New York and Colorado, told Bellingcat she received calls about cases involving NCII “all the time”. 

“It kind of amazes me, given the amount of media attention this has gotten over the years, that people are still engaging in this type of abuse so cavalierly,” said Mahoney, whose firm specialises in providing legal services for abuse survivors and children harmed in welfare systems.

Mahoney and Rocket agreed that sites sharing NCII often had real-world implications for victims, especially when images were posted alongside personal information, including names, contact information and professions. 

“We have clients who … their children were kicked out of Catholic school, or they lost their mainstream job, or relationships ended, or families cut them off simply because content was posted online without their consent and viewed by others,” Rocket said. 

Mahoney said online abuse can turn into offline abuse when victims have their personal information, like their name, profession and contact information, posted with their images.  She has seen clients who had strangers show up at their homes or places of work, threatening their physical safety – a situation she said was “really terrifying”. 

In July last year, LeakedBB closed a marketplace it had hosted for more than five years, which allowed users to sell leaks and services to each other. Lucifer NightStar, the administrator account on the site, said there were allegations of people selling “UA [underage] material”, which was “not something we want on [LeakedBB]”.

Screengrab of a post where Lucifer NightStar explained why the marketplace section had been shut down.

On one section of the forum, which was specifically for sharing content from other sites that hosted leaked pornographic content, LeakedBB had a disclaimer: “Please note that posting any content on any one below the legal age of 18 is against the law. We have a zero tolerance policy on such things and your account will immediately be banned / reported.”

But this warning did not appear on other sections of the forum, including those featuring threads of “amateur nudes” described as having been leaked. Some threads on the forum, which remained accessible shortly before the entire site was taken down, also described images of “young teens”. 

While it is not known if those descriptions are accurate, in a recent post on Reddit a person asked for help taking down non-consensual photos they said were taken when they were a minor, hacked from Snapchat, and posted on LeakedBB, among other sites. 

“I am in school to become a teacher and searched my name on google. If you go down a bit these websites come up,” they wrote. “I am so devastated and can’t believe this has happened to me.” 

While speaking to The Press outside his residence on June 25, Maharaj said that when it came to publishing non-consensual pornography and child sexual abuse imagery, “It should be obvious anyone’s against that.”

Who Is Lucifer NightStar?

Lucifer NightStar was the username for the only account with the title of “Administrator” on the LeakedBB forum. This user posted FAQs for the site and almost every forum announcement throughout its history. 

The URL of this account’s profile page shows the user ID (UID) of “1”. According to documentation for MyBB, a free and open source forum software that LeakedBB has credited for powering the site, the first user of the forum is assigned the UID “1” and has super administrator privileges – meaning their account cannot be deleted, banned or otherwise altered by regular administrators.

While the profile did not state the user’s location, it did show a local timestamp based on the user’s timezone settings, which matched GMT+12 – a timezone used in several countries in Oceania, including New Zealand and Fiji. 

Lucifer NightStar’s recent posts generally avoid mentioning non-consensual intimate imagery, focusing on administrative updates and issues, troubleshooting and the annual Christmas contest. However, in the first few months of the forum’s existence, the user posted a thread with a “LeakedBB Exclusive” of “leaked Kiwi girls”.

One of Lucifer NightStar’s first posts on LeakedBB, sharing content described as “leaked Kiwi girls”.

In another discussion thread from 2020, Lucifer NightStar vouched for a user’s ability to “influence” another member’s ex-girlfriend to share nudes.

(Top) LeakedBB user offering their services to obtain nudes from another user’s ex-partner; (Below) A response from Lucifer NightStar vouching for this user being a “premium collector”. Personal information redacted by Bellingcat

Maharaj did not respond to The Press and Bellingcat’s question about whether he was Lucifer NightStar. However, one of the administrator’s posts led us to a clue pointing to Maharaj’s possible connection with LeakedBB. 

Logica Ltd and MyBBplugins

In one post in May 2021, responding to a user reporting problems paying with Apple Pay, Lucifer NightStar shared a screenshot of what the payment screen should look like. A company name was visible in this image: “Logica LTD”.

Screenshot of a forum post by Lucifer NightStar on how to pay for a premium upgrade for LeakedBB using Apple Pay, showing the company name “Logica LTD”.

New Zealand company records show that Logica Limited was registered by Maharaj in February 2021, just months before this post. The company address is also in Christchurch, where Maharaj lives.

(Note: This is a different company from Logica Partners Limited, based in Auckland, which has no apparent connection with Maharaj or LeakedBB and is unrelated to this investigation.) 

The records from the New Zealand Companies Office show that Maharaj has been the sole director of Logica Limited since its incorporation. He stated on his LinkedIn profile that he was self-employed as the CEO of Logica NZ from May 2020 to August 2021. 

(Maharaj’s LinkedIn profile appears to have been deleted between June 13 and June 15, after The Press and Bellingcat’s initial enquiries and during the period his lawyer said he was in Fiji attending a family member’s funeral.)

Left: Screengrab of Jitendra’s work history from LinkedIn; right: Company registration information for Logica Limited (redaction by Bellingcat). Sources: LinkedIn, New Zealand Companies Office

But that was not the only connection to Logica Limited. On May 4, 2022, a YouTube user with the display name “LeakedBB” uploaded a video on how to pay for memberships on the site. This video was also embedded on LeakedBB’s homepage. 

The video showed how users could pay by credit card. When they clicked to purchase a membership, LeakedBB would redirect them to another website to buy a digital avatar pack with a price corresponding to their selected membership tier. 

After purchasing this “referral product”, users were encouraged to leave a comment and a positive rating to receive an “extra bonus month”. Archived versions of the website show view counts in the tens of thousands for some of these avatar packs. 

The thumbnails of the “digital avatars” as well as their price and description, as shown in the video, were identical to those shown on the archived version of a site, logica.nz, which is recorded as Logica Limited’s website on OpenCorporates. This site also lists “Logica LTD” in its copyright information at the bottom of its landing page

(Bellingcat last accessed a live version of the video on June 15. By July 1, we noticed that the video had been removed by the uploader.)

Left: YouTube video on how to purchase upgrades on LeakedBB. Right: Archived purchase screen of the same avatar pack on Logica.nz

In a forum thread on LeakedBB dedicated to explaining alternative ways to pay for membership, hundreds of users posted that they had just purchased the “Mystic Avatar Pack” or the “Pixel Avatar Pack” to gain access to the site. One user included screenshots of their purchase, showing the site URL to be “logica.nz”. Other users also stated that they had made the purchase on this website and were waiting to receive their upgrades.

Shared screenshot from a LeakedBB user who purchased a “Pixel Avatar” pack in exchange for membership, showing that they left a comment, like other users, on the purchase page on logica.nz. Personal information redacted by Bellingcat

This website’s landing page now displays only a note stating that it is under maintenance. However, according to archives captured by the Internet Archive, it was still selling “digital avatar packs” in March 2025.

This type of payment structure not only conceals the nature of the transaction from the payment processor (as non-consensual content violates most platforms’ terms of service), but it also hides the transactions for the user, as payments are not described as being made to “LeakedBB” on bank statements.

When asked about the links between LeakedBB and Logica Limited, Maharaj only told The Press at the doorstep interview on June 25 that “Logica was my company. I cannot say what happened there right now”.

According to the New Zealand Companies Register, Logica Limited is in good standing, with its most recent annual filing submitted by Maharaj in March 2026. 

The Domain Name System (DNS) records of LeakedBB revealed another connection that seems to point back to Maharaj. Using online investigations tool DNSlytics, we viewed DNS records for the website and found that in 2020, the MX (mail exchange) record for LeakedBB.com was set to LeakedBB.net. An MX record is the mail server set up to accept emails for that domain. For LeakedBB.com, this was later changed to ProtonMail. 

While the WHOIS ownership of LeakedBB.net is obscured, we found it on a list of sites that had DNS certificates issued by another site, mybbplugins.com. A DNS certificate is used to prove ownership of a domain and requires an administrator to validate that certificate. 

According to WHOIS records from cyberthreat intelligence platform DomainTools, mybbplugins.com was publicly registered to Maharaj from December 2011 to February 2019, after which the registrant information was redacted.

The same site also issued a DNS certificate for a domain bearing Maharaj’s name (jitendramaharaj.com) as well as two domains that include part of his first name, jit-pay.cc and thejitshow.com. DNS certificates for these domains were issued between 2016 and 2021, according to free Certificate Transparency monitoring site crt.sh. Both “leakedbb” and the domain names linked to Maharaj’s name (i.e. “jitendramaharaj”, “jit-pay” and “thejitshow”) were also used as subdomains for mybbplugins.com, records from DomainTools show. 

Another link appeared when we inspected the code of the oldest saved archive of the payment screen on LeakedBB, from November 2019, which showed a ProtonMail address associated with the PayPal form at the time with a string of seven digits as the username. 

This string of seven digits is an exact match for what appears to be part of a Fiji-based phone number listed on WHOIS records for websites registered to Maharaj’s name including mybbplugins.com, from 2008 to 2011. It is unclear whether Maharaj was using this phone number in 2019, by the time LeakedBB was set up, and a different Fiji-based phone number was used with his name when the registration for mybbplugins.com was renewed in 2016.

Top: The archived HTML code for LeakedBB’s payment page, with a ProtonMail email linked to its PayPal account. Bottom: The WHOIS domain registry for mybbplugins.com, registered to Maharaj in 2011, with a phone number matching the digits to the ProtonMail email. Graphic: Galen Reich

Explore some of the links between Maharaj and LeakedBB:

Graphic: Galen Reich

From MyBB to LeakedBB

Bellingcat also found several other apparent connections between Maharaj and other applications hosting adult content. 

An account with the username “Jitendra M.” has been posting on the MyBB community forum since 2008, with the account ID originally using the username “Darkmew”. An archived capture of this account’s profile information showed a date of birth and a location in Fiji. 

This date of birth matches the one listed on a Facebook profile Bellingcat found under Maharaj’s name. His LinkedIn profile also shows that prior to moving to Christchurch, he worked in Nadi, Fiji, and he has listed addresses in the city for some of the domains registered to his name, as well as an email with a Fijian domain. This user also mentions that they are a pilot

Jitendra M.’s profile bears a “former staff” label, indicating that he used to work for MyBB. A previous commit (save) of a file containing details of MyBB team members shows that the full name associated with this account’s user ID and username was “Jitendra Maharaj”, and his website was listed as jitendra-maharaj.com. 

Archived versions of this site show photos and details that match those from Maharaj’s public social media profiles and interviews. For example, a 2011 capture shows that he mentioned being a pilot at a company called Pacific Sun. Pacific Sun was later rebranded as Fiji Link, and Maharaj’s LinkedIn profile, before it was deleted, stated that he worked for Fiji Link from 2009 to 2015. A blog post on the site also refers to mybbplugins.com as the author’s “newest endeavour”.

Left: Archived profile of “Darkmew”’s profile on MyBB; Right: Screengrab of information from a Facebook profile under Maharaj’s name, which has either been made private or deleted as of publication.

Very shortly after joining the MyBB community forum in Feb 2008, Jitendra M. asked about using MyBB for “warez” (an internet slang term for pirated digital content) and/or adult content. He stated that he was “interested in using it for a [sic] adult forum”. 

During this time, he also posted asking about streaming videos from a server and how to use a PayPal account without a credit card for “people putting money into my account for services I provide”. In late 2008, Jitendra M. purchased a web domain, reaperscrypt.info, which Wayback Machine archives show hosted pornographic content while it was online in 2009. This domain was publicly registered to Maharaj from November 2008 to January 2010. 

In 2013, he posted about selling the mybbplugins.com domain. However, as previously mentioned, Maharaj’s name was still publicly registered as the owner of the domain until February 2019, when registration data was redacted.

Top: Post by Jitendra M. about using MyBB for warez and adult sites using MyBB; Bottom: Post about selling mybbplugins.com

Bellingcat was able to view Facebook and Instagram accounts under Maharaj’s name and showing his profile picture in early May. These accounts painted a picture of a family man, with his public photos mainly showing his wife and children. His Facebook account had been either deleted or made private by May, and his Instagram account, while still active, has not been updated since 2013.

Archives of an X account using the same username as Maharaj’s Facebook and Instagram accounts also show several posts from November 2019 promoting LeakedBB. 

Archived tweets from an account, using the same username as what appeared to be Maharaj’s former Facebook and Instagram accounts, which posted links to LeakedBB in November 2019. Personal information redacted by Bellingcat

The “Darkmew” username that Jitendra M. originally used was also used for a GitHub account which hosts a repository described as the “official repository for Pay it Now – PIN Token”. This account, which now redirects to an account with the username “JitMaharaj”, has also forked (or copied) two apps created by other people: one to create a subscription platform “like onlyfans.com” that uses cryptocurrency for payments; the other designed to scrape and report illicit content from LeakedBB.

Screengrabs from the “JitMaharaj” GitHub account, which forked repositories for an application designed to create a platform “like ‘onlyfans.com’, and another to report illicit content from LeakedBB.

These forked repositories were among 38 visible on JitMaharaj’s account on June 17, but by July 1 – after a June 22 query from The Press asking Maharaj whether he owned this account – there were only 25 repositories listed on this account. The two repositories mentioned above were among those removed.

Maharaj did not respond to questions about whether he owned any of the accounts or domains mentioned in this section.

‘Hiding Behind Screens’

Mahoney said that successfully removing clients’ images from platforms like LeakedBB was a time-consuming task. “Some sites, usually the sites hosted overseas, will just ignore the request and won’t take them down,” she said.

In the US, which accounted for almost half (40 percent) of LeakedBB’s web traffic in May, the Take it Down Act recently came into effect. The new federal law requires platforms to quickly remove non-consensually shared intimate imagery when it is reported.

However, there has been little discussion of the law on LeakedBB. One user asked in the “Help” forum how this act would affect the site and its members back in October 2025, but Lucifer NightStar never responded to this post.

LeakedBB user asking about the Take It Down Act

Rocket said having content removed for her US-based clients could be difficult when the platforms were based overseas: “A lot of it depends on where the platform is hosted, who runs their ad network and who is monetising – who their payment processors are,” she said. 

LeakedBB accepted cryptocurrency payments through NOWPayments, a cryptocurrency payments gateway based in the Netherlands and Estonia. The purchase page for its subscription plans, which allowed users to gain unrestricted access to the site, redirected to a NOWPayments purchase screen to transfer cryptocurrency to LeakedBB. 

In response to questions from Bellingcat, NOWPayments confirmed that LeakedBB’s activities violated its terms of service. The payments provider said it had deactivated LeakedBB’s account and blacklisted the platform immediately, as of June 4. 

LeakedBB did have a form for people to request that their content be taken down under the Digital Millennium Copyright Act (DMCA), a US copyright law. However, this required victims to submit personal information such as a physical address and a business email address, and stated that it would reject requests that used email addresses from free services like Google and ProtonMail. Such details appear to go beyond those required for DMCA takedown requests on other sites: for example, Google only requires a first and last name, and an email address from any domain.

In one Reddit thread discussing the difficulty of removing content from LeakedBB under the DMCA, someone commented: “Some of this seems fairly standard, some of it seems like it’s designed to make people not request a takedown for fear of doxing [sic] themselves.”

On the page to submit DMCA takedown requests, LeakedBB also stated that successful requests would lead to them removing content hosted on their servers, but not links to third-party hosting providers – which is how a large portion of the content was made available to the website’s users. 

In New Zealand, where Maharaj is based, posting intimate imagery without consent is illegal under the Harmful Digital Communications Act. People face up to two years imprisonment or a fine up to NZ$50,000 (US$29,200), while for a company, the fine can be as high as NZ$200,000. 

Netsafe is the only approved body in the country that handles complaints under this act. The agency’s chief online safety officer Sean Lyons told The Press that the law was quite novel and other jurisdictions were “envious” when it was enacted – it was able to respond to generative AI technology that didn’t exist when it was written, and gave New Zealand courts powers to issue takedown orders, even in other countries.

Still, Lyons said the law had its limitations: it was mostly intended for use where one individual was harming another, and if the responsible party was overseas, the law’s efficacy largely relied on responsible platforms doing the right thing. 

“There are times when within our process, we will have contacted platforms or hosts and they will have said, ‘Who the heck are you?’…[Or] ‘We know what we’re doing, we are quite comfortable with what we are doing, and we don’t give a stuff about what it is that you are telling us, or about New Zealand law, or about the harm.’”

Mahoney and Rocket agreed that current laws were limited in their effectiveness against sites like LeakedBB. 

“The fact of the matter is there are places where … until there is an enforceable international law, that content is going to be available forever, which means there is a risk of it being shared forever,” Rocket said. 

Mahoney said image-based abusers have also become more sophisticated over time: “Technology is advancing, and the law is always playing catch-up,” she said. 

But she suggested that identifying those responsible for the abuse could have a deterrent effect: “The anonymity that people have hiding behind screens really contributes to this and emboldens people to act in ways that are very abusive to people.

“If people understand that there’s a risk that their identity and their bad behaviour will be revealed, the hope is that it will curtail some of this and dissuade people from engaging in this type of conduct, which is so, so harmful to the victims.” 

If you are a victim or know anyone who is affected by image-based abuse, resources and support are available through StopNCII.org.


Galen Reich and Melissa Zhu from Bellingcat and Michael Wright from The Press contributed to this article. 

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Identifying the Crypto Entrepreneur Linked to Popular Forum Trading in ‘Leaked’ Nudes of Women appeared first on bellingcat.

UNK_MassTraction Exploits Roundcube Flaws Against US, Canadian Universities

China-linked UNK_MassTraction targets US and Canadian universities through Roundcube flaws, stealing sessions and opening access to research mail servers.

Anonymous-Linked Hacktivist Aubrey Cottle Jailed Over Texas GOP Cyberattack

Canadian hacktivist Aubrey Cottle, known as Kirtaner and once linked to Anonymous, gets 18 months for a 2021 Texas GOP website cyberattack.

AI models capable of devastating attacks on governments and business months away, rare Five Eyes statement warns

Signal agencies in Australia, the US, the UK, New Zealand and Canada sound alarm after Trump blocks foreign nationals from Anthropic’s Fable AI model

Powerful AI models capable of devastating new cyber attacks on governments and businesses are mere months away, intelligence agencies for the Five Eyes have warned in a rare joint statement, urging leaders to “act now”.

The surprising public intervention by signals agencies for Australia, the US, the UK, New Zealand and Canada comes after the Trump administration earlier this month decided to block “foreign nationals” from using a much-hyped AI model built by tech company Anthropic, called Fable.

Continue reading...

© Photograph: Andre M Chang/ZUMA Press Wire/Shutterstock

© Photograph: Andre M Chang/ZUMA Press Wire/Shutterstock

© Photograph: Andre M Chang/ZUMA Press Wire/Shutterstock

  • ✇bellingcat
  • Super-Potent Synthetic Opioids Spread Across US Amid Fentanyl Crackdown Jonathan Moens
    This article was co-published with Signal Ohio and STAT. In high school, Ashley Delgado dreamed of becoming a doctor and one day buying her father a Rolls-Royce. “She wanted to heal people,” said her father, James Taylor. She had a high GPA, Taylor added, and did especially well in science and Latin. In her mid-20s, Ashley suffered a leg injury and was prescribed OxyContin. The painkiller marked the beginning of a yearslong descent through addiction — from prescription opioids to methamph
     

Super-Potent Synthetic Opioids Spread Across US Amid Fentanyl Crackdown

18 de Junho de 2026, 05:59

This article was co-published with Signal Ohio and STAT.

In high school, Ashley Delgado dreamed of becoming a doctor and one day buying her father a Rolls-Royce. “She wanted to heal people,” said her father, James Taylor. She had a high GPA, Taylor added, and did especially well in science and Latin.

In her mid-20s, Ashley suffered a leg injury and was prescribed OxyContin. The painkiller marked the beginning of a yearslong descent through addiction — from prescription opioids to methamphetamine, then heroin, and finally, fentanyl.

With her family’s support, Ashley spent time in a rehabilitation facility in her hometown of Cleveland, Ohio, and in recovery she moved into a sober living home. But on an early summer morning in 2023, Ashley’s body was found on a dead-end street just outside the city. One sandal was missing. Tucked inside her bra was a folded scrap of paper containing a tan powder. She was 29.

Ashley Delgado died in August 2023. Source: Supplied

“I have lost my father, my grandmother — that hurts,” Taylor said. “But when you lose your child, that’s the worst thing on the planet, because they’re not supposed to go before you.”

Toxicology tests would later show a mix of substances in Ashley’s system, including protonitazene and metonitazene, powerful synthetic opioids from a little-known class of drugs known as nitazenes. Her death was ruled accidental.

Before his daughter’s fatal overdose, Taylor had never heard of nitazenes. Developed in the 1950s as potential painkillers, the drugs never reached the market because they were deemed unsafe for medical use. He was shocked to learn they could be up to 40 times more potent than fentanyl and 500 times stronger than heroin.

Nitazenes are predominantly sold online, both on the clear web and dark web, and are often laced into other substances to increase their potency. Experts say this puts unsuspecting users seeking more common drugs, such as oxycodone, fentanyl, or stimulants like cocaine, at risk of fatal overdoses.

Left: Ashley, aged about 5, with her father James Taylor in Cleveland, Ohio. Right: Ashley and her dog, Gucci, after graduating from high school in 2012. Source: Supplied

The US Drug Enforcement Administration (DEA) started tracking nitazene-related seizures around 2014, but it wasn’t until 2019 that it saw a marked increase. Since then, federal authorities have scheduled dozens of nitazenes as illegal substances, launched undercover operations, filed indictments, and imposed tariffs on China, where many of the laboratories manufacturing and supplying nitazenes and fentanyl are known to reside.  

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Yet, figures provided to Bellingcat by the United Nations Office on Drugs and Crime (UNODC) show the United States has reported 26 different kinds of nitazenes since 2019 — the second highest number globally, after Canada.

And data from the Centers for Disease Control and Prevention (CDC) on nitazene-involved overdose deaths suggest that cases continue to rise. More than 1,100 fatalities have been confirmed through the CDC’s State Unintentional Drug Overdose Reporting System (SUDORS), but experts believe the number of Americans who have died from them since 2019 could be as high as 2,000. 

Alex Krotulski, the director of the Centre for Forensic Science Research and Education in Pennsylvania, told Bellingcat that deaths are underreported because nitazenes were not routinely tested for.

“There are only limited forensic toxicology labs that test for nitazenes, so if a nitazene was present and the lab didn’t test for it, the number wouldn’t appear in SUDORS,” he said. “Also, for labs that do test for nitazenes, they have missed cases prior to their testing.” The most recent years for which there is CDC data, 2023 and 2024, show they were the deadliest, with 747 confirmed deaths.

A Bellingcat investigation last year found more than 1,000 nitazenes advertisements populating online marketplaces, forums and the dark web. Source: Bellingcat

In this months-long open source investigation, Bellingcat combed through dozens of criminal court proceedings, filed national, state, and county-level Freedom of Information requests, and obtained scores of medical examiner reports to produce the most detailed account yet of how nitazenes are infiltrating US borders and destroying lives. 

The investigation found that, despite efforts to curb their spread across the country, nitazenes are proliferating online. It also shows that, by the time nitazenes reach American users, they are almost always mixed with several other drugs, including methamphetamines, cocaine and, most notably, fentanyl. 

As of this year, 48 of 50 US states have reported nitazene seizures.

Less Fentanyl, More Nitazenes

Fentanyl is by far the biggest opioid killer in the US. With more than a quarter of a million deaths since 2021 and about 200 fatalities a day, fentanyl is one of the country’s most urgent public health crises. But drug experts warn that nitazenes can be even more potent and are being mixed with fentanyl and other substances, creating increasingly lethal combinations.

The Faces of Fentanyl memorial exhibit, at the DEA’s headquarters in Arlington, Virginia, displays more than 7,000 photos of people who have lost their lives to fentanyl poisoning or overdose. Source: DEA

“We’re always concerned about fentanyl being mixed in with other drugs — cocaine, meth, heroin,” said Frank Tarentino, Associate Chief of Operations for the DEA’s Northeast Region. “You add nitazenes to that and it makes it exponentially more dangerous and frightening for drug law enforcement, parents, caregivers, educators, and the young.”

Data obtained from the DEA’s National Forensic Laboratory Information System (NFLIS) show reports of confirmed seizures of nitazenes rising sharply — from 43 positive tests in 2019 to almost 2,000 in 2024 (the most recent year for which figures are available). By March this year, more than 8,000 nitazene reports had been recorded since 2019. But experts said that not all laboratories can test for nitazenes — which come in many forms including powders, pills, and sprays — and many don’t feed into the NFLIS system, meaning these numbers are almost certainly an underestimate.

We asked the DEA for a breakdown of reports of nitazenes by state. Ashley Delgado’s home state of Ohio stands out. NFLIS data from 2019 to 2024 indicate that more than a third of all positive nitazene laboratory reports nationally are linked to Ohio. 

Separate data from the CDC shows Ohio has also recorded the highest number of nitazene-related overdose deaths in the US since 2021. In 2020, there were just four fatalities linked to the drug; in 2021 that number rose to 90. Between 2022 and 2024, according to government data, there were 200 more deaths.

“It is a risk to our community,” said AmandaLynn Reese, chief programme officer at Harm Reduction Ohio, a non-profit that supports people who use drugs. “There’s been several instances of nitazenes being reported within the community, and I think we’re going to see more of that, especially as we’re seeing less fentanyl.”

To learn more about what was happening in Ohio, Bellingcat filed a public records request for county-level figures to the state’s Bureau of Criminal Investigation (BCI). The data shows that the counties of Scioto, Butler and Cuyahoga — areas long affected by the opioid crisis — account for almost half of all nitazene detections across the state, by weight.

In the 2000s, Portsmouth in Scioto County became known as the “pill mill capital” of America due to widespread overprescribing of opioids. More recent data continue to show Scioto with one of the highest rates of drug overdose deaths in the state. In Cuyahoga County, which includes Cleveland, drug-related mortality rates tripled the national average in 2022. 

Two years ago, Ohio’s Governor Mike DeWine issued executive orders to schedule nine different nitazenes and legalised the use of tools to test for drugs including nitazenes. 

The reasons why Ohio has been so hard hit are still not fully understood. “Ohio’s geography has long been a suspected contributing factor,” said Erin Reed, director of RecoveryOhio, a statewide initiative coordinating Ohio’s response to addiction. The organisation cited a 2001 article pointing to Ohio’s unique geographic and infrastructural features — including vast land, air and sea transportation networks — as key reasons for the state being a hub for drug trafficking. 

Local organisations like Harm Reduction Ohio are pushing for more drug-checking services, education, and greater accessibility to testing strips and life-saving medications like Naloxone, a drug that is used to reverse an opioid overdose. “People are going to use drugs,” Reese said. “We don’t know the supply, but those are ways you can engage in your drug use to increase safety and reduce harm.”

Dealer’s Choice

Bellingcat obtained medical examiner reports from Cuyahoga County for all nitazene-related deaths in 2023 and 2024, which provide an insight into how the drugs are being consumed. The autopsy records show that 45 people — 31 men and 14 women aged 29 to 72 — died after taking nitazenes over the two-year period. Among them were university graduates and former athletes, an Army veteran, an ironworker and an addiction counselor.  

Just before Christmas in 2024, a young man from Cleveland died after taking drugs that included etonitazene. A couple of weeks earlier, the body of an elderly woman was found in her home after she ingested drugs that included metonitazene and protonitazene. In the summer, a mother of two children in her thirties consumed a similar lethal mix. All except one of the 45 deaths was ruled accidental. 

And in every instance, nitazenes were detected alongside fentanyl, and often with a cocktail of other drugs such as heroin, cocaine, methamphetamine and benzodiazepines. The reason for this wide variety, Tarentino, the DEA agent said, is that dealers often mix nitazenes into other drugs to make them more powerful and addictive, and ultimately to give them a competitive edge. 

“It becomes a brand,” he said. “The unfortunate circumstance that we find ourselves in is that the dealer’s choice becomes a deadly decision.” Not only are these mixtures deadly — they can also be highly profitable. 

“We used to see organisations that were predominantly selling and transporting cocaine or just heroin or just methamphetamine,” Tarentino said. “Now, we’re seeing organisations move coke, heroin, meth, fentanyl, pills, powder – everything. So we see these poly-drug organisations, and then we see these poly-drug mixtures.” Source: DEA 

Court records analysed by Bellingcat show nitazenes have been sold at prices ranging from roughly US $4,000 to $12,000 per kilogram. But Tarentino said the DEA’s internal estimate puts $12,000 at the lower end of the range, with prices going up to as much as $40,000. Given their potency, even small quantities can be diluted into hundreds of thousands — or potentially millions — of doses once mixed and pressed into pills. “A little bit can go a long way,” Tarentino said, “and they can make a lot of money.”

A Freedom of Information Act request to the US Customs and Border Protection (CBP) revealed that in 2024 and 2025 — the only years for which the agency has monitored nitazenes separately — 41 consignments of the drug were intercepted. The data shows that most of these shipments arrived by mail, primarily from mainland China, Hong Kong and the United Kingdom. The quantities tended to be small, ranging from less than 1 gram to almost 700 grams. 

The UK has also recorded an increase in high-strength nitazenes in recent years. John Fahey, a spokesman for the National Crime Agency, said criminals used the UK as a “transit point” for shipping illicit drugs and that officials were working closely with US law enforcement on nitazene-related cases. Source: DEA

But that’s not always the case. An analysis of US federal court records linked to prosecutions of nitazenes indicates that roughly 90 kilograms of material containing nitazenes in different forms (powder and pills) have been seized over the past three years. Nearly two-thirds of that amount, about 60 kilograms, stem from a single case.

In that case, prosecutors allege that a man named Valkar Singh drove a blue Maserati from Canada into the US carrying six industrial-sized buckets with more than 100,000 pills containing  isotonitazene. According to court filings, Singh transported the drugs to a Bronx, New York address, where he was arrested by undercover law enforcement officers. 

Tarentino, who is familiar with the Singh case but could not comment on it specifically, said a lot of work is being done to prevent drugs being smuggled across the Canadian border. “Canada has become a major concern, but also a major partner in trying to stop the synthetic opioids that are coming into the United States,” he said.

Lawyers for Singh, who has pleaded guilty and is awaiting sentencing, declined to comment.

Photos of buckets containing isotonitazenes in the trunk of Singh’s car. Pills only contain trace levels of active ingredients, meaning the exact quantity of nitazenes is unknown. Still, experts say this seizure was significant, considering the drug’s potency. Source: US District Court for the Southern District of New York

The scale of the alleged seizure makes this case an outlier. Of 46 federal cases identified by Bellingcat between 2021 and 2025, the next highest nitazenes seizure was about 9 kilograms. By comparison, data provided by the European Union Drugs Agency shows roughly 18 kilograms of nitazene-related seizures (pills, powder, liquid) across the EU between 2019 and 2023. 

“It’s very large,” said Jared Brown, scientific affairs officer at the UNODC. “One hundred thousand pills is probably at the limit of what we hear about in terms of maximum types of quantities that get seized.” 

The evidence suggests that most buyers are individual dealers who purchase relatively small quantities online, rather than organised criminal groups. “It’s street-level or mid-level dealers [in the US] that are introducing the nitazenes into the drug supply, not the big drug traffickers,” said Philip Berry, a visiting senior lecturer at King’s College London who formerly worked in counter-narcotics at the UK Home Office.

Court documents show that buyers can easily find nitazene suppliers online: on dark web marketplaces, standalone chemical supplier websites, or even on social media platforms. The suppliers often market the drugs by listing their chemical identifier and social media contact details. Often, the ads include an image of a young Asian woman striking a pose. 

Buyers are often individual dealers who contact sales representatives via encrypted channels and negotiate a deal. In those conversations, representatives will sometimes disclose how they claim to evade customs, for example by declaring the product as cosmetics or electronic accessories.

Ads for nitazenes — such as these ones Bellingcat viewed this month — are found on dozens of sites, from  social media platforms to prominent Asian-headquartered marketplaces that target international buyers. Source: Bellingcat

A detailed account that illustrates this modus operandi comes from the 2023 case against a man named Will Catis in Florida — the state with the second highest number of confirmed nitazene reports. Court documents show that a basic internet search led Catis to multiple nitazene advertisements listed by Jiangsu Bangdeya New Material Technology Co., LTD, a Chinese company sanctioned by the US Treasury for offering illicit substances for sale, including fentanyl and protonitazene.

Catis purchased approximately four kilograms of nitazenes from Jiangsu Bangdeya in batches no larger than 500 grams. The drugs were sent via the US Postal Service to Deerfield Beach, Florida. Once received, Catis mixed the nitazenes with other drugs, pressed the substance into a brick and sold it to other drug traffickers. Catis was jailed for 12 years after pleading guilty to possessing and intending to distribute nitazenes.  

One court case from Florida describes how a couple who lived in a converted garage bedroom in Hernando County bought nitazenes through the mail from Chinese companies they contacted online. Jacob Spinoza and his girlfriend Veronica Jo Barback regularly abused the drugs and distributed them locally, according to court documents. Both pleaded guilty. Spinoza was sentenced to nine years in prison, and Barback received a three-year sentence.

Jacob Spinoza and Veronica Jo Barback under the influence of nitazenes. Court records said Spinoza survived more than 20 overdoses in 2022. Source: US District Court Middle District of Florida

Another notable case reveals how a man allegedly ran a drug trafficking operation from a prison in Ohio. Investigators said Brian Lumbus Jr worked with a middleman, Giancarlo Miserotti, who contacted drug manufacturers in China to get nitazenes shipped through Italy to avoid custom checks. Once in Ohio, the plan was to distribute the drugs to other states, court documents said. 

But law enforcement agents were listening in on conversations between Lumbus and other members of the drug network, who expressed caution about the potency of nitazenes. “Man, we got to be careful … somebody died,” Lumbus said in one phone conversation, according to court documents. “Ohhh … it was too strong,” Miserotti responded. “I think the ratio of the pink [metonitazene] was thick.” 

Lumbus is awaiting trial. Miserotti was arrested in Italy in 2023 and sentenced to more than 13 years in prison. 

Arms Race

Enforcement actions have targeted the online marketplace ecosystem. In June 2025, Archetyp Market, a major dark web platform used to sell drugs, was dismantled in a coordinated operation involving Europol. US authorities have also indicted several China-based companies and individuals accused of offering nitazenes and related synthetic opioids for sale. Still, advertisements for nitazenes continue to litter online markets, constantly adapting to new regulatory regimes.

Nitazenes, such as this listing for etonitazene, which is up to 500 times stronger than heroin, are openly advertised online. Source: Bellingcat

In July 2025, China placed the majority of nitazenes under national control. Tightened regulations — both in China and the US — have tried to stem the flow of nitazenes. But drug experts warn that manufacturers are already exploiting loopholes in China’s regulations by marketing chemically similar synthetic opioids known as “orphines.” 

Jared Brown, of UNODC, said orphines are also thought to come from China and are about as powerful as fentanyl. “Orphines have just enough of the molecule difference that it isn’t covered by the core definition that China has made,” he said. 

This is not the first time Chinese synthetic opioid manufacturers have adapted to regulations. In 2019, China banned all fentanyl-related substances, including some major precursors. The number of distinct fentanyl analogues reported to the UNODC subsequently plummeted, while reports of nitazenes quickly picked up. Now that China is clamping down on nitazenes, orphines are on the rise. More than 150 cases involving orphines were reported in the US between 2024 and 2025, the majority of which are in Illinois.

“Always adapting, always changing – we call them ‘shape shifters’,” said Tarentino. “They’re this global Hydra that are always changing, evolving and adapting to their environment and taking full advantage of all of these different loopholes and vulnerabilities that exist.”


Reporting for this story was supported by the Fund for Investigative Journalism.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Super-Potent Synthetic Opioids Spread Across US Amid Fentanyl Crackdown appeared first on bellingcat.

Why Canadian Telecom Providers Are Prime Targets for Cyberattacks

Canadian telecom providers face mounting cyber threats from ransomware, SIM swapping, data breaches, and nation-state attacks targeting critical infrastructure.
  • ✇Firewall Daily – The Cyber Express
  • Toronto Police Bust Mobile Smishing Network Targeting Thousands Samiksha Jain
    A major Canada SMS blaster cybercrime case has come to light as Toronto Police charge three men with 44 offences in what authorities describe as a first-of-its-kind investigation in the country. The case, part of Project Lighthouse, highlights a growing threat where cybercriminals use mobile technology to target thousands of people at once. The investigation began in November 2025 after a security partner alerted police to a suspected SMS blaster operating in downtown Toronto. What followed w
     

Toronto Police Bust Mobile Smishing Network Targeting Thousands

Canada SMS blaster cybercrime case

A major Canada SMS blaster cybercrime case has come to light as Toronto Police charge three men with 44 offences in what authorities describe as a first-of-its-kind investigation in the country. The case, part of Project Lighthouse, highlights a growing threat where cybercriminals use mobile technology to target thousands of people at once. The investigation began in November 2025 after a security partner alerted police to a suspected SMS blaster operating in downtown Toronto. What followed was a months-long probe into a sophisticated operation that combined mobility, deception, and large-scale disruption.

What Is the Canada SMS Blaster Cybercrime Case?

At the center of the Canada SMS blaster cybercrime case is a device that mimics a legitimate cellular tower. When nearby mobile phones connect to it, users receive fraudulent messages that appear to come from trusted organizations. These messages often include links to fake websites designed to steal sensitive information such as banking credentials and passwords. This method is widely known as “smishing,” a form of phishing carried out through text messages. However, the scale and mobility of the device used in this case set it apart from typical cyber fraud schemes. Deputy Chief Rob Johnson said the operation posed serious risks beyond financial fraud. He noted that the technology had the capability to reach thousands of devices simultaneously, raising concerns about public safety.

Large-Scale Disruption Across the Greater Toronto Area

Investigators found that the SMS blaster was not stationary. It was operated from vehicles, allowing suspects to move across the Greater Toronto Area and deploy the device in multiple locations. According to Detective Sergeant Lindsay Riddell, tens of thousands of devices connected to the rogue network over several months. Police also recorded more than 13 million network disruptions, during which affected devices were unable to connect to legitimate cellular networks. These disruptions had serious implications. During those moments, access to emergency services such as 9-1-1 could have been impacted, making the Canada SMS blaster cybercrime case not just a financial threat but also a public safety concern.

Arrests and Seizure of Devices

Toronto Police executed search warrants on March 31 at residences in Markham and Hamilton, leading to the arrest of two suspects. Authorities seized multiple SMS blasters along with a significant amount of electronic evidence. A third individual later turned himself in on April 21. All three now face a combined total of 44 charges linked to the operation. The Canada SMS blaster cybercrime case involved extensive coordination between multiple agencies, including the Royal Canadian Mounted Police National Cybercrime Coordination Centre, regional police services, financial institutions, and telecom providers. Officials say this collaboration was key to identifying and disrupting the activity.

A New Type of Cyber Threat in Canada

Law enforcement officials emphasized that this is the first known case of SMS blaster technology being used in Canada. The case reflects how cyber-enabled crimes are becoming more advanced and harder to detect. Authorities noted that while the technology is new, the objective remains the same: to gain unauthorized access to personal and financial information. The Canada SMS blaster cybercrime case shows how attackers are combining traditional fraud tactics with newer tools to scale their operations.

Public Advisory and Safety Measures

Police are urging the public to remain cautious when receiving unexpected text messages. Users are advised not to click on suspicious links or share personal information through unsolicited messages. Officials recommend accessing banking services only through official applications or by directly entering website addresses into browsers. Victims of suspected fraud are encouraged to report incidents to law enforcement. Deputy Chief Johnson also acknowledged the role of the Toronto Police Coordinated Cyber Centre and partner agencies in handling the investigation. He stressed that staying informed and vigilant remains one of the most effective defenses against such threats.
  • ✇bellingcat
  • Agents of Chaos: Unpacking the Actions of Border Patrol Agents Across the US Bellingcat Investigation Team
    This investigation is part of a collaboration between Bellingcat, Evident Media and CalMatters. You can watch Evident’s investigative video here, and read CalMatters’ report here. In early January 2025, a gardener named Ernesto Campos was pulled over by Border Patrol agents in the city of Bakersfield, California.  The agents were a long way from home: Bakersfield is over 240 miles (386km) from the US border with Mexico. They were there as part of Operation Return to Sender, a Border Pa
     

Agents of Chaos: Unpacking the Actions of Border Patrol Agents Across the US

17 de Março de 2026, 19:16

This investigation is part of a collaboration between Bellingcat, Evident Media and CalMatters. You can watch Evident’s investigative video here, and read CalMatters’ report here.

In early January 2025, a gardener named Ernesto Campos was pulled over by Border Patrol agents in the city of Bakersfield, California. 

The agents were a long way from home: Bakersfield is over 240 miles (386km) from the US border with Mexico.

They were there as part of Operation Return to Sender, a Border Patrol surge in the city that acted as a portent of what was to come across the US in 2025.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Video footage shows one agent threatening to break Campos’ car window as they believed he was transporting an undocumented individual. 

Campos filmed the agents, who he said slashed his tyres before arresting him and a passenger. The agents’ faces later appeared on local news reports detailing the incident.

Ten months later, two of the agents visible in footage recorded by Campos were filmed in Chicago as Border Patrol agents descended on the city for what was dubbed “Operation Midway Blitz”.

One was seen grabbing a man by the throat before slamming him to the ground with help from other agents.

@govpritzker.illinois.gov 37 and Kedzie, East Garfield, Illinois. This is assault.

[image or embed]

— Daniel Connerton (@lordnad.bsky.social) 4 October 2025 at 20:56

The other was seen punching a man in the face before pulling his gun on protesters in a Chicago suburb.

These confrontations were not isolated incidents.

An image from court documents shows a Border Patrol agent unholstering his gun at an incident in Evanston, Illinois.

A federal judge in Illinois said in November that the use of force by federal agents in Chicago – including the use of tear gas and other less lethal munitions on multiple occasions –  “shocks the conscience”.    

A restraining order issued by that Illinois judge was vacated on appeal earlier this month. But what took place on the streets of Chicago also happened in other locations, with some of the same agents involved.

Bellingcat has worked with our partners at Evident Media and CalMatters to analyse over 85 hours of social media and bodycam footage, as well as court documents and incident reports, to try to unpack the actions of Border Patrol agents across the country. 

With agents often masked and badge or identification numbers not always visible, understanding exactly who has enforced the immigration surges of the past year has been difficult. This, in turn, has made public questioning and accountability around use-of-force incidents challenging. 

Subscribe to the Bellingcat newsletter

Subscribe to our newsletter for first access to our published content and events that our staff and contributors are involved with, including interviews and training workshops.

Nonetheless, we observed over 25 agents who appeared in more than one city, either by recognising their faces or matching badge numbers that were visible on their vests or arm patches. Many were seen alongside former Border Patrol Commander at Large, Gregory Bovino, on at least one occasion. 

But this is likely just a fraction of the agents who moved around the country to take part in Border Patrol surges in cities like Los Angeles, Chicago and Minneapolis. When speaking to reporters in January, Border Czar Tom Homan said he had spoken to some agents who had “been in theatre for eight months”. Many wore masks in the videos viewed by Bellingcat, and it was not always possible to identify number patches from social media or bodycam footage alone.

Although some of the agents we logged appeared on neighbourhood walkabouts or in footage where little happened, others could be seen using force on multiple occasions. For this story, we have focused on the actions of five agents whom we have been able to identify and who appear to have repeatedly used force in at least two, but often more, locations. We have decided to name those we have been able to identify just as we would name any officer involved in incidents like those detailed. But these were by no means the only agents whom we saw using force across one or multiple cities.

The footage we analysed also appears to show a steady escalation of violence and confrontational incidents as 2025 progressed, culminating in widespread use-of-force incidents in Chicago and Minneapolis, where two people, Renee Good and Alex Pretti, were killed by Immigration and Customs Enforcement (ICE) and Border Patrol agents, respectively, in early 2026.

Agents on the Move

While former Border Patrol Commander at Large Gregory Bovino is no longer in a national role, some of the agents observed and documented for this report appear to have travelled from his El Centro sector over the past year.

These included agent Timothy Donahue and Georgy Simeon, who were filmed by Ernesto Campos in Bakersfield. Donahue was the agent who was subsequently pictured pointing his gun at citizens just outside Chicago after a traffic incident (Donahue stated in his incident report that his car was rammed by an activist – something also described in Illinois federal judge Sara Ellis’ opinion – although Donahue’s report made no mention of punching a man in the face or unholstering his weapon). It was Simeon, meanwhile, who was filmed slamming a man to the ground after grabbing him by the throat.

Donahue was also spotted in social media footage in Los Angeles in June last year pushing a citizen who was blocking his vehicle, as well as grabbing a man on an immigration raid inside a car wash.

The Chicago publication, Unraveled Press, previously reported that Donahue was the owner of a social media account that made seemingly racist and sexist posts. Bellingcat and others have checked this account and found that an old profile picture showed an image of Donahue. Bodycam footage from outside a detention centre near Chicago also showed Donahue tackle a journalist from Unraveled without apparent warning.

Footage from Donahue’s own bodycam on Oct. 3 also appears to show him compiling an incident report with ChatGPT. The possibility of CBP agents using ChatGPT to compile incident reports was addressed by Judge Ellis in her ruling issuing a restraining order in November. She wrote that using ChatGPT to write reports “undermines their credibility and may explain the inaccuracy of some reports filed by CBP officers”.

The evidence doesn’t enable us to determine if Donahue used ChatGPT to compile the Oct. 31 incident report in which he did not mention he punched a man and unholstered his gun. 

Bodycam footage released with court documents shows a Border Patrol agent using ChatGPT to compile an incident report. 

Our reporting partners CalMatters emailed and called Donahue prior to publication. The email received no response. Donahue answered his cellphone but said, “never, ever call my cellphone again,” and hung up.

Simeon did not respond to emailed questions prior to publication, and calls to a number listed under his name went unanswered. 

The Department of Homeland Security (DHS) did not respond to questions posed about the actions of Donahue and Simeon detailed in this report or the agency’s use-of-force policies. They also did not respond to questions about whether it was permissible for agents to use generative AI platforms like ChatGPT to compile incident reports.

While the actions of Donahue and Simeon made news reports in various cities, the pair were far from alone in having their actions filmed and documented across the country. 

Kristopher Hewson, a supervisory agent based out of Bovino’s El Centro sector, was seen on bodycam footage in Chicago spraying an individual who was being held down by agents with what he detailed in his incident report as oleoresin capsicum (OC), also known as pepper spray, from what appears to be just a few inches away. The individual was on the ground and had one hand behind his back, but agents could be heard asking for his other hand during the incident. Hewson said in his incident report (see here and here) that the individual had been resisting arrest, but he also stated that he deployed the pepper spray from two feet away. Bodycam footage (see below) showed the canister beside the individual’s head right after a burst of spray can be heard.

Bodycam footage shows an individual being held down before pepper spray is released while he remains on the ground. Annotations after 15 seconds made by Bellingcat.

Hewson, who wore a mask but was identifiable in several videos by the C-29 ID number on his uniform, was later spotted in Minneapolis. He also said his name during one incident that allowed us to find other bodycam footage releases that belonged to him. In one video, his mask slipped, which allowed us to compare his face to images on his social media accounts.

Court testimony revealed that he was present in Los Angeles during a Border Patrol surge in the city in the summer of 2025. He was also seen alongside Bovino on numerous occasions, including in Chicago, where Bovino can be heard greeting him by saying, “Hey, Hewson”, in one video captured by the filmmaker Jeff Perlman.

In bodycam footage from Chicago a man can be heard saying that the person Hewson pepper-sprayed was his son, who was just 15 years old. This appears to be backed up by an incident report showing the individual’s date of birth. A short time later, Hewson can be heard shouting “get back or you will be gassed” at a group of protesters immediately before deploying tear gas towards them. As he throws the canister, a person can be heard shouting, “You’re not de-escalating shit, bro”. Hewson stated in his incident report (see here and here) that he gave a warning that CS gas was coming, but he did not detail how that warning was virtually instantaneous. 

All of these actions came two weeks after a judge issued a temporary restraining order on Oct. 9, preventing agents from using chemical agents on protesters and journalists unless there was an imminent threat of physical danger to federal forces. While that order was lifted in March 2026, it was still in force during the incidents detailed in this story.

Hewson was seen in Minneapolis in early 2026 alongside Bovino. He was captured on footage marching towards and tackling a Target employee, a teenage US citizen, who was directing insults at agents. A melee ensued at the front door of the Target store before two people were handcuffed and taken away by agents. Hewson’s C-29 number was visible as he led one of the men away. Both of those arrested were later released.

Hewson was questioned as part of a preliminary injunction hearing in Chicago, where, among other things, he stated (pages 183 and 184) that protesters have the right to shout and even swear at officers as long as they aren’t impeding their ability to carry out their work. He also said during questioning that tear gas “doesn’t harm people” (page 189). Multiple individuals who were impacted by the release of gas and chemical irritants in Chicago stated otherwise in incidents detailed in Judge Ellis’ ruling. 

When reached on the phone by CalMatters, Hewson said he could not comment. DHS did not respond to questions posed about the actions of Hewson detailed in this report or the agency’s use-of-force policies.  

El Paso Agents

Hewson was present and visible in footage when ex-Border Patrol Commander at Large Bovino appeared to push and manhandle a protester who crossed his path on Nicollet Avenue in Minneapolis. 

Also beside Bovino and Hewson that day were two officers based out of El Paso bearing the ID numbers EZ-2 and EZ-17. Both of these agents are seen wearing vests of the Border Patrol Tactical Division (BORTAC), a specialised unit that, according to the CBP, has a selection process “designed to mirror aspects of the US Special Operations Forces’ selection courses”. 

Bellingcat and Evident Media previously reported how EZ-17 fired less lethal munitions at protesters from close range a day after Renee Good was shot and killed by an Immigration and Customs Enforcement (ICE) officer in Minneapolis.

EZ-17 was accompanied during that incident by EZ-2, who could be seen spraying a chemical irritant in the face of a man who appeared to have thrown a snowball at him. EZ-2 was also seen throwing two female protesters to the ground outside Roosevelt High School in Minneapolis on Jan. 7. 

Both EZ-17 and EZ-2 were present in Chicago. EZ-17 was seen passing a tear gas canister to Bovino at an incident in the city’s Little Village neighbourhood on Oct. 23

The Chicago publication, Unraveled, previously identified EZ-17 as Edgar Vazquez and EZ-2 as Michael Sveum. Bellingcat was able to corroborate these identifications using similar techniques. Firstly, for Vazquez we compared images on his Facebook page with footage from EZ-2’s bodycam, which showed Vazquez inside a vehicle without a mask.

Ernesto Vazquez photo taken from Facebook (left) and image taken from bodycam footage in Chicago (right). Source: CBP via Loevy.com

EZ-2 was identified in a similar manner. Bodycam footage from EZ-2 showed him looking at his phone. On the lockscreen was a picture of a man smiling and wearing a blue jacket. That same picture was posted on Sveum’s social media accounts and appeared to have been taken at an ultramarathon event whose organisers posted Sveum’s name alongside that same image.

Bodycam footage (left) shows a lockscreen with a picture of a man that matches images seen on archived posts from the social media accounts of Michael Sveum.

When reached by phone by CalMatters reporters, Vazquez said that he could not comment. Sveum hung up immediately after CalMatters’ reporter introduced himself. DHS did not respond to questions posed about the actions of Vazquez or Sveum detailed in this report or the agency’s use-of-force policies.   

Dozens of other incidents where agents appeared to escalate rather than de-escalate situations, as well as use force or less lethal munitions, were logged as part of this investigation. This included agents pointing guns at protesters (see here and here) as well as using violent force and less lethal munitions on protesters, journalists and bystanders.

Bovino himself appeared to instigate confrontations with people, such as in Chicago, when he can be seen throwing a man to the ground before agents pounce on him, although he stated during his Illinois deposition that he did not think such actions represented a use-of-force incident. 

The former Border Patrol Commander at Large told CalMatters that he could not speak to the media without DHS approval prior to publication of this story. Requests sent to DHS to speak with Bovino went unanswered.

‘Unusual and Beyond the Pale’

According to John Roth, a former DHS Inspector General, and Steve Burnell, a former DHS General Counsel, the events of the past year, involving masked agents descending on select cities, have eroded trust and credibility in DHS and law enforcement.

While both agreed that there had to be professional immigration enforcement operations, they said that has to be done in a way that is responsible and ensures accountability when lines are crossed. 

“This is sort of a scary Orwellian thing”, Roth said. “I don’t think the public understands how unusual and beyond the pale it is to have these roving sort of groups of masked agents, out there handling the public.”

Burnell said that the inability to identify agents carrying out their work as enforcement officers was a particular concern: “At the end of the day, ICE and everybody at DHS are public servants. They’re supposed to be working for the public. And, you know, if somebody is working for you, you should have a right to know who they are, and you should have a right to hold them accountable and protest what they’re doing.”

Roth and Burnell both served under President Barack Obama and during President Donald Trump’s first term. The pair have testified to Congress in recent months, raising the alarm about what they see as a dismantling of accountability at DHS. Prominent members of the US government, including President Trump, have offered repeated support to Border Patrol agents, even after the death of protesters such as Renee Good.

Our partners at Evident and CalMatters showed Roth and Burnell some of the footage described in this report. While they refrained from commenting on individual incidents, Roth described the footage generally as “difficult to watch”.

“The question I’d ask. Have [agents] inserted themselves into something that requires them to use force,” said Roth. “In which case that would be a violation of DHS policy,” he added, referring to use-of-force policies that detail how law enforcement officers may use force when no “reasonably, safe and feasible alternative appears to exist”.

“It’s actually DHS policy that you [are required] to attempt to de-escalate when that’s possible. I mean, they don’t have a duty to retreat, but they do have a duty not to insert themselves into a place where use of force is necessary,” Roth said.

Burnell described a lot of what has happened over the past year as a type of “dominance display”.

“It’s there to send a message. And that is not de-escalatory. It’s the opposite,” he said.

Bellingcat, CalMatters and Evident Media jointly sought to contact DHS as well as all of the agents mentioned in this story prior to publication. 

We asked DHS whether any of the incidents detailed in this report violated DHS use-of-force policies or whether those policies had been updated under the current administration. 

We also asked if DHS was taking any action or providing further training to agents to ensure the public’s constitutional rights are respected during immigration enforcement operations carried out by Border Patrol.

DHS did not respond before publication.


Youri van der Weide, Kolina Koltai and Eoghan Macguire from Bellingcat, as well as Sergio Olmos from CalMatters and Kevin Clancy from Evident Media, contributed reporting to this piece.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Agents of Chaos: Unpacking the Actions of Border Patrol Agents Across the US appeared first on bellingcat.

  • ✇Security Boulevard
  • Canada Needs Nationalized, Public AI Bruce Schneier
    Canada has a choice to make about its artificial intelligence future. The Carney administration is investing $2-billion over five years in its Sovereign AI Compute Strategy. Will any value generated by “sovereign AI” be captured in Canada, making a difference in the lives of Canadians, or is this just a passthrough to investment in American Big Tech? Forcing the question is OpenAI, the company behind ChatGPT, which has been pushing an “OpenAI for Countries” initiative. It is not the only one eye
     

Canada Needs Nationalized, Public AI

11 de Março de 2026, 08:04

Canada has a choice to make about its artificial intelligence future. The Carney administration is investing $2-billion over five years in its Sovereign AI Compute Strategy. Will any value generated by “sovereign AI” be captured in Canada, making a difference in the lives of Canadians, or is this just a passthrough to investment in American Big Tech?

Forcing the question is OpenAI, the company behind ChatGPT, which has been pushing an “OpenAI for Countries” initiative. It is not the only one eyeing its share of the $2-billion, but it appears to be the most aggressive. OpenAI’s top lobbyist in the region has met with Ottawa officials, including Artificial Intelligence Minister Evan Solomon...

The post Canada Needs Nationalized, Public AI appeared first on Security Boulevard.

  • ✇bellingcat
  • Satellite Imagery Reveals Strikes on Iranian Police Stations Jake Godin
    US President Donald Trump said on January 2 that the US was “locked and loaded and ready to go”. Trump was talking aloud about intervening in Iran if it continued a violent crackdown on demonstrators who had taken to the streets over spiralling inflation and ongoing repression.  Thousands of Iranian’s were reported to have been killed by state security forces in just under a month. According to Amnesty International, the Islamic Revolutionary Guard Corps (IRGC), the Basij plainclothes militia
     

Satellite Imagery Reveals Strikes on Iranian Police Stations

4 de Março de 2026, 09:35

US President Donald Trump said on January 2 that the US was “locked and loaded and ready to go”. Trump was talking aloud about intervening in Iran if it continued a violent crackdown on demonstrators who had taken to the streets over spiralling inflation and ongoing repression

Thousands of Iranian’s were reported to have been killed by state security forces in just under a month. According to Amnesty International, the Islamic Revolutionary Guard Corps (IRGC), the Basij plainclothes militia, police forces and other plain-clothed agents carried out the deadliest violence against protesters in decades.

On Saturday, February 28, the United States and Israel launched a large-scale attack against Iran, killing Supreme Leader Ayatollah Ali Khamenei and targeting military infrastructure throughout the country. President Trump initially told Iranians they should seize control of the government but on Tuesday this week said: “If you’re going to go out and protest, don’t do it yet. It’s very dangerous out there. A lot of bombs are being dropped.” Almost 800 Iranians have been killed in US and Israeli strikes so far, according to the Iranian Red Crescent. 

While the US has released a list of military targets, including IRGC headquarters and missile systems, Bellingcat has reviewed strikes against another type of target inside the Islamic Republic — police stations.

Experts told the New York Times that strikes against these facilities may be part of an effort to motivate Iranians to challenge the regime, although satellite analysis alone doesn’t allow us to tell if it is the US, Israel or both nations who have targeted police stations.

Mapping Targeted Police Stations

Using medium-resolution PlanetScope satellite imagery from Planet Labs, Bellingcat has been able to locate at least 15 local police stations or similar buildings that were struck between March 1 and March 3. Videos and photos shared on social media also show the aftermath of some of these strikes.

Comparing the March 1 PlanetScope satellite imagery with imagery taken on March 3, it’s possible to make out visible signs of building destruction throughout Tehran. Some of these sites have already been widely-reported on, including the strike on Supreme Leader Ali Khamenei’s compound and official residence.

But Bellingcat reviewed damage to a number of smaller buildings throughout Tehran and cross-referenced the locations with data on Google Maps, Open Street Maps and Wikimapia where we found that several were listed as police stations. The majority of sites we identified are in dense urban areas. 

Video shared by Iranian state broadcaster Tasnim News showed the aftermath of a strike on what it describes as a “diplomatic police station” near Ferdowsi Square — one of downtown Tehran’s main intersections. Another video taken at the same location shows at least two people on the ground with a large amount of damage to nearby buildings. Geolocation of the videos puts them at 35.7032, 51.4189, adjacent to a school and office buildings. 

An annotated image from Google Earth showing where a police station was destroyed in an airstrike. Video from Iran’s Tasnim News shows buildings that match those in the satellite imagery.

Another video, geolocated by a volunteer with Geoconfirmed — a volunteer geolocation collective — shows a heavily damaged police station near Tehran’s Grand Bazaar. PlanetScope imagery from March 3 shows heavy damage to the area around the police station.

Photos and video from the Golestan Palace, a UNESCO World Heritage Site that sits adjacent to the police office, shows that it also sustained damage.

Iran’s Police and Law Enforcement

Iran’s security apparatus includes a network of police, plain clothes officers, civilian militia battalions known as Basij and the Islamic Revolutionary Guard Corps. During recent protests security forces were seen shooting protestors on the streets, and many of those killed showed signs of being shot in the head.

Iran has experienced several waves of anti-regime protests over the past 15 years, all of which have been put down by the authorities who have not shied away from using extreme violence to contain them.

Although the Financial Times reported speaking to a Tehran resident that said one of the police stations we identified, in the Gisha neighborhood, had hosted a branch of Iran’s morality police, it is thus far unclear from the satellite data whether any of the police stations had any particular role during the recent protests.


Trevor Ball, Logan Williams and Felix Matteo Lommerse contributed reporting to this piece for Bellingcat. Anisa Shabir and Stéphanie Ladel contributed from Bellingcat’s Volunteer Community.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Satellite Imagery Reveals Strikes on Iranian Police Stations appeared first on bellingcat.

  • ✇bellingcat
  • “Bombs will fall Everywhere”: The American, Israeli and Iranian Weapons Being Deployed in Middle East Trevor Ball
    The United States and Israel launched an attack on Iran on Saturday morning, killing Supreme Leader Ayatollah Ali Khamenei as well as several senior regime figures and striking multiple sites across the country. Iran retaliated by firing at targets across the region, including Israel, Bahrain, Qatar, the UAE and other Gulf states. The conflict is ongoing despite no declaration of war by the US Congress. US President Donald Trump initially called for regime change in Iran but has since delivered
     

“Bombs will fall Everywhere”: The American, Israeli and Iranian Weapons Being Deployed in Middle East

3 de Março de 2026, 09:26

The United States and Israel launched an attack on Iran on Saturday morning, killing Supreme Leader Ayatollah Ali Khamenei as well as several senior regime figures and striking multiple sites across the country. Iran retaliated by firing at targets across the region, including Israel, Bahrain, Qatar, the UAE and other Gulf states. The conflict is ongoing despite no declaration of war by the US Congress. US President Donald Trump initially called for regime change in Iran but has since delivered a mixed message about the aims of “Operation Epic Fury”.

Israel has said it dropped more than 2,000 bombs in the first 30 hours of the war. While the US claims to have struck over 1,000 targets in the first 24 hours, with President Trump stating that “bombs will fall everywhere”. In response, Iran is reported to have launched at least 390 missiles and 830 drones in the first two days.
Bellingcat has been monitoring strikes across the region, including those that caused civilian harm, and identified a wide variety of weapons have been used so far, including missiles and drones.

US-Made Weapons and Tomahawks Launched

The US reported that some of the first weapons they launched were Tomahawk missiles. Footage from the US McFaul also showed Tomahawks being launched.

There is also reporting that a new variant of the Tomahawk was used in these strikes.

Imagery of many other different munitions used by the US, Israel and Iran have appeared on social media. 

This article covers some of the munitions Bellingcat has seen imagery of as the war enters its fourth day.

Many of the weapons used so far have also been deployed in other recent US conflicts, including the 12-day Israel-Iran war, and US strikes in Yemen and Venezuela

The US is the major supplier of arms to allies in the region, including for Israel, Kuwait, Qatar, UAE, and Jordan.

On Sunday, the US Department Of Defence (DOD) published photos showing weapons being prepared for loading on aircrafts, including the MK-80 series of bombs like MK-82 500-pound bombs, and BLU-109 2,000-pound ‘bunker busters’ equipped with Joint Direct Attack Munition (JDAM) bomb guidance kits.

Left:  Feb. 27. 500-pound bombs equipped with JDAM guidance kits. Right: Feb. 28. 2,000-pound BLU-109 ‘bunker busters’ equipped with JDAM guidance kits. Sources: US Navy/DVIDS and US NAVY/DVIDS.
Left: Feb. 27. 500-pound bombs equipped with JDAM guidance kits. Right: Feb. 28. 2,000-pound BLU-109 ‘bunker busters’ equipped with JDAM guidance kits. Sources: US Navy/DVIDS and US NAVY/DVIDS.

The DOD has also released several photos showing the C variants of the AGM-154 Joint Standoff Weapon (JSOW). As documented by the Open Source Munitions Portal, this weapon has been used recently by the US in Yemen and Venezuela.

Feb. 27. AGM-154C JSOW bombs being loaded onto aircraft. Source: US Navy/DVIDS

The DOD also released a slideshow showing images from the first 24 hours of the war, including an image showing the first combat use of the Precision Strike Missile. The DOD further released a list of some equipment used, including the THAAD ballistic missile defense system.

Image of a Precision Strike Missile being fired in the first 24 hours of the war. Source: US CENTCOM.

Many of the weapons deployed by the US have also been used by Israel. This includes the MK-80 series of bombs, BLU-109 bombs and Joint Direct Attack Munition (JDAM) bomb guidance kits.

A Feb. 28. image shows an IAF F-15 equipped with a BLU-109 bomb with a JDAM guidance kit. Source: Israeli Air Force.

Israel also produces some of its own munitions, which they released video or photos of since the start of the conflict, including MK-83 1,000-pound bombs equipped with Israeli SPICE-1000 bomb guidance kits.

A Mar. 1. screenshot showing IAF personnel loading a MK-83 1,000 pound bomb equipped with a SPICE-1000 bomb guidance kit. Source: IAF.

Israel also produces RAMPAGE missiles, visible in the image below. 

A Feb. 28. image showing an IAF F-16 with a RAMPAGE missile. Source: IAF.

On Sunday, the DOD said they had used the Low-cost Unmanned Combat Attack System (LUCAS) one-way attack drones in strikes. The LUCAS drone is a US copy of the Iranian Shahed one-way attack drone.

Several LUCAS drones. Source: US CENTCOM.

A video of a crashed LUCAS drone has subsequently appeared online, reportedly in Iraq. 

While Bellingcat could not geolocate this video, then men seen in the footage can be heard speaking Arabic while US CENTCOM has said that this is the first time they have used this drone in combat.

Local Iraqi residents are taking the newly deployed, nearly intact American LUCAS drone for themselves. pic.twitter.com/fbx411iAYU

— Special Kherson Cat 🐈🇺🇦 (@bayraktar_1love) March 2, 2026

A video shows a LUCAS drone that allegedly crashed in Iraq.

Iranian Attacks

Iran has retaliated by firing one-way attack drones, including Shahed variants, and missiles at Israel, and US-bases in various countries across the region, including UAE, Qatar, Kuwait, Jordan and Iraq. 

Iranian Shahed drones have hit civilian buildings in the Gulf, as well as US military bases.

Palm Jumeirah in Dubai was attacked by Shahed kamikaze drones.

[image or embed]

🦋Special Kherson Cat🐈🇺🇦 (@specialkhersoncat.bsky.social) 28 February 2026 at 15:37

A Shahed drone crashes into a hotel in Dubai on Feb. 28.

In Bahrain, a Shahed was seen crashing into a residential building on Feb. 28.

Virtually a first person view of the Iranian drone hitting the high-rise building in Manamah, Bahrain.

[image or embed]

— (((Tendar))) (@tendar.bsky.social) 28 February 2026 at 18:57

A Feb. 28. video shows a Shahed drone hitting a residential tower in Bahrain.

Many missiles have a booster, a rocket motor that detaches from the missile after it is expended. These boosters fall to the ground under the flight path of the missile. 

Bellingcat verified that Iranian missile boosters have fallen in nearby countries caught in the crossfire, including Qatar and Jordan (see below post geolocated to Al-Hashmi St. in Irbid, Jordan), while some Israeli boosters have reportedly fallen in Iraq.

اهلنا في اربد الله يحميكم pic.twitter.com/LvHWgicE4F

— فواز الذياب (@FawazElziyab) February 28, 2026

A Feb. 28. post shows an Iranian ballistic missile booster that fell on Al-Hashmi St. in Irbid, Jordan.

Iranian Missiles Intercepted

The US and Israel, as well as several Gulf countries, have fired missiles, intended to destroy Iranian missiles or drones in the air before they reach their targets. Many Iranian weapons have been intercepted, but others have successfully hit, including in a strike on a US command post in Kuwait, killing six US troops.  

Most ballistic missile interceptors are “hit-to-kill” where they are designed to destroy missiles by the impact. These interceptors have their own components that fall to the ground, as well as the debris from interceptions.

Remnants of Patriot Interceptor missiles, which are operated by the US and several Gulf countries, have been seen, and countries including the UAE have reported they have intercepted missiles. The UAE has claimed that 165 missiles and 541 drones were fired at the country, most were intercepted.  

Feb. 28. Two photos showing the same remnants of a US-made Patriot Air Defense System PAC-3 CRI interceptor missile published by the UAE MOD. The UAE operates the Patriot system. Source: UAE Ministry of Defense.

A Sea of Unverified Images and Misidentification of Munitions

Many close-up images of munition debris have been posted on social media over recent days which are difficult to geolocate. While we have not been able to verify the location of these munitions, we used reverse image search tools to verify they had not been posted online prior to the current conflict. The munition remnants are also consistent with those used by the US, Israel and Iran. But as we cannot geolocate or chronolocate them yet, we cannot fully verify them. Many of these images have been posted with false claims about the object and who fired it.

Despite Bellingcat being unable to fully verify them, we are including a selection of them with accurate identifications, due to the likelihood that more images of these same objects will continue to appear online as the war continues.

One example of incorrectly identified munitions, is the below picture of an aircraft’s external fuel tank, or drop tank that was posted on Telegram on March 1 alongside the claim that it is an Israeli missile.

A Mar. 1. image shows a drop tank from an Israeli jet reportedly found in Anbar, Iraq. Source: NAYA.

Drop tanks are used on jets to extend the range and are jettisoned after use, resulting in these tanks falling to the ground. These tanks have been mistaken for missile parts in previous conflicts.

Despite Iran’s prevalent use of missiles, not all missile boosters are Iranian. On February 28 missile boosters from Israeli air-launched ballistic missiles were reportedly found just east of Tikrit, Iraq. The below image shows the booster from Israel’s Blue Sparrow series, and can be matched to images previously identified and posted on the likes of the Open Source Munitions Portal.

A short while ago, a missile landed near Duraji village in the Dauda area of the Khurmatu district.#Isreal #Iran pic.twitter.com/qzZLNUgekD

— Sarwan Wllatzheri (@SarwanBarzani_) February 28, 2026

A Feb. 28. post shows an Israeli Blue Sparrow series missile booster, reportedly found in Duraji, Iraq.

Additionally, unexploded WDU-36/B warheads from Tomahawk missiles were reportedly found –, one in Kirkuk, Iraq and one found near Jablah, Syria. Tomahawk warheads and other remnants are frequently misidentified, often as drones.

Left: Feb. 28. Unexploded Tomahawk warhead reportedly found in Kirkuk, Iraq. Right: Mar. 2. Unexploded Tomahawk warhead reportedly found near Jablah, Syria. Sources: NAYA and Qalaat Al Mudiq.

These titanium cased warheads comprise a small part of the much larger Tomahawk missile, and have been found intact in numerous countries when the warhead has failed to explode, as seen in images shared on the Open Source Munitions Portal. 

Unexploded Tomahawk warheads from strikes in other conflicts have also been identified by the Open Source Munitions Portal .

Remnants of an Israeli Arrow 2 interceptor missile were posted online, falsely identified as an Iranian missile, and were allegedly found in eastern Syria.  These images could again be matched to those found from previous conflicts on the Open Source Munitions Portal.

An Iranian missile fell in Al-Shoula area, south of DeirEzzor eastern Syria!. pic.twitter.com/TsWVuda2nf

— Omar Abu Layla (@OALD24) March 1, 2026

A Israeli Arrow 2 interceptor missile falsely identified as as an Iranian missile in a post on X.

An Ancient US Munition Used by Iran

One photo of a remnant reportedly found in Ahvaz, Iran, included a false claim that it was a US ATACMS missile. Bellingcat was able to confirm the image does not match ATACMS construction by comparing it to imagery of that munition. We have as yet been unable to confirm if it was indeed located in Ahvaz, Iran – although we were able to identify the munition.

U.S. ATACMS tactical ballistic missile remains found in Ahvaz, Iran.@Osinttechnical pic.twitter.com/plytSUI4w6

— Open Source Intel (@Osint613) March 1, 2026

An actuator section of a MIM-23 HAWK missile, falsely identified by the post above as an ATACMS missile.

The markings on the remnant include an  “FSN” or federal stock number, that can be looked up to identify the item. The FSN was replaced by the national stock number (NSN) in 1974, meaning this missile was produced prior to 1974.

The markings on a actuator section of a MIM-23 HAWK missile.

Bellingcat looked up the  FSN/NSN (1410002343266) which corresponds with the US manufactured MIM-23B HAWK, an air defence missile. 

A US DOD document with the specific FSN, found by open-source researcher Alpha_q_OSINT. Source: US Defense Ammunition Center.

There are many other US, Israeli and Iranian munitions that may have been used in the current conflict, but images have not yet appeared on social media.

With fresh strikes carried out overnight/ early Tuesday and President Trump saying that “likely more” US troops will die, the conflict continues to escalate and shows no sign of ceasing in the days ahead. And despite the death of Ayatollah Ali Khamenei the Iranian regime has vowed revenge and continued strikes against Israel, the US and their Gulf allies.


Bellingcat’s Carlos Gonzales, Jake Godin and Felix Matteo Lommerse contributed research to this article. Anisa Shabir from Bellingcat’s Volunteer Community also contributed to this piece.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post “Bombs will fall Everywhere”: The American, Israeli and Iranian Weapons Being Deployed in Middle East appeared first on bellingcat.

  • ✇bellingcat
  • Epstein Files: X Users Are Asking Grok to ‘Unblur’ Photos of Children Kolina Koltai
    In the days after the US Department of Justice (DOJ) published 3.5 million pages of documents related to the late sex offender Jeffrey Epstein, multiple users on X have asked Grok to “unblur” or remove the black boxes covering the faces of children and women in images that were meant to protect their privacy.  While some survivors of Epstein’s abuse have chosen to identify themselves, many more have never come forward. In a joint statement, 18 of the survivors condemned the release of the fil
     

Epstein Files: X Users Are Asking Grok to ‘Unblur’ Photos of Children

10 de Fevereiro de 2026, 11:57

In the days after the US Department of Justice (DOJ) published 3.5 million pages of documents related to the late sex offender Jeffrey Epstein, multiple users on X have asked Grok to “unblur” or remove the black boxes covering the faces of children and women in images that were meant to protect their privacy. 

While some survivors of Epstein’s abuse have chosen to identify themselves, many more have never come forward. In a joint statement, 18 of the survivors condemned the release of the files, which they said exposed the names and identifying information of survivors “while the men who abused us remain hidden and protected”. 

After the latest release of documents on Jan. 30 under the Epstein Files Transparency Act, thousands of documents had to be taken down because of flawed redactions that lawyers for the victims said compromised the names and faces of nearly 100 survivors. 

But X users are trying to undo the redactions on even the images of people whose faces were correctly redacted. By searching for terms such as “unblur” and “epstein” with the “@grok” handle, Bellingcat found more than 20 different photos and one video that multiple users were trying to unredact using Grok. These included photos showing the visible bodies of children or young women, with their faces covered by black boxes. There may be other such requests on the platform that were not picked up in our searches.

Requests by X users for Grok to unblur and identify the images of children from the Epstein files, overlaid on an image of Epstein next to a young child in a pool. Source: X; collage by Bellingcat

The images appeared to show several children and women with Jeffrey Epstein as well as other high-profile figures implicated in the files, including the UK’s Prince Andrew, former US President Bill Clinton, Microsoft co-founder Bill Gates and director Brett Ratner, in various locations such as inside a plane and at a swimming pool.

From Jan. 30 to Feb. 5, we reviewed 31 separate requests from users for Grok to “unblur” or identify the women and children from these images. Grok noted in responses to questions or requests by some users that the faces of minors in the files were blurred to protect their privacy “as per standard practices in sensitive images from the Epstein files”, and said it could not unblur or identify them. However, it still generated images in response to 27 of the requests that we reviewed. 

We are not linking to these posts to prevent amplification.

The generations created by Grok ranged in quality from believable to comically bad, such as a baby’s face on a young girl’s body. Some of these posts have garnered millions of views on X, where users are monetarily incentivised to create high-engagement content.

Examples of posts by X users asking Grok to unredact images from the latest Epstein release, some with millions of views. Source: X

Of the four requests we found during this period that Grok did not generate images in response to, it did not respond to one request at all. In response to another request, Grok said deblurring or editing images was outside its abilities, and noted that photos from recent Epstein file releases were redacted for privacy. 

The other two requests appeared to have been made by non-premium users, with the chatbot responding: “Image generation and editing are currently limited to verified Premium subscribers”. X has limited some of Grok’s image generation capabilities to paid subscribers since January amid an ongoing controversy over users using the AI chatbot to digitally “undress” women and children. 

X did not respond to multiple requests for comment. 

However, shortly after we first reached out to X on Feb. 6, we noticed that more guardrails appeared to have been put in place. Out of 16 requests from users between Feb. 7 to Feb. 9, which we found using similar search terms as before, Grok did not attempt to unredact any of the images. 

In most cases, Grok did not respond at all (14), while in two cases, Grok generated AI images that were completely different from the images uploaded in the user’s original request. 

When a user commented on one of these requests that Grok was no longer working, Grok responded: “I’m still operational! Regarding the request to unblur the face in that Epstein photo: It’s from recently released DOJ files where identities of minors are redacted for privacy. I can’t unblur or identify them, as it’s ethically and legally protected. For more, check official sources like the DOJ releases.”

As of publication, X had not responded to Bellingcat’s subsequent query about whether new guardrails had been put in place over the weekend.

Fabricated Images

This is not the first time AI has been used to fabricate images related to Epstein file releases. Some images that were shared on X, which appeared to show Epstein alongside famous figures such as US President Donald Trump and New York City mayor Zohran Mamdani as a child with his mother, were reportedly AI-generated. Some of the individuals shown in the false images, such as Trump, do appear in authentic photos, which can be viewed on the DOJ website.

Far left: AI-generated photo of Trump and Epstein with several children. Middle and far right: AI-generated photos of a young Mamdani and his mother, alongside Epstein, former US president Bill Clinton, Amazon CEO Jeff Bezos, Microsoft co-founder Bill Gates and Epstein associate Ghislaine Maxwell. Source: X. Annotations by Bellingcat

X users also previously used Grok to generate images in relation to recent killings in Minnesota by federal agents. 

For example, some users asked Grok to try to “unmask” the federal agent who killed Renee Good, resulting in a completely fabricated face of a man that did not look like the actual agent, Jonathan Ross, and a false accusation of a man who had nothing to do with the shooting.

Bellingcat’s Director of Research and Training @giancarlofiorella.bsky.social appeared on CTV yesterday to discuss the misleading AI-generated images that were used to falsely identify ICE agents and weapons at the centre of the two fatal shootings in Minneapolis youtu.be/mL7Fbp3UrSo?…

[image or embed]

— Bellingcat (@bellingcat.com) 5 February 2026 at 09:36

After Alex Pretti was shot and killed by federal agents in Minneapolis, people used AI to edit video stills, resulting in AI images that showed a completely different gun than the one actually owned by Pretti. In another instance, an AI-edited image of Pretti’s shooting falsely depicted the intensive care unit nurse holding a gun instead of his sunglasses. 

Grok has also been at the centre of a controversy for generating sexually explicit content.

On Twitter/X, users have figured out prompts to get Grok (their built in AI) to generate images of women in bikinis, lingerie, and the like. What an absolute oversight, yet totally expected from a platform like Twitter/X. I’ve tried to blur a few examples of it below.

[image or embed]

— Kolina Koltai (@koltai.bsky.social) 6 May 2025 at 03:20

Multiple countries including the UK and France have launched investigations into Elon Musk’s chatbot over reports of people using it to generate deepfake non-consensual sexual images, including child sexual abuse imagery. Malaysia and Indonesia have also blocked Grok over concerns about deepfake pornographic content. 

One analysis by the Center for Countering Digital Hate found that Grok had publicly generated around three million sexualised images, including 23,000 of children, in 11 days from Dec. 29, 2025 to Jan. 8 this year. X’s initial response, in January, was to limit some image generation and editing features to only paid subscribers. However, this has been widely criticised as inadequate, including by UK Prime Minister Keir Starmer, who said it “simply turns an AI feature that allows the creation of unlawful images into a premium service”. The social media platform has since announced new measures to block all users, including paid subscribers, from using Grok via X to edit images of real people in revealing clothing such as bikinis.


Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here and Mastodon here.

The post Epstein Files: X Users Are Asking Grok to ‘Unblur’ Photos of Children appeared first on bellingcat.

  • ✇bellingcat
  • Alex Pretti: Analysing Footage of Minneapolis CBP Shooting Bellingcat Investigation Team
    To stay up to date on our latest investigations, join Bellingcat’s WhatsApp channel here On January 24, Alex Pretti, a 37-year-old intensive care unit nurse at the Minneapolis Veterans Affairs Health Care System, was shot and killed by federal agents on Nicollet Avenue in Minneapolis, Minnesota. The shooting comes just over two weeks after Renee Good was shot and killed by a federal agent in the same city.  The United States Department of Homeland Security claimed Pretti was killed after a
     

Alex Pretti: Analysing Footage of Minneapolis CBP Shooting

25 de Janeiro de 2026, 16:48

To stay up to date on our latest investigations, join Bellingcat’s WhatsApp channel here

On January 24, Alex Pretti, a 37-year-old intensive care unit nurse at the Minneapolis Veterans Affairs Health Care System, was shot and killed by federal agents on Nicollet Avenue in Minneapolis, Minnesota. The shooting comes just over two weeks after Renee Good was shot and killed by a federal agent in the same city. 

The United States Department of Homeland Security claimed Pretti was killed after an “armed struggle” with DHS officers and that it seemed he had wanted to “do maximum damage”. Yet video footage shared online, showing shortly before and during the incident, appears to contradict that claim.

Some of the earliest available footage of the encounter was posted to Instagram and shows an agent crossing the street to talk to Pretti who appears to be filming with his phone, which he is holding in his right hand. According to DHS, agents were conducting an immigration arrest in the area. 

The agent can be seen placing his hand on Pretti’s torso to push him back and away from the middle of the road towards the sidewalk. 

Another video shared on Reddit shows what happened after this initial contact, as well as the lead-up to the shooting. Pretti appears to put himself between two women after they were both shoved by a DHS agent. He is holding a cellphone, held sideways in his right hand.

A video shows Pretti recording federal agents roughly a minute before he is shot. Pretti’s right hand is holding a cellphone, filming. Source: Neuroscissus/Reddit

An agent can then be seen spraying Pretti with a substance from a canister, and continuing to spray him as he turns his back to him. At least five additional federal agents approach and attempt to force Pretti to the ground while one appears to strike him with a spray can. 

Twenty-five seconds after Pretti is first sprayed, a shot is heard followed by nine more shots in the span of about six seconds. Additional video from the scene shows Pretti lying motionless on the ground.

Video Analysis

Bellingcat further analysed the Reddit video, a separate video posted to Facebook and others taken at the scene to break down the key moments of the shooting, splicing them together (see Bluesky post below) to view in more granular detail.

We’ve placed the available videos of the shooting of Alex Pretti by federal agents in Minneapolis today into the same synchronised timeline and are continuing to analyse further.

[image or embed]

— Bellingcat (@bellingcat.com) 24 January 2026 at 20:39

Closer inspection of the videos shows that an agent appears to remove a weapon from the melee before the first shots are fired. 

In both the Reddit and Facebook video, a federal agent wearing a grey jacket can be seen approaching federal agents who are on top of and struggling with Pretti. Notably, the agent’s hands are empty as he approaches. He can be seen reaching into and rummaging amid the bodies. About twelve seconds later, he is seen carrying a handgun away from the scene. 

Another video, also posted to Reddit, shows the agent removing a gun from a holster in Pretti’s waistband before he is shot.

Federal Agent in grey jacket can be seen reaching to pull the gun out of Pretti’s holster. Brightness increased by Bellingcat. ChaseTacos/Reddit. Annotations by Bellingcat.

Several aspects of the gun the federal agent is seen moving away with appear to match the gun DHS claim belonged to Pretti (and which they posted to X), a Sig Sauer P320, chambered in 9mm. Some posts online mistakenly claimed the photo of the gun was old due to a misunderstanding of Google Reverse Image Search.

While some law enforcement agencies issue Sig Sauer P320 guns to their agents, the gun that DHS claims Pretti had is customized, and visually distinct from those that are standard issue. 

These distinct features include a white pistol grip, black pistol frame, brown slide, and a red dot sight mounted atop the slide. The red dot sight and these various colours are visible on the gun the federal agent is seen leaving with.

Left: Screenshot showing a federal agent retreating with a gun retrieved from Pretti’s rear waistband, as Pretti is shot by another federal agent. Right: Photo released by DHS of the gun they say belonged to Pretti. Sources: Philophon/Reddit and Department of Homeland Security Annotations by Bellingcat.

Before the agent who takes the gun leaves the scene, it appears someone shouts “gun”, as can be heard in this video that was posted to X, and another video posted to Reddit

This Reddit video also shows that almost immediately after the agent in the grey jacket leaves with the gun, a single gunshot can be heard, followed by nine other shots.

Slowing it down, the same video shows that as the federal agent in the grey jacket removes Pretti’s gun, an agent in a black beanie, who appears to have a line of sight on the gun being removed, begins to draw his own weapon. As soon as the agent in the grey jacket moves away with the gun and leaves, the agent in the black beanie steps to where the agent in the grey jacket had been with his finger on the trigger and fires the first shot. 

Two agents appear to fire their weapons from the footage available, one wearing a black beanie and another wearing a brown beanie, as can be seen in this video.

A screengrab from a Facebook video shows the agent in the brown beanie (left) and the agent in the black beanie (right), both in white box, who fired the shots. Annotations by Bellingcat.

At the same time as the first shot is fired, the agent in the grey jacket is leaving with the gun taken from Pretti’s holster. An alternate angle appears shows that the slide of this firearm does not move to the rear. This would indicate that it was not fired. Multiple agents, including the agent in the grey jacket, look towards the man in the black beanie immediately after the first shot. Despite some online speculation, there is as yet no evidence that Pretti’s gun was fired.

Bellingcat synced and slowed three videos to show where the agent in the black beanie, and grey jacket, with both drawn guns are when the first shot occurs. What some commenters have suggested is impact marks appear to be snow, that is visible before any shots occur. 

Three-way video sync and slow+zoom showing the moment of the first shot before Alex Pretti was killed by DHS agents in Minneapolis yesterday. There’s some claims that Pretti’s gun was the source of the first shot after it was taken from him, though in these videos it doesn’t appear that’s the case.

[image or embed]

— Jake Godin (@godin.bsky.social) 25 January 2026 at 18:33

What’s more, the agent with the black beanie’s right arm that was seen holding the gun moves backwards as the first shot is heard, likely due to the recoil from firing.

After firing once, the agent in the black beanie repositions, and then quickly fires three more shots at Pretti’s back at close range while he appears to try to stand up.

Left: Federal agent in grey jacket reaching for Pretti’s holster as the agent in the black beanie stands over him and begins drawing his gun. Right: Federal agent in the grey jacket begins to retreat, with Pretti’s holster now visibly empty, shortly before the agent in the black beanie fires. Bellingcat increased the brightness of the screenshots. Source: ChaseTacos/Reddit. Annotations by Bellingcat.

In this video, multiple agents are piled on top of Pretti while his hands can be seen in front of him, on the ground. His hands remain in front of him as the agent in the grey jacket recovers the gun and moves away.

Pretti on the ground moments before the first shot is fired, while the agent in the grey jacket removes his gun. We see that both of his hands are on the ground in front of him (white box) and not near his holstered weapon near his back. Source: Reddit Annotations by Bellingcat.

Pretti collapses onto the ground after the first shots and the agents back away. A second agent (the one wearing the brown beanie hat) then draws his gun and fires at least one shot. This is the fifth shot that is heard. The agent in the black beanie can be seen and heard firing more shots. Shots five through ten all fired at Pretti’s motionless body.

Left: Pretti on the ground (white box) and the two federal agents who have fired, one with a black beanie, and one with a brown beanie. Right: Federal agent firing at Pretti’s motionless body. Source: Social Media. Annotations by Bellingcat.

The agents can be seen from another angle, with the agent in the black beanie visibly firing into Pretti’s motionless body.

Two federal agents with guns drawn pointing at Pretti, whose body has been blurred by Bellingcat. The federal agent in the black beanie can be seen firing. Source: Neuroscissus/Reddit.

A video taken shortly after the shooting shows two agents searching Pretti’s body with one appearing to be heard asking: “Where’s the gun?”.

Bellingcat contacted the Department of Homeland Security to ask why Pretti was shot and killed and whether he was in possession of his gun when the first shots were fired.

DHS did not respond by time of publication.

DHS and CBP statements have so far only stated that one agent fired shots, identifying them as an eight year veteran of Customs and Border Patrol who fired “defensive shots”. It is not known which of the two agents who appeared to fire shots in the videos analysed by Bellingcat is an eight year veteran of CBP. 

Border Patrol Commander Greg Bovino, on CNN the day after the shooting, when shown video of the gun being removed before the shooting and asked why border patrol agents shot an unarmed man said, “You don’t know he was unarmed. I don’t know he was unarmed.” Deputy Attorney General Todd Blanche, when asked if Pretti was unarmed, said on Meet the Press, “I do not know and nobody else knows either, which is why we’re doing an investigation”. 

In the same CNN interview, Bovino also said that “The victims are the Border Patrol agents.” and that “The suspect [Pretti] put himself in that situation.”

Minneapolis Police Chief Brian O’Hara said that Pretti was a legal gun owner with a permit to carry and did not have a criminal record.


Jake Godin, Trevor Ball, Kolina Koltai and Carlos Gonzales contributed to this report.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here and Mastodon here.

The post Alex Pretti: Analysing Footage of Minneapolis CBP Shooting appeared first on bellingcat.

  • ✇bellingcat
  • Five Shots in Five Minutes: Analysing One Federal Agent’s Use of Less-Lethal Launcher in Minneapolis Trevor Ball
    This investigation is part of a collaboration between Bellingcat and Evident Media. You can watch Evident’s video here. The fatal shooting of Renee Nicole Good by Immigration and Customs Enforcement (ICE) agent Jonathan Ross in Minneapolis on Jan. 7 sparked nationwide protests, with often violent clashes breaking out between protesters and federal agents. Some of the most intense protests took place in Minneapolis itself, with an agent using a less-lethal launcher in ways that experts told B
     

Five Shots in Five Minutes: Analysing One Federal Agent’s Use of Less-Lethal Launcher in Minneapolis

16 de Janeiro de 2026, 13:30

This investigation is part of a collaboration between Bellingcat and Evident Media. You can watch Evident’s video here.

The fatal shooting of Renee Nicole Good by Immigration and Customs Enforcement (ICE) agent Jonathan Ross in Minneapolis on Jan. 7 sparked nationwide protests, with often violent clashes breaking out between protesters and federal agents. Some of the most intense protests took place in Minneapolis itself, with an agent using a less-lethal launcher in ways that experts told Bellingcat were “punitive” and “questionable at best”.  

This agent, an elite Border Patrol officer who was masked but identifiable through the uniform number patch EZ-17, was captured on camera firing his B&T GL06 40mm less-lethal launcher at protesters five times in five minutes as he travelled down a street adjacent to where Good was killed.

EZ-17 on the streets of Minneapolis on Jan. 8. Source: Michael Nigro/Sipa USA via Reuters Connect

While “less-lethal” weapons are not designed to kill, they can still result in serious injuries and even death when misused. In California, a protester said he was permanently blinded in one eye after he was shot with a less-lethal weapon at a protest on Jan. 13. Footage shows a DHS officer firing a PepperBall gun at his face at close range, causing him to bleed. 

Last year, a judge in Illinois ordered an injunction limiting federal agents’ use of force in the state due to what she described as aggressive use of force against peaceful protesters that “shocks the conscience”. However, Bellingcat found multiple examples of force and riot control weapons being used during immigration raids and in apparent violation of that order in the weeks immediately after.

Experts told Bellingcat that most of the less-lethal shots fired by EZ-17 after arriving at the site of Good’s shooting with Border Patrol Commander Gregory Bovino on Jan. 7, also appear to breach CBP’s use-of-force policy. 

Bellingcat analysed videos from news outlets and social media and mapped out all five shots the agent fired.

Five shots EZ-17 fired in five minutes near the location of Good’s shooting, numbered by the order they occurred with approximate locations. The general path of travel of EZ-17 and the location of where Renee Good was shot and killed is marked. Sources: Status Coup News, Dymanh and Google Earth. Graphic: Evident Media / Jennifer Smart

Four of these shots appeared to be aimed directly at protesters’ faces at close range, while a fifth was fired from a distance towards a crowd after tear gas had already been deployed. A sixth shot, captured at another location on the same day, also shows EZ-17 firing a shot from the same launcher at someone at head-level.

As of publication, DHS had not responded to Bellingcat’s requests for comment.

The Agent

In footage captured by independent news outlet Mercado Media, EZ-17 is seen inside the crime scene tape perimeter, standing near Bovino, with eight 40mm munitions on his belt. 

EZ-17 with eight visible munitions on his belt, including a 40mm CS “Muzzle Blast” (red box), and three sponge-nosed direct impact munitions (blue box) approximately 30 minutes before he fires his first shot. Annotations by Bellingcat. Source: Mercado Media @ 36:28 Annotations by Bellingcat

These included three sponge-nose impact rounds, which are designed for “pain compliance” through the direct force of impact, and five cylindrical munitions that can be filled with different payloads and chemical irritants. “BLAST” in blue text is visible on one munition, indicating a “Muzzle Blast” munition with a CS gas fill – commonly known as tear gas. At least three additional 40mm munitions are visible in his plate carrier. 

Another video by independent news network Status Coup News showed uninterrupted footage capturing five shots from the time the agent exited the crime scene perimeter (at 5:02) shortly before firing the first shot, to when he left in a truck with other agents (9:23) immediately after firing the fifth shot. 

The back of EZ-17’s vest shows that he belongs to CBP’s Border Patrol Tactical Unit (BORTAC). BORTAC is a specialised and highly trained unit that, according to the CBP, has a selection process “designed to mirror aspects of the US Special Operations Forces’ selection courses”. 

The patch on the back of EZ-17’s vest (centre) shows that he belongs to BORTAC. Source: Status Coup News

Members of BORTAC have regularly accompanied Bovino as he leads Trump’s immigration raids, including EZ-17 and EZ-2, another CBP agent that was frequently seen beside EZ-17 in the footage from Jan. 7. Both agents have continued to accompany Bovino on raids in Minnesota in subsequent days.

EZ-17 was also spotted alongside Bovino at an incident in Illinois, where a CBP agent in front of him appeared to shoot a protester at close range.

Five shots EZ-17 fired in five minutes near the location of Good’s shooting, numbered by the order they occurred. Sources: Status Coup News and Dymanh

First Shot

In the Status Coup Media video, EZ-17, and three other CBP agents, including EZ-2, can be seen leaving the crime scene tape perimeter set up after Good’s death, pushing protesters who are physically blocking them. Snowballs are thrown at the CBP agents. 

EZ-17 and EZ-2 push a man to the ground who is blocking them. The video shows a clear view of his belt, and the eight munitions visible on his arrival at the scene are still loaded at this point.

EZ-17’s belt is visible after he and EZ-2 push a man who was physically blocking them to the ground, seconds before EZ-17 fires his first shot, at 5:15. Source: Status Coup News

EZ-17 initially aims at the man he had pushed to the ground, but then turns and aims at the face of another nearby protester who did not appear to be involved in any previous physical contact with the agents. As EZ-17 aims at the face of this protester, the man raises his arms to shield himself before EZ-17 fires. 

EZ-17 fires his first shot, at 5:19. Source: Status Coup News. Blurring by Bellingcat

The large cloud of chemical irritant appears to disperse from the barrel immediately on firing for this shot as well as the next three shots EZ-17 fires.

This is consistent with the “Muzzle Blast” 40mm munitions produced by Defense Technology, which were seen in images of the agent’s belt.  Defense Technology says in its product specifications for 40mm “Muzzle Blast” munitions that these rounds provide “instantaneous emission” of a chemical agent in the immediate area (30 feet) of the person shooting them. 

Second Shot

Seconds later, after EZ-17 is hit by a snowball, he turns and fires towards the face of a man who is filming in the direction the snowball came from. It is unclear if this man is the intended target or someone else in the crowd behind him. 

EZ-17 firing the second shot. This shot can be heard and partially seen at 5:37 in the Status Coup News video. Left: Screenshot before firing. Centre and Right: Screenshots taken after firing. Source: Dymanh/TikTok at 0:22

Third Shot

The third shot is at a man who was seen on video throwing a snowball that hits EZ-2.

Man throwing snowballs at CBP agents after the second shot. Source: Mercado Media; annotation by Bellingcat

EZ-17 and EZ-2 chase this man, with EZ-2 spraying him in the face with Oleoresin Capsicum (OC) spray, also known as pepper spray or mace. EZ-2, when leaving the perimeter, can be seen carrying a Vexor Professional-branded canister.

Vexor exclusively produces various types of OC spray, and does not list any chemical irritant sprays that do not contain OC on its website. 

Top: EZ-2 visibly deploys at least two streams of OC spray at the man. Bottom: EZ-2 is seen leaving the crime scene tape perimeter earlier with a “Vexor Professional” branded canister. Vexor manufactures various OC spray products. Source: Status Coup News. Annotations by Bellingcat

The man slowly walks closer to the agents, saying that he has been maced. EZ-17 pushes the man, then aims at the man’s face and fires. 

The seals that keep the chemical irritant inside the 40mm canister before it is fired can be seen hitting the man in this shot, with the smoke surrounding his face.

Seals from the 40mm Muzzle Blast munition. Source: Dymanh Chhoun. Annotations by Bellingcat

Fourth Shot

After the third shot, an unmarked white CBP truck turns off the street and tries to drive down an alley. Protestors begin physically blocking the vehicle, throwing snowballs and other objects at it. The windshield gets cracked, and the back window gets broken. EZ-17 and EZ-2 physically push the protesters blocking the truck out of the way, with EZ-2 also deploying what appears to be a canister of OC spray.

A person begins banging on the windows of the truck, and EZ-17 rushes around the truck to fire his launcher towards this person’s face.

EZ-17 is seen firing his fourth shot at a person who was banging on the truck windows at 9:02. Source: Status Coup News 

University of St. Thomas School of Law professor Rachel Moran, who reviewed the videos at Bellingcat’s request, said that of the six shots we identified as being fired by EZ-17 this one appeared to be “the most reasonably related to carrying out the duty of helping the vehicle evacuate” as the person targeted was “still pounding aggressively” on the vehicle when EZ-17 fired the shot.

Fifth Shot

After EZ-17’s fourth shot, EZ-2 deploys a tear gas grenade, and the CBP truck moves down the alley, away from protesters. 

EZ-2 deploying a tear gas grenade at 9:09. Source: Status Coup News

EZ-17 can be seen reloading next to EZ-2, who is holding a canister that appears to be OC spray, and another CBP agent holding a PepperBall gun.

EZ-17 (in red box) reloading the 40mm launcher at 9:18. Source: Status Coup News. Annotations by Bellingcat

The CBP agent with the PepperBall gun appears to cross over to the other side of the truck, and EZ-2 appears to begin to enter the vehicle. 

CBP agent with PepperBall gun (yellow box) walking to the opposite side of the truck, EZ-2 standing in front of EZ-17 (red box) at 9:20. Source: Status Coup News. Annotations by Bellingcat

As soon as the back right door on the truck closes, gas from the muzzle can be seen from where EZ-17 was standing. 

Visible gas exiting the muzzle at 9:22. Source: Status Coup News

This fifth shot appears to be “skip-fired” or aimed towards the ground before ricocheting upwards, at close range, resulting in three visible projectiles going towards the crowd of people, narrowly missing some. 

Although the footage is blurry with the tear gas from the grenade EZ-2 threw still clouding the air, EZ-17 appears to be the only agent who could have fired this: EZ-2 was not armed with a projectile launcher, and PepperBall guns like the one carried by the other CBP agent do not have munitions that release multiple projectiles with a single shot.

Three different projectiles visible after the muzzle gas, at 9:22. Source: Status Coup News

Chemical irritant smoke was seen being released by the projectiles from this last shot as it travelled through the air. 

One projectile visibly emits chemical irritants as it travels through the air, at 9:23. Source: Status Coup News

The multiple projectiles are consistent with the 40mm “SKAT Shell” by Defense Technology, which ejects four separate submunitions upon firing, each dispensing chemical irritants. In one of the videos, a SKAT Shell is seen in EZ-17’s belt.

EZ-17’s belt before firing the second shot, with a visible SKAT-SHELL SAF-SMOKE to the right of the direct impact munitions on his belt. Source: Dymanh/TikTok at 0:21

Roosevelt High School

In another video from the same day, EZ-17 was filmed again alongside Bovino when CBP showed up at Roosevelt High School in Minneapolis at dismissal time

This video showed EZ-17 again firing his B&T GL06, apparently towards someone’s head, this time someone who threw a snowball at a CBP agent. 

EZ-17 after firing his B&T GL06 launcher at a high school student’s face. Source: Matthew Moore/Facebook

‘Punitive and Unlawful’

Patrick Wilcken, Amnesty International’s Researcher on Military, Security and Policing issues, said that while the overall situation shown in the videos was tense, with “verbal abuse, some shoving/throwing of snowballs and the attempted obstruction of a vehicle”, there did not seem to be any substantial physical threat to the agents that would have justified the use of less-lethal weapons. 

Wilcken, who reviewed the videos of all six shots fired by EZ-17 at Bellingcat’s request, said the actions of agents shown in these videos – pursuing fleeing protesters and in some instances firing at protesters who appeared to be trying to protect themselves – were “punitive and unlawful”. 

CBP’s use-of-force policy states that weapons such as 40mm launchers are only authorised for use against subjects offering “active” or “assaultive” resistance. Similarly, DHS’ use-of-force policy guidance says agents may use force “only when no reasonably effective, safe and feasible alternative appears to exist”, and may only use the level of force “objectively reasonable in light of the facts and circumstances” that they face at the time force is applied.

“Officers should only resort to less lethal weapons when faced by a serious physical violence posing a threat to themselves or others that is not possible to diffuse in any other way,” Wilcken said. “They must exercise force with restraint, to the minimum extent possible while respecting and enabling the right to peaceful assembly.”

University of St. Thomas School of Law professor Rachel Moran agreed that whether the use of less-lethal weapons is justified largely depends on the level of threat or aggression the agent faces from the person targeted. Although she said the fourth shot could be justified in helping the CBP vehicle evacuate, Moran said the justification for the other shots was “questionable at best” based on the footage. 

For example, Moran noted that although the man in the third shot had thrown a snowball at another officer, any threat had dissipated by the time EZ-17 shot him because the man had already run away and clearly had his hands up with nothing in them. “The shot appears to be more retaliatory than defensive”, she said. 

Similarly, for the incident at Roosevelt High School, Moran noted that EZ-17 did not appear to be in any danger from the snowball, as the person who threw it was already retreating before the agent fired.

Moran said that if EZ-17 was carrying a B&T GL06 40mm launcher, he did appear to violate CBP policy by directly aiming at people’s faces.

The weapon used by EZ-17 is visible as he points it towards a protester. Source: Status Coup News. Blurring by Bellingcat

CBP’s use-of-force policy states that agents using munitions launchers, including 40mm launchers “shall not intentionally target the head, neck, groin, spine, or female breast”. However, Bellingcat’s analysis of the six shots fired by EZ-17 showed that he appeared to be aiming at the head of targets in five of these cases. 

Travis Norton, a retired police lieutenant and use-of-force consultant, told Bellingcat that standard training and manufacturer guidance for 40mm launchers recommended aiming at “large muscle groups of the lower body” while avoiding “prohibited target areas” like the head, neck, chest, spine and groin. This helps to reduce the risk of significant injury, Norton said. 

Norton said that 40mm launchers are not intended for random or area fire: “Their use is limited to clearly identified individuals who are engaging in violent or dangerous behaviour and cannot be safely addressed by other means.”

Although he declined to comment on specific incidents based solely on video footage, Norton said that skip-firing – which was used in the fifth shot identified by Bellingcat, and the only shot where a person did not appear to be targeted at head-level – was generally not a standard or recommended practice in most law-enforcement training programs. 

“Because ground conditions, angles, and projectile behaviour are unpredictable, skip-firing reduces accuracy and control and increases the risk of unintended injury,” Norton said. 


Pooja Chaudhuri contributed research to this piece.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here and Mastodon here.

The post Five Shots in Five Minutes: Analysing One Federal Agent’s Use of Less-Lethal Launcher in Minneapolis appeared first on bellingcat.

  • ✇bellingcat
  • Analysing Footage of Minneapolis ICE Shooting Jake Godin
    To stay up to date on our latest investigations, join Bellingcat’s WhatsApp channel here On Jan. 7 Renee Good, a 37-year-old mother of three, was shot and killed by a federal agent on Portland Avenue in Minneapolis, Minnesota. The incident was captured on several separate videos and spread rapidly on social media. The videos were soon accompanied by competing analysis and narratives as to what had happened. Bellingcat looked at five videos filmed during the incident, including one apparent
     

Analysing Footage of Minneapolis ICE Shooting

13 de Janeiro de 2026, 11:39

To stay up to date on our latest investigations, join Bellingcat’s WhatsApp channel here

On Jan. 7 Renee Good, a 37-year-old mother of three, was shot and killed by a federal agent on Portland Avenue in Minneapolis, Minnesota. The incident was captured on several separate videos and spread rapidly on social media. The videos were soon accompanied by competing analysis and narratives as to what had happened.

Bellingcat looked at five videos filmed during the incident, including one apparently from the phone of Jonathan Ross, the ICE agent who shot and killed Good.

While each video alone provides valuable information, the five together provide a fuller picture of the situation as it unfolded.

Synced Overview

One of the ways to visualise the full incident was by tracking the movements of the key players on an overview map, which Bellingcat did shortly after the incident on Jan. 7. 

Using eyewitness video shared by Daniel Suitor on Bluesky we tracked the movements of federal agents at the scene – including Ross as he moved around the street. The video also captured the position and movements of Good’s vehicle before, during and after the shots were fired.

We’ve also updated our animated map of the positions of agents and vehicles during the incident here with new footage published by @cnn.com that shows the shooter closer to a white SUV prior to the shootingbsky.app/profile/bell…

[image or embed]

— Bellingcat (@bellingcat.com) Jan 8, 2026 at 18:38

Close-Up View

Another video, filmed by a bystander and later shared by the Minnesota Reformer, shows a closer view of Ross’ movements in the moments immediately before the shooting. 

In the video, Ross can be seen with his phone in his left hand filming Good before he pulls his gun out of its holster with his right hand. Roughly one second elapses before he fires the first round through Good’s front window. Two more shots follow.

A still from that same video captures Ross as he walks past in the seconds after the shooting. A camera app appears open on his phone.

A still image in a video published by the Minnesota Reformer. A video app can be seen open in the federal agent’s phone.

Agent’s Phone

On Jan. 9, a video filmed by Ross was published on X by a conservative news outlet called Alpha News. 

By syncing this video up with the other four available videos, it was possible to observe more of what occurred, including from Ross’ rough perspective. However, it is important to note that Ross was holding the phone slightly away from his body, so what appears in the video would be marginally different to what would have been his line of sight. 

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

In the footage, Good can be seen backing up before veering to the right as Ross and the camera move to her left. It is not clear from this footage exactly how close the car came to Ross, as the cellphone points up and away as the vehicle moves forward. Someone can be heard saying “whoa” before gunshots are heard. 

An angle captured from down the street (middle lower right in the synchronised video below and in full view here) – which some have suggested shows Ross being hit by the vehicle – does appear to show the vehicle pass close to the agent as he fires. However, the close-up video shared by the Minnesota Reformer (middle top and in full view here) shows Ross moving out of the way and to the side of the vehicle as he fires.

Another video published by CNN (middle lower left) shows a head-on view of the incident from surveillance footage.

New footage from the ICE agent’s phone who shot at Renee Nicole Good in Minneapolis has emerged, posted by AlphaNews on X. We’ve placed that footage in a synced timeline with the other currently available footage.

[image or embed]

— Bellingcat (@bellingcat.com) Jan 9, 2026 at 21:23

Almost one week after the incident, protests have been held in Minneapolis and other cities in the US. 

US President, Donald Trump, and Department of Homeland Security, Kristi Noem, initially said that Good had tried to run over an ICE officer after blocking the road, labelling her a “domestic terrorist”. However, the Democratic mayor of Minneapolis, Jacob Frey, said that version of events was “garbage” and disproven by the video footage.

On Monday Jan. 12, Noem, told FOX News that more ICE agents would be sent to Minnesota.

Individual links to each of the five videos detailed above can be found here, here, here, here and here.


Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here and Mastodon here.

The post Analysing Footage of Minneapolis ICE Shooting appeared first on bellingcat.

❌
❌