Visualização de leitura

Leaked Russian Cyber-Operations Training Materials

This is interesting:

The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security.

[…]

The reporting also linked a 2024 Department No. 4 graduate, Aleksei Kondrashov, to Military Unit 74455, widely known as Sandworm.

That unit has been associated with destructive cyber activity against Ukraine and other targets, including the 2017 NotPetya attack.

The reports do not establish that every listed graduate participated in a named operation; assignments should therefore be described as reported unit placements, not proof of individual operational involvement.

The Bauman material reframes Russia’s cyber capability as an institutional system, not merely a collection of well-known threat groups.

It suggests that Moscow has formalized a recurring pathway from university recruitment to military service, where students receive supervised technical and ideological preparation before entering intelligence, cyber, and security roles.

For defenders, the leak reinforces the need to track Russian operations as a combined threat: espionage, destructive activity, military reconnaissance, technical surveillance, and influence campaigns may draw on related personnel pipelines and overlapping doctrine.

The exposure of Department No. 4 also provides researchers with a clearer lens for understanding how the GRU sustains cyber capacity beyond the familiar APT28 and Sandworm brand names.

Tracking a Sanctioned Russian Vessel’s West African Odyssey

Sign up here to receive Bellingcat’s biggest investigations by email as soon as they are published.

A sanctioned vessel that was previously reported to have transported weapons destined for Russian mercenaries has been traversing ports on the west coast of Africa since March, exhibiting what experts told Bellingcat  was an unusual set of movements and behaviours.

Patria (IMO: 9159921) has been sanctioned by the US, Ukraine and Canada.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Radio France International (RFI) reported last year that it was one of two ships to deliver weapons to Conakry in Guinea that were intended for the Kremlin-controlled Africa Corps and their operations in Mali.

Satellite imagery and Automated Identification System (AIS) data from Lloyd’s List Intelligence shows Patria has shuttled between the Port of Douala in Cameroon and the Port of Owendo in Libreville, Gabon four times since March. 

It has also twice stopped in anchorage off the coast of Lagos, Nigeria: first in March and then again at the time of publication. Analysis shows the vessel also spent time in anchorage off the coast of Equatorial Guinea. 

The online news site, Modern Ghana, first reported Patria’s presence off the coast of Lagos in July after X-users @SONNAROW_OSINT and @RFNOSBlog picked up on Patria’s position.

It is not clear what Patria has delivered or picked up at these ports. Nor is it clear why it has spent so long going back and forth between them. But experts Bellingcat spoke to said the unusual patterns of behaviour raised numerous questions.

Charlie Brown, a former US Naval Officer and Senior Advisor at United Against Nuclear Iran said the combination of Patria’s repeated regional port calls, extended periods at anchor, and an apparent absence of a normal point-to-point trading cycle warranted scrutiny, especially as the ship is under sanction and is previously reported to have shipped arms. 

Tracking the Patria

Patria is a cargo vessel that has a distinct shape and features. Its bridge is located on the bow and it has a bright red deck that contrasts with its blue hull and two yellow cranes. 

At the end of the deck, the ship has a built-in ramp for vehicles (the Patria is a so-called roll on/roll off, or RoRo, vessel that is designed to transport wheeled vehicles). Its chimney is located next to the ramp.

Footage of the Patria, posted on Youtube on Jan 22, 2024. Credit: Hanro Shipping – Sakhalin Projects LLC / YouTube Channel @hanroship

This, in combination with the length of the ship (101 m), allowed Bellingcat to pick the vessel out in satellite imagery. AIS data helped us further track its long journey which began in the Sea of Japan, in Russia’s far-east, in January.

For the most part, we were able to match Patria’s AIS position with corresponding satellite imagery. We found no evidence of obvious spoofing incidents (where a ship intentionally broadcasts misleading AIS data) by the vessel during its months-long voyage, however, there were some instances where satellite images were not available and thus spoofing by the vessel cannot be completely ruled out.

MapLibre | Protomaps© OpenStreetMap contributors

Port of Olga, Russia

AIS data indicates that Patria loaded at the Port of Olga in the Sea of Japan between Jan. 21 and 23. Patria can also be seen on satellite imagery on these dates.

Credit: Planet Labs PBC.

Port of Douala, Cameroon

AIS data indicates that Patria unloaded some cargo in the Port of Douala between Mar. 11 and 12. Again, the ship can also be seen in satellite imagery on these dates.

Credit: Planet Labs PBC.

Lagos Anchorage, Nigeria

AIS data indicates Patria anchored off the coast of Lagos from Mar. 14 to 15.

A Sentinel-2 image from the 15th appears to show another ship next to Patria. AIS data indicates that this is JS Gratitude, a bunkering tanker. This close proximity suggests that Patria was refuelling.

Credit: Contains modified Copernicus Sentinel data 2026.

Bata Anchorage, Equatorial Guinea

AIS data and satellite imagery indicate Patria stayed off the coast of Equatorial Guinea for several days.

Credit: Planet Labs PBC.

Port of Owendo, Libreville, Gabon

AIS data and satellite imagery indicate Patria loaded at the Port of Owendo in Libreville after spending a few days off the coast.

Credit: Planet Labs PBC.

Port of Douala, Cameroon

AIS data and satellite imagery indicate Patria stayed at the Douala Anchorage from Apr. 6 to 14, before unloading at the Port of Douala between Apr. 14 and 18.

Credit: Planet Labs PBC.

Port of Owendo, Libreville, Gabon

AIS data suggests Patria loaded in Libreville again between Apr. 22 and 26.

Port of Douala, Cameroon

AIS data, supported by satellite imagery, indicates Patria stayed at the Douala Anchorage for nearly a month from Apr. 27 to May 21 before unloading in Douala from May 21 to 27.

Credit: Planet Labs PBC.

A third trip between the Port of Owendo, Libreville to Douala, Cameroon

AIS data indicates, after nearly a month’s wait in Douala anchorage, Patria again loaded at Owendo before returning to Douala to unload.

A fourth trip between the Port of Owendo, Libreville to Douala, Cameroon

AIS data indicates Patria again loaded at Owendo before returning to Douala to unload.

Lagos Anchorage, Nigeria

AIS data indicates, after a short visit to the Libreville anchorage, Patria anchored off the coast of Lagos where it remained at the time of publication.

Credit: Planet Labs PBC.

Examining the Patria’s Draught

We reviewed the draught of the ship at each port visit and found that the ship’s draught always dropped after a stay at the Port of Douala, suggesting it was unloading there.

A ship’s “draught” is the distance from the bottom of the hull (the keel) to the waterline. When loaded, a ship is heavier and sits lower in the water (e.g. a draught of six metres) than when it is unloaded (e.g. a draught of four metres).

Draught is the depth of a ship below the waterline. 

In the period from March to July, the Patria made five port calls to Douala and each time the draught decreased. Conversely, it called four times at the Port of Owendo in Libreville, each time the draught increased, meaning the ship became heavier, suggesting it was loading.

The draught is self-reported by ships but usually when it arrives at ports this kind of data is checked – reporting accurate draught is also a safety issue for ships arriving and departing at ports. 

Bellingcat asked the ship’s owners, managers and both ports if items were being transferred from Libreville to Douala but did not receive a response at time of publication.

Brown, the former US Naval Officer and now a Senior Advisor at United Against Nuclear Iran, said Patria’s movements were unusual.

“A sanctioned vessel linked to a prior military logistics shipment spending nearly six months operating between a small cluster of West African ports, Douala, and Owendo, without returning to a clear commercial trading pattern warrants scrutiny,” Brown told us.  


“While innocent explanations such as mechanical issues, commercial disputes, lack of cargo, chartering delays, or prolonged maintenance are possible, the combination of repeated regional port calls, extended periods at anchor, and an apparent absence of a normal point-to-point trading cycle is atypical for a merchant vessel.” 

He added that the current period of more than 30 days at the Lagos Anchorage, in particular, is noteworthy. 

David Soud, Head of Research and Analysis at I.R Consilium also told Bellingcat that Patria’s prolonged Lagos Anchorage could have innocent explanations such as its need for ongoing repairs, or that its operators were out of money, but added that there could also be more calculated reasons and it was laying low for a while.

Bellingcat analysed AIS data from Lagos Anchorage and found that while there has been high congestion, no other RoRo or container vessel waited longer than 10 days to enter the port in the period that Patria has been at Lagos Anchorage. At time of writing, Patria has been in anchorage for more than 30 days.

Regarding the Patria’s apparent deliveries of cargo between Libreville in Gabon, and Douala in Cameroon, Soud told Bellingcat:

“Given the vessel’s history of transporting military equipment to African seaports for overland delivery to Russian and allied forces in the Sahel, it’s not out of the question that some form of supplies for Russian or other forces could be picked up in Gabon, whose government has developed a closer relationship with Moscow, to be discharged in Douala, which is the main entry point for goods going to Central African Republic.”

Bellingcat asked the Nigerian Ports Authority why Patria had been in anchorage for so long, whether it had applied to dock and whether the port was aware of its sanctioned status but did not receive a response at time of publication.

The ports of Douala in Cameroon and Owendo in Libreville, Gabon did not respond to Bellingcat’s requests for comment about the Patria’s visits and the cargo it was carrying.

Bellingcat also contacted the two companies connected to the vessel – Hanro Shipping and Sakhalin Shipping Company which are listed as the vessel’s owner and manager respectively in sanctions documents. We also contacted the company connected to JS Gratitude. We did not receive a response at time of publication.


Youri van der Weide, Galen Reich, Yörük Işık contributed to this report.

Cover image: Planet Lab image shows the Patria at the Port of Douala, Cameroon, on April 17, 2026. Credit: Planet Labs PBC.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Tracking a Sanctioned Russian Vessel’s West African Odyssey appeared first on bellingcat.

UK Cybercrime Journal: H1 2026 Social Media Fraud Trends

What Happened

HMRC Issues Warning to TikTok Users

  • On 4 June 2026, HM Revenue and Customs (HMRC) uncovered a suspected £153 million tax fraud scam involving TikTok.
  • The scheme allegedly involved individuals posting advertisements on the TikTok, enticing users to hand over sensitive tax information, including business VAT registration details or personal self-assessment credentials for a financial reward.
  • Using the stolen tax details, the fraudsters could file bogus repayment requests with HMRC.
  • The warning comes after two Romanian men, aged 22 and 25, were apprehended by HMRC officers in east London on 23 April 2026 in connection with the alleged fraud.

Lloyds Bank found Two Thirds of Fraud Cases Started on Meta 

  • On 6 June 2026, Liz Ziegler, the Lloyds fraud prevention director disclosed that 68% of fraud reports from their customers started on a Meta platform, including Facebook, Instagram, and WhatsApp.
  • The average claim value submitted to Lloyds Bank is now above £500, an increase of about £100 from last year. Plus, victims were sending up to £66 million a year to fraudsters after falling victim to a scam advert via Meta, up from £27 million in 2023.
  • The most common scams involve fake tickets for concerts, festivals and sporting events. Meta’s Facebook Marketplace is also plagued by fake adverts for cars, bikes, campervans and mobility vehicles.
  • Other categories of fraud on Meta platforms, collected by Lloyds between March 2025 and 2026, include: wedding photobooths, tattoo deposits, vapes, wigs, Moncler jackets, football shirts, Dyson products and Amazon Alexas. Fraudulent transactions for deposits for flats, mobile phones, household furniture and gym equipment have also been observed.

UK Finance Recorded £221.5m Lost to Investment Scams

  • In June 2026, UK Finance's Annual Fraud Report recorded the highest loss total ever recorded and the highest total number of cases ever reported at 14,893, which was 26% higher than 2025.
  • Up to £221.5m was lost to scams in which victims were persuaded to transfer funds to a fake investment or fictitious fund. This figure also marked a 40% rise more than 2025.
  • The primary observed tactics involved in investment scams include traditional cold calling to pressurise victims into acting quickly to claim an opportunity before it expires, as well as adverts on social media offering unrealistic rates of returns on investments, and hand-delivered letters.
  • The types of investments fraudsters used as bait in 2026 involved gold, property, carbon credits, cryptocurrencies, land banks, and wine.

Fraudsters arrested in Nigeria following NCA intelligence sharing

  • In February 2026, the National Crime Agency (NCA) announced that seven men were arrested in Nigeria after intelligence identified an online investment scam compound targeting UK victims. These arrests were the result of co-operation between the National Crime Agency, Meta and the Nigerian Police.
  • Using hundreds of fake Facebook accounts accounts to impersonate cryptocurrency traders, the Nigeria-based scammers targeted people who used legitimate investment platforms.
  • The scam compound was also allegedly recruiting and training young people in targeting victims for future investment frauds and phishing attacks. A total of 26 phones, 42 sim cards and a laptop were seized on 13 January.

Analyst Comment 

H1 2026 reinforces the transition from email-centric fraud campaigns to social-media-powered fraud operations, with platforms increasingly serving as the primary source of victims for organised cybercriminal groups. Fraudsters are also adapting scams to the culture and user behaviour of individual platforms, such as generate short promotional videos on TikTok or listing fake items for sale on Facebook Marketplace. Rather than deploying identical scams everywhere, criminals tailor campaigns to the platform's intended purpose. Recommendation algorithms and advertising ecosystems provide fraudsters with scalable victim acquisition channels that were previously unavailable through traditional phishing campaigns.

Advances in artificial intelligence (AI) and large language models (LLMs) has also meant it is much easier for cybercriminals to carry out scams on a much larger scale than they were previously able to. Autonomous systems can enable them to send out messages at scale and contact users by telephone at scale. Plus the scam attempts are also more convincing as they can mimic voices and appearance of celebrities or even a target’s friends and family.

The scale of fraudulent activities across social media is so large, it requires vast resources and expertise to monitor, detect, and prevent. At the same time, the response from HMRC, banks, social media companies, the NCA, and international law enforcement suggests increasing recognition that combating social media fraud requires coordinated action.

The volume of fake accounts on social media used for scams does also validate the calls for increased verification and security checks on such platforms. The UK Government's proposal to introduce a national digital ID system, however, was met with fierce opposition. Up to 2.9 million people signed a UK parliament petition to show their disagreement with such a system.

Defensive Takeaways 

  • Reduce Public Exposure: Fraudsters increasingly use information shared on social media to personalise scams and identify potential victims. Consider making profiles private or limiting visibility to trusted contacts and if you no longer actively use a social media platform, consider deleting the account entirely.
  • Be on Guard for Scams: Sponsored advertisements should not automatically be considered legitimate. Refuse any financial rewards in exchange for your login credentials. Be cautious of investment opportunities promoted solely through social media. Assume Facebook Marketplace listings can be fraudulent.
  • Report Suspicious Activity: Reporting scams helps remove fraudulent content and supports law enforcement investigations. Useful UK reporting channels include Report Fraud and the UK NCSC's Suspicious Email Reporting Service report@phishing.gov.uk.
  • Seek Support after a Scam: Victims should not assume financial losses are unrecoverable. It can be possible to get funds returned if they contact their bank immediately, preserve screenshots and transactions records, and report the incident to Report Fraud. Further, if a victim is dissatisfied with how their bank handled their case, they can complain to the Financial Ombudsman Service.

Relevant Sources 

  1. https://www.independent.co.uk/news/uk/crime/tiktok-hmrc-tax-fraud-scam-b2989914.html
  2. https://www.thetimes.com/article/840020a8-1210-47c9-9262-e3139116b652?shareToken=771d08288cd2ac9d0ba13194f43d75a0
  3. https://www.theguardian.com/money/2026/jun/15/investment-fraud-uk-more-than-220m-lost-last-year-scams-ai
  4. https://www.ukfinance.org.uk/system/files/2026-06/UK%20Finance%20Fraud%20Report%202026.pdf
  5. https://www.nationalcrimeagency.gov.uk/news/fraudsters-arrested-in-nigeria-following-nca-intelligence-sharing 

Heading Off: New Technique Helps Track Grain Smuggling Expansion to Libya

On February 15, 2026, the bulk carrier, Grumant (IMO: 9385879) was pictured at the occupied Ukrainian Port of Feodosia on the Crimean peninsula. Satellite imagery suggests it had already been there for several days.  It appeared to stock up on grain before departing on a two-month-long journey eventually docking at the Port of Benghazi in Libya on April 18.

While there have been previous reports of grain shipments from occupied Ukraine arriving in Libya, this is only the second time a Russian ship has been observed delivering what the Ukrainian government describes as “stolen” grain to the country. The previous case involved the Damas Wave which travelled in January of last year to the port of Misrata which is under the control of the UN-recognised Government of National Unity (GNU). In addition to satellite imagery, Bellingcat deployed a new technique that analysed Grumant’s heading data which was contained in AIS information provided by Lloyd’s List Intelligence, to help confirm Grumant’s presence in Feodosia. 

Bellingcat has been tracking smuggled Ukrainian grain shipments as they find new markets, five of the ships we previously identified have since been sanctioned by the EU while another was sanctioned by the US Department of Treasury.

MapLibre | Protomaps© OpenStreetMap contributors

Bosphorus Strait

Grumant transits the Bosphorus Strait in the middle of the night.

Credit: Yörük Işık.

Black Sea

Grumant enters a region of the Black Sea known for GNSS interference, meaning that Grumant’s publicly reported Automated Identification System (AIS) position is unreliable.

Port of Feodosia

On February 15, a high resolution satellite image confirms the ship is docked at the port of Feodosia at berth No. 1 that is used for bulk and metal cargo. Matching features visible include Grumant’s grey decking, its seven hatches and bright yellow front mast. What appears to be leftover grain can be seen under the two port crates, immediately next to the ship.

Credit: Satellite image ©2026 Vantor.

Black Sea

Grumant exits the area of signal interference, meaning that its reported position on ship tracking services is now reliable again. Its AIS messages indicate it is travelling towards the Bosphorus.

Bosphorus Strait

Grumant transits the Bosphorus Strait towards the Sea of Marmara. Judging by the draft, with no visible red paint on its hull, the ship appears to be fully laden.

Credit: Yörük Işık.

Izmir Anchorage

Grumant arrives in Izmir, Turkey on February 23 and anchors off the coast until March 13.

Over the course of three weeks, Grumant never enters the Port of Izmir. It is not known if it was denied entry. Bellingcat asked the port operators but did not receive a response before publication.

Credit: Planet Labs PBC.

Aliağa

Grumant then loiters off the coast of Aliağa, about 50 km from Izmir. It stays here until March 16, never entering the port. It again is not known if it was denied entry. Bellingcat asked the port operators but did not receive a response before publication.

Near Benghazi

Grumant arrives in Libyan waters and stays off the coast of Benghazi until April 1.

Libyan Waters

Grumant briefly leaves the coast of Benghazi, but returns a few days later.

Benghazi

Grumant leaves the anchorage on April 18 and docks at the port of Benghazi where it unloads the grain. The ship was captured in a Vantor satellite image on April 20.

It leaves port on April 23, and heads back towards the Bosphorus.

Credit: Satellite image ©2026 Vantor.

Bosphorus Strait

After spending a few days off the coast of Tuzla, Grumant transits the Bosphorus towards the Black Sea.

Credit: Yörük Işık.

Lloyd’s List Intelligence has previously reported on the expansion of Russia’s grain smuggling operations, beyond the occupied port of Sevastopol to include Feodosia port

According to the Ukrainian activism, journalism and hacker group, Kiborg News, Grumant used deceptive shipping practices to deliver grain to Latakia, Syria in 2024. The report included several of Grumant’s shipping manifests, which showed it had repeatedly exported grain from Occupied Crimea to Syria. 

Heading Data Helps Locate Grumant

It is standard maritime practice that ships broadcast Automatic Identification System (AIS) messages which include a ship’s position, heading, and draught (among other information).

Because of longstanding Global Navigation Satellite System (GNSS) interference in parts of the Black Sea, the position data transmitted by an affected ship’s AIS system is often unreliable.

Between February 7 and February 19, 2026, data from Lloyd’s List Intelligence shows the Grumant transmitted 29 AIS messages, with unreliable positions in the vicinity of Feodosia. We know these positions are unreliable as they are erratic and some of them report the ship as being positioned on land.

Unreliable AIS positions – Grumant’s reported positions between February 7-19, 2026, via Lloyd’s List Seasearcher.

However, according to the IMO, the heading data transmitted by a ship’s AIS system must come from an onboard compass. A compass is unaffected by GNSS interference, meaning it is a more reliable source of information in these conditions.

Over the same dates, all 29 AIS messages reported the ship’s heading as 267 degrees or 268 degrees. The Port of Feodosia has a heading of 267.5 degrees. The close agreement between the ship’s heading and port heading strongly suggests that Grumant was moored at the port between February 7 and February 19, 2026.

We conducted an extra check of the heading data by reviewing satellite imagery available of berth 1 at Feodosia Port, which suggests that the same vessel was present on several days between February 6 and February 18. Imagery on Feb. 6 shows the port was empty in the morning and occupied in the afternoon. Grumant exited the area of GNSS interference on February 21, and berth 1 at the port was captured on satellite image on February 22 and appeared empty. The low resolution satellite imagery is only used as an additional check to see if a vessel is at the berth.

Timeline of open source observations related to Grumant’s presence (tick) or absence (cross) at Feodosia port. Empty entries indicate a lack of available data.
Sentinel-1 timelapse of Feodosia Port, Copernicus Sentinel data 2026. Annotations by Bellingcat.
PlanetScope timelapse of Feodosia Port, Planet Labs PBC. Annotations by Bellingcat.

Bellingcat checked all vessels transmitting AIS in the vicinity of Feodosia Port and found that Grumant was the only one that consistently transmitted a heading matching the Port of Feodosia over the period of interest.

We shared our research with Charlie Brown, a former US Naval Officer and Senior Advisor at United Against Nuclear Iran where he focuses on maritime sanctions enforcement and the tracking of illicit shipping. Brown told Bellingcat that while satellite imagery of vessels remained key for identification, when looking for reliable data in a spoofing environment it made sense to look at the various elements of AIS data to try and find some accurate information, despite GNSS spoofing.

“It’s quite standard for the independent gyro compass to be providing the heading […] I think the majority would not [be subject to spoofing] so it’s a good methodology to parse out the particular data and then make some inferences from that.”

“It’s neat to think of what can be derived from data that would otherwise be dirty or wrong. So there’s still some elements of use in there.”

He added that in theory there are probably some compasses that are subject to spoofing as well. 

He told Bellingcat that it was fair to say the heading data of the Grumant supported identification, but stressed the need to cross-reference with other data sources. 

While in this instance it has been possible to use AIS data to help verify the location of Grumant, it is relatively unusual to have access to this information. 

Ships that call to the occupied territories frequently disable their AIS transponders to do so.

This activity, known as “dark port calls”, is a common tactic for those engaging in illicit or sanctioned trades. 

Grumant does not transmit AIS messages from February 8 to 11, but this is the longest gap in data (see diagram above), with intermittent messages coming through after that point.

It is unclear why Grumant continued to transmit AIS during the period it was loading in Feodosia. 

A review of Lloyd’s List Intelligence data from January 2025 shows that on a previous voyage to the Black Sea the Grumant operated “dark” for 59 days.  

Visual Identification

On February 15, 2026, high resolution imagery showed Grumant docked in the Port of Feodosia. We compared it with other recent images of Grumant to confirm the match. 

The ship in the satellite image has a grey-coloured deck, which is uncommon enough for it to stand out. Many bulk carriers have cranes (including the ships we previously covered such as Krasnodar, Zafar and Zaid), Grumant does not have any. It also has seven hatches (openings for the grain) and a bright yellow front mast that matches the mast of Grumant (see the image of it transiting the Bosphorus). We can match the Grumant in the Feodosia image, not only to pictures of the Grumant shot from the ground, but also to the satellite image from Benghazi.

The length and breadth of the ship also matches that of the Grumant; 180 metres by 22.90 metres. 

Above: Image of the Grumant transiting the Bosphorus. (In yellow: the mast, red: the seven hatches, green: four vent masts, two on either side). Credit: Yörük Işık. Middle: Satellite image of the Grumant in Feodosia on February 15, 2026. (Matching elements are denoted in the same way as the image above). Bottom: Grumant captured at Benghazi port on April 20. Credit: Satellite image ©2026 Vantor. Annotations by Bellingcat.

Libya’s Relationship with Russia and Ukraine 

Libya has complicated internal dynamics with essentially two administrations in charge of different parts of the country – the Government of National Unity (GNU) in the west and the Libyan National Army (LNA) in the east.

In recent years, Russia has backed the LNA’s General Khalifa Haftar, based out of Benghazi, in the east of the country. But Jalel Harchaoui, a political scientist specialising in Libya with the Royal United Services Institute (RUSI), stressed that the two sides of this conflict, the LNA and the UN-recognised GNU, are not currently fighting. Instead they are in a flawed, multi-year truce.

Therefore, the east-west divide isn’t as clear-cut as during the civil war. While all shipments going to Benghazi and Tobruk are overseen by the LNA, not all shipments going to the city of Misrata (which is run by the GNU) are meant for the GNU-dominated part of the country. 

Harchaoui told Bellingcat: “the Tripoli government is in some regards pro-Ukraine, but if there’s business that can be done with Russia through the very opaque port of Misrata and all the right people get paid, the business is going to take place.”

That observation is potentially significant given at least one previously tracked vessel that went from occupied Ukraine to Libya docked in Misrata.

This was not the case of the Grumant, however, which arrived in an LNA-controlled part of the country. It is not known from open sources alone if the authorities in Libya or at the port in Benghazi knew the grain carried by Grumant had come from occupied Ukraine.

Bellingcat contacted the Benghazi-based LNA government and representatives of the Tripoli-based GNU government via the Libyan Embassy in The Netherlands. We also contacted the Port of Benghazi, Port of Imzir in Turkey as well as the Ukrainian and Russian authorities. Representatives of the LNA did not respond to requests for comment before publication, nor did the Port of Benghazi or Port of Izmir. The Libyan Embassy in The Netherlands replied to Bellingcat after publication, stating that Benghazi and eastern Libya are not under the authority or administrative control of the Government of National Unity and therefore they are not currently in a position to comment on Bellingcat’s findings.

Ukraine Continues to Pursue the “Shadow Grain Fleet”

“The port of Feodosia, located in the temporarily occupied Autonomous Republic of Crimea, is not under Ukrainian control, and any commercial activity conducted there is illegal,” the Ministry for Development of Communities and Territories of Ukraine and the Ministry of Foreign Affairs of Ukraine told Bellingcat in a joint response. 

They told us the loading of grain exported from the temporarily occupied territories is an illegal act and Russia was using ports as logistics centers to export stolen Ukrainian agricultural products.

“The expansion of such routes to third countries, in particular to North Africa, demonstrates Russia’s ongoing efforts to circumvent international sanctions and monetize resources stolen from the occupied Ukrainian territories.” 

The Ukrainian Ministry of Foreign Affairs sent information about Grumant’s (IMO: 9385879) “illegal activities” to the diplomatic missions in Great Britain, the Republic of Turkey and the Republic of Tunisia over the course of March to May this year, the ministries told Bellingcat. 

Ukraine is continuing to pursue legal action against Russia’s “shadow grain fleet” they told us. For instance, earlier this month a Swedish court approved the transfer of the Russian “shadow grain fleet” vessel CAFFA to Ukraine for investigation after it was arrested in Swedish waters. 

This case has set a new precedent, going beyond sanction and fines previously handed out to such vessels, and allowing for the detention and confiscation of a shadow fleet vessel in European jurisdictions, the ministries said.

According to Russian court documents Grumant’s previous owner Murmansk Shipping Company was dissolved and “Decision/Reshenie” LLC were listed as the International Safety Manager and operator of Grumant. Decision/Reshenie were also listed as the operator of Grumant in another court document, from an unrelated case. 

Bellingcat attempted to contact Decision/Reshenie to ask about Grumant’s grain shipment from Feodisia Port to Benghazi Port, but they had not responded at time of publication.


Youri van der Weide, Galen Reich, Yörük Işık and Bridget Diakun contributed to this report.

Cover image: Planet Lab image shows Grumant anchored off Izmir, Turkey on February 27. Credit: Planet Labs PBC.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.


The post Heading Off: New Technique Helps Track Grain Smuggling Expansion to Libya appeared first on bellingcat.

Tracing Digital Links Between Viory and Ruptly

“In the age of misinformation, the line between fact and fiction is blurrier than ever.”

“For those of us working in video news, verification isn’t a nice-to-have. It’s a necessity. It is how we protect the stories we help shape and how we earn and maintain trust in an increasingly chaotic information ecosystem,” Abu Dhabi-registered video news agency Viory posted on LinkedIn on April 9, 2026, offering training to help newsrooms and journalists sort fact from fiction. 

The self-described “video news agency of the Global South” has delivered journalism training to multiple national press agencies across Africa, Asia and the Middle East.

However, when it comes to Viory itself, the line between fact and fiction is very blurry indeed. 

Bellingcat has found multiple links between the digital infrastructure of Viory and Ruptly news agency, a branch of sanctioned Russian propaganda outlet Russia Today, including shared IP addresses, a Viory-linked site using a digital security certificate registered to Ruptly, and Ruptly sending site performance data to Viory. While there have been previous reports on suspected links between the two outlets, our investigation adds new evidence about Viory’s ties to Ruptly media. 

When contacted for comment, both Viory and Ruptly denied any connection with each other.

Composite Image created by Bellingcat.

‘Video News Agency of the Global South’

Viory’s main offering is raw video footage of news events provided via subscription. According to Viory, its clients include “major international news outlets, local media organisations, and independent creatives in more than 170 countries”.

If its own figures are to be believed, Viory was strikingly well established at its launch in November 2023, by which time it claimed to have a “pre-assembled team of over 150 full-time staff, and an established network of over 3,000 video journalists across the world”.

The name “Viory” is a trade name. The company’s legal name is Darpo Vision FZ LLC, according to its website, which also states that it is registered in Abu Dhabi. In August 2024, Darpo Vision FZ LLC filed for a trademark in the US for the name Viory, which was approved in December of 2025

As of May 2026, Bellingcat found press releases and news reports referencing at least 30 agreements between Viory and partners in more than 22 countries, as well as cooperation agreements with government agencies, training agreements with universities and regional journalism bodies. 

This includes:

Viory also sponsored a glitzy event for its inaugural Global South Video News Awards in December 2025 at Abu Dhabi’s first-ever BRIDGE Summit.

Ruptly Revisited

Ruptly is a video news agency formerly based in Berlin and ultimately controlled by Russia Today (RT), which is owned by Russian state media company ANO TV-Novosti. ANO TV-Novosti has been on the EU sanctions list since December 2022 for spreading “pro-Kremlin propaganda and disinformation” and supporting Russia’s war against Ukraine. 

RT launched Ruptly, which operated in Berlin via a German-registered subsidiary in 2013, with the goal of “becom[ing] the go-to alternative resource in a highly concentrated market of professional news video footage, and to deliver coverage of stories that other agencies miss.”

Sanctions imposed on RT following Russia’s 2022 invasion of Ukraine choked off Ruptly’s source of funds in Germany, leading the German company to begin insolvency proceedings in October 2024. Ruptly continues to operate from Moscow as of 2026.

As with Viory, Ruptly’s main offering is providing raw news footage to subscribers around the world. It relies on a large network of international freelancers and stringers. In 2016 RT claimed that Ruptly had “surpassed” newswire services AFP and Reuters on YouTube, and was serving more than 600 media organisations in 45 countries.

Felix Huesmann of the German outlet RedaktionsNetzwerk Deutschland (RND), was the first to outline links between Ruptly and Viory while covering the insolvency proceedings of Ruptly. He found that Darpo Vision’s original details on the Abu Dhabi Creative Media Authority’s site included an email address d.toktosunova@gmail.com. It has not been confirmed who this email address belongs to; however, the username matches the first name initial and surname of Dinara Toktosunova, the managing director of Ruptly. When asked about this email address by Huesmann  in 2024, Ruptly “explained that Toktosunova is focused on securing the future of the Ruptly team [in Moscow] and is not working anywhere else as a managing director.”The activist group, OSINT For Ukraine, also outlined links between Ruptly and Viory, including the movement of multiple key staff between the two organisations and strong similarities between the two organisations’ platforms and content.

Darpo Vision’s Security Certificate

The legal entity behind Viory, Darpo Vision, was set up in one of Abu Dhabi’s free zones – special economic areas that have business-friendly incentives such as tax exemptions and that allow 100 percent foreign ownership. The free zones also offer what some describe as high levels of “corporate privacy,”  which others assert has created a haven for shell companies and opaque corporate structures.

Darpo Vision initially had its own web domain, darpo.vision. The site has since been removed. Whois records show that the domain was registered by Darpo Vision FZ LLC in December 2022 to a PO Box in Abu Dhabi, using a Russian domain name registrar and a Moscow phone number. 

Initially, Darpo.vision had its own Secure Sockets Layer (SSL) certificate – a digital certificate that authenticates a website’s identity, allowing it to secure and encrypt data. However, VirusTotal data shows that as of at least June 2024, darpo.vision was using a wildcard SSL certificate registered to ruptly.video. A Wildcard SSL certificate is a single certificate with a wildcard character (*) in the domain name field. This allows the certificate to secure a single domain and multiple subdomains. You can see historical SSL certificates for darpo.vision.


James Wilson, a software and networking engineer with 20 years of experience and currently Enterprise Technology editor at Risky Business Media, told Bellingcat that to prevent unauthorised use or forgery of SSL certificates, a private key is needed to create and use a wildcard certificate across multiple domains. 

“The fact that darpo.vision was using a wildcard SSL certificate for ruptly.video indicates that whoever was running darpo.vision also had access to the private key for ruptly.video’s SSL certificate. Normally, only the people operating Ruptly’s web hosting infrastructure would be likely to have access to that,” Wilson explained. 

When asked by Bellingcat about whether there were alternative possible explanations, Wilson suggested that it was theoretically possible that someone may have hacked Ruptly and stolen their private SSL key. 

“However, using that wildcard SSL certificate on a domain that didn’t match the wildcard in the certificate defies explanation as the browser would alert the user to the certificate error,” he added.

Shared IP Addresses

Bellingcat also identified multiple shared IP addresses which appeared to be concurrently in use by both Ruptly and Viory between May 2025 and May 2026. 

From 2025 onwards, the Russian IP address 158.160.132.25 has been used concurrently by viory.video, ruptly.video, ruptly.agency and ruptly.tv, according to VirusTotal. Similarly, since the beginning of 2026, IP address 84.252.135.88 has been used concurrently by viory.video, viory.team, ruptly.video, ruptly.agency and ruptly.tv, according to VirusTotal. 

VirusTotal data shows that from 2025 onwards, IP address 158.160.166.22 has been used by ruptly.video and viory.video while from 2026 onwards, IP address 158.160.226.68 has been used by viory.video and ruptly.tv. The VirusTotal data appears to show these IP addresses being used exclusively by Ruptly and Viory as of 2025 and 2026. However, VirusTotal does not necessarily capture all domains which resolve to an IP, and other domains may also have resolved to these IP addresses, which were not observed by VirusTotal’s passive DNS replication service. It is also important to note that in some cases, unrelated domains use the same IP addresses.

Ruptly Sends Site Performance Data to Viory

Viory’s and Ruptly’s site infrastructure was also linked through data sent via Sentry, an internal error tracking and performance monitoring platform. 

An API scan of Ruptly’s main client login page, ruptly.agency, on March 26, 2026, shows that the page was sending data to a subdomain of viory.team. This domain appears to be used by Viory primarily for backend purposes, based on subdomains which appear to refer to common developer and site management tools such as Traefik and ArgoCD, in addition to Sentry.io. Notably, two subdomains also appear to refer to Ruptly. 

The purpose of one domain sending data to another domain’s Sentry project is generally to consolidate all of the relevant performance and error data in one place for in-house developers to monitor. 

The ruptly.agency page’s request to viory.team also includes an authentication key for Viory’s Sentry project. Ruptly.agency is not the only Ruptly domain sending Sentry data to viory.team. As of May 9, 2026 the login page for ruptly.video’s own Sentry project, sentry.ops.ruptly.video, automatically redirects to sentry.ops.ruptly.video/auth/login/viory/. Ruptly Video’s Sentry login page also features “Viory” as the title.

The ruptly.video Sentry login page is also sending data to the viory.team Sentry project, the ruptly.agency homepage and using a favicon hosted on viory.team.

A third Ruptly domain, ruptly.tv, also sends performance data to viory.team’s Sentry project via cms.dev.ruptly.tv. 

James Wilson noted that in each case, the Ruptly domains sending data to Viory appeared to be using a different Sentry key.

“If you look at each of these snippets sending telemetry data [from the Ruptly domains], the specific Sentry keys for sentry.ops.viory.team are different for each. I presume that someone with access to Viory’s Sentry keys has generated and included fresh Sentry keys in each of these instances in order to differentiate between the telemetry from this site versus others using the same Sentry instance,” Wilson said. 

“This cuts against the idea that this is, for example, a case of someone just lazily copy-pasting code on Ruptly’s domains. It suggests that each of these snippets was likely to have been deliberately included. The alternative explanation of changing these API keys to some arbitrary value seems much less plausible given the lack of diligence in ensuring other aspects of the content didn’t cross-reference the domains.”

‘Ruptly’ Page Title on Viory Test Page

Finally, Bellingcat found a page at frontend.dev.viory.video/en that appears likely to be a developer test page for the front page of Viory’s main domain viory.video.

Notably, however, the page title reads “Stream trending news | Ruptly.” The page description included in the source code also refers to Ruptly:  

“Follow breaking world news in real-time and stream the latest developments in politics, sports, finance, science, tech, and more from one of the top online news sites. Download and share international news today with award-winning news agency Ruptl” [sic].

Screenshot of frontend.dev.viory.video/en page, captured May 10th 2026. Archived source.

Wilson said that the use of the Ruply page title and text on the Viory test page “looks like a case of lazy copy and pasting”.

“That could potentially be done by someone outside of Ruptly, although it would be strange.”

While this particular piece lies on the lower end of the spectrum of proof, Wilson said that together with the other stronger pieces of evidence, including multiple Ruptly domains appearing to send data to Viory using different API keys, and Ruptly’s wildcard SSL certificate on Darpo Vision’s site, the weight of evidence for a connection between Ruptly and Viory adds up.

“None of the pieces of evidence are watertight on their own, but when you add them together it’s difficult to think of other plausible explanations for all of them being true at the same time,” he added.

“None of the pieces of evidence are watertight on their own, but when you add them together it’s difficult to think of other plausible explanations for all of them being true at the same time,”

-James Wilson

Bellingcat also found that Ruptly appears to have connections to a company in Hong Kong. Company records from July 2022 indicate that this company was originally named Ruptly Limited, but in September of that year, the company’s name was changed to Lotus Production Limited. 

The Hong Kong company remains registered as active and filed annual reports in September 2025.

Russian Slant in the ‘Global South’ 

Anna Hiller, a Bangkok-based Consultant Research Analyst for the Institute for Strategic Dialogue told Bellingcat that the resources provided by Viory can be an attractive pool of source material for smaller media outlets, governments and academic institutions with small budgets.

She told Bellingcat that Viory’s editorial choices are clear when looking at the site’s videos.

“When accessing Viory, the prominence of pro-Russian and pro-China content is immediately noticeable, including numerous articles focused on Vladimir Putin, Russia-China cooperation, and broader China-related narratives.”  

Bellingcat contacted Viory, Darpo Vision and Lotus Production Limited to ask about the connections we found between the Viory website and Ruptly and between Lotus Production Limited and Ruptly. 

Viory said that it had no connection with Ruptly. “Viory has no connection with Ruptly; any suggestion otherwise based on ordinary use of similar digital platforms, tools or cloud providers is poorly founded and inaccurate; Viory is a UAE-based, privately held, self-funded and 100% privately owned organisation, and receives no funding, direction or instructions from any state media,” the company said in an email response. 

Ruptly also said it was not connected to Viory. It declined to respond to Bellingcat’s questions, including about specific findings such as Ruptly’s domains sending technical performance and error data to Viory, calling these questions “irrelevant”.


Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Tracing Digital Links Between Viory and Ruptly appeared first on bellingcat.

Banned Russian Submunitions Found After Mali’s Military Announces Airstrikes

This investigation is a collaboration between Bellingcat and Jeune Afrique. You can read Jeune Afrique’s article in French here.

Unexploded Russian-made cluster munition bomblets, as well as damage consistent with bomblet impacts, have been found in a village in northern Mali – despite the West African country being a state party to the Convention on Cluster Munitions (CCM) which prohibits their use. 

The deployment of cluster munitions in northern Mali was first reported by Radio France International last week, citing local sources yet without showing images of the munitions or strikes in the reporting. However, social media footage posted on May 17, and since analysed by Bellingcat and our publishing partner, Jeune Afrique, shows unexploded Russian manufactured ShOAB-0.5 submunitions (bomblets).

Bellingcat geolocated a video showing the unexploded ShOAB-0.5 bomblets in the village of Tadjmart (18.977305, 0.86072), located approximately 55-kilometers (34-miles) south of the larger town of Aguelhok in northern Mali. This matches the location of airstrikes announced by the Malian Armed Forces (FAMa) on May 17. FAMa claimed it had identified armed groups in the area.

A map detailing where the Tadjmart strike, signified by the red flame, was recorded. Courtesy MapCreator.

Russia’s paramilitary Africa Corps group, which is controlled by the Russian government and which replaced the Wagner mercenary group in the country, has been supporting Malian military operations.

Mali’s civil war has been ongoing since 2012. But the conflict has spiked in recent weeks as Tuareg separatists from the Azawad Liberation Front (FLA) and militants from the al-Qaeda affiliated Jama’at Nusrat al-Islam wal-Muslimin (JNIM) seized control of parts of the country in coordinated attacks against Malian and Africa Corps forces.

Les mercenaires continuent de larguer des bombes sur des maisons et certains diront pourquoi se révolter contre ces genres des pratiques inhumaines ne respectant aucun Droit. https://t.co/5jynKwUgeW pic.twitter.com/nB3ym4yooc

— Mohamed Lilly (@MedLilly1) May 17, 2026

The footage geolocated by Bellingcat shows the unexploded submunitions near buildings, alongside multiple small craters, consistent with submunition explosions.

Left: Unexploded ShOAB-0.5 submunition found approximately 55 km south of Aguelhok. Right: ShOAB-0.5 Submunition. Sources: X and Armament Research Services.

The buildings and landmarks visible in the footage allowed us to geolocate where it was taken.

Geolocation of the video showing unexploded ShOAB-0.5 submunitions and the craters to the village of Tadjmart (18.977305, 0.86072). Sources: Airbus Imagery via Google Earth and X.

Additional footage geolocated by Bellingcat to nearby coordinates 18.97954, 0.85989 shows destroyed and burning buildings several hundred meters away, although this damage is not consistent with cluster munition use. The damage appears more significant than that which would be caused by submunition impacts.

Geolocation of the additional footage showing destruction several hundred meters away from where the submunitions were geolocated. Sources: Airbus Imagery via Google Earth and X.

Cluster munitions are explosive weapons which open mid-air to release large numbers of submunitions. They are prohibited from being used by signatories of the Convention on Cluster Munitions (CCM) because they are indiscriminate, saturate a wide area and can leave behind highly volatile unexploded bomblets which can kill civilians long after deployment. 

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

While Mali is a signatory to the CCM, Russia is not a state party to the agreement. 

Brian Finucane, a senior adviser with the US Program at the International Crisis Group, told Bellingcat that as a party to the CCM, Mali is “subject to its prohibitions and requirements. These include not only prohibitions on the use of cluster munitions, but also obligations to clear and destroy such munitions on its territory.”

ShOAB-0.5 submunitions are carried by the Russian RBK-500 cluster munition dispenser. A single RBK-500 dispenser can deploy about 565 ShOAB-0.5 submunitions. There is as yet no footage posted online showing a spent dispenser linked to this incident.Footage did circulate online on May 16 showing the remnants of an RBK-500. It was claimed to have been used in a separate cluster munition strike in the Timbuktu region of Mali. However, this footage was not geolocatable, given it only shows a close up of the dispenser at night, nor was it possible to tell when the footage was taken.

A second video appears to show the same dispenser, but shows the side with visible Russian markings denoting the model: “РБК-500; ШОАБ-0.5; ТГ-30”. This identifies the dispenser, RBK-500, the submunition inside, ShOAB-0.5, and the explosive filler, TG-30.

Left: Markings visible on RBK-500 ShOAB-0.5 dispenser reportedly found in Mali. Right: Reference image of RBK-500 ShOAB-0.5 cluster munitions loaded onto an aircraft. Sources: محمدن أيب أيب and Telegram.

RBK-500 dispensers are deployed by Russian-made aircraft including several MiG and Su models. According to the 2024 IISS Military Balance report, Mali does not have any known operational Russian fixed-wing attack aircraft. Two Russian Su-25 aircraft delivered to Mali – one in 2022 and another in 2023 – are reported to have crashed and been out of service since late 2023.

An Su-24M model has since appeared in satellite imagery captured at Modibo Keita International Airport in Bamako. The imagery was first published by France 24 in April 2025, although it was unclear if this aircraft was, or has been, operated by Africa Corps or Malian forces.

Bellingcat contacted the Malian military and Russian Ministry of Defence requesting comment, and asking which force was responsible for deploying cluster munitions. We did not receive a substantive response by publication time beyond the initial statement made by the FAMa which detailed it was responsible for the May 17 strike.

A video posted on May 17, by an account linked to Azawad rebels in Northern Mali, shows a person handling components of a ShOAB-0.5 submunition, seemingly unaware of the danger. However, as the video shows only a close up of the submunition, it has not been possible to geolocate the video or confirm when it was taken.

Les Azawadiens ne fabriquent pas les armes au contraire ils les démontent ! pic.twitter.com/0tqOb6ut9G

— Oumayya AG Ambeiry (@AgOumayya) May 17, 2026

The FLA condemned the use of cluster munitions in a statement published on May 18. 

Bellingcat has previously reported on the use of cluster munitions in Syria and Ukraine and the danger they pose to civilians.


Youri van der Weide contributed to this report.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Banned Russian Submunitions Found After Mali’s Military Announces Airstrikes appeared first on bellingcat.

Unearthing a Colombian Politician’s Connections to Neo-Nazi Active Club Group

This investigation is a collaboration between Bellingcat and Colombian media outlet Cerosetenta. You can read Cerosetenta’s piece in Spanish here.

A video posted on Feb. 26 shows several men painting over graffiti in Restrepo, a neighbourhood in Bogota, Colombia, and replacing them with images of their own: a logo used by Colombian political candidate and businessman Jorge Rodriguez, who is one of the men shown in the footage.

“Today we are defending public space to stop generating hatred in future generations!” said the caption posted on Instagram by Rodriguez, who unsuccessfully ran for office in the March 2026 congressional elections as part of Centro Democratico, the country’s largest right-wing party. 

But at least one of the graffiti-ed pieces they painted over carried a message critical of, rather than promoting, hate: “Creole Nazis will not pass” – using a term that refers to Nazi sympathisers in Latin America. 

A screenshot of Rodriguez’s Feb. 26, 2026 video showing men painting over graffiti with the words “Nazis Criollos no pasaran”, or “Creole Nazis will not pass”. Source: Instagram

And although the faces of most of the men shown in the video were pixelated, the tattoos visible on one of them have multiple similarities with a prominent member of neo-Nazi group Active Club Bogota – an individual known as Javier “Orlik” Ruiz, whom Rodriguez follows on Instagram and who “liked” the video.

In response to Bellingcat and Cerosetenta’s queries via Instagram, Rodriguez did not answer questions about his relationship with Active Club Bogota or the individual we identified as appearing in his videos, but said he was “not obligated to respond to any interview or request without a court order”. He also threatened legal action if we used his image or name in this investigation, saying that this would violate his rights to privacy, reputation and data protection, as well as the right to his own image. 

Take our survey

Help shape the future of our collective.

Similarly, Ruiz did not reply to questions that Bellingcat sent via email, including on his role in Active Club Bogota, but responded to our query by threatening legal action if we used his name, image or background information about him without his “prior, express and informed authorisation”. Ruiz said in his email that, among other things, processing his personal data without authorisation could be considered a violation of personal data under Colombian law.

After Bellingcat replied to both Rodriguez and Ruiz, noting that they did not answer our questions and inviting them again to do so, Ruiz responded with another legal threat referencing data laws – again without answering any questions related to this investigation. 

Bellingcat and Cerosetenta have consulted legal experts in both the Netherlands, where Bellingcat is headquartered, and in Colombia on the question of how privacy laws in both countries are balanced against the right to freedom of expression. In light of (amongst other factors) the public interest in this information and the fact that both Rodriguez and Ruiz qualify as “public figures” (persons who have, through their acts or their position, entered the public arena), the reporting in this article and the editorial choices made by Bellingcat are protected by the freedom of expression.

Both Rodriguez’s and Ruiz’s full responses are included at the end of this article.

Active Club Bogota is the local branch of the international Active Club movement. It hosted celebrations of Adolf Hitler’s birthday at a Bogota community centre in 2025 and 2026. At the 2025 event, the group hosted a Nazi-inspired book burning. This year, the group celebrated with Nazi swastika cupcakes, a swastika-emblazoned birthday cake and the screening of a 1940 Nazi propaganda film.

A still from an April 2025 video posted by Active Club Bogota, showing a Spanish translation of Jewish Holocaust victim Anne Frank’s diary, placed in a charcoal barbecue to be burned outside a Bogota community centre. A Spanish-language translation of a book of essays by physicist Albert Einstein, who was Jewish, was also burned.
An April 2026 photo posted on Active Club Bogota’s Telegram channel showing a portrait of Hitler and cupcakes decorated with swastikas.
A photo of an event held at the same community centre commemorating Hitler’s birthday in 2026, posted on Active Club Bogota’s public Telegram channel. Blurring in the original posted image.

Bellingcat and our Colombian partner Cerosetenta reached out multiple times via email and phone to the president of the relevant Community Action Board managing the community centre where these events were held, using contact information listed in a document by the local mayor’s office. As of publication, we have not received a response to our emails, and calls to the president of the community centre have gone unanswered.

Active Club Bogota, which has had an online presence since early 2024, appears to be the only officially recognised South American chapter of the neo-Nazi network started in the US by white supremacist Robert Rundo. The international movement, which Bellingcat has covered extensively, is known for using fitness, fighting and fashion to recruit young men and boys into the far right, normalise fascist ideas and prepare them for physical violence against perceived enemies. 

Active Club Bogota’s official Instagram account followed just over 60 accounts earlier this year. Rodriguez’s public Instagram account was, and continues to be, one of them. In March this year, Rodriguez also “liked” a March 2026 post from the group that featured a flag for a neo-Nazi movement. 

A March 15, 2026 Instagram post from Active Club Bogota, showing Jorge Rodriguez’s “like” on the post. Bellingcat has obscured account details in the photo.

While Rodriguez was unsuccessful in his bid for a seat in parliament, garnering just 4,401 votes, he presents himself as a prominent member of Centro Democratico and claims to have founded the party’s largest youth group. 

He has appeared in photos and events on his social media alongside notable figures from the party, such as former Vice Minister of Justice Rafael Nieto Loaiza, party director Gabriel Vallejo, presidential candidate Paloma Valencia and the party’s founder, Alvaro Uribe Velez.

Alexander Ritzmann, a senior advisor with the Counter-Extremism Project (CEP), told Bellingcat that an affiliation between Active Club Bogota and a political actor like Rodriguez should be taken seriously.

Heidi Beirich, co-founder of Global Project Against Hate and Extremism (GPAHE), said that any sort of legitimacy lent to an outwardly neo-Nazi group, like those that make up the Active Club movement, “sets a dangerous precedent”.

Bellingcat’s investigation into Active Club Bogota also suggests that the group has connections with the international far-right, with allies and “brothers” from Brazil to Spain, as well as apparent links with Combat 18, a violent neo-Nazi network accused of being an “international criminal organisation” and terrorist group. There is no evidence to suggest that Rodriguez has any connections to these other groups.

Centro Democratico was the biggest challenger to Colombian President Gustavo Petro’s left-wing coalition Pacto Historico in the March elections, securing 17 seats in the Senate, up from 13 in 2022, and a majority of 32 seats in the House of Representatives, double the 16 it won in the previous elections.

Subscribe to the Bellingcat newsletter

Subscribe to our newsletter for first access to our published content and events that our staff and contributors are involved with, including interviews and training workshops.

In response to Bellingcat’s queries, Centro Democratico National Director Gabriel Vallejo said the party was unaware of any proven links between Rodriguez and far-right, neo-Nazi, or extremist groups. 

Vallejo said that the Party’s candidates retain the right to exercise their freedom of expression and define their ideological affinities within the limits of the Constitution and the law. 

However, Vallejo said that Centro Democratico does not support or endorse any type of link with organisations or movements that incite hate speech, violence or the glorification of crime. 

“The Party maintains a firm stance in defence of the Constitution, the law, democratic institutions, and respect for human dignity, as well as in the protection of the public interest and fundamental rights,” he said. “In this regard, any conduct that contravenes these principles is contrary to the Party’s guidelines and will be subject to the corresponding actions in accordance with the Statutes and applicable regulations.”

Tattoo Identifications

In Rodriguez’s Feb. 26 video, the former political candidate can be clearly seen. However, several others had their identities obscured, with one particular individual being completely pixelated from head to toe in almost every frame he appeared in, even where only part of his arm was visible. 

Screenshots from the Feb. 26 video showing a heavily pixelated individual

But thanks to a few frames where parts of the individual’s arms or hands are briefly unpixelated, or where colouration shows through the pixelation, Bellingcat was able to match the person shown in the video to a prominent Active Club Bogota member and possible leader – an individual who goes by Javier or “Orlik” Ruiz – who Rodriguez follows on Instagram and vice versa. 

Between April and May 2024, the first few weeks after Active Club Bogota’s Telegram channel was set up, eight posts listed an author who went by “Orlik Ruiz”. 

Bellingcat searched online for social media accounts and information related to “Orlik Ruiz” and quickly found numerous public social media accounts that appear to belong to the same individual, with posts showing photos of his face and tattoos. Several of these accounts used the name Javier Ruiz. These accounts included a YouTube account featuring 2022 video clips showing Ruiz and other men at a shooting range, holding what appear to be automatic rifles.

Screenshots from Javier or “Orlik” Ruiz’s Telegram and social media accounts. Source: Telegram, Instagram, YouTube; redaction of handles by Bellingcat

In most of these social media accounts, Ruiz posted numerous photos exposing his face and, more frequently, his tattoos from multiple angles, allowing Bellingcat to confirm that the same individual appears in the vast majority of Active Club Bogota’s online content.

Active Club Bogota’s Telegram channel listed an account with the name “Javi” as the group’s main contact. There were more than 30 posts on this account’s own profile page, and though the face of the person shown in the photos posted from this account was obscured, the matching tattoos in many of these posts all pointed to the same person.

Left: A screenshot of an August 2025 video posted by Active Club Bogota showing Javier Ruiz, identifiable by his tattoos including a Nazi swastika flag tattoo and blue band on his left arm. Right: A cropped photo of Ruiz, the same blue band tattoo visible on his left arm, posted on one of his VKontakte accounts in 2020.

Ruiz’s tattoos had several distinctive features that appeared across multiple photos. The backs of both of his hands are tattooed up to the base knuckles. He also has an arrow tattoo on his left middle finger, pointing down towards the base knuckle, and a red design that circles his left wrist. 

These match several features of tattoos on the individual’s left hand that can be made out despite the pixelation, including what appears to be red colouration on the individual’s wrist, heavy dark hand tattooing, and also discolouration on the left middle finger, suggesting tattoos on that finger.

A pixelated left hand in the Feb. 26 video at 0:37, with colouration of tattoos showing through the pixelation. The brightness of the photo has been adjusted by Bellingcat
A cropped photo of Ruiz from his own Telegram account, showing red tattooing on his left wrist, similar heavy left hand tattoos and two dark left middle finger tattoos, like the individual in the Feb. 26 video

While blurred footage alone is not enough to confirm matching tattoos, several other significantly more detailed and clearer comparisons could be made. 

In one frame, a very similar arrow to that seen in photos of Ruiz appears on the left middle finger of the individual shown in the video.

Left: An arrow tattoo visible on Ruiz’s left middle finger in a photo from his Telegram account. Right: A similar-looking mark visible on the left middle finger of the pixelated individual in Rodriguez’s Feb. 26 video (at 0:43). Annotations by Bellingcat
The screengrab showing the mark on the pixelated individual’s left middle finger overlaid on the photo from Ruiz’s Telegram account in a GIF created and annotated by Bellingcat. The images have been rotated, and the lighting of the screengrab has been adjusted for clearer comparison. 

In addition, there are gaps in the tattoos and a rounded shape visible on his left arm that are consistent in position with photos of Ruiz’s tattoos.

A gap in the tattoos (red arrow) and rounded shape (blue arrow) visible on the unidentified man’s left arm in a screengrab of the Feb. 26 video at 0:19 (left), is consistent with images of Ruiz’s tattooed left arm posted on Telegram (centre and right).

There are also several frames in the video where the individual’s right hand is visible. These unpixelated, although still blurry, frames show the individual has heavy tattooing on their right hand that forms a curved shape between their knuckles. This is consistent with the shape of the tattoos on the right hand of Active Club Bogota’s Ruiz as seen in photos posted on the group’s Telegram channel and on social media.

Top left and right: Cropped frames from the Feb. 26 video (at 0:41) showing the individual’s right hand and heavy right-hand tattooing; brightness adjusted by Bellingcat. Bottom left and right: Cropped screenshots from a Jan. 2025 Active Club Bogota video (left) and a Dec. 2025 Instagram video by an Active Club Bogota member (right) showing Ruiz’s right hand and his hand tattoo

Another frame shows a small red tattoo visible on the middle-right finger as well as a detail between the index finger and right pinky. This matches with other, clearer images of Ruiz’s tattoos visible on his private Instagram.

Left: A screenshot of a photo from Ruiz’s private Instagram account. Right: a photo of the right hand from the Feb. 26 video (at 0:41). A small anchor tattoo below the knuckle and a detail in his hand tattoo can be seen in the same position.

Furthermore, in several frames of the video, the pixelated individual’s upper-right arm is visible, showing red colouration that is consistent in size and shape with images of Ruiz’s tattooed right arm.

A screenshot from the Feb. 26 video (at 0:44), showing red and black tattooing on the pixelated individual’s upper right arm. The brightness of the photo has been adjusted by Bellingcat
A cropped photo of Ruiz from his own Telegram account, showing very similar red and black tattooing on his upper right arm as the individual in the Feb. 26 video

Promoting Fascist Ideas in the Region

The first sign we could find online of Active Club Bogota’s appearance on the city’s neo-Nazi scene was in early 2024, when its official Telegram channel was created. 

The official Active Club website that Rundo, the American founder of the Active Club movement, has openly promoted in several podcasts features a map of “official” Active Clubs around the world. As of the time of publication, Active Club Bogota is the only one in South America on the map.

A screenshot of South America from a map on the official Active Club website, featuring the only “official” group on the continent, Active Club Bogota.

But social media posts from Active Club Bogota suggest that the Colombia-based group has been attempting to promote the development of other Active Clubs in Latin America, with mixed results.

In September 2025, Active Club Bogota promoted a new Active Club in Brazil, boasting that “our brothers … have also taken a big step forward.” 

A screenshot of a September 2025 post from Active Club Bogota

This Brazilian Active Club Telegram channel no longer exists as of February 2026. 

Also in September 2025, Active Club Bogota promoted the Telegram channel of a new Active Club in Argentina, which they referred to as “our Argentinian friends”. This Telegram channel, like the Brazilian Active Club Telegram channel, no longer exists as of February 2026.

In December 2025, Active Club Bogota promoted the Telegram channel of another new Active Club based in Mexico City, which the Colombian channel referred to as “our Mexican brothers, who are joining this great movement that seeks to reclaim our identity and heritage”.

Beirich, the co-founder of GPAHE, said that Active Clubs are a concerted effort to market the far right to a new generation of young people. 

“Active Clubs can and do serve as a bridge between older generations of neo-Nazis and the current wave of youth engaging with the movement,” she said.

“Groups like the one in Bogota are hyper-local enterprises that also connect its members to a transnational extremist network of other Active Clubs and white supremacist groups that share a similar worldview,” she added.

Ritzmann, from CEP, also said that the threat posed by the group should not only be measured by its size. “Even a small local chapter can function as a recruitment hub, a training environment, and a bridge into wider transnational extremist networks,” he said.

International Connections

Our identification of Ruiz also led to evidence of links between Active Club Bogota and international neo-Nazi networks Blood & Honour and Combat 18.

In a May 2024 photo posted on his public Telegram account, a man whose face is covered by a cloth mask and further obscured with a digital image was pictured standing next to two neo-Nazi musicians who were in Bogota to perform at a concert that Ruiz had promoted on his Telegram account. One of the musicians is British neo-Nazi Ken McLellan, who has long been associated with Blood & Honour. 

The tattoos on the lower left leg and right hand of the man whose face was obscured appear to be the same as Ruiz’s – matching the shape, colour and position – based on photos publicly posted on Active Club Bogota’s Telegram channel.

Ruiz, identifiable by his tattoos on his lower left leg and right hand (shown in photos in the “Tattoos Identification” section), posing with Michael Grosch, a member of a German neo-Nazi band (centre) and British neo-Nazi Ken McLellan (right)
Left: The lower leg tattoo of a man shown in Ruiz’s photo. Right: The same tattoo on Ruiz’s left leg, from public Telegram posts on Active Club Bogota’s Telegram channel.

Blood & Honour is an international neo-Nazi network founded in the United Kingdom in 1987; McLellan and his band were present at this founding meeting and still regularly perform at Blood & Honour-affiliated concerts. Blood & Honour’s affiliate group Combat 18, described as the “armed branch” of Blood & Honour, was founded in 1992. 

Members and associates of Blood & Honour and Combat 18 have been accused of crimes including possessing explosives and drug trafficking. Individuals associated with both groups have been convicted of crimes including attempted murder, murder and terrorism. Both groups have been designated terrorist organisations in Canada since 2019 and have been subject to financial counter-terrorism sanctions in the United Kingdom since January 2025. 

Screenshots from videos posted by Active Club Bogota in October 2024 (left) and January 2025 (right), both featuring a flag commonly associated with international neo-Nazi networks Blood & Honour and Combat 18. The individual speaking is wearing a t-shirt in support of Active Club founder Robert Rundo.
Above: A cropped version of a photo posted by Active Club Bogota in March 2026, showing Blood & Honour and Combat 18 insignia on a table of merchandise and literature. Below: A rotated close-up of the Blood & Honour/C18 merchandise.

A Colombia-based neo-Nazi fashion retailer that sells t-shirts with Combat 18 symbolism and branding also lists Ruiz as the main contact on its Telegram channel (Bellingcat is not naming the retailer to avoid amplification). 

On its WhatsApp Business account, this retailer advertises neo-Nazi clothing and paraphernalia, including content with Combat 18’s name, symbolism and branding, as well as content promoting bands with documented links to Combat 18. Active Club Bogota has also promoted this retailer on its own Telegram channel. After reaching out to Meta, the parent company of WhatsApp, a spokesperson told Bellingcat that “this account breaks our terms of service and we have banned it”. As of publication, the WhatsApp Business account has been blocked.

Screenshots of t-shirts sold by a Colombian-based retailer featuring Combat 18 content. This retailer lists Active Club Bogota’s Ruiz as its main contact and has been promoted on Active Club Bogota’s Telegram channel.

After a series of arrests of alleged members in Spain in October 2023, Spanish authorities publicly called Combat 18 an “international criminal organisation” and claimed the Spanish wing of the group has relations with Combat 18 members in South America. 

Spanish media outlet El Periodico further reported that this police operation against Combat 18 in October 2023, according to their sources, “was mounted to pursue organised crime and other related offences, including drug trafficking”. 

Bellingcat established another link between the two groups through another individual associated with Active Club Bogota. 

In a 2015 post on one of Ruiz’s public Facebook accounts, an individual (in red below) who at the time was a bassist with a neo-Nazi band that sang songs praising and promoting Combat 18, is visible with a black tattoo on his left bicep.

 A March 2015 photo from one of Ruiz’s Facebook accounts; the caption indicates that Ruiz was posing “with the members” (“con los socios”) of a Bogota neo-Nazi band.

Almost a decade later, in January 2025, Active Club Bogota posted a video that featured an individual with a tattoo that appeared to be in the same shape and placement.

Above: Zoomed-in view of the neo-Nazi bassist’s left arm from Ruiz’s 2015 photo. Below: The tattoo of an individual shown in a January 2025 Active Club Bogota video practising jiu-jitsu (screengrab rotated for comparison).

The bassist’s name was mentioned in two posts by Juan de Dios Osuna Montanez, the alleged leader of Combat 18 in Spain, on Instagram in May 2024. 

Both posts featured a photo of what Montanez described as “little gifts directly from Colombia,” with Montanez thanking an account under this individual’s name, calling him his “brother.” These posts occurred during the same time period during which Active Club Bogota posted content from Catalonia, in northeastern Spain.

The photos Montanez posted of the apparent gifts are nearly identical, with the only difference being that the second photo is more zoomed in than the first. The photo shows a sticker with Active Club Bogota’s logo and branding, a t-shirt reading “Blood & Honour Colombia Division,” a sticker featuring both Blood & Honour and Combat 18’s logo, as well as packages of candy and coffee that Bellingcat was able to identify as being from small Colombian brands. 

“Little gifts directly from Colombia. Thanks brother and family.” The Instagram account belonging to the individual tagged in the post has since become inaccessible.

Montanez did not respond to Bellingcat’s request for comment via Instagram and Facebook, but we were blocked by his Instagram account after we reached out. We were unable to find any other public contact information for Montanez.

Ritzmann of CEP said that Active Club Bogota’s repeated display of the Combat 18 flag on its Telegram channel signals identification with one of the most explicitly militant neo-Nazi traditions in Europe.

He added that while some Active Clubs avoid overtly antisemitic references to avoid scrutiny by law enforcement, reduce negative media attention and attract new recruits without frightening them away, Active Club Bogota “appears to sit at the more explicit edge of the Active Club strategy” with its open celebration of Hitler’s birthday and its antisemitic messaging. 

“The network wants to appear harmless enough to avoid scrutiny, but radical enough to attract militants. Active Club Bogota is an example of how that balance can shift toward overt neo-Nazi mobilisation while still remaining inside the wider transnational Active Club ecosystem,” he said.

Full Response from Jorge Rodriguez to Bellingcat’s Queries

[April 24, 2026]

Translated to English
“In response to your questions, I would like to inform you that I am not obligated to respond to any interview or request without a court order. Therefore, I will not respond to any interviews. Furthermore, should you decide to use my name or image, I wish to state that I DO NOT AUTHORISE THE USE OF MY NAME, SOCIAL MEDIA ACCOUNTS OR ANY RELATED CONTENT.

Likewise, if you use my image or name, it constitutes a violation of my fundamental rights to privacy, reputation, habeas data, and the right to my own image, the latter of which has been repeatedly recognised and protected by the jurisprudence of the Constitutional Court.

The unauthorised use of my image or name may constitute a punishable offence, and I will be authorised to initiate the corresponding legal actions to restore my rights.

Sincerely,

Jorge Rodríguez”

In Spanish (Original)

“De conformidad con sus preguntas, me permito indicarle que no estoy obligado a responder ninguna entrevista o requerimiento sin que medie orden judicial. Por lo anterior, no responderé ninguna entrevista, asimismo, en caso de que ustedes decidan utilizar mi nombre o imagen me permito indicar que NO AUTORIZO LA UTILIZACIÓN DE MI NOMBRE O IMAGEN, REDES SOCIALES Y DEMÁS.

De igual manera, si ustedes utilizan mi imagen o nombre es una transgresión de mis derechos fundamentales a la intimidad, al buen nombre, al habeas data y al derecho a la propia imagen, este último reconocido y protegido de manera reiterada por la jurisprudencia de la Corte Constitucional.

Incluso la utilización de imagen o nombre sin autorización puede constituir una conducta punible y estaré autorizado de iniciar las acciones legales correspondientes en aras del restablecimiento de mis derechos.

Cordialmente,

Jorge Rodríguez”

First Response from Javier Ruiz to Bellingcat’s Queries

[April 21, 2026]

Translated to English
“As the data subject of the aforementioned personal data, I hereby submit this formal request regarding the use of my name, image, and background information in an interview request, without my prior, express, and informed consent.

The described conduct constitutes a potential violation of my fundamental rights to privacy, reputation, habeas data, and the right to my own image, the latter repeatedly recognised and protected by the jurisprudence of the Constitutional Court.

Likewise, the processing of my personal data without authorisation contravenes the provisions of Law 1581 of 2012 and its implementing decrees and could constitute the offence of personal data violation under Article 269F of the Colombian Penal Code.

Therefore, through this document, I expressly and immediately request:

– The suspension of any use, processing, circulation, or dissemination of my name, image, and other personal data.

– The permanent deletion of any content, file, record or publication in which my personal information has been used without my authorisation.

– A precise indication of the origin of the information, the purposes of its processing, and the third parties with whom it has been shared.

For the purposes of the foregoing, I grant a maximum period of forty-eight (48) hours from the receipt of this communication to demonstrate compliance with the requirement.

In case of non-compliance, I will be obligated to initiate the corresponding legal actions, including filing a writ of protection for the violation of my fundamental rights, as well as administrative proceedings before the Superintendency of Industry and Commerce and any applicable criminal actions.

This communication is understood as a formal prior request.

Sincerely,

J.R.”

In Spanish (Original)

“En mi calidad de titular de los datos personales referidos, me permito formular el presente requerimiento formal en relación con el uso de mi nombre, imagen y antecedentes dentro de una solicitud de entrevista, sin que medie autorización previa, expresa e informada de mi parte.

La conducta descrita constituye una posible vulneración de mis derechos fundamentales a la intimidad, al buen nombre, al habeas data y al derecho a la propia imagen, este último reconocido y protegido de manera reiterada por la jurisprudencia de la Corte Constitucional.

De igual forma, el tratamiento de mis datos personales sin autorización contraviene lo dispuesto en la Ley 1581 de 2012 y sus decretos reglamentarios, y podría adecuarse a la conducta tipificada como violación de datos personales conforme al artículo 269F del Código Penal Colombiano.

En virtud de lo anterior, por medio del presente escrito requiero de manera expresa e inmediata:

– La suspensión de cualquier uso, tratamiento, circulación o difusión de mi nombre, imagen y demás datos personales.

– La eliminación definitiva de cualquier contenido, archivo, registro o publicación en la que se haya hecho uso de los mismos sin mi autorización.

– La indicación precisa del origen de la información, las finalidades del tratamiento y los terceros con quienes haya sido compartida.

Para efectos de lo anterior, otorgo un plazo máximo de cuarenta y ocho (48) horas contadas a partir de la recepción de la presente comunicación, a fin de que se acredite el cumplimiento de lo requerido.

En caso de incumplimiento, me veré en la obligación de iniciar las acciones legales correspondientes, incluyendo la interposición de acción de tutela por la vulneración de mis derechos fundamentales, así como las actuaciones administrativas ante la Superintendencia de Industria y Comercio y las acciones penales a que haya lugar.La presente comunicación se entiende como requerimiento previo formal.

Cordialmente,

J.R.”

Second Response from Javier Ruiz to Bellingcat’s Queries

[May 7, 2026]

In English

“SUBJECT: FORMAL REQUEST FOR CESSATION AND WITHDRAWAL – NOTIFICATION OF VIOLATION OF FUNDAMENTAL RIGHTS AND DATA PROTECTION REGIME (LAW 1581 OF 2012)

In my capacity as a fully identified [Colombian] citizen and exercising my legal rights as the owner of personal data, I hereby submit this prior and peremptory request based on the following factual and legal grounds:

1. Lack of Consent and Legal Basis:

The unauthorised use of my name, image, and biographical information has been established within the framework of your informational activities. I declare that there has been no prior, express, informed, or qualified authorisation for the processing of said data, contravening the principle of legality and purpose established in Article 4 of Law 1581 of 2012.

2. Autonomy of the Right to One’s Own Image (Judgment T-040 of 2013): I hereby notify you that, in accordance with the jurisprudence of the Constitutional Court in its Judgment T-040 of 2013, the right to one’s own image is an autonomous and independent right. Therefore, the capture, use, or dissemination of my image and name requires my express consent, and journalistic practice does not grant an open licence for its exploitation without prior authorisation, especially when there is no public interest that proportionally justifies it.

3. Violation of Fundamental Rights:

Your actions constitute an arbitrary interference that affects my right to Habeas Data, my right to a good name (Art. 15 of the Colombian Penal Code), and, specifically, my right to my own image. According to the jurisprudence of the Honourable Constitutional Court, the use of a person’s image without their consent constitutes an overreach of journalistic practice that is not protected by freedom of information when it affects the private sphere.

4. Criminal and Administrative Liability: I hereby warn you that the processing of personal data without proper authorisation could constitute the conduct defined in Article 269F of the Colombian Penal Code (Violation of Personal Data), in addition to the fines imposed by the Superintendency of Industry and Commerce (SIC) for non-compliance with data protection regulations. 

LEGAL CLAIMS:

• IMMEDIATE CESSATION: The suspension of any act of processing, restricted circulation, or dissemination of my identity, image, or sensitive data.

• PERMANENT DELETION: The removal of any record from your databases or digital platforms containing information whose collection has not been authorised.

• TRACEABILITY REPORT: Submission of certification detailing the origin of my data and the identification of third parties to whom it has been transferred or transmitted.

TERM AND WARNING: You have a non-extendable term of forty-eight (48) hours to demonstrate compliance with the requests made herein. Silence or a negative response will authorise the initiation of a tutela action for the immediate protection of my fundamental rights, as well as the corresponding Administrative Complaint before the Office of the Superintendent Delegate for the Protection of Personal Data of the Superintendency of Industry and Commerce (SIC) and criminal proceedings before the Office of the Attorney General of Colombia.

1) Freedom of expression cannot infringe upon the right to privacy and honour.

2) The right to receive information, or rather, to inform, cannot supersede the duty not to disseminate defamatory information about a person or organisation.

3) A request for information from an independent, foreign media outlet cannot be based on erroneous presumptions regarding rulings, orders, and precedents pertaining to the Colombian judicial system. I thank you in advance for your attention, but I wish to clarify that I do not desire any response, understanding that you are complying with the order I have given and established.”

In Spanish (Original)

“ASUNTO: REQUERIMIENTO FORMAL DE CESE Y DESISTIMIENTO – NOTIFICACIÓN DE VULNERACIÓN DE DERECHOS FUNDAMENTALES Y RÉGIMEN DE PROTECCIÓN DE DATOS (LEY 1581 DE 2012)

En mi condición de ciudadano(a) plenamente identificado(a) y en ejercicio de mis facultades legales como titular de datos personales, presento ante ustedes este requerimiento previo y perentorio con base en los siguientes fundamentos de hecho y de derecho:

1. Ausencia de Consentimiento y Base Legal:

Se ha evidenciado el uso no autorizado de mi nombre, imagen y antecedentes biográficos en el marco de su actividad informativa. Manifiesto que no ha mediado autorización previa, expresa, informada ni calificada para el tratamiento de dichos datos, contraviniendo el principio de legalidad y finalidad establecido en el Artículo 4 de la Ley 1581 de 2012.

2. Autonomía del Derecho a la Propia Imagen (Sentencia T-040 de 2013):

Les notifico que, conforme a la jurisprudencia de la Corte Constitucional en su Sentencia T-040 de 2013, el derecho a la propia imagen es un derecho autónomo e independiente. Por tanto, la captura, uso o difusión de mi imagen y nombre requiere de mi consentimiento expreso, sin que el ejercicio periodístico otorgue una licencia abierta para su explotación sin autorización previa, especialmente cuando no existe un interés público que lo justifique de manera proporcional.

3. Vulneración de Derechos de Carácter Fundamental:

Su actuación constituye una injerencia arbitraria que afecta mi derecho al Habeas Data, al Buen Nombre (Art. 15 C.P.) y, de manera específica, al Derecho a la Propia Imagen. Según la jurisprudencia de la Honorable Corte Constitucional, el uso de la imagen de una persona sin su anuencia es una extralimitación del ejercicio periodístico que no encuentra amparo en la libertad de información cuando se afecta la esfera privada.

4. Responsabilidad Penal y Administrativa:

Les advierto que el tratamiento de datos personales sin la debida autorización podría configurar la conducta tipificada en el Artículo 269F del Código Penal Colombiano (Violación de datos personales), además de las sanciones pecuniarias que la Superintendencia de Industria y Comercio (SIC) impone por el incumplimiento del régimen de protección de datos.

PRETENSIONES LEGALES:

• CESE INMEDIATO: La suspensión de cualquier acto de tratamiento, circulación restringida o difusión de mi identidad, imagen o datos sensibles.

• SUPRESIÓN DEFINITIVA: La eliminación de cualquier registro en sus bases de datos o plataformas digitales que contenga información cuya recolección no haya sido autorizada.

• INFORME DE TRAZABILIDAD: Remitir certificación detallando el origen de mis datos y la identificación de terceros a quienes les hayan sido transferidos o transmitidos.

TÉRMINO Y ADVERTENCIA:

Cuentan con un término improrrogable de cuarenta y ocho (48) horas para acreditar el cumplimiento de lo aquí solicitado. El silencio o la respuesta negativa facultará el inicio de la Acción de Tutela para la protección inmediata de mis derechos fundamentales, así como la respectiva Denuncia Administrativa ante la Delegatura para la Protección de Datos Personales de la SIC y las acciones penales ante la Fiscalía General de la Nación.

1) La libertad de expresión no puede coartar el derecho a la privacidad y a la honra. 

2)El derecho a recibir información o más bien; a informar no puede supeditar el deber de no difundir información calumniosa sobre una persona u organización 

3) Un requerimiento de información por un medio independiente y extranjero no puede basarse en presunciones erróneas sobre sentencias, órdenes y antecedentes correspondientes al sistema judicial colombiano

De ante mano agradezco la atención prestada, sin antes aclarar que no deseo respuesta alguna, teniendo claro que acatan la orden dada y establecida de mi parte.”


Carlos Gonzales and Pooja Chaudhuri contributed research to this piece.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Unearthing a Colombian Politician’s Connections to Neo-Nazi Active Club Group appeared first on bellingcat.

Mining China’s ‘Little Red Book’ for Open Source Gold

The challenges of conducting open-source research in China are well-documented. Consistently named one of the most digitally oppressive countries in the world, China blocks some of the world’s largest social media platforms, such as Facebook, Google, and YouTube. Those that are still accessible are mostly Chinese-owned, strictly regulated and monitored in real time by AI systems as well as tens of thousands of “internet police”

But despite these strict controls, Chinese apps – which boast more than a billion estimated users – remain an information goldmine for investigative journalists covering stories both within and outside China.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Since most foreign sites are banned, Chinese platforms are the largest resource available to journalists and researchers interested in what’s going on in the world’s second-most populous country. Even when a topic is being censored, patterns in the censorship can themselves serve as investigative leads: a 2020 BuzzFeed News investigation, for example, mapped out detention camps in Xinjiang by examining areas that had been blanked out on China’s Baidu Maps.

With millions of Chinese people living overseas, social media activity by members of the diaspora can also turn into global stories.

Serial rapist Zou Zhenhao, a Chinese PhD student, was jailed in London last year after one of his victims posted a warning on Xiaohongshu, also known as Little Red Book or Rednote, an app popular with young Chinese women living abroad. Another woman Zou had raped reached out to the original poster, who put her in touch with the police – leading to the conviction of a man described by police as possibly one of the worst sexual predators in British history.

Founded in 2013 as a Hong Kong shopping guide, Xiaohongshu has evolved into a lifestyle and e-commerce platform that has been compared with Instagram, Pinterest and Amazon. Last year, it reported about 300 million monthly active users, rivalling some of China’s largest social media platforms.

Xiaohongshu saw a surge in international users in January 2025 amid a threatened ban on short video app TikTok. Photo: VCG via Reuters Connect

The app’s 600 million daily searches by the end of 2024 also accounted for half of market leader Baidu’s search volume, demonstrating that it is emerging as a critical search and discovery engine, not just a social platform.

Although primarily a Chinese-language app, Xiaohongshu gained attention in the English-speaking world last year, when millions of American TikTok users flocked to the platform in anticipation of a TikTok ban under US President Donald Trump. 

Responding to the surge of international users – sparked by the #TikTokRefugees trend – Xiaohongshu rolled out an AI-powered translation feature, making the app more accessible to non-Chinese audiences. This also meant that journalists without Chinese language skills can more easily communicate on and navigate the platform.

Despite its growing popularity both within and outside China, the app is relatively new and underexplored compared to more well-established platforms such as Weibo. 

This guide aims to provide a starting point for those looking to explore Xiaohongshu for open-source investigations, including an overview of its main user demographics, potential topics to explore and strategic search methods specific to the app. 

User Demographics and Topics

According to Xiaohongshu’s official data, the platform’s demographic profile is mainly young, female and urban. As of 2024, 70 percent of its users were women, with half of all users belonging to Gen Z and living in China’s largest cities. 

As previously mentioned, the app has also gained popularity with the Chinese diaspora. Many Chinese nationals living abroad use it as a search engine for local information, posting and searching for content related to their daily lives, from restaurant recommendations and apartment hunting to navigating foreign bureaucracies and finding community resources. 

This demographic profile makes Xiaohongshu particularly well-suited for investigating stories about consumer fraud and urban livability issues. For example, Chinese outlets like Jiemian have used Xiaohongshu posts to expose the grey-market ecosystem of paid reviews and fake endorsements tied to the platform’s e-commerce model, while in 2022, International Financial News traced a mother-and-baby store scam that defrauded over 400 parents back to product recommendation posts on the platform.

Given its predominantly female user base, Xiaohongshu has also evolved into one of China’s most important spaces for feminist discourse and women’s issues. Academic researchers have used content on the platform to analyse local discussions on menstrual shaming, sexual harassment, and the controversial “divorce cooling-off period” introduced in 2021. As Rest of World reported, women have increasingly congregated on Xiaohongshu, where they outnumber male users and have found ways to trick the app’s recommendation algorithm so their posts are shown mostly to other women.

The Relevance of Censorship

Political content and current affairs about China are largely absent from the app – a result of both active censorship and platform design. 

All Chinese social media platforms, including Xiaohongshu, operate under strict content moderation requirements from the Cyberspace Administration of China. A leaked 143-page internal document published by China Digital Times in 2022 revealed how Xiaohongshu censors respond to government directives in “real-time”, blocking content related to politically sensitive topics such as criticism of the Chinese Communist Party, labour strikes and student suicides. Xiaohongshu’s commercial focus also makes it less likely that these topics would be discussed on the platform: as Rest of World reported, the platform functions less like Weibo – a public square for current events – and more like “a giant mall, where shoppers tell each other what to buy”.

Related articles by Bellingcat

The Challenges of Conducting Open Source Research on China
Resources

The Challenges of Conducting Open Source Research on China

Coverage of international affairs is also tightly controlled: only state-owned or state-controlled news organisations can obtain licences to publish original news content. However, content about life abroad, particularly stories about the cost of living, healthcare, or social problems in Western countries, circulates more freely on platforms including Xiaohongshu, and provide journalists with insight into how Chinese diaspora communities engage with local political systems. 

For example, when the 2025 Miss Finland was accused of making anti-Asian gestures, searching for “芬兰小姐” (Miss Finland) and “投诉” (complaint) on Xiaohongshu revealed a trove of collective action: users shared different complaint pathways, posted templates for filing reports, and documented various outcomes from their complaints. 

For such large-scale public events, Xiaohongshu can be both an organising platform and a rich source for tracking how diaspora communities coordinate responses to discrimination, providing journalists with insight into grassroots activism and transnational advocacy networks.

Getting Started

Xiaohongshu is available for download on both Apple’s App Store and Google Play worldwide, or can be accessed via a web browser. In international app stores, the app appears under the name “RedNote,” but this is the same application as Xiaohongshu – content and accounts are shared across both. The key difference is that RedNote users who register with overseas phone numbers are automatically tagged as international users, which affects the content the algorithm surfaces to them.

For users who download the app outside mainland China, Xiaohongshu automatically detects the device language and location. Upon first login, international users are prompted with an option to automatically translate all content into English (or their device language). If enabled, posts and comments will display with translations by default, and the algorithm will prioritise English-language content and posts created by or for international users, such as expat influencers.

For researchers and journalists seeking to observe the platform as Chinese users experience it, consider disabling automatic translation. This allows you to see content as it natively appears and helps you distinguish between posts created for international audiences versus those created for domestic users – a distinction that matters when assessing how representative your sample is for the relevant topic.

The default home feed, or the “Explore” tab, is where the algorithm surfaces content based on your engagement history, location and user profile. The feed uses a grid layout displaying post thumbnails with titles and like counts.

On the top right corner of the screen, the search bar also allows keyword searches across posts, users and topics. Results can be filtered by content type (e.g. notes, videos, users or products) and sorted by relevance or recency.

The search bar on the top right and the Explore page are some of the most relevant features for journalists and researchers on Xiaohongshu. Source: Xiaohongshu

Using the Search Bar

Xiaohongshu’s search function is relatively basic. You can search by keywords and filter by time and location, but the options are general: time filters include “past day,” “past week,” or “past six months,” while location filters offer “same city” or “nearby”. 

For example, searching “Canada” returns posts tagged with that keyword, which you can then sort by recency or proximity. 

Search results for “Canada” in English (left) show mainly travel and tourism-related content, while a search in Chinese (right) shows more content posted in Chinese by Chinese people about living in Canada. Source: Xiaohongshu

For breaking news events, try searching location names or names of individuals involved in the incident, filtering for the most recent posts to capture real-time reactions and on-the-ground accounts before they’re censored or deleted.

Xiaohongshu primarily uses algorithms to curate and push content through personalised feeds. For journalists using Xiaohongshu for investigative purposes, it can be useful to actively search for topics of interest to train your algorithm – the more you search and engage with specific content, the more relevant posts the algorithm will surface to you.

However, if you are researching the platform itself – studying what content Xiaohongshu promotes, how censorship operates, or what narratives dominate – you may want to start from a clean slate. In that case, consider periodically turning off personalised recommendations (Settings → Privacy Settings → Personalisation Options), clearing your browsing history, clearing cached data, or using a fresh account to observe what the platform shows to a “neutral” user.

Language and Lingo

During the influx of “TikTok refugees” in January 2025, Xiaohongshu launched a translation feature for users outside mainland China, enabling the automatic translation of comments and posts. 

However, this does not translate search queries. The platform’s search engine is still optimised for Chinese, though there is a “prioritise English” filter for overseas users, and searching in English will return some results.

Searching for “Canada” in English, with “EN preferred” selected, will mainly return posts in English. Source: Xiaohongshu

But the language you search in shapes far more than just your results – it determines which version of the platform you see. When you search in English or use an international account, the algorithm treats you as a foreign user and surfaces content accordingly: influencers explaining why they love living in China, comparisons showing Chinese life favourably against the West. 

This isn’t a neutral cross-section of the platform – it is a curated bubble. To access what Chinese users actually discuss among themselves, it would be more effective to search in simplified Chinese and, ideally, use a China-registered account if you have access to one. If you don’t read Chinese, you can also consider using a translation tool (Google Translate, DeepL, or an AI assistant) to convert your search terms into simplified Chinese before entering them.

Despite such tools and the in-app translation feature, it is always useful when researching using Chinese platforms to work with a native speaker familiar with the local context. They can flag when an innocuous-seeming term actually carries hidden meaning, and help identify coded conversations about a censored topic.

On Xiaohongshu specifically, this coded language extends beyond political topics to include anything the platform’s algorithm might flag as “vulgar” or promotional. For example, users substitute fruits and neutral terms for body parts or sexual content to avoid being flagged as inappropriate – the peach emoji for buttocks, or 炒菜 (“cooking”) for explicit material. They may also use abbreviations and emojis for commercial terms to evade anti-marketing filters, such as “vx” (the abbreviation of how WeChat is pronounced in Chinese) or “➕绿” (“plus green”, apparently referring to WeChat’s green logo) for WeChat, or “米” (rice) or the moneybag emoji for money.

Advanced Search Strategies

For more sophisticated searching, consider using third-party marketing analytics tools like Xinhong and Qiangu, which can show trending topics, popular posts and engagement metrics, as well as identify key content creators posting about specific subjects. 

For example, on Xinhong, when you search for “Canada” in Chinese, it also shows show trending related searches such as “加拿大总理” (Canadian Prime Minister). Clicking through these suggestions leads to recent posts—for example, posts about Mark Carney’s latest statements at Davos, along with user comments and reactions.

A search on the Xinhong platform for “Canada” in Chinese also suggests related trending topics (in green box) such as “in Canada”, “living in Canada” and “Canadian Prime Minister”. Source: Xinhong, annotation by Bellingcat

While these tools are designed for marketers, they provide journalists with valuable capabilities: tracking how topics evolve, identifying influential voices in specific communities, and discovering related hashtags or discussions that might not surface through basic platform search. These tools often require paid subscriptions but can significantly enhance research efficiency for long-term investigations.

Another valuable feature is Xiaohongshu’s group chat function, where users gather around shared keywords and topics—from city-specific communities to niche interests. These groups are often highly active and provide access to candid community discussions that don’t appear in public posts. To find relevant groups, go to MessagesGroup Square, where you can browse categories or search by keyword and request to join.

Monitoring active group chats related to relevant topics, whether that’s a specific city, industry, or issue, can help journalists and researchers stay updated on emerging issues and detect potential story leads before they become widely visible on public feeds.

Preserving the Evidence

Chinese social media content can disappear quickly and without warning due to censorship, making immediate preservation critical. 

Always take two preservation steps immediately upon discovering relevant content:

First, screenshot the entire post, including the URL, timestamp, username, like/comment counts, and location tags. These metrics establish context and authenticity. Use tools that capture full-page screenshots rather than just visible portions, as posts can be long and comments extensive. Second, archive the web page using services like archive.today or Wayback Machine. Note that these services capture only static content – comments and engagement metrics may not be fully preserved and should be screenshotted separately.

For Xiaohongshu specifically, always preserve the user’s unique ID found in their profile URL when viewed on a browser, which follows the format “user/profile/[unique ID]”. Users can change their display names, but this unique identifier remains constant, allowing you to track accounts over time even after name changes. This is critical for long-term investigations or when monitoring specific sources.

The unique ID of a user can be found in the profile URL on a browser. Source: Xiaohongshu

Xiaohongshu operates under the same legal and censorship constraints as all Chinese social media platforms, and researchers should approach it with appropriate caution. Content moderation is extensive: users who post about sensitive subjects risk having their content removed or their accounts suspended, and the platform is required to comply with government data requests. For researchers, this means the information you find represents only what has survived the censorship process.

That said, Xiaohongshu remains a remarkably rich resource for open-source research. Its strength lies precisely in its apolitical, lifestyle-oriented identity: while political discussion is suppressed, candid conversations about everyday life flourish. For journalists willing to invest in learning the platform’s rhythms, building Chinese-language search skills, and understanding its coded vocabularies, Xiaohongshu offers a window into how ordinary Chinese people talk among themselves – an area that remains largely untapped by international media.


Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Mining China’s ‘Little Red Book’ for Open Source Gold appeared first on bellingcat.

Painkiller Pipeline: 300 Million Tapentadol Pills Sent from India to West Africa

This article is the result of a collaboration with Indian media outlet Newslaundry. You can find Newslaundry’s editorially independent coverage here.

Collage illustration by Klawe Rzeczy. Elements from Unsplash.

Indian companies have shipped more than 320 million synthetic opioid pills to West Africa – where they have not been approved by regulators – over the past three years, a Bellingcat investigation has found.

Export records from trade data provider 52wmb show that more than 1,400 consignments of tapentadol worth almost USD $130 million were sent from India to West Africa between January 2023 and December 2025.

Tapentadol, a painkiller two to three times more potent than tramadol, has not been approved for use in most West African countries, where some nations are grappling with an escalating opioid abuse epidemic.

However, this investigation shows that dozens of Indian suppliers have flooded the region with tapentadol over the past three years. Where dosages were listed, more than half the pills were in powerful strengths of 200mg or more – dosages that are not even approved in India.

The exports, cross-checked against records provided by trade data aggregator ImportGenius, show most tapentadol pills sent between 2023 and 2025 had the coastal nations of Sierra Leone and Ghana listed as their declared destinations.

The two West African countries were collectively marked as the destination for more than 80 per cent of the total value of tapentadol sent to the region.

Tapentadol exports from India to West Africa (Choropleth map)

Experts have documented how drug traffickers adapt quickly to international regulations and law enforcement efforts. In 2018, India tightened export controls around the opioid tramadol, one of the most trafficked synthetic drugs to West Africa.

In 2021, the International Narcotics Control Board (INCB) said large-scale tapentadol trafficking had been identified, particularly in consignments destined for Africa. It had previously noted that India’s strengthened tramadol controls could lead traffickers to substitute the drug with other potent synthetic opioids.

A BBC investigation last year revealed that Indian company Aveo Pharmaceuticals was illegally exporting tablets containing a mix of tapentadol and the muscle relaxant carisoprodol to West Africa. This led India’s drug regulator, the Central Drugs Standard Control Organisation (CDSCO), to ban the manufacture and export of all combinations of the two drugs.

Bellingcat’s investigation, in collaboration with Indian publishing partner Newslaundry, reveals that the supply of tapentadol pills from India to West Africa has surged in recent years.

Export data from 52wmb shows the value of tapentadol sent to the region has risen from about USD $27 million in the three year period from 2020 to 2022, to almost USD $130 million from 2023 to 2025.

Julius Maada Bio, Sierra Leone’s president, in 2024 declared a national emergency over rampant drug abuse and branded kush – a toxic blend of psychoactive substances including cannabis and synthetic opioids – a “death trap”.

Authorities in Sierra Leone have intercepted illegal tapentadol, including last July when the National Revenue Authority (NRA) said it thwarted a smuggling operation near its north-west border with Guinea.

The NRA and other agencies including the Transnational Organised Crime Unit, National Drug Law Enforcement Agency, and the Pharmacy Board of Sierra Leone did not respond to Bellingcat’s requests for comment.

Sierra Leone’s NRA said customs officers seized tapentadol near a border crossing in July. Source: National Revenue Authority

Ghana’s Narcotics Control Commission (NACOC) said the illegal importation of tapentadol was first recorded in 2022 after international efforts to curb the tramadol crisis resulted in criminal networks shifting production to other pharmaceutical opioids including tapentadol, tafrodol and carisoprodol.

The agency has recorded a “steady rise” in tapentadol trafficking over the past three years, with authorities seizing more than 3.7 million tablets (250mg strength). Most were traced back to India, it said.

“NACOC investigations confirm that the bulk of tapentadol is trafficked into Ghana through seaports and by air, via express courier services,” a spokesperson said. “At the ports, the drug is concealed in containerized cargo falsely declared as pharmaceuticals, electrical materials or household goods. Express courier services are used for smaller, high-value quantities, often packed alongside legitimate consignments to avoid detection.”

NACOC said Ghana had emerged as both a destination and transit hub for tapentadol, with the majority of intercepted consignments bound for Niger, Mali, Burkina Faso and Nigeria. When sold domestically, it said the street drug was promoted as a tramadol substitute.

Ghana’s Food and Drugs Authority (FDA) said last year that the abuse of pharmaceutical opioids such as tapentadol — commonly known on the street as “Red” — was on the rise.

The FDA told Bellingcat it had “never issued any permit” for the manufacture or importation of tapentadol, in any strength, to any importer or to any country. It said any tapentadol shipments to Ghana were for “trans-shipment to neighbouring country”.

Import data for Ghana shows that no tapentadol entered the country between 2023 and 2025, which supports NACOC’s position that the drugs are being concealed and falsely declared. Import data for Sierra Leone was not available through 52wmb.

Ghana’s FDA destroyed 230 cartons of the illegally imported tapentadol last April and seized 7,700 tapentadol tablets at a border crossing last August. NACOC said it was combatting opioid importation through regulation, enforcement and cooperation with its counterparts in other countries. Source: FDA

India’s drug and pharmaceutical exports have grown to more than $30 billion a year, according to the Pharmaceuticals Export Promotion Council of India (Pharmexcil), a division of the ministry of commerce and industry.

While tapentadol is available in India on prescription in strengths of up to 100mg (immediate release) and 200mg (extended release), authorities are aware of its risk of misuse. Last year, the Indian drug regulator’s Technical Advisory Board said the Department of Revenue may be requested to schedule the painkiller under the Narcotic Drugs and Psychotropic Substances Act, which would tighten rules around its export.

To export pharmaceutical products at strengths that are not approved in India, exporters are required to obtain an export “no objection certificate” (NOC) from the CDSCO, for which they have to submit proof of the drug’s approval in the importing country. Publicly available information shows tapentadol is not approved for use in any of the West African nations identified as part of this investigation.

The CDSCO did not respond to questions from Bellingcat or our publishing partner, Newslaundry.

In response to “Right to Information” requests submitted by Newslaundry, the CDSCO said only two companies had been granted authorisation to manufacture tapentadol for export between 2019 and 2024. However, the trade data analysed by Bellingcat did not list either company as an exporter of tapentadol to West Africa.

The CDSCO also said it had issued export NOCs for tapentadol to 51 companies since 2024, but that these were not for export to West African countries.

Meanwhile, Bellingcat’s analysis of trade data shows that more than 60 Indian suppliers have exported tapentadol to West Africa since 2023. The exporters are mostly pharmaceutical companies but also include smaller operations, such as one company owned by a Nigerian man who sent more than US $4 million of tapentadol to Niger and Ghana.

In the BBC’s investigation, journalist Surabhi Tandon reported on the increase in cross-border smuggling of tramadol, “a catch-all name to describe the range of opioids used as street drugs”, from Ghana to Nigeria. Source: BBC News

Dinesh Thakur, co-author of the book Truth Pill, told Newslaundry there were gaps in India’s drug regulatory framework that made it possible for potentially unsafe medicines to be manufactured and exported without proper oversight.

“There is no regulatory framework which checks a genuine importer and counterfeit importer between countries,” said Thakur, a former pharmaceutical executive who now works as a public health activist.

Mohammed Adinoyi Usman, a consultant anaesthetist at Rasheed Shekoni Federal University Teaching Hospital in Nigeria, said tackling Africa’s opioid crisis was complicated by a lack of resources across the region, weak government responses, and inaction by law enforcement agencies.

He said more collaboration and intelligence sharing was needed, especially across West African countries, to combat the problem. “We see so many opioids coming into our region because of a range of factors including under-funded institutions like customs and drug agencies, weak border controls and corruption,” he said.

“Africa is different. Even southern Africa is different from western Africa – each region has its peculiarities. In Nigeria, we don’t have well-functioning institutions to help control it. But our government is trying.”

Dr Usman said access to prescription opioids in Africa was inadequate, and pointed to research showing the disparity in distribution of legal opioids to low-income countries compared to high-income nations that consume the bulk of the world’s pain relief medication. He said opioid abuse was linked to crime and negative health outcomes.

“Sadly, access to prescription opioids is very limited in Africa,” Dr Usman said, “but the costs of illegal use are high.”


Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Painkiller Pipeline: 300 Million Tapentadol Pills Sent from India to West Africa appeared first on bellingcat.

‘Snoopy’, ‘Adolf’ and ‘Password’: The Hungarian Government Passwords Exposed Online

Almost 800 Hungarian government email addresses and associated passwords are circulating online, revealing basic vulnerabilities in the security protocols of ministries involved in classified and sensitive work.

A Bellingcat analysis of breach data shows that 12 out of the government’s 13 ministries have been affected, which in some cases have exposed the confidential information of military personnel and civil servants posted abroad. 

Among those affected were a senior military officer responsible for information security, a counter terrorism coordinator in the foreign affairs department, and an employee whose role was to identify hybrid threats against the country.

The revelations come as Hungarians head to the polls this Sunday to decide if Viktor Orbán, leader of the right-wing populist party Fidesz and the country’s longest-serving prime minister, will be elected to a fifth consecutive term.

This is not the first time that deficiencies in the Hungarian government’s IT security have been revealed. In 2022, ahead of Hungary’s last election, Direkt36 reported that Russia’s intelligence services had gained access to the computer network of the Hungarian foreign ministry, including its internal communications channels.

It said Russian cyber attacks against the Hungarian government had been occurring for at least a decade and extended to the foreign ministry’s encrypted network for transmitting classified data and confidential diplomatic documents.

At the time, the foreign ministry denied it had been hacked. But in 2024, news outlet 444 published a letter that had been sent from Hungary’s National Security Service to the foreign ministry six months before the cyberattack was first reported. The letter linked the attacks to Russia and described more than 4,000 workstations and 930 servers as “unreliable”.

As part of this new analysis, Bellingcat identified a total of 795 unique email and password combinations among thousands of search results for Hungarian government domains in breach databases. Key departments that handle the country’s governance, defence, foreign affairs and finances were the worst affected.

The analysis does not include central government agencies that operate under the government’s official ministries and use separate domains, such as the tax and customs administration or the police – meaning breaches affecting government employees could be even more widespread.

The findings are not evidence of high-tech infiltration of Hungarian government systems. Instead, our analysis indicates that the breaches are more likely the result of poor digital hygiene. In many cases, staff used simple passwords along with their government email addresses for what appear to be non-work-related matters, such as signing up to dating, music, sport and food websites.

Some government workers used easy-to-guess passwords such as variations of the word “Password” or the number sequence “1234567”. One employee whose credentials were exposed in the 2012 LinkedIn hack used the password “linkedinlinkedin”. Another, in the defence ministry, used their surname. One leaked password from an employee in the foreign affairs ministry was “embassy13hungary”. 

Multiple breaches also contained phone numbers, addresses, dates of birth, usernames and IP addresses – data that, when exposed, could pose security risks.  

Additionally, a search of breach databases showed instances where computers have been infected with malware designed to steal login credentials. These records show that 97 machines across Hungarian government departments had been compromised, with stealer logs from as recently as last month found in the data.

Bellingcat contacted the Hungarian government’s spokesperson and the Prime Minister’s office, but did not receive a response.

The Weakest Link: Searching Breach Data

Breach databases are large collections of credentials harvested from previous cyber incidents. These databases can be searched by domain to identify email addresses belonging to a specific organisation, company or government. 

Darkside allows users to search a repository of breach data from the clear and dark web.

Bellingcat used Darkside, a paid service by District 4 Labs, to search the main email domains assigned to each of the Hungarian government’s 13 ministries. 

In total, 795 breaches containing government emails and associated passwords were identified. But most – 641 breaches – were linked to just four central institutions. 

In the examples detailed below, staff have been anonymised. However, Bellingcat has confirmed these accounts are genuine by cross-checking the employees named in the breaches against media reports and online profiles, such as LinkedIn.  

Ministry of Interior – this “super-ministry” oversees everything from health and education to the police, immigration, disaster management and local government 

Bellingcat identified 170 sets of emails and passwords linked to the domain used by the ministry in charge of domestic affairs. Passwords used by staff in this department included “Arsenal” and “Paprika”. Some used passwords that contained only three or four letters. We traced these accounts to professional profiles and government web pages listing both junior and senior staff.

One senior official in the prison service used the password “adolf”. After it appeared in breach databases the password was changed twice – first to a five-digit number and then to what appeared to be the name for a pet dog. The passwords were subsequently breached again. Bellingcat identified this employee through several instances of their name and email address being listed on public-facing documentation, including a press release celebrating an award for outstanding professional work.  

Ministry of Defence – responsible for national defence policy and directing the country’s defence forces

The credentials of staff working for the Ministry of Defence were found in 120 compromised records. This includes a 2023 breach of NATO’s eLearning services which resulted in 42 records containing emails, passwords and phone numbers becoming public.

The breaches peaked in 2021 but continued up to 2026. Included in the data were stealer logs, indicating that machines within the department may have been infected. 

Military personnel from junior ranks to command positions were identified. A Brigadier General used a common six letter nickname, based on his own, to sign up to a film festival. A Colonel specialising in “information security” took inspiration from an English football manager for his password: “FrankLampard”. A district director used the password “123456aA”, while a high-ranking member of Hungary’s delegation to NATO used a password that translates in English to “cute”. 

Ministry of Foreign Affairs and Trade – responsible for international relations, Hungarian embassies and consulates operate under the direction of the department

The credentials of current and former foreign affairs personnel have been exposed in dozens of data breaches from 2011 to February 2026. In total, there were 107 email and password combinations linked to this government ministry. 

Among the staff affected was a deputy head of mission, consuls, diplomats and communications personnel posted in Europe, the Americas and the Middle East. These include a counter terrorism coordinator, an EU spokesperson, and an individual whose role was to identify hybrid threats to Hungary.

Although the breaches peaked in 2020, with emails being found in 42 separate breaches indexed by Darkside, MFA emails have been circulated, often with passwords, in 36 separate breaches since the beginning of 2024. The most recent breaches were in 2026.  

Simple passwords appear to have left Hungary’s foreign affairs ministry vulnerable. In some cases, employees used a password that consisted of their own name and a two digit number. Others appeared to take inspiration from pop culture: “porsche911”, “frogger” and “Batman2013” are examples of real passwords used by staff.

Ministry of National Economy – oversees economic policy and financial strategy, including budget preparation and reducing national debt

Bellingcat’s analysis shows that staff in the Ministry for National Economy suffered 99 breaches. The Ministry of Finance, which was merged into this department in 2025, had suffered 145 breaches.

Among the breached data were the credentials of a deputy state secretary, who used the password “snoopy”. Other staff members used their date of birth or the word “Jelszo” – the Hungarian word for password.

A senior advisor who currently works in the ministry had their credentials breached four times using four different passwords, including “Kurvaanyad1” (roughly translated to “your mother is a wh**e”).

Cybersecurity Not Taken Seriously

Szabolcs Dull, a political analyst and the former editor-in-chief of the independent Hungarian news websites Index and Telex, said the government had failed to prioritise data security. 

“It’s clear from the data breaches that have come to light that government agencies did not take data security seriously,” he said. 

“This suspicion arose even when Russian hackers breached the foreign ministry’s IT system. That is why I believe Hungarian politicians and the public will interpret this new information as a continuation and confirmation of the Russian hacking story.”

Dull added that he was not aware of any investigation having been launched following the 2022 revelations of the Russian hack.

Kata Kincső Bárdos, a cybersecurity expert in Hungary, said it was difficult to understand why stricter controls would not be consistently enforced in government environments handling sensitive data.

She said governments should not only apply baseline rules for passwords – such as that staff use long, unique passwords and multi-factor authentication (MFA) – but also continuously monitor for compromised credentials and suspicious access patterns.

“Without MFA, systems become significantly more vulnerable to common attack methods such as phishing and credential stuffing,” she said. “A single compromised password can provide immediate access to internal systems.” 

Bárdos added that unauthorised access to government systems should automatically trigger incident response procedures, investigation and containment measures.

“It is also important to note that targeting lower-level employees is a well-documented and common tactic,” she said. “Attackers frequently gain initial access through phishing or weak credentials and then move laterally within systems.”


Bellingcat’s Ross Higgins and investigative journalist Eva Vajda contributed to this article.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post ‘Snoopy’, ‘Adolf’ and ‘Password’: The Hungarian Government Passwords Exposed Online appeared first on bellingcat.

New Mexico’s Meta Ruling and Encryption

Mike Masnick points out that the recent New Mexico court ruling against Meta has some bad implications for end-to-end encryption, and security in general:

If the “design choices create liability” framework seems worrying in the abstract, the New Mexico case provides a concrete example of where it leads in practice.

One of the key pieces of evidence the New Mexico attorney general used against Meta was the company’s 2023 decision to add end-to-end encryption to Facebook Messenger. The argument went like this: predators used Messenger to groom minors and exchange child sexual abuse material. By encrypting those messages, Meta made it harder for law enforcement to access evidence of those crimes. Therefore, the encryption was a design choice that enabled harm.

The state is now seeking court-mandated changes including “protecting minors from encrypted communications that shield bad actors.”

Yes, the end result of the New Mexico ruling might be that Meta is ordered to make everyone’s communications less secure. That should be terrifying to everyone. Even those cheering on the verdict.

End-to-end encryption protects billions of people from surveillance, data breaches, authoritarian governments, stalkers, and domestic abusers. It’s one of the most important privacy and security tools ordinary people have. Every major security expert and civil liberties organization in the world has argued for stronger encryption, not weaker.

But under the “design liability” theory, implementing encryption becomes evidence of negligence, because a small number of bad actors also use encrypted communications. The logic applies to literally every communication tool ever invented. Predators also use the postal service, telephones, and in-person conversation. The encryption itself harms no one. Like infinite scroll and autoplay, it is inert without the choices of bad actors ­- choices made by people, not by the platform’s design.

The incentive this creates goes far beyond encryption, and it’s bad. If any product improvement that protects the majority of users can be held against you because a tiny fraction of bad actors exploit it, companies will simply stop making those improvements. Why add encryption if it becomes Exhibit A in a future lawsuit? Why implement any privacy-protective feature if a plaintiff’s lawyer will characterize it as “shielding bad actors”?

And it gets worse. Some of the most damaging evidence in both trials came from internal company documents where employees raised concerns about safety risks and discussed tradeoffs. These were played up in the media (and the courtroom) as “smoking guns.” But that means no company is going to allow anyone to raise concerns ever again. That’s very, very bad.

In a sane legal environment, you want companies to have these internal debates. You want engineers and safety teams to flag potential risks, wrestle with difficult tradeoffs, and document their reasoning. But when those good-faith deliberations become plaintiff’s exhibits presented to a jury as proof that “they knew and did it anyway,” the rational corporate response is to stop putting anything in writing. Stop doing risk assessments. Stop asking hard questions internally.

The lesson every general counsel in Silicon Valley is learning right now: ignorance is safer than inquiry. That makes everyone less safe, not more.

The essay has a lot more: about Section 230, about competition in this space, about the myopic nature of the ruling. Go read it.

How India’s Ruling Party is Using AI to Boost Hate Speech in States Near Bangladesh

The video posted by a state branch of India’s ruling Bharatiya Janata Party (BJP) showed Assam chief minister Himanta Biswa Sarma shooting an image of two men in Muslim skull caps. “Foreigner-free Assam”, read one caption across the video. “Why did you not go to Pakistan?” said another. 

Screenshots of the now-deleted video shared by BJP on Feb. 7 showing Assam Chief Minister Himanta Biswa Sarma shooting an AI-generated version of INC leader Gaurav Gogoi (in a white skull cap) and another unidentified, bearded man. Source: BJP4Assam/X

One of the men in the photo that Sarma was portrayed as shooting was Gaurav Gogoi, a leader of the Indian National Congress (INC), the BJP’s main competitor in Assam for the state’s upcoming legislative elections next month

Gogoi has stated that he is Hindu but enjoys visiting different religious sites and observing their norms. He has been photographed wearing traditional Muslim attire during religious occasions such as Eid

But the image of him in the video shared by BJP Assam, wearing a casual singlet with a skull cap, was not one of those occasions. 

Bellingcat has seen several dozen videos posted by the BJP that use generative artificial intelligence (AI) alongside anti-Muslim and anti-Bangladeshi messaging in the border states of Assam and West Bengal in December last year, ahead of legislative elections scheduled in both states for April.

Left: Original photo shared by Gogoi on Jun. 17, 2025. Right: An image shared by BJP Assam that was edited with AI to show Gogoi with a skull cap, beard and Quran. Source: gauravgogoiasm/Facebook, BJP4Bengal/Facebook

Bellingcat analysed 499 social media posts containing photos and videos shared on Facebook, Instagram and X by the BJP’s official accounts in the two states for this time period, finding 194 posts that appeared to meet the United Nations’ definition of hate speech: discriminating against persons or communities based on inherent characteristics such as religion and national origin. Of these, 31 (about one in six of the hateful posts) contained the obvious use of AI-generated imagery. 

visualization

Chart: Galen Reich

These appear to be part of a larger pattern of politicians and parties globally using generative AI to amplify hateful or divisive content, particularly ahead of major political events such as elections. 

Ahead of the New York City mayoral race last year, Andrew Cuomo’s official X account shared, then deleted, an AI-generated video depicting Mamdani eating rice with his hands and a Black man in a keffiyeh shoplifting. In Italy, several opposition parties complained to a communications watchdog after deputy prime minister Matteo Salvini’s League party published a series of AI-generated images depicting men of colour attacking women or police officers. And in the UK, videos by an AI-generated rapper funded by the far-right Advance UK party, with lyrics targeting Muslims, were viewed millions of times. 

A Campaign of Hate

Both Assam and West Bengal share a border with Bangladesh. BJP, the world’s largest political party, is currently in power in Assam, where legislative elections are scheduled on Apr. 9. West Bengal, which goes to the polls on Apr. 23, is governed by the Trinamool Congress (TMC).

Map: Pooja Chaudhuri. Source: Goran tek-en, CC BY-SA 4.0, via Wikimedia Commons 

Tensions between India and Bangladesh worsened after former Bangladeshi Prime Minister Sheikh Hasina, who enjoys close ties with Delhi, was ousted in 2024 and fled to India

US-based international affairs expert Mohammed Zeeshan told Bellingcat that the “dehumanising and debasing” terminology used in India to refer to alleged illegal Bangladeshi immigrants, including by senior ministers, has caused resentment towards India in Bangladesh. 

“The situation, in fact, was so bad that Hasina herself had subtly warned the Modi government in public statements that Indian domestic rhetoric was endangering Bangladeshi Hindus, who bore the brunt of that resentment,” Zeeshan said. 

Zobaida Nasreen, a professor of anthropology at Dhaka University, said that anti-Muslim rhetoric intensified by BJP leaders reinforces the belief in Bangladesh that Muslims and Bengalis are being collectively targeted in India.

“Viral videos containing this message tend to spread quickly across Bangladeshi media and social platforms especially on Facebook, enhancing perceptions of hostility and triggering anti-India sentiment or nationalist backlash,” she added.

In December, the month our dataset was collected, Dipu Das, a Hindu garment worker, was beaten to death at an anti-India protest in Bangladesh over allegations that he had made derogatory remarks about Islam. 

And while the administration led by Bangladesh’s newly elected leader Tarique Rahman has sought to reset strained ties, most of the hateful social media posts we saw posted by the BJP in December attacked Bangladeshi Muslims and/or Bengali-origin Muslims in India, showing how tensions between the two countries continue to influence political messaging in India’s border states.

Bellingcat’s analysis included a total of 202 posts by BJP Assam and 297 by BJP’s West Bengal branch on their official accounts. We also looked at posts shared by BJP’s main opponent parties – 194 from INC in Assam and 357 from the TMC in West Bengal – during the same time period in December. 

This included all visual social media posts (containing photos or videos) by each party in December, except those that did not appear to contain any overt political messaging, such as those simply commemorating public holidays. We only counted each photo or video once, regardless of how many platforms it was shared across. 

Although all of the major parties contesting in the Assam and West Bengal state elections appeared to use AI-generated imagery in some of their posts, there appeared to be a particularly high concentration of hateful messaging in the ones posted by the BJP’s accounts. 

In Assam, we identified 28 posts by BJP using apparently AI-generated imagery, of which 24 carried hateful messaging. Of the 194 INC posts we looked at from December, 41 appeared to feature AI-generated imagery, but none of these appeared to carry hateful messaging. 

In West Bengal, we found 14 BJP posts that contained clear indicators of AI-generated imagery, seven of which were hateful. We also identified 15 posts by the incumbent TMC that appeared to feature AI imagery, but none of these appeared to meet the definition of hate speech. 

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

When contacted for comment, BJP Assam spokesperson Rupam Goswami did not directly respond to questions on the party’s general use of AI but said they did not post any AI-generated photos of Gogoi. “BJP does not stoop so low,” he told Bellingcat.

As for the “point blank” shooting video, Goswami initially said the person responsible had been punished and removed from the party. However, when asked about Sarma saying that he would re-post the video with those he was depicted shooting labelled as “Bangladeshis”, Goswami said, “[Bangladeshis] need to be completely suppressed.”

BJP West Bengal did not respond to multiple requests for comment by Bellingcat via phone and email.

It is important to note that as generative AI technology improves, it can be increasingly difficult to detect AI-generated imagery. Our manual count of AI-generated imagery only included posts that had obvious signs of generative AI such as unnaturally smooth textures and multiple people with the same faces. It is therefore possible that there were other images in our dataset where generative AI was used more subtly. 

However, Joyojeet Pal, Professor of Information at the University of Michigan, told Bellingcat that the quality of these visuals, or whether they looked real, was not the priority. 

“What politicians in India have understood is that the sociocultural drivers of misinformation are most important for elections, so they harp on about things to the extent that they have started to not care about form over substance. It looks bad? It doesn’t matter,” he said.

More important to voters, according to Pal, was whether they already believed in the narrative contained in the videos, which generative AI could help create more quickly: “AI is helping cement polarised opinions by giving you the kind of content you have already decided you want to engage with.” 

When asked about INC’s use of AI, party spokesperson Aman Wadud said that it was obvious that some of the videos they posted were made with AI and that there was no intention to mislead. 

“AI can be both destructive and creative. We are using it in a creative manner, we are not using it in a destructive manner. We don’t violate people’s dignity, we don’t falsely accuse people,” he said.

TMC did not respond to Bellingcat’s multiple requests for comment via phone and email by publication time.

Portraying Bengali Muslims as ‘Foreigners’

The largest category of hateful messaging Bellingcat observed in the BJP’s posts targeted Bangladeshi or Bengali-origin Muslims, referring to them as “infiltrators” or “foreigners”. We counted 66 such posts by the BJP’s Assam and West Bengal branches from December, of which eight appeared to contain obvious AI-generated imagery. 

Bengali-origin Muslims are often stereotyped as “illegal immigrants” in the state, although members of the community have lived in India since the late 1800s

Last year, the BJP deported thousands of alleged undocumented migrants – reportedly including Indian Muslim citizens – to Bangladesh. Human rights groups have called the deportations unlawful and discriminatory, as well as lacking in due process

One video referencing this theme shows AI-generated visuals of protests against “illegal infiltration” in Assam, with the caption urging people to “wake up” or the country would “turn into Bangladesh”. 

A different one uses real footage from past violence in Assam mixed in with images of Muslim men. A song playing in the background accuses them of taking over “Assamese land” and shows AI images of “Assamese” people, i.e. those not in stereotypical Muslim clothing, crying.

An AI-generated image of a crying man in non-Muslim clothing and a traditional Assamese scarf on his shoulders. Source: BJP4Assam/X

Both videos use religious markers to draw a distinction between “infiltrators” – men in skull caps or lungis associated with Bengal-origin Muslims – and “citizens” in non-Muslim attire. 

Clothing is often used by the Hindu far-right as a visual shorthand for identity and a deepening religious divide. In 2019, Prime Minister Narendra Modi said of protests against a controversial citizenship law that those responsible for violence could be “identified by their clothes”

In the hateful posts seen by Bellingcat, both real and AI-generated images of opposition figures – particularly Gogoi – were shown alongside messaging that suggested that they supported “foreigners” or “infiltrators”. 

The Center for the Study of Organized Hate (CSOH) also noted, in a 2025 report on AI-generated imagery and Islomophobia in India, that Hindu far-right politicians and media outlets have invoked and reinforced the trope of Muslims as “infiltrators” for years. 

“AI-generated images on these themes reinforce associations between Muslim identity and illegality, reinforcing xenophobic and Islamophobic stereotypes. In doing so, they play a powerful role in justifying exclusionary policies and normalising discrimination against Muslims,” the report said. 

‘Save Hindus’

Zenith Khan, a data analyst who worked on the CSOH report, noted that AI-generated propaganda was often tightly knit with current political moments, and its impact depended on “timing it right” especially when “people are emotionally charged”. 

The violence against the minority Hindu community in Bangladesh has been used by the BJP to raise concerns over the safety of Hindus in India. 

Days after Das’ lynching, the Assam state branch of BJP posted a video with an image of his face – except that it was manipulated with AI to show tears streaming from his eyes. “Save Hindus”, said the text accompanying the video. 

Posts by BJP’s West Bengal unit also seemed to frame Muslims as criminals or threats. A video, styled after the TV show “Stranger Things”, raised alarms over an “upside down” version of the state under the current government. 

A man is depicted being chased by men in skull caps. Arrows label them as “Ralib,” “Galib,” and “Chalib” – a play on Muslim names ending in “-lib” – in case the skull caps left any ambiguity about their Muslim portrayal. 

“Stranger Things” themed post that depicts Hindus under threat from Muslims in West Bengal. Source: BJP4Bengal/X

INC filed a police complaint in September last year against the BJP for sharing AI videos targeting Gogoi and the Muslim community, as well as another complaint in relation to the video of Sarma portrayed as shooting two men “point blank” in February. 

INC Assam spokesperson Wadud said that no action had been taken on the party’s police complaints as far as he knew. 

Disinformation researcher Bharat Nayak told Bellingcat that it has always been tech platforms’ responsibility to control new types of content. 

“The goal post can’t shift. This has always been a tech problem,” he said. 

When this responsibility is shrugged off, Nayak added, the result is a lack of accountability. “If you’re using old videos from other countries as new, you will have people countering you. But AI-generated videos can be shared without context just to spread hate – like showing people in skull caps – and the ‘when, where, how’ questions vanish.”

Both Meta – which owns Facebook and Instagram – and X have policies against hateful conduct. 

Meta also announced in 2024 that it would start adding “AI info” labels to more content detected as AI-generated, while some X users spotted a similar feature introduced on the platform last month. Only five of INC’s AI visuals that we identified – and none of those by TMC or the BJP – had a disclaimer that said “AI-generated”. 

Bellingcat reached out to Meta and X for comment on whether the posts we identified breached their terms of use regarding hateful conduct or labelling AI-generated posts. A Meta spokesperson said they were reviewing the flagged content and “will take appropriate action on any violations of our policies”. As of publication, X had not responded.


Kalim Ahmed from Bellingcat’s Discord Community contributed research to this piece.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post How India’s Ruling Party is Using AI to Boost Hate Speech in States Near Bangladesh appeared first on bellingcat.

How Wildlife Traffickers Are Using Coded Language to Sell Protected Animals On Facebook

A Bellingcat investigation has identified nine Facebook groups with a combined membership of more than 70,000 people, in which coded language has helped illegal wildlife dealers evade bans on the platform for years. Facebook says it prohibits any form of animal trading on its platform.

Investigating the operators behind all nine groups, Bellingcat identified six Facebook profiles that led back to a single broker in Jakarta, Indonesia. This investigation was carried out in partnership with Mongabay. You can read their report in English here and in Bahasa Indonesia here.

In an open Facebook group, brazenly titled “West Bogor Animal Selling and Trading Forum,” one member posts an advert for a vulnerable rhinoceros hornbill.

Screenshots of an online advertisement for a rhinoceros hornbill chick, a protected and vulnerable species, posted on Facebook on July 11, 2025.

Commenting on the advert, another member warns: “Just be careful not to get caught.” 

Screenshot of a Facebook conversation, translated from Bahasa Indonesia and posted in July 2025. Annotated by Bellingcat.

“That’s the risk,” replies the seller. 

Under Indonesian law, the capture, trade, or possession of a rhinoceros hornbill is punishable by up to five years’ imprisonment or a fine of up to Rp100 million (US$6,000). (According to Statistics Indonesia, the average monthly wage in August 2025 was just over Rp3 million or US$180.)

Meta also states that the buying and selling of animals on its platforms is prohibited. However, in this group, along with eight others identified by Bellingcat, animals have been traded in plain sight for years, including wild and protected species. Three of the nine groups have been live on Facebook for at least five years. Four have been active for 12 months or more, and the remaining two were created in 2025.

Screenshots of tortoises, monkeys, and owls for sale, posted in Facebook adverts in October 2025.

All nine groups state in their “About” tab that they are based in or around Jakarta, the Indonesian capital. As one of the most biodiverse countries in the world, Indonesia is a hotspot for poachers and a key transit hub in the illegal wildlife trade.

A quick scan of these groups revealed a variety of protected species for sale, including Javan coucals, Javan scops owls, Javan langurs, binturongs, and both wreathed and rhinoceros hornbills.

In one of the most active groups, West Bogor Animal Selling and Trading Forum, more than 200 adverts were posted in a single week. Of these, 18 advertised vulnerable species, including these two infant silvery gibbons. 

Screenshots of two infant silvery gibbons advertised on Facebook on May 10, 2025.

With fewer than 2,500 mature individuals left in the wild, the silvery gibbon is considered endangered. Under Indonesian law, trading in this species can result in up to five years’ imprisonment or a fine of up to Rp 100 million (US$6,000).

Otters were also frequently posted in the group. Popular in the Southeast Asian pet trade, most otter species are protected due to declining numbers in the wild. However, because many of the adverts were for infants, it was not always possible to determine which otter species was being sold, and therefore whether it was protected.

“Using Codes So The Group Stays Safe”

Despite Facebook’s total ban on animal trading, including pets, in the group titled: Civet/Pet Buying and Selling in the Greater Jakarta Area, members were instructed in the “About” tab to “prioritise using codes so the group stays safe from being banned.”

Screenshot of the group’s About description. Translated and annotated by Bellingcat.

Alphanumeric codes were used to discuss animal prices in eight of the nine groups identified by Bellingcat. According to the Indonesian news outlet Jateng Today, the use of pricing codes, intended to circumvent Facebook’s automated moderation systems, is not uncommon among animal traders on the platform.

Such codes use the letters A, B, and C to denote different Indonesian rupiah denominations. A stands for a Rp100,000 note (about US$6), while B represents a Rp50,000 note (about US$3). An accompanying number specifies the quantity, so A3 indicates three Rp100,000 notes.

Screenshot of a conversation on Facebook discussing the price of animals. Blurring by Bellingcat.

In the post below, one member asks, “A2 dapet apa?” – “What does A2 (Rp 200,000; US$12) get you?”

Screenshot from the Facebook group ‘Buying and Selling civets/pets in the Greater Jakarta area,’ posted on Facebook, August 6, 2024.

The post received 69 replies, with members offering everything from otters to owls, civets and geckos.

The term “Wc” – a common shorthand in animal trading groups for “wild-caught” – was also frequently used across all nine groups. Under Indonesian law, even if a species is not listed as vulnerable or protected, capturing and selling wild animals without a permit is illegal.

Related articles by Bellingcat

The Hunt for Malaysia’s Elusive Wildlife Trafficker
Asia-Pacific

The Hunt for Malaysia’s Elusive Wildlife Trafficker

Asked whether its moderation systems could detect cost codes (as text or embedded in images) or key terms such as WC (when found next to images of animals), Meta responded: 

“Bad actors constantly evolve their tactics to avoid enforcement, which is why we partner with groups like the World Wildlife Fund and invest in tools and technology to detect and remove violating content.”

The Operators

While investigating the operators behind all nine groups, Bellingcat identified six Facebook profiles that led back to one individual broker based in Jakarta. 

By navigating to the “People” tab in one of the groups, a list of admins and moderators appears, including an account referenced below as AB. Despite AB’s profile being locked, a search with the term “wa.” (WhatsApp’s click-to-chat feature) returned dozens of animal adverts alongside a phone number.

Screenshot of AB’s Facebook post including a phone number. Posted June 11, 2025.

Using the phone number to search for AB’s historic posts, six out of the nine groups under investigation were found to have adverts for vulnerable species, including this advert for a binturong

Screenshot of an advert for a “Bintu” short for binturong. Posted by AB, September 2024. 

Listed as vulnerable by the International Union for Conservation of Nature (IUCN), keeping a binturong, let alone trading it commercially, is prohibited under Indonesian law.

AB has also advertised this “Celepuk Wc”, a wild-caught scops owl, seen below. Although the species itself is not protected, selling a wild-caught owl in Indonesia without a permit (which are tightly regulated) violates Indonesian law.

Owls for sale, posted by AB. Left: Labelled “Wc” for wild-caught. Right: “BC” for bred in captivity. 

By following the phone number shared by AB, five more Facebook profiles were uncovered. The six profiles frequently shared similar adverts, often within days of each other, for the same species, sometimes featuring a similar interior background, and always listing the same telephone number.

Six different accounts posting similar-looking animal adverts, while all using the same contact phone number.

Late last year, one of the accounts referenced below as W, posted this wreathed hornbill, a protected species in Indonesia. 

Screenshot of an advert for a wreathed hornbill. Posted by Waa, November 2025. 

Of the six profiles, only one, named Azie Soka Smithh has ever posted personal data, including a profile picture of a man with a child. 

An advert for a civet, posted by Azie Soka Smithh and tagging the same phone number as used by the other five accounts.

Further investigation into Azie Soka Smithh confirmed their presence on other platforms, including Telegram and Instagram. However, their full legal name remained unknown. While searching for visual clues to their location, it became apparent that the vast majority of images had been tightly cropped, revealing little about their whereabouts – except for a handful of images that appeared to have been taken at the same location: a pet shop.

In the adverts shown below, a poster can be seen on the wall behind the cage displaying the shop name Station Sato Exotic and a phone number. Of all the images seemingly taken in the same shop, none featured species protected under Indonesian law. However, the long-tailed macaque shown below is considered endangered according to IUCN due to declining numbers in the wild. 

Adverts posted by two different accounts but with the same shop name and phone number visible in the background. The right image features a long-tailed macaque.

A Google search for the shop’s name and number returned a Google Maps listing for Station Sato Exotic. A man named “beni” had left a five-star rating as well as several dozen photos and videos of the pet shop’s interior, including one that appeared to show a man sitting next to an identical poster as seen in the animal adverts. 

Screenshot of Beni’s Google review, including (right) a video of a man sitting beside a poster for Station Sato Exotic. Posted July 2021.

According to beni’s Google account, his full name is Beni Abdul Hamid (translated from Arabic). His bio reads: “We sell various kinds of accessories, cages, animal feed, etc” (translated from Bahasa Indonesia).

Of the 16 photos and 25 videos posted by Beni, several showed a left hand holding animals up to the camera, with a distinctive mole visible on the wrist. A seemingly identical mole appeared in several of the adverts posted by the six Facebook accounts sharing the same phone number. Notably, the mole and wrist were not seen holding species protected under Indonesian law. However, the long-tailed macaque shown below is considered endangered according to IUCN.

A distinctive mole appears in multiple animal adverts posted by (left) Beni on Google Listings, (centre) AB on Facebook and (right) another of the six accounts using the shared phone number. The centre and right images feature a long-tailed macaque.

Upon visiting Station Sato Exotic, our partners at Mongabay confirmed that Google reviewer Beni Abdul Hamid was in fact the owner. His son, Jordan Bastian, who was present on the day, told their reporter he now manages the shop on his father’s behalf.

Bastian confirmed that it was his wrist and mole in the adverts and that he had taken all of the photos inside the shop. However, he said he was not behind any of the six Facebook accounts and that they were most likely run by a local broker. He explained that his business relies on a network of brokers operating on Facebook and WhatsApp. He sends them photos of the animals he has for sale, and they handle sourcing and organising everything with the buyer in exchange for a cut of the profits.

“I’m a broker. I’m involved in marketing the animals, so I provide the photos,” said Bastian. “I don’t want to know about the buyer.”

When shown the Facebook account for Azie Soka Smithh, Bastian confirmed that the man in the profile picture was a local broker, but one who seldom visited the shop.

Station Sato Exotic Pet Shop also has an online presence on Tokopedia, a major Indonesian marketplace. The platform’s guidelines prohibit the sale of endangered species, but are not clear regarding the sale of other animals, including pets.

Of Station Sato Exotic’s 71 current listings, the large majority have been miscategorised. Animals are listed as tools, toys, aquarium decorations and books. They are also miscategorised as other species; for example, birds and squirrels have been listed as hamsters or reptiles.

One advert features a vulnerable cuckoo species, the Sunda Coucal. Endemic to Java and numbering fewer than 10,000, this bird has been listed as vulnerable since 1994.

Screenshot of Station Sato Exotic’s Tokopedia page promoting the sale of a vulnerable cuckoo species. The page reports that four birds have already been sold. 

Asked whether he had sold many animals via Tokopedia, Bastian said his account had been blocked after he was banned for selling squirrels. When shown the advert above for the Sunda Coucal, he said he was surprised to learn it was classified as vulnerable. Tokopedia did not respond to requests for comment regarding an advert for a vulnerable species appearing on their platform. 

On the sale of protected or vulnerable species more broadly, Bastian admitted he had in the past, but has since stopped, describing “the risk is big” and saying he prefers to “play it safe.” 

After contacting the local authorities for comment, three officers from the West Java Natural Resources Conservation Agency (BBKSDA) made a surprise visit to Station Sato Exotic, due to the shop having previously been reported for selling protected species. Head of Conservation Stephanus Hanny said that upon arrival, “We went inside and checked every animal… We did not find any protected species.” He added that even the sale of non-protected wildlife requires a permit, which the shop does not currently hold. However, since it’s not a criminal offence, Hanny said they could only issue the owners with a warning. 

Bellingcat also contacted the phone number associated with Azie Soka Smithh. The person replied, confirming they managed all six accounts but denied selling any animals, including protected and vulnerable species. “I’m just a hobbyist. An animal lover,” they said. 

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Given that the account had been found advertising vulnerable and protected species for sale, the Indonesian Director General of Forestry Law Enforcement, Dwi Januanto Nugroho, said authorities would investigate. Asked how their team of investigators was adapting to the illegal wildlife trade growing online, Nugroho replied:

“Criminal behaviour continues to reproduce itself in order to survive. In fact, it can evolve faster than the law enforcement system itself. In response …cyber patrols and desk analysis via the operations room will continue to be intensified, while we further optimise support from volunteer networks, working partners, and public participation.”

After contacting Meta, all six accounts, including Azie Soka Smithh, and all nine groups, totalling 70,000 members, were shut down. Meta confirmed: “We removed the Facebook groups and profiles in question for violating our Restricted Goods and Services Policy.”

Merel Zoet and Claire Press contributed to this report.

Bellingcat is a non-profit and the ability to carry out our work depends on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here and Mastodon here.

The post How Wildlife Traffickers Are Using Coded Language to Sell Protected Animals On Facebook appeared first on bellingcat.

How Russia’s War Has Devastated Civilian Life in Ukraine

In the tiny town of Krasnopillia in rural Ukraine, the stillness of the night is shattered by the whine of a Russian drone. Seconds later, a community hospital bursts into flames. Sparks and debris rain down across the skeletons of trees as the fire sends plumes of smoke into the pitch-black sky.

Dozens of people are evacuated, according to local media reports – but as rescuers respond, in what appears to be a double-tap strike, Russian forces hit a shelter where more than 20 patients are huddled, including some with limited mobility. 

The strike in March 2025 comes just hours after a larger regional hospital in the northeastern Sumy governorate is targeted, decimating the primary health facilities serving the small town of Krasnopillia, whose prewar population was around 7,700. Healthcare services for the town “practically ceased” in the wake of the strikes, Olena Pryima, a local school director, told Bellingcat in a phone interview. 

“[The Russians] destroy the infrastructure so that people do not have the opportunity to live and exist normally. You cannot consult a doctor, nothing,” she said. “And now these people who remain, God forbid, the ambulance will not go there, just because the security situation does not allow it.”

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Her own school was among the many buildings destroyed in Russian strikes, and she says it has been impossible to rebuild amid the ongoing war. “We try to heat some accommodations, in spite of everything … especially since this winter is very difficult,” Pryima said. “But we are not talking about rebuilding at all now. We have hope; we are collecting some documents [such as testimonies and damage assessments], since this will end someday – and then we can rebuild something.”

For the past four years, Bellingcat has been documenting and verifying incidents such as these, chronicling the extensive damage to civilian life and infrastructure after the onset of Russia’s full invasion which began in February 2022.  

In over 2,500 cases of civilian harm that we have verified – the vast majority of which occurred on Ukrainian territory, although dozens also took place in Russia – more than 1,100 residential structures were hit. Hundreds of other civilian sites such as schools, playgrounds, fire stations, hospitals, churches, cultural centres, museums, businesses and farms have been impacted too. 

Our data – which includes cases that Bellingcat researchers were able to definitively geolocate using open source evidence, and does not reflect the full extent of civilian harm across Ukraine – pinpoints more than 300 attacks on schools or childcare facilities, 170 hits on healthcare or humanitarian sites, and four dozen incidents targeting food and related infrastructure. 

While many attacks were clustered around four main cities – Kharkiv, Donetsk, Kherson and Kyiv – we documented strikes across all areas of the country. Of the weapons that could be identified through available open source information, cluster munitions were used in more than 100 cases. 

Cluster munitions, which are banned in more than 100 countries (but not Russia or Ukraine), have killed more than 1,200 people since the war began, with Ukraine recording the highest number of annual casualties worldwide from these weapons in 2024 for the third consecutive year, according to the Landmine and Cluster Munition Monitor. 

Bellingcat and members of its volunteer community logged all verified incidents of civilian harm on an interactive TimeMap over a four-year period spanning February 2022 to December 2025. The map is no longer being updated, but it remains online as an archive (and can be seen below). 

An interactive map detailing incidents of civilian harm between February 2022 and December 2025.

Since Russia’s invasion four years ago, the civilian toll in Ukraine has been stark, with around 15,000 killed – including more than 750 children – and 40,600 injured, according to a January 2026 report by the Office of the United Nations High Commissioner for Human Rights. 

An analysis last year by Armed Conflict Location and Event Data (ACLED) found that Russia followed “a persistent pattern of targeting of populated areas … often indiscriminate, other times more deliberate”. 

Related videos from Bellingcat

New apartment complexes are listed for sale on Russian websites. Meanwhile, Ukrainians are struggling to reclaim their homes.

ACLED’s data for the period of February 2022 to late January 2026 highlights thousands of residential strikes across Ukraine, along with more than 750 attacks on healthcare facilities, 1,200 on educational sites, and 2,400 on energy infrastructure. A February 2025 World Bank report says it will take more than US$500bn to rebuild Ukraine. 

These numbers tell only part of the story. While much global media attention has focused on the politics of the Russia-Ukraine war, or highlighted strikes on large urban centres, civilians in remote rural villages have suffered outsized impacts from the destruction of schools, hospitals and cultural institutions – the key threads tying their communities together.

In Verkhna Syrovatka, a small village in Sumy of around 3,800 people, images from the scene of shelling in May 2025 revealed a massive hole in the community’s blue-roofed cultural house. Inside the facility, which once served as a place for rehearsals, children’s classes and folk ensembles, photographs and trophies could be seen amid piles of splintered wood and cracked concrete.

The village’s only school was also impacted, with many of its windows blown out, forcing classes to move online. This devastation reflects a countrywide trend, as UNICEF reports that Ukrainian children are falling behind in core subjects such as reading, maths and science.

Incidents of civilian harm recorder by Bellingcat in Verkhna Syrovatka. Readers can click or tap the dots to learn more about each incident.

Further south, the village of Opytne in the Donetsk region is gradually being erased, amid a series of Russian attacks dating back more than a decade to the 2014 occupation of the Crimean Peninsula. 

The village has changed hands repeatedly in recent years. In December 2022, drone footage revealed large-scale destruction of its residential area, including a medical office, music school and church. According to media reports, perhaps only half a dozen residents remain out of more than 1,000 who lived in the village a decade ago.

Image left shows the village of Opytne in 2021, before Russia’s full invasion (Credit: Airbus/Google Earth Pro). Image right shows the village of Opytne in 2024 (Credit: Maxar/Google Earth Pro).

A couple of months later, in February 2023 in Dvorichna, a rural settlement in the Kharkiv region, Russian forces launched another double-tap strike: as first responders searched for survivors from an earlier attack on the village council building, several emergency vehicles were hit. 

Located just south of the Russian border, Dvorichna has been occupied on and off since 2022. As a result, the village, whose population was roughly 3,500 four years ago, is estimated to house only 80 residents today.

Across Ukraine, the catalogue of horrors is endless. In Pravdyne, a small village in the Kherson region, the prewar population of more than 1,000 people was reported to have dwindled to fewer than 200 by late 2022. Corpses showing signs of torture have been exhumed from garden beds; in one case, residents reportedly buried the bodies of Ukrainian soldiers under slabs of slate to prevent dogs from reaching them. 

Incidents of civilian harm recorder by Bellingcat in Pravdyne. Readers can click or tap the dots to learn more about each incident.

In Sumy Oblast, Russian drone and missile attacks have forced residents to flee homes they inhabited for half a century. In the village of Hroza in northeastern Ukraine, one-fifth of the population died in a single attack while attending the funeral of a soldier, according to local officials.

What may never be calculated are the impacts this brutal conflict will have on future generations.

Incidents of civilian harm recorder by Bellingcat in Hroza. Readers can click or tap the dots to learn more about each incident.

Back in Krasnopillia, the local school director, Pryima says residents have tried hard to stay in what she calls “the zone of resilience”, but it has been a struggle.

“It’s very scary to fall asleep, because you don’t know if you’ll wake up in the morning,” she said, noting that residents live in constant fear of the drones that fly overhead, keenly aware that a bomb may drop at any moment. 

For Ukrainian children, the effects have been especially dire.

“Those children, before the full-scale invasion, were carefree, cheerful – what children should be,” Pryima said. “Those children are no longer there.” 


Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post How Russia’s War Has Devastated Civilian Life in Ukraine appeared first on bellingcat.

How Russia’s Invasion is Impacting Ukraine’s Youth

Last month, in the dead of a cold Autumn night, residents in the Ukrainian town of Balakliia were woken by the sound of two massive explosions.

Social media footage showed apartments ablaze, balconies obliterated and a deep crater smouldering in a parking lot.

Three people were killed and 13 injured in the November 17 attack, Ukraine’s State Emergency Services (SES) said. Four of those injured were children, the SES added. A kindergarten, situated just over a hundred metres from one of the impact sites, was also reported to have suffered damage.

Since the beginning of the full-scale invasion of Ukraine, schools, educational facilities and spaces used by children have repeatedly been damaged in strikes or closed because of them.  

According to the United Nation’s agency for children, UNICEF, many schools remain closed or continue to be disrupted by air raid alarms. Almost one million children have also been forced to study online, UNICEF states.

Balakliia lies in Kharkiv Oblast in the north east of Ukraine. Another Russian strike carried out there earlier in November caused damage near the town’s main square. Located just over 100 metres away was a high school and not far from that a local theatre school. While neither of those facilities appeared to be directly damaged, many other educational institutions have not been so lucky.

Educational Facilities in the Firing Line

A Ukrainian government website (saveschools.in.ua) has been tracking the number of kindergartens, high schools, colleges and universities that have been damaged and destroyed across the country.

At time of publication 3,676 educational facilities have been damaged nationwide and 394 destroyed, according to saveschools.in.ua.

These trends are reflected in social media data collected by Bellingcat.

Since the start of Russia’s full-scale invasion, Bellingcat has been gathering and verifying social media footage showing incidents of civilian harm. 

More than 2,500 incidents have been identified during this period, including attacks on hospitals, power stations, residential buildings and cultural sites. The full dataset is public and can be found here. But this is likely just a fraction of the damage caused across Ukraine as the data only captures incidents recorded and published on social media channels that have been verified.

Amongst this dataset are more than 200 cases of educational facilities that have been damaged or destroyed.

In September this year, for example, social media footage captured the moment a Russian drone hit an administrative building at Kharkiv’s National University of Pharmacy.

As far  back as July 2022, a school for the visually impaired in eastern Kharkiv was hit by Russian rockets, leaving windows smashed and classrooms burned out.

Just a few months before that, footage posted online appeared to show the remains of a missile that hit a school in the town of Merefa, situated around 30 kilometres to the southeast of Kharkiv.

Kharkiv’s Youth Bears Burden

More educational facilities have been damaged or destroyed in Kharkiv Oblast than in any other territory currently held by Ukraine, according to Bellingcat’s dataset and saveschools.in.ua statistics.

In Kharkiv city and its surrounding areas, Bellingcat found and archived footage of at least 26 schools, kindergartens, colleges or universities that have been damaged and destroyed since Russia’s full-scale invasion. A further 36 strikes that impacted areas around educational facilities in Kharkiv but did not directly hit them were also verified and archived by Bellingcat.

Bohdan Levchykov, a 15-year-old teenager, walks by a damaged habitation building in Balakliia, on October 13, 2025. OLEKSII FILIPPOV / AFP

Sustained attacks on educational facilities as well as widespread disruption to studies caused by the war are having a lasting impact on Ukraine’s young people, children’s rights groups say. 

A report from Save the Children earlier this year detailed how attacks on educational facilities had doubled in Ukraine over the course of 2024. The same report found that parents were scared to send their children to school and that many children were being forced to resort to online learning at home.

A 2024 report from UNICEF has found Ukrainian children are falling behind children in other countries across all/multiple subjects including  reading, maths and science.

In Balakliia, journalists from Agence France-Presse (AFP) bureaus in Paris and Kharkiv spoke to teenage student Bohdan Levchykov who said he studies at home and seldom leaves the house. Levchykov also spoke about the impact of losing his father in the early months of the war.

About an hour’s drive to the northwest, in the town of Khorocheve, a psychologist with the non-profit Voices of Children , Maryna Dudbyk, told AFP that the ongoing war means that everyone is living under stress. 

“This has a huge impact on children’s emotional state,” she said.

“We diagnose a lot of fear and anxiety among children. Adolescents suffer from self-harm, suicidal thoughts, and the loss of loved ones.”

Beyond Schools

Other facilities, beyond schools, regularly enjoyed by children have also been impacted by the war, compounding the challenges young people face.

Bellingcat’s dataset found 28 incidents where swimming pools, parks, football pitches, bowling alleys or museums had been impacted in and around Kharkiv. A further 16 incidents were recorded in areas surrounding such facilities. The below interactive shows (in red) incidents where educational or recreational facilities used by young people have been impacted by Russian strikes in and around Kharkiv. The other markers in the map (in purple) detail additional civilian harm incidents Bellingcat has been able to verify. A wider dataset of showing incidents that have impacted areas surrounding educational and recreational facilities can be found here.

Incidents of civilian harm directly affecting schools and childrens’ leisure facilities are highlighted in red.

One video from March this year showed young men playing football scrambling for cover as a drone can be heard overhead before an explosion can be seen.

Although Ukraine’s policymakers are facing many challenges as Russia’s invasion of Ukraine approaches its fifth year,  the mental health of the country’s youth is on their minds.

Oksana Zbitnieva, head of the Interministerial Coordination Center for Mental Health told AFP that “130,000 frontline health professionals—nurses, pediatricians, family doctors—have received certified training as part of a WHO mental health program.” 

Meanwhile, more than 300 “resilience centres” welcome children and parents across the country, with three hundred more expected to be built next year, according to Ukrainian Social Affairs Minister Denys Uliutine. 

New concepts are also being tested and tried.

Children leave an underground school in Kharkiv, on October 16, 2025. OLEKSII FILIPPOV / AFP

In Kharkiv, underground schools – located beneath the streets of the city – are being set up to help bring children back into the classroom.

City authorities told AFP there would be 10 underground schools operational by the end of 2025.

At a school visited by AFP, a rotating system allows it to continue offering children in-person education, even if only for a limited time, each week. The school enables every  child to attend  half a day of their class in-person each week. When the  child returns home they continue their education via remote classes, while another student comes into school for their half day spot. This allows the school to accommodate 1,400 children, including on weekends. 

Yet recent events in Kharkiv highlight that normal life is far from returning, despite recent peace efforts.

At the end of October, a kindergarten in the west of the city was struck by a Russian drone.

Footage from the scene showed panicked parents and disoriented children being carried from away by emergency workers as smoke billowed from the kindergarten.

Despite the scale of the destruction visible in social media footage, only one person (an adult male) was reported to have died during this strike.

For many youngsters in Ukraine, there may be no reclaiming the childhood that war has taken from them.

But Bohdan Levchykov in Balakliia believes there are still things to look forward to.

He told AFP about  the friends he had made online   – including one named Lana who lives more than 400km away in the city of Dnipro- and his  hopes of  meeting them in real life one day.

“I’ve talked about it with my mother,” he told AFP. 

“Maybe our parents can arrange something for us to meet,” he said hopefully.


Eoghan Macguire, Youri van der Weide and Logan Williams contributed to this report for Bellingcat as did Stéphanie Ladel and Olivia Gresham from Bellingcat’s Volunteer Community.

Boris Bachorz reported and conducted interviews for AFP with the help of Natalia Yermak.

A version of this story can be found on the website of the Central European Digital Media Observatory (CEDMO) website.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Twitter here and Mastodon here.

The post How Russia’s Invasion is Impacting Ukraine’s Youth appeared first on bellingcat.

Russia’s Smuggled Grain Finds New Market in Saudi Arabia

A joint investigation by Bellingcat and Lloyd’s List has identified Saudi Arabia as the newest country to import grain directly from a Western-sanctioned port in occupied Crimea, as Russia attempts to secure recognition of the Ukrainian territory via a US-led peace plan.

Satellite imagery and Automated Identification System (AIS) data from Lloyd’s List Intelligence shows the bulk carrier Krasnodar (IMO: 9296781) sailed from Avlita Grain Terminal in Sevastopol to Saudi Arabia on two occasions between September and November 2025. Bellingcat confirmed Krasnodar’s journeys ended at Saudi Arabia’s King Abdullah Port in September and the Port of Jazan in November.

These journeys show that Saudi Arabia has joined buyers in Iran, Syria, Egypt, Turkey, Venezuela and Houthi-controlled territories in Yemen who are willing to accept what the Ukrainian government describes as “stolen” grain. 

MapLibre | Protomaps© OpenStreetMap contributors

Black Sea

Krasnodar goes dark – an AIS gap lasting more than two weeks begins on August 22.

Occupied Crimea: Port of Sevastopol

Imagery shows Krasnodar docked at Berth 21 of the Avlita grain terminal at the Port of Sevastopol on August 27.

Credit: Planet Labs PBC

Black Sea

Krasnodar turns its AIS back on in the Black Sea, as required to transit the Bosphorus on September 6.

Bosphorus Strait

Krasnodar transits the Bosphorus. Judging by the draft, with no visible red paint on its hull, the ship appears to be fully laden.

Credit: Yörük Işık

Saudi Arabia: King Abdullah Port

Imagery (as well as AIS data) shows Krasnodar docked at the King Abdullah Port. A pile of what appears to be grain is visible to the right of the image on September 18.

Credit: Planet Labs PBC

Bosphorus Strait

Returning via the Suez Canal, Krasnodar transits through the Bosphorus on September 28 with its red paint fully visible, indicating it is not heavily laden.

Credit: Yörük Işık

Black Sea

Krasnodar goes dark – an AIS gap lasting more than one week begins on October 6.

Occupied Crimea: Port of Sevastopol

Satellite imagery shows Krasnodar docked, with its hatches open, at Berth 21 of the Avlita grain terminal on October 8.

Satellite image ©2025 Vantor

Black Sea

Krasnodar turns its AIS back on in the Kerch strait. After a few days loitering in the Kerch strait, it transits through the Bosphorus.

Bosphorus Strait

With no red paint visible and the Plimsoll line near maximum draft, the vessel appears to be fully laden when it transits the Bosphorus on October 26.

Credit: Yörük Işık

Saudi Arabia: Jazan City

AIS data shows Krasnodar docked at Jazan City for Primary and Downstream Industries for seven days. Planet imagery captured it on November 6.

Credit: Planet Labs PBC

After leaving Jazan, Krasnodar returned to the Black Sea via the Bosphorus on November 23.

It stopped transmitting AIS for a third time on November 24 for nine days and has been intermittently transmitting data since.

Krasnodar was again captured in satellite imagery docked at the Avlita terminal in Sevastopol on November 26. 

Krasnodar captured in satellite imagery docked at the Avlita terminal in Sevastopol on November 26. Credit: Planet Labs PBC

Petrokhleb-Kuban Denies Visiting Avlita Terminal

Documents accessed on Russia’s federal registry indicate the vessel is leased by Russian firm Petrokhleb-Kuban, a major player in Russian and international grain markets. 

Petrokhleb Kuban told Bellingcat it “categorically denies any allegations of involvement in the theft of grain from Ukrainian regions”.

It added that Petrokhleb-Kuban does not export grain from the Avlita terminal to any country.

“Petrokhleb-Kuban does not operate at the port of Avlita and does not ship grain from there. All grain shipped by Petrokhleb-Kuban is produced by Russian farmers,” a spokesperson said. 

“The vessel Krasnodar follows all widely accepted safety protocols and does not disable its AIS while on passage. The AIS signal in the Black Sea is being jammed by the military due to the ongoing conflict between Russia and Ukraine.”

The spokesperson also said the vessel Krasnodar was loading barley at the port of Kavkaz, “as confirmed by bills of lading and port clearance.”

AIS interference is rampant in the Black Sea, however, instances of jamming typically do not last more than a couple of days. Further, third-party disruptions impact all vessels in one area indiscriminately. 

Bellingcat reviewed the AIS traces of vessels sailing near Krasnodar. In both voyages, Krasnodar was the only vessel in that area that stopped transmitting AIS data for that period of time.  

Bellingcat also checked available Planet Labs PBC and Sentinel-2 satellite imagery covering the grain terminal in Port Kavkaz during the two periods of August and October where Krasnodar has absent or unreliable AIS coverage and found no vessels matching the length of the Krasnodar.

Bellingcat identified Krasnodar in Avlita terminal on three occasions, by cross referencing satellite images of Krasnodar and recent images and video of the ship. Krasnodar was last detected at Avlita terminal in satellite imagery on November 26, again with its AIS switched off.  Krasnodar’s chimney is navy blue in colour, except for a white band on the left, right, and front side of the chimney. The ship’s other features – five grey hatches, four grey cranes, a red deck, a green floor on the bridge, all visually match known images of the ship.

Finally, the ship’s measurements (a total length of 183 metre according to Russia’s shipping registry) matches what we see in satellite images.

Visual Comparison: Images of Krasnodar at Avlita Terminal and other recent images of Krasnodar

The Krasnodar has a dark blue (midnight navy blue) chimney with a white band that runs around the sides and the front of the chimney, leaving the back completely blue.

A close up of the Krasnodar photographed in the Bosphorus on October 26, 2025. Credit: Yörük Işık.

The life boats are immediately to the left and right of the bridge. The boats can also be seen in satellite imagery from Saudi Arabia. The image below shows Krasnodar in Jazan.

Krasnodar seen in Satellite Image at the Port of Jazan, Saudi Arabia on November 6, 2025. Credit: Planet Labs PBC.

Satellite imagery also clearly shows the colour of deck (dull red), the floor colour of the bridge (green), the colour of the hatches and the cranes (grey). All of that, as well as the chimney (navy blue with white) can be matched with satellite imagery from Sevastopol that show Krasnodar docked at the Avlita grain terminal.

Left: Krasnodar seen in Satellite Image at the Port of Jazan, Saudi Arabia on November 6, 2025. Right: Krasnodar seen in Satellite Image docked at Avlita grain terminal in the Port of Sevastopol on October 8, 2025. Credits: Planet Labs PBC and 2025 Vantor.

Five grey hatches and a red deck. The image on the left is from Jazan (November 6). The image on the right is from Sevastopol (October 8).

A close up of the above images. Credits: Planet Labs PBC and 2025 Vantor.

If we zoom in on the bridge, we can also see that the shape and the colour (grey) of the top of the bridge are also a visual match. 

The chimney is not very clearly visible in the image from Jazan but it is clear that the chimney is dark in colour. The image from Sevastopol shows a dark blue chimney with a white band, which was also visible in images and video of Krasnodar.

Left: Krasnodar seen in Satellite Image docked at Avlita grain terminal in the Port of Sevastopol on October 8, 2025. Right: A close up of the Krasnodar taken in the Bosphorus on October 26, 2025. Credits: 2025 Vantor and Yörük Işık. Annotations by Bellingcat.

We see red on the hull, below the water line, in the Sevastopol satellite image. You can also see it in the image from when the ship transited the Bosphorus. The rest of the hull is dark.

Left: Krasnodar seen in Satellite Image docked at Avlita grain terminal in the Port of Sevastopol on October 8, 2025. Right: Krasnodar photographed in the Bosphorus on October 26, 2025. Credits: 2025 Vantor and Yörük Işık.

There are no live or historic sanctions on Krasnodar, according to Lloyd’s List Intelligence data.

Saudi Arabia Joins List of Importers of Russia’s Smuggled Grain


Krasnodar’s voyages from Sevastopol to Saudi Arabia demonstrate that Russia is continuing to expand its grain exports from occupied Crimea to new markets as it negotiates to end the war in Ukraine.

Crimea’s occupied ports have become important assets for Moscow, having evolved into key logistics hubs for dark grain exports over the course of the war.

Prior to the full-scale invasion of Ukraine in 2022, the ports in occupied Crimea were used for the small-scale export of grain and scrap metal, mostly to Syria and Turkey.

The occupation of additional territory in Donetsk and Zaporizhia enabled Russia to establish a new supply route, resulting in more grain being shipped south to Crimea for export to international markets.

The Port of Sevastopol and the Avlita grain terminal remain under European, UK and US sanctions. While no UN sanctions specifically target the port, a majority of UN member states have passed resolutions condemning Russia’s invasion of Ukraine and its occupation of Crimea since 2024. 

Ukraine has repeatedly tried to dissuade countries from purchasing shipments loaded with what it describes as “stolen” grain from occupied regions.

In 2023, Iran received its first grain shipments from Sevastopol. In 2024, it was joined by Venezuela, Libya, Egypt and the Houthis, which control territory in Yemen. Last month, Bellingcat revealed that the bulk carrier Irtysh (IMO: 9664976) delivered grain from the Crimean port of Sevastopol to the Houthi-controlled port of Saleef in Yemen despite Western Sanctions. 

Bellingcat and other news outlets have identified a total of eight countries that have imported grain directly from occupied Crimea.

While Saudi Arabia is the latest direct importer from Sevastopol, it is unclear if authorities are aware of the origin of the cargo. 

The grain shipments follow a similar pattern to Russia’s shadow fleet, which moves sanctioned oil barrels. In both cases steps are taken to disguise the origin of the cargo and port of loading.

Most ships calling to Crimea disable their AIS transponders, which is considered a deceptive shipping practice, and fraudulent documents are issued. 

Alona Shkrum, First Deputy Minister for Development of Communities and Territories of Ukraine, told Bellingcat that Ukraine was closely monitoring Russian exports from occupied territories. She said Ukraine had discussed the issue with Saudi Arabia on the sidelines of recent talks at the International Maritime Organisation Assembly.

She told Bellingcat that Ukraine had “received assurances that Saudi authorities are actively counteracting the risks posed by shadow fleet operations and other violations of international maritime law.” 

She added that Ukraine would continue to work with partners to identify and sanction vessels involved in the illegal export of grain from occupied territories. 

Bellingcat contacted both the Saudi Arabian Ministry of Foreign Affairs and the Russian Ministry of Foreign Affairs; neither responded to requests for comment. 

US-Russia Peace Plan and Ownership of Ukraine’s Ports


The US-Russia 28-point peace proposal includes the recognition of Crimea, Luhansk and Donetsk as “de facto” Russian. Ownership of Crimea and the occupied territories bordering the Sea of Azov is critical for securing shipping routes to and from Russia, and these ports play a vital role in supporting economic growth in the region. 

However, the impact of ceding control of this region and the port of Sevastopol to Russia is not mentioned in either the original US draft plan or subsequent amended versions.

Ian Ralby, chief executive of the maritime and resource security consultancy I.R. Consilium said while it was a high priority for Ukraine to ensure access to the grain market through the Black Sea is preserved, Russia is continuing to try to expand its global access to ports. 

“We see that there is a resurgence in Russia’s efforts on port access.”

“As the prospect of potential peace begins to loom, even though it seems to be much farther off than many would want, there is likely to be a renewed focus on the key strategic assets that matter for the future, and the ports have to be foremost among them.” 


Bridget Diakun, Yörük Işık, Youri van der Weide, Peter Barth and Galen Reich contributed to this report.

Cover image: Planet Lab image shows Krasnodar docked at Jazan City, Saudi Arabia on November 6. Credit: Planet Labs PBC.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Twitter here and Mastodon here.

The post Russia’s Smuggled Grain Finds New Market in Saudi Arabia appeared first on bellingcat.

From School to Battlefield to Grave: How Russian Cossacks drive young people to war

From School to Battlefield to Grave

How Russian Cossacks drive young people to war

This video was posted in April 2024 by Беркут, a student association within a Russian Federal University.

Students, about to leave for an Airsoft competition, stand in military formation outside a campus building.

This is Олег Монин who took Berkut’s oath four months earlier. Through this veiled Cossack Youth Organisation, he trained in combat tactics with returned fighters and transitioned from pretend to real weapons.

Within a year, Oleg abandoned his studies and enlisted in БАРС-15, a Cossack Volunteer Battalion fighting in Ukraine.

By Feb. 10, 2025 Oleg was dead. He died aged 19, less than four months after deployment in Ukraine.

As of February 2025 there were more than 18,500 Cossacks on the front lines in Ukraine and approximately 50,000 in the army reserve.

Cossack societies, organisations, and even military units provide an identity that is indigenous to Russia, Visiting Assistant Professor at Miami University, Dr Marcello Fantoni told Bellingcat.

This identity is “rooted in ‘traditional’ values, martial prowess, military readiness, orthodox religiosity and a culture not influenced by the ‘corrupting’ West,” Fantoni added via email. This is why “education is central to the overall enterprise”.

Oleg’s story demonstrates how the Cossacks drive young people from a school club to a war zone and enable a state-sponsored alternative mobilisation force.

WHO ARE THE RUSSIAN COSSACKS?

The Cossacks played an important role in the formation of the Russian Empire. They lived in communities called hosts on the edges of the empire. They operate under a military hierarchy ruled by a chief, the Ataman. Due to their loyalty to the Tsar, the Cossacks were repressed by the Bolsheviks after 1917.
Credit: Journal “Chronicle of War”, 1915; Nicholas II among officers

When the Soviet Union collapsed in 1991, the Cossacks’ descendants called for a “rebirth”. In 2005, a bill submitted by President Vladimir Putin allowed registered Cossack organisations members to serve in military units and police forces.
Credit: tamvesti.ru

New hosts were created in traditionally non-Cossack lands with a variety of institutions to direct them. In 2018, the government united them in the “All-Russian Cossack Society”. Putin tries to marginalise the traditional Cossack groups, analyst Paul Goble told Bellingcat while the ones “he has created for his own purposes” play a “major role in military and patriotic education”.
Credit: Kremlin

There are 13 registered Cossack Hosts across all of Russia.

Only 8 of Russia’s 83 recognized Federal Subjects do not have a registered Cossack Host.

In 2018, the Black Sea Cossack Host of Crimea entered the register. The peninsula has been under Russian occupation since 2014. The Cossack legacy is also vitally important to Ukrainian identity.

There are new hosts in the occupied Ukrainian territories of Kherson, Zaporizhzhia, Donetsk, and Luhansk.

Russian Cossack organisations have been “very active within the occupied Ukrainian regions,” Dr Fantoni told Bellingcat. They “recruit local residents and then deploy them for cultural and military purposes,” allowing Russia “to contest and even co-opt a central tenet of Ukrainian national identity – Cossackdom,” he said.

The national “All-Russian Cossack Society” VSKO was created in 2018, and in 2019, the State Duma gave Russian President Vladimir Putin exclusive authority to appoint its national Ataman.

Credit: Portal 'Russian Cossacks'; Vitaly Kuznetsov

At the top of the VSKO is Ataman Vitaly Kuznetsov, a Cossack General.

Credit: All-Russian Cossack Society; Vitaly Kuznetsov and Nikolai Doluda

Kuznetsov was appointed in November 2023, succeeding the first-ever national Ataman – Nikolai Doluda, then 70 years old and a sanctioned individual.

Kuznetsov has also become a leading Cossack interacting with the Russian state.

Credit: Kremlin; Dmitry Mironov and Vitaly Kuznetsov

Including with Dmitry Mironov, assistant to President Putin and Chair of the Council for Cossack Affairs.

Credit: All-Russian Cossack Society; Vitaly Kuznetsov and Dmitry Chernyshenko

And Deputy Prime Minister of Russia Dmitry Chernyshenko.

Credit: All-Russian Cossack Society; Vitaly Kuznetsov and Leonid Pasechnik

As well as Leonid Pasechnik, head of the Luhansk People’s Republic. Kuznetsov thanked Pasechnik in June for helping create three Cossack Cadet Corps in the occupied region.

Credit: Portal 'Russian Cossacks'; Vitaly Kuznetsov with Cossack students of the K.G. Razumovsky Moscow State University of Technology

According to Kuznetsov, the VSKO priorities are “development of military Cossack societies in all directions: education, culture, history, and most importantly, youth. Everything through youth.”

EVERYTHING THROUGH YOUTH

Cossack education can be divided into primary, secondary, and tertiary levels, all with the goal of promoting a unified system.

Credit: sestroretsk.com; Cossack kindergarten pupils

At the primary level are the Cossack kindergartens, which compete nationally to be named the best.

Credit: MOU 'Secondary School No. 43 named after V.F. Margelov'; Cossack students

There are Cossack schools and regular schools with a Cossack affiliation. Data from 2022 claim there were just under 2000 such institutions with around 210,000 students, but recent claims point to over 300,000 students.

Credit: shakhty-media.ru; Cossack Cadets

The most intense level of Cossack education is the Cossack Cadets Corps, of which there are 31 across the country, with the newest corps created in Russia’s Far East. They also compete nationally.

Credit: Moscow State University of Technology and Management named after K.G. Razumovsky (PKU); Cossack University graduation ceremony

Finally, the Association of Cossack Universities has 26 members, with many concentrated in Rostov and Krasnodar. There is also a Union of Cossack Youth, which in 2022 had more than 163,000 members. More than 5,500 Cossack youth took part in military exercises on training grounds in 2023.

Oleg’s story demonstrates how young people outside formal Cossack education can still get pulled in. It also shows that the Cossacks are but one of several interlaced strategies for “military-patriotic” education.

Oleg grew up in Saratov.

Image of youth practicing putting on a gas mask, posted on VKontakte by Lyceum N.3.
Credit: Image of youth practicing putting on a gas mask, posted on VKontakte by Lyceum N.3.

He studied in Lyceum N.3, a state-funded educational institution in Saratov. Often, the school promotes events like the national Zarnitsa competition. It includes activities like “putting on gas masks” or “sniper games” for third graders.

Credit: Military student club 'Fakel'; Students in military fatigues at an Avangard 24h training.

The school’s military club “Fakel” acts as an intermediary for these events and other nationwide military education initiatives such as the 24-hour-long Avangard training for tenth graders.

Credit: MAOU 'Lyceum No. 3 named after A.S. Pushkin'; School director receives an award for contribution to patriotic education.

In 2024, Natalia Saprykina, the director of Lyceum N.3, was awarded a Letter of Gratitude for her “contribution to the patriotic education of the younger generation” by a Deputy of the Regional Duma.

Oleg graduated from high school in 2023 at the age of 17.

In the same year he enrolled in InPIT, a higher education institution of the Saratov State Technical University.

By November Oleg had turned 18 and was wearing military fatigues and practising survival skills alongside other candidates of a “military-patriotic” student association named Berkut, at another local university, the Saratov State Law Academy (SSLA).

Credit Telegram @infberkut; Photo from Berkut's survival skills training.

Though Berkut is not explicitly a Cossack organisation, we established several connections between the head of Berkut, Alexander Andreevich, and Cossack organisations. As we’ll see, Andreevich was present at multiple military style training camps that Oleg took part in.

Neither Berkut’s VKontakte nor Telegram channel descriptions mention the Cossacks.

Credit: VKontakte @svpo_berkut; Translated screenshot of Berkut's VKontakte description.

Neither does its page in the University website.

Credit: SSLA; Screen grab of Berkut's page in the SSLA website.

The association’s official objectives are “forming a positive image of military service” and “popularisation of service in the Russian army and law enforcement agencies”. It is headed by Alexander Andreevich.

Credit VKVideo @svpo_berkut: Still from one of Berkut's VK videos.

However, some of Berkut’s videos include the banner of a Молодёжная казачья организация.

Credit: Telegram @atamanfetisov; Translated Telegram post by Andrey Fetisov.

A Telegram post by Andrey Fetisov, the Saratov District Ataman, refers to Berkut as a “Cossack Youth Movement”.

Even though Berkut (left) shares a name and eagle iconography with a notorious Ukrainian special police force (right), part of which defected to Russia during the occupation of Crimea in 2014, Bellingcat found no link between the two organisations.

Credit: VKVideo @svpo_berkut; Berkut Logo
Credit: Wikipedia; Emblem of the Berkut special police force of Ukraine.
FROM WAR GAMES TO REAL WEAPONS

By December 2023, nearing the end of the first semester, Oleg and the other candidates took the Berkut oath, making them official members. Oath-taking ceremonies are “invented traditions” among Cossack forces.

Credit: VKontakte @svpo_berkut; Berkut Oath Ceremony

Atop the dais stand senior members of Berkut, including the head of the organisation – Alexander Andreevich.

Credit: VKontakte @svpo_berkut; Berkut Oath Ceremony

Andreevich is an active Cossack who has been working under the guidance of District Ataman Andrey Fetisov since at least April 2023.

Credit: Instagram @fetisov_; Alexander Andreevich and Andrey Fetisov

More recently, in January 2025, they were both delivering a lesson to Cossack children for Yunarmiya, exemplifying the overlapping network of youth militarisation initiatives.

In July 2025, they both attended Saratov’s Council of Atamans that was hosted at the Ministry of Internal Policy and Public Relations of Saratov. Local organisations often meet there.

Credit: VKontakte Sergey Frolov; Alexander Andreevich and Andrey Fetisov at a Saratov council meeting.

In August 2024, Andreevich attended the iVolga Cossack Youth Festival, where he met Kuznetsov. The only two people featured speaking in an official video.

Credit: VKontakte @svpo_berkut; Alexander Andreevich and Vitaly Kuznetsov at a Cossack Youth Festival

Andreevich also led Oleg to two military-inspired events in April 2024.

The first, on April 13, was the annual Airsoft competition.

Credit: VKontakte War Games: Operation Satellite; Berkut members stand in formation at the Airsoft event
Credit: VKontakte @svpo_berkut; Oleg and other Berkut members inside a training helicopter

Five days later they went to a training that included trench tactics and simulated helicopter jumps.

Credit: VKontakte Alexander Andreevich; Oleg, Andreevich and other Berkut members at Rosgvardia training ground

Since 2023, Oleg often wore a distinctive yellow and red “Скорпион” call sign patch on his chest when wearing military fatigues, which distinguishes him from other youth at the events. That and other distinctive features identify him even with a mask or goggles.

Credit: Vkontakte Oleg Monin; Profile picture from Oleg's VK and Telegram posted on 2023-09-10
Credit: Vkontakte Oleg Monin; Profile picture from Oleg's VK posted on 2023-04-13

Bellingcat was able to geolocate this place to be a Rosgvardia training ground on the outskirts of Saratov.

Credit: VKontakte @svpo_berkut; Graphics for the geolocation of training in Rosgvardia training grounds

Notably, the trenches are not visible on Google Earth but are on Yandex Maps, which has more recent imagery for the region.

Credit: VKontakte @svpo_berkut; Trenches photo from Rosgvardia training grounds
Credit: VKontakte @svpo_berkut; Berkut at Rosgvardia training

This group photo tells its own story. The flags visible are, from left to right, for the Volga Cossack Host, the Immortal Regiment, the Kuban Cossack Host, and Veteran News.

Oleg is at the far right wearing his “Scorpion” and Berkut patches.

This time, ex-fighters were there too.

Sergey Frolkov is an ex-fighter in the war on Ukraine. He regularly posts photos with an Akhmat special forces patch, associated with Kadryovites . He is also a member of the local Combat Brotherhood association.

Credit: VKontakte Sergey Frolkov; Cropped photo of Sergey Frolkov

As is Oleg Mysov, another returned fighter who also engages in “patriotic education of youth” events.

Credit: VKontakte Oleg Mysov;Cropped photo of Oleg Misov

Both have attended Cossack events. Even though in this photo they are holding the Volga Cossack Host flag, Bellingcat could not clearly identify them as Cossacks.

A third man, Andrey Berdnikov is indeed a Cossack and a former fighter of BARS-15, the Battalion Oleg joined, though he was reportedly expelled by his Commander. On the left, Alexander Andreevich.

Credit: VKontakte PATRIOT; Cropped photo of Andrey Berdnikov

Bellingcat contacted Sergey Frolkov, Oleg Mysov and Andrey Berdnikov before publication to ask about their roles, but did not receive a response.

Five months later, in September 2024, Oleg went on a two-day training. Andrey Fetisov got a special thanks for the opportunity.

Credit: VKontakte Andrey Fetisov; Photo from the Sep 2024 training featuring Oleg

Bellingcat geolocated it to a military training ground in Samara, the same location where other Cossack recruits trained before deploying to BARS-15. Fetisov himself shared photos of this training ground two weeks after stepping down as Ataman to join BARS-15. Andreevich left and Oleg right in this photo.

Credit: VKontakte Andrey Fetisov; Geolocation graphics with Oleg and Andreevich

They used real weapons this time. A video montage shows participants firing live rounds.

Credit: VKontakte Andrey Fetisov

This is a photo that includes Oleg, Fetisov, and Andreevich. The first media we found for this event is from early September which is consistent with the sun position in this photo and the grass patches seen in satellite imagery from early September 2024.

Credit: VKontakte Andrey Fetisov; Geolocation graphics of photo with Oleg, Andreevich, and Fetisov

Bellingcat contacted Kuznetsov, Fetisov and Andreevich to ask about their roles in the Cossack community, but they haven’t responded.

This is the last time Bellingcat was able to trace Oleg’s whereabouts with open sources before he joined BARS-15.

VOLUNTARY RECRUITMENT

Many countries have a volunteer reserve system for getting more soldiers in times of war. In Russia, the system is known as BARS, created in 2015 and intensified in 2021. All BARS fighters sign a contract with the Ministry of Defense and get paid.

Mapping the geolocated positions of these units in the UAControlMaps Project dataset reveal widespread areas of operations. BARS Battalions are often reorganised. Estimates put the total number so far at over 30 BARS Battalions and 10 of them have overt Cossack affiliation.

Cossacks also operate as detachments in other military structures. By their own reckoning, in February there were more than 18,500 Cossacks on the front lines in Ukraine. In May the first-ever national Ataman, Nikolai Doluda, gave a higher figure of 46,000 Cossacks.

As of 2024, British Professor Rod Thornton estimated that BARS constitute some 10-30,000 troops in Ukraine, 15% of the total invasion force.

The Mediazona project tracks individual Russian losses in Ukraine and publishes bi-weekly reports. As of Nov. 21, 2025, they identified 149,241 publicly named casualties, Oleg among them.

The project also tracks volunteer casualties.

Deaths of volunteer fighters constituted 12.8% of losses in 2022 and 21.9% 2023. In 2024 they more than doubled to 45.7%. As of Nov. 21, verified deaths of volunteer fighters for 2025 were at 42.8%.

BARS-15

BARS-15 is a Cossack battalion created on May 15, 2022, and named Ермак after a historical Ataman. Originally composed of Cossacks from multiple hosts, mainly Volga and Oremburg, it now draws its members from the Volga Host only.
Credit: All-Russian Cossack Society

These are some of BARS-15 specific patches.

Credit: Telegram @bars15ermak; BARS-15 patch
Credit: OK Alexander Cherepanov; BARS-15 patch
Credit: VKontakte Kolya Karbon; BARS-15 patch
Credit: Telegram @izvestia64; BARS-15 patch
Credit: VKontakte @atamanovko; BARS-15 patch
Credit: VKontakte @atamanovko; BARS-15 patch
Credit: Rutube SAMARA | 450media; BARS-15 patch
Credit: Telegram @vskoru; BARS-15 patch
Credit: Telegram @vvko_russia; BARS-15 patch

While in BARS-15 Oleg was reportedly assigned to the 15th Separate Guards Motor Rifle Brigade. Several sources place BARS-15 as subordinate to the 15th Separate Guards Motor Rifle Brigade also known as the Black Hussars, headquartered at the Samara Oblast. Bellingcat geolocated this video from September 2024 to their training grounds.

Credit: VKontakte Oleg Monin; Profile picture from Oleg's VK posted on 2023-04-13

The panel reads Black Hussars. Oleg is on his knee in front of Andreevich, wearing his distinctive “Scorpion” patch.
Credit: VKontakte @svpo_berkut

The number of active Cossack fighters in BARS-15 is reportedly 400, a number echoed by a former Commander, with other sources saying over 900 volunteers have passed through as of September 2024. They reportedly took part in the invasion of Avdiivka among other combat activities in Ukrainian cities both in Donetsk and Luhansk.
Credit: VKontakte @vvko_russia

Bellingcat geolocated this warehouse to the west of Selydove, Donetsk, using satellite imagery and reference images from when the warehouse was a concrete products factory.

Credit: LLC 'Sembiz-1' Selidovsky Reinforced Concrete Plant; Geolocation graphics over crop from facebook image of warehouse
Russia captured Selydove in October 2024. BARS-15 posted from there in January 2025 and June 2025.

One of its former members is Andrey Fetisov, who temporarily stepped down as Saratov District Ataman and joined BARS-15 between approximately November 2023 and June 2024.
Credit: Telegram @izvestia64

The identification of Fetisov’s call sign – СЛЕНГ – suggests he took on military roles such as “Deputy Commander for Educational Work” and “Political Officer”.

In April 2024, Fetisov received a Medal for Bravery from Vitaly Kuznetsov, the national Ataman. Within six months, Fetisov would be taking Oleg to the BARS-15 training camp.
Credit: Telegram @izvestia64

There are many reasons why people are motivated to join Cossack groups, Dr Fantoni told Bellingcat, adding that these motivated individuals “are the driving force” behind militarisation. “Some do it out of patriotic motivations, others for political, economic or individual status gain, some even because this can protect oneself from future mobilisation to an actual fighting unit,” he said.

In the end

Oleg’s connection to the Cossacks was not typical. He did not attend a Cossack school or university and still found himself in their midst via the military youth groups he joined. As his story demonstrates, Cossacks are embedded into the education system. Their involvement includes Berkut showcasing Kalashnikovs to kids in a mall, a teacher and returned BARS-15 fighter weaving camouflage nets with children, a former BARS-15 commander giving inspirational lessons to young students, and Cossack cadets drawing “heartfelt mementoes” to send to BARS-15.

The Russian government announced that funding for the Cossacks will double in the next two years and it continues to implement its Strategy in relation to the Russian Cossacks 2021-2030.

The first-ever national Ataman and Kuznetsov’s predecessor, Nikolai Doluda, is working on a new national law on the Cossacks and the creation of a mobilisational reserve from the Cossacks.

This image first appeared on Oleg’s obituary posted by Fetisov. The vehicle, road, and equipment are consistent with those used by other fighters with the Black Hussars around February 2025.

According to recruitment posts BARS-15 training takes three weeks. A recent study found that to be the norm in Russia’s military while also labelling training as “low-quality and ineffective”.

Oleg’s obituary, published by his University states that “based on the results of training, he was appointed commander of a 120 mm mortar crew”.

Bellingcat reached out to Oleg’s parents.
His mother said she couldn’t speak about Oleg’s death,

it still hurts too much.

Additional research by Timothy B, Afton Briones, Sarah Grossman, Alexandra Malikova, Mitchell Polman, Olivia Gresham, Bonny Albo, Adam Arthur, Robert Chapman of the Bellingcat Volunteer Community.

Youri van der Weide and Aiganysh Aidarbekova contributed to this report.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here and Mastodon here. With the unpredictability of social media algorithms making it harder for news outlets to reach audiences consistently, we have also started a WhatsApp channel that you can join to stay updated on our stories.

Satellite images are courtesy of Yandex, Maxar, Airbus, MapBox and Google Earth.

Co-funded by the European Union. Views and opinions expressed are those of the author(s) only and do not necessarily reflect those of the European Union or the European Health and Digital Executive Agency (HADEA). Neither the European Union nor the granting authority can be held responsible for them.

The post From School to Battlefield to Grave<span id="hide-colon">:</span> <span class="subtitle">How Russian Cossacks drive young people to war</span> appeared first on bellingcat.

Meet Rey, the Admin of ‘Scattered Lapsus$ Hunters’

A prolific cybercriminal group that calls itself “Scattered LAPSUS$ Hunters” has dominated headlines this year by regularly stealing data from and publicly mass extorting dozens of major corporations. But the tables seem to have turned somewhat for “Rey,” the moniker chosen by the technical operator and public face of the hacker group: Earlier this week, Rey confirmed his real life identity and agreed to an interview after KrebsOnSecurity tracked him down and contacted his father.

Scattered LAPSUS$ Hunters (SLSH) is thought to be an amalgamation of three hacking groups — Scattered Spider, LAPSUS$ and ShinyHunters. Members of these gangs hail from many of the same chat channels on the Com, a mostly English-language cybercriminal community that operates across an ocean of Telegram and Discord servers.

In May 2025, SLSH members launched a social engineering campaign that used voice phishing to trick targets into connecting a malicious app to their organization’s Salesforce portal. The group later launched a data leak portal that threatened to publish the internal data of three dozen companies that allegedly had Salesforce data stolen, including ToyotaFedExDisney/Hulu, and UPS.

The new extortion website tied to ShinyHunters, which threatens to publish stolen data unless Salesforce or individual victim companies agree to pay a ransom.

Last week, the SLSH Telegram channel featured an offer to recruit and reward “insiders,” employees at large companies who agree to share internal access to their employer’s network for a share of whatever ransom payment is ultimately paid by the victim company.

SLSH has solicited insider access previously, but their latest call for disgruntled employees started making the rounds on social media at the same time news broke that the cybersecurity firm Crowdstrike had fired an employee for allegedly sharing screenshots of internal systems with the hacker group (Crowdstrike said their systems were never compromised and that it has turned the matter over to law enforcement agencies).

The Telegram server for the Scattered LAPSUS$ Hunters has been attempting to recruit insiders at large companies.

Members of SLSH have traditionally used other ransomware gangs’ encryptors in attacks, including malware from ransomware affiliate programs like ALPHV/BlackCat, Qilin, RansomHub, and DragonForce. But last week, SLSH announced on its Telegram channel the release of their own ransomware-as-a-service operation called ShinySp1d3r.

The individual responsible for releasing the ShinySp1d3r ransomware offering is a core SLSH member who goes by the handle “Rey” and who is currently one of just three administrators of the SLSH Telegram channel. Previously, Rey was an administrator of the data leak website for Hellcat, a ransomware group that surfaced in late 2024 and was involved in attacks on companies including Schneider Electric, Telefonica, and Orange Romania.

A recent, slightly redacted screenshot of the Scattered LAPSUS$ Hunters Telegram channel description, showing Rey as one of three administrators.

Also in 2024, Rey would take over as administrator of the most recent incarnation of BreachForums, an English-language cybercrime forum whose domain names have been seized on multiple occasions by the FBI and/or by international authorities. In April 2025, Rey posted on Twitter/X about another FBI seizure of BreachForums.

On October 5, 2025, the FBI announced it had once again seized the domains associated with BreachForums, which it described as a major criminal marketplace used by ShinyHunters and others to traffic in stolen data and facilitate extortion.

“This takedown removes access to a key hub used by these actors to monetize intrusions, recruit collaborators, and target victims across multiple sectors,” the FBI said.

Incredibly, Rey would make a series of critical operational security mistakes last year that provided multiple avenues to ascertain and confirm his real-life identity and location. Read on to learn how it all unraveled for Rey.

WHO IS REY?

According to the cyber intelligence firm Intel 471, Rey was an active user on various BreachForums reincarnations over the past two years, authoring more than 200 posts between February 2024 and July 2025. Intel 471 says Rey previously used the handle “Hikki-Chan” on BreachForums, where their first post shared data allegedly stolen from the U.S. Centers for Disease Control and Prevention (CDC).

In that February 2024 post about the CDC, Hikki-Chan says they could be reached at the Telegram username @wristmug. In May 2024, @wristmug posted in a Telegram group chat called “Pantifan” a copy of an extortion email they said they received that included their email address and password.

The message that @wristmug cut and pasted appears to have been part of an automated email scam that claims it was sent by a hacker who has compromised your computer and used your webcam to record a video of you while you were watching porn. These missives threaten to release the video to all your contacts unless you pay a Bitcoin ransom, and they typically reference a real password the recipient has used previously.

“Noooooo,” the @wristmug account wrote in mock horror after posting a screenshot of the scam message. “I must be done guys.”

A message posted to Telegram by Rey/@wristmug.

In posting their screenshot, @wristmug redacted the username portion of the email address referenced in the body of the scam message. However, they did not redact their previously-used password, and they left the domain portion of their email address (@proton.me) visible in the screenshot.

O5TDEV

Searching on @wristmug’s rather unique 15-character password in the breach tracking service Spycloud finds it is known to have been used by just one email address: cybero5tdev@proton.me. According to Spycloud, those credentials were exposed at least twice in early 2024 when this user’s device was infected with an infostealer trojan that siphoned all of its stored usernames, passwords and authentication cookies (a finding that was initially revealed in March 2025 by the cyber intelligence firm KELA).

Intel 471 shows the email address cybero5tdev@proton.me belonged to a BreachForums member who went by the username o5tdev. Searching on this nickname in Google brings up at least two website defacement archives showing that a user named o5tdev was previously involved in defacing sites with pro-Palestinian messages. The screenshot below, for example, shows that 05tdev was part of a group called Cyb3r Drag0nz Team.

Rey/o5tdev’s defacement pages. Image: archive.org.

A 2023 report from SentinelOne described Cyb3r Drag0nz Team as a hacktivist group with a history of launching DDoS attacks and cyber defacements as well as engaging in data leak activity.

“Cyb3r Drag0nz Team claims to have leaked data on over a million of Israeli citizens spread across multiple leaks,” SentinelOne reported. “To date, the group has released multiple .RAR archives of purported personal information on citizens across Israel.”

The cyber intelligence firm Flashpoint finds the Telegram user @05tdev was active in 2023 and early 2024, posting in Arabic on anti-Israel channels like “Ghost of Palestine” [full disclosure: Flashpoint is currently an advertiser on this blog].

‘I’M A GINTY’

Flashpoint shows that Rey’s Telegram account (ID7047194296) was particularly active in a cybercrime-focused channel called Jacuzzi, where this user shared several personal details, including that their father was an airline pilot. Rey claimed in 2024 to be 15 years old, and to have family connections to Ireland.

Specifically, Rey mentioned in several Telegram chats that he had Irish heritage, even posting a graphic that shows the prevalence of the surname “Ginty.”

Rey, on Telegram claiming to have association to the surname “Ginty.” Image: Flashpoint.

Spycloud indexed hundreds of credentials stolen from cybero5dev@proton.me, and those details indicate that Rey’s computer is a shared Microsoft Windows device located in Amman, Jordan. The credential data stolen from Rey in early 2024 show there are multiple users of the infected PC, but that all shared the same last name of Khader and an address in Amman, Jordan.

The “autofill” data lifted from Rey’s family PC contains an entry for a 46-year-old Zaid Khader that says his mother’s maiden name was Ginty. The infostealer data also shows Zaid Khader frequently accessed internal websites for employees of Royal Jordanian Airlines.

MEET SAIF

The infostealer data makes clear that Rey’s full name is Saif Al-Din Khader. Having no luck contacting Saif directly, KrebsOnSecurity sent an email to his father Zaid. The message invited the father to respond via email, phone or Signal, explaining that his son appeared to be deeply enmeshed in a serious cybercrime conspiracy.

Less than two hours later, I received a Signal message from Saif, who said his dad suspected the email was a scam and had forwarded it to him.

“I saw your email, unfortunately I don’t think my dad would respond to this because they think its some ‘scam email,'” said Saif, who told me he turns 16 years old next month. “So I decided to talk to you directly.”

Saif explained that he’d already heard from European law enforcement officials, and had been trying to extricate himself from SLSH. When asked why then he was involved in releasing SLSH’s new ShinySp1d3r ransomware-as-a-service offering, Saif said he couldn’t just suddenly quit the group.

“Well I cant just dip like that, I’m trying to clean up everything I’m associated with and move on,” he said.

The former Hellcat ransomware site. Image: Kelacyber.com

He also shared that ShinySp1d3r is just a rehash of Hellcat ransomware, except modified with AI tools. “I gave the source code of Hellcat ransomware out basically.”

Saif claims he reached out on his own recently to the Telegram account for Operation Endgame, the codename for an ongoing law enforcement operation targeting cybercrime services, vendors and their customers.

“I’m already cooperating with law enforcement,” Saif said. “In fact, I have been talking to them since at least June. I have told them nearly everything. I haven’t really done anything like breaching into a corp or extortion related since September.”

Saif suggested that a story about him right now could endanger any further cooperation he may be able to provide. He also said he wasn’t sure if the U.S. or European authorities had been in contact with the Jordanian government about his involvement with the hacking group.

“A story would bring so much unwanted heat and would make things very difficult if I’m going to cooperate,” Saif said. “I’m unsure whats going to happen they said they’re in contact with multiple countries regarding my request but its been like an entire week and I got no updates from them.”

Saif shared a screenshot that indicated he’d contacted Europol authorities late last month. But he couldn’t name any law enforcement officials he said were responding to his inquiries, and KrebsOnSecurity was unable to verify his claims.

“I don’t really care I just want to move on from all this stuff even if its going to be prison time or whatever they gonna say,” Saif said.

❌