Visualização de leitura

Investigating a Murder: Public Records Uncover New Clues in Chinatown Cold Case

Sign up here to receive Bellingcat’s biggest investigations by email as soon as they are published.

Illustration by Oisín Mac Con Iomaire

On a June night in 1996, in a basement apartment in Boston’s Chinatown, a killer put a pistol to the back of a young man’s head and pulled the trigger. The victim’s body was wrapped in quilts, lowered into the trunk of a car and driven about 20 miles southwest of the city, where it was dumped in the woods. It lay undiscovered through two New England winters until a dog walked home carrying a human bone. 

For three decades, authorities did not release the victim’s name to the public. He is listed in the National Missing and Unidentified Persons System (NamUs) as #UP12385, one of 202 unidentified people recorded in the state of Massachusetts. The circumstances of his discovery are reduced to five words: “Skeletal remains found in woods.” The case remains unsolved.

Bellingcat spent more than a year investigating in an effort to put a name to the victim. Using open sources, including freedom-of-information requests and newspaper archives, as well as interviews with investigators who worked on the case, we pieced together the story of the man’s life and death in an era before the internet kept a digital record. In total, we submitted 27 public records requests to 18 local, state and federal law enforcement agencies. We also contacted more than two dozen investigators, prosecutors, crime victims, journalists, experts and community groups connected to the case, though most said they did not recall the 30-year-old murder. 

We learned that authorities identified the victim as Fu Chun Wang, a 26-year-old undocumented Chinese immigrant who did not speak English. We also learned of a sweeping investigation into Chinese organised crime in New England in the late 1990s. Authorities suspected Wang was a member of the Fukienese Flying Dragons, a gang the FBI described at the time as a “violent offshoot” of the larger Flying Dragons crime ring.

Fu Chun Wang’s mugshot. Source: Released by Sharon Police Department

Based in New York’s Chinatown, the Fukienese Flying Dragons were active across much of the East Coast. The gang trafficked migrants, extorted and robbed businesses, kidnapped for ransom and murdered rivals. Authorities believed Wang belonged to the Boston faction of the group, which was suspected of carrying out home invasions targeting Asian and Asian-American restaurant owners and staff across New England in 1996. 

Heavily redacted FBI documents and correspondence between local and state authorities show that a federal operation investigating the home invasions uncovered information about Wang’s murder and other crimes. The operation, whose name is redacted, was led by the US Attorney for the District of New Hampshire.

Authorities suspected that the Boston-based members of the Fukienese Flying Dragons were also involved in prostitution, illegal gambling and kidnappings in multiple states. Investigators examined possible ties between the gang and a suspect in one of Boston’s deadliest mass killings: the 1991 Chinatown Massacre

According to these newly released files, investigators received information that Wang had been murdered by members of his own gang shortly after Boston Police arrested and charged him for using credit cards stolen in one of the home invasions. While some gang members were identified as suspects and investigated, none were ever charged and convicted for the murder.

A Dog with a Bone

On April 10, 1998, a resident in Sharon, an affluent suburb southwest of Boston, called the police. Their black Labrador retriever had returned from the woods carrying a large bone. Four days later, testing by the coroner’s office in Boston determined it was a human femur likely belonging to an adult male. Police searched the woods, where a detective uncovered more bones near a bundle of quilts. Inside, they found a decomposed skeleton. 

A coroner ruled that the victim was a man in his twenties or thirties who was possibly Asian or Native American. He had long black hair with blonde streaks. There were at least two overlapping bullet holes in the back of his skull. Local media reported at the time that the victim had been shot “execution style”. A single, corroded .380 calibre shell casing was found inside the quilt. The victim was wearing a green-and-white striped rugby shirt, denim jeans and white leather sneakers on the night he died. Loose change, a pocket knife and a tarnished set of keys were found nearby on the forest floor. 

Blurred
Crime scene photos showing remains found in the woods, near the intersection of Walpole Street and Bluff Head Road, in April 1998. Source: Sharon Police Department

A botanist from Harvard University determined the body had likely been in the woods for at least 18 months. Experts from The Smithsonian Institution told police that forensic facial reconstruction would be “of questionable value” due to the damage caused by the gunshot injuries. 

Before his murder, open source records of Wang’s life amounted to a few scattered data points: interactions with authorities, apartment rentals, a loan application and a hospitalisation following a car accident. 

Police reports after his death show investigators pieced together a patchy collection of biographical data. He was from a family of five in Dongshan, a village in the southeastern Chinese province of Fujian, and was likely born into poverty. During his autopsy, it was noted that his teeth showed signs he had been “undernourished” as a child. He moved to the US to work in the restaurant industry and eventually joined a gang. 

A January 1994 Immigration and Naturalisation Service (INS) record containing Wang’s fingerprints. Source: Released by Sharon Police Department

Wang migrated at a time when thousands of Fujianese were arriving in the US every month in search of a better life. Like many migrants at the time, he entered the country without documentation. By 1994, when Wang met with immigration authorities in Boston, he gave his address as an apartment on East Broadway in New York’s Chinatown. Two years later, he was issued an employment authorisation card. Boston Police would learn from the Immigration and Naturalisation Service (INS) that Wang had been granted political asylum.

Search results on Ancestry.com suggest that prior to living in Massachusetts, Wang had also lived in Virginia and Vermont. Records from the Sharon Police Department corroborate these findings. In Virginia, police learned that he worked in restaurants and had applied for a loan to buy a car, a 1994 green Mitsubishi Mirage. 

In Vermont, Wang worked at a Chinese restaurant called Men-at-Wok until he was injured in a car accident in May 1996. After he was reported missing a month later, his car sat unclaimed in an auto body shop in Vermont until a bank sought to reclaim it.

Wang’s INS employment authorisation card. Source: Released by Sharon Police Department

Unclaimed checking and savings accounts at Fleet National Bank are listed under Wang’s name and the Quincy address in the Massachusetts unclaimed property database. The amount of money in these accounts is not publicly available, but the presence of unclaimed funds in his name, along with his abandoned car, are some of the many indicators that he met with foul play.

‘We’ll Kill Your Family’

In the summer of 1996, Chinese restaurant owners and their staff in suburban Boston and New Hampshire were terrorised by a wave of violent home invasions and robberies. Police described the suspects as “an organised group of Asian individuals”.

Composite sketches of two suspects in a July 1996 home invasion in Merrimack, NH based on witness descriptions. Source: Merrimack Police Department

The modus operandi was often the same. In the early morning hours, young men barged into rooming houses while Chinese restaurant workers slept. Sometimes they robbed the business owners’ homes. Armed with guns and knives, the intruders tied up their victims before stealing cash and valuables. One woman who was attacked at knifepoint told police an assailant threatened: “Shut up or I will kill you”. In another case, a victim was stabbed.

The assailants were described as young men or teenagers. In several cases, victims reported that they spoke Fuzhou, also known as Foochow, a language originating from eastern Fujian Province. 

Jim Keating, a retired Sharon Police detective, told Bellingcat that many Asian gang extortions and robberies in the Boston area at the time were not reported. “They were all afraid of these guys, because they said, ‘We’ll come back and we’ll kill your family.’ And they would.”

In the span of a few months in 1996, similar robberies occurred in the Massachusetts towns of Bedford and Westborough, as well as Malden, a city about 10 kilometres north of Boston. These were followed by home invasions in the bordering state of New Hampshire, in Wolfeboro, Merrimack, Lebanon and Manchester. It is unclear if the home invasions and robberies were connected, but Bellingcat’s review of historic newspaper clippings and newly released police documents suggest that at least one other gang may have been responsible for some of the crimes. 

In response to the crime spree, local, state and federal law enforcement agencies coordinated investigative efforts. Bellingcat obtained files detailing a federal operation led by the US Attorney for the District of New Hampshire. It included agents from the FBI, INS, Drug Enforcement Administration, Bureau of Alcohol, Tobacco, Firearms and Explosives, Customs Service, Border Patrol and Royal Canadian Mounted Police, along with officers from state, county, and local law enforcement agencies in New England.

Local media coverage of the home invasions in 1996. Source: Janet Wilson, The Boston Globe

Ben Leong, a retired Boston Police detective, said Asian gangs committing robberies, extortion and home invasions against restaurant owners and their staff were common in the 1990s. He said many of these crimes went unreported for cultural reasons, over fears of gang retaliation, and because victims did not trust law enforcement.

“Back then there were many factions of gangs,” he said. “The gang members were recruited throughout the country, nationally and internationally. Law enforcement was always playing catch up to identify the prevalent groups, and the individual members and leaders committing illegal activity.” 

Leong, who is president of the International Organisation of Asian Crime Investigators and Specialists (IOACIS), said authorities had a better understanding of gang culture in Boston by around 1996 when local, state and federal agencies began sharing information.

Murdered in Chinatown

On June 9, 1996, one day after a home invasion in Wolfeboro, New Hampshire, Boston police were called to a Macy’s department store when a man tried to use credit cards stolen in the robbery to buy jewellery and electronics. He was arrested and booked on charges of receiving stolen property. The man was Fu Chun Wang.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

In Sharon Police records, Wang was described as “very depressed” and “possibly suicidal”. He told a Boston Police detective that he urgently needed to send $1,000 to his family in China. Other records said his father was ill and needed money. Files found on Judyrecords.com, a free database that purports to include more than 770 million US court case records, show that Wang was arraigned and a court appointed a defence attorney to him. He was bailed out after pleading not guilty. 

Less than two weeks later, on June 21, Wang was reported missing to the Quincy Police Department in Massachusetts. The police report said Wang was last seen in Boston’s Chinatown on June 13, two days after he left jail. Police records indicate that a female friend of Wang’s had asked an attorney to file the missing persons report. The attorney who reported him missing told Bellingcat that he did not remember Wang. 

The Sharon Police Department’s murder case file notes that within weeks of finding the human remains in the woods, they received information from Boston Police and the FBI that “Wang was murdered in Chinatown” in June 1996 and “his body [was] never found”. 

Investigator’s handwritten notes about Wang’s case. Source: Sharon Police Department

Not all documents were released to Bellingcat, and some names were redacted. Fragmentary notes and witness statements provide the only clues to Wang’s final days. In handwritten records, Sharon Police said a man who was described as the “head of [an] Asian gang in Boston” had Wang killed over the New Hampshire breaking-and-entering incident.

A note in the Sharon Police file described a witness to Wang’s murder as a “Flying Dra” and a “NY gangster”. Retired detective Jim Keating confirmed to Bellingcat that Wang, along with his associates and killer, were suspected members of the Fukienese Flying Dragons. He said he believed Wang was murdered because he posed a risk to the gang following his arrest.

Investigator’s notes describing a witness as a gang member. Source: Sharon Police Department

Documents released by the Merrimack Police Department and Sharon Police Department said that an inmate in New York who, in 1997, was serving a 25-year sentence for attempted kidnapping, offered to share information about Wang’s murder with the FBI in return “for a reduction (sentence)”. The inmate implicated the gang in at least two 1996 New Hampshire home invasions and also gave authorities information about the murder.

The account is heavily redacted but includes a note that the US Attorney for New Hampshire was making arrangements to interview the man. Police in New Hampshire said they believed the inmate “was truthful in his statements and has knowledge about the murder of Mr Wang”. Keating confirmed to Bellingcat that he and investigators from other law enforcement agencies traveled to New York to interview the man. He said the inmate, a suspected member of the Fukienese Flying Dragons, gave a statement on Wang’s murder. 

Keating said that investigators had learned of a dispute on the night of the murder between Wang and the gang’s leader. He said Wang had planned to run an illegal gambling operation at an apartment, which the gang boss was using as a prostitution venue. This led to an argument at another location, and when Wang left for the apartment the boss followed him. 

But Keating said that based on the information gathered throughout the investigation, he believes the primary motive for Wang’s murder was his arrest over the use of credit cards stolen in the Wolfeboro home invasion. With that arrest, Wang presented a risk to the rest of the gang because investigators could tie them to the home invasions. “Wang broke the basic rules by taking something that was identifiable and using it, and that’s what the whole damn thing was about,” Keating said.

Crime scene photos of the basement unit on Oxford Place in Boston’s Chinatown where Wang was murdered. Source: Sharon Police Department

Keating told Bellingcat that the crime scene had been damaged by flooding after the murder. He said he used a power saw to cut off the bottom of a door in the unit and that lab testing revealed the presence of Wang’s blood. 

Investigators also worked to confirm Wang’s identity by testing the DNA of the remains found in the woods. In a 1999 case summary written by a Massachusetts State Police Trooper, it was noted that the FBI was attempting to locate Wang’s parents through police in China.

Three months later, the FBI’s Hong Kong office sent a communique to Boston confirming that the Chinese Ministry of Public Security and Interpol had located Wang’s parents. Wang’s mother, it said, was willing to provide a DNA sample for comparison. 

The FBI communique is the final document in the newly released files that details the efforts to confirm Wang’s identity with DNA. However, Keating told Bellingcat that a DNA sample was obtained from Wang’s mother in China. It was brought back to the US for testing and confirmed to be a match, he said. “I don’t know when the DNA was collected or who did it. But I know that they did that,” Keating said. “There is no question about who he was.” 

Bellingcat contacted both the Norfolk and the Suffolk County District Attorneys to confirm the DNA match, but did not receive a response to questions about DNA testing or the victim’s identity. Other former law enforcement officers named in the files released to Bellingcat have not responded to requests for comment. 

One document included in the murder file references discussions between homicide investigators and the FBI about charging Wang’s killer with home invasion offences. The note discusses the potential to have a witness testify against Wang’s suspected killer. It is unknown whether he was ever charged. 

The Shooter

The man authorities suspected of shooting Wang, or ordering his killing, was described in the documents as the head of the Fukienese Flying Dragons in Boston. Police said he was an undocumented immigrant from Fujian Province who ran a sex trafficking ring. 

A redacted note in the Sharon Police Department murder file references Wang’s suspected killer as “a player” in the Chinatown Massacre, an infamous 1991 case in which five men were shot dead in a basement gambling parlour in Boston. In another note in the case file, investigators wrote that he was “thought to be a federal informant”. 

The name of the gang boss was redacted in the police file released to Bellingcat.

Keating said Wang’s identity was confirmed by DNA and that blood evidence, corroborated by witness statements, placed his killing in the Boston Chinatown apartment. The retired Sharon detective said at that point, the Boston Police Department and the Suffolk County District Attorney’s Office should have, respectively, taken over the investigation and prosecution of the case. 

The Boston Police Department did not respond to questions from Bellingcat. It does not include the killing in its list of unsolved homicides. 

The Suffolk County District Attorney’s Office said it did not have records for Wang’s murder. “Unfortunately, after a thorough search with assistance from our homicide unit, no responsive records could be located,” it said.

In response to Bellingcat’s original public records request, the Norfolk County District Attorney’s office, which covers Sharon, said the files were exempt from public disclosure because they pertained to “an active and ongoing criminal investigation”.

A spokesman for the office said last week that the circumstances surrounding the remains of an adult male discovered in Sharon in April 1998 “remain under investigation” by a state police detective assigned to the Norfolk District Attorney’s Unsolved Case Unit. 

The FBI confirmed that the agency assisted state and local partners in an operation investigating home invasions in the late 1990s but did not answer questions about Wang’s murder or his suspected killer. “Given that we’re not the lead, we’ll refer you to Massachusetts State Police,” a spokeswoman said.

Massachusetts State Police referred questions to the Suffolk and Norfolk County District Attorney’s offices.

It remains a mystery why Wang’s killer was never charged and prosecuted for his murder. “They got away with so much. Blatantly got away with so much,” Keating said of the gang. “Killing people for these guys was like … these guys were all expendable.”

The Norfolk District Attorney’s Office encouraged anyone with any information about the case to contact the Massachusetts State Police Tip Line or the Sharon Police Department.


Melissa Zhu contributed research to this article.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Investigating a Murder: Public Records Uncover New Clues in Chinatown Cold Case appeared first on bellingcat.

Global Crackdown on West African Crime Networks Leads to 58 Arrests

West African Organized Crime Groups

An eight-month international operation targeting West African organized crime groups has resulted in 58 arrests and the identification of 263 suspects across 22 countries, according to INTERPOL. Operation Jackal IV, conducted from November 2025 to June 2026, focused on disrupting criminal networks, tracing illicit funds, identifying high-value targets and supporting arrests and prosecutions. The operation brought together countries across six continents to tackle the growing global threat posed by West African criminal networks, including Black Axe and similar groups. These networks have been linked to a significant share of global cyber-enabled financial fraud, including romance scams, cryptocurrency and investment scams, and business email compromise fraud.

Operation Jackal IV Targets West African Organized Crime Groups

Operation Jackal IV also targeted money laundering activities used to move and conceal criminal proceeds across borders. INTERPOL coordinated cross-border intelligence sharing, analysis and operational support during the operation. It also provided specialized training to strengthen international investigations into financial crime. Tomonobu Kaya, Director of the INTERPOL Financial Crime and Anti-Corruption Centre, said the operation showed the importance of international cooperation in following illicit financial flows and disrupting criminal networks. [caption id="attachment_113806" align="aligncenter" width="600"]West African Organized Crime Groups Image Source: INTERPOL[/caption]

Major Arrests and Financial Crime Investigations

In Argentina, authorities identified 196 individuals linked to a major Crime-as-a-Service network suspected of providing website domains and money laundering support to West African organized crime groups. The investigation resulted in 17 arrests, with an INTERPOL Operational Support Team assisting with analysis of seized data and identification of suspects and criminal networks. South African authorities raided seven locations in Johannesburg linked to a syndicate involved in romance and investment scams targeting retirees in English-speaking countries. Investigators arrested 39 people, seized USD 2.67 million and blocked 257 bank accounts. In Italy, investigators identified an individual connected to a pan-European money laundering network that used shell companies, remittance services and cash withdrawals. One account processed EUR 845,000, or about USD 736,000, through 560 transactions involving 20 financial instruments. Romanian authorities dismantled a criminal group operating an investment scam through a call centre. The group promoted high returns from stocks and cryptocurrencies, with victims' money transferred to electronic wallets controlled by perpetrators. Authorities estimated that EUR 143 million had been stolen and laundered globally. Eleven people were arrested, while cash, cryptocurrency, six real estate properties and luxury watches were seized.

Sextortion and Crime-as-a-Service Emerge

Beyond individual investigations, the operation highlighted emerging threats involving sextortion and Crime-as-a-Service. INTERPOL identified an increase in West African organized crime groups using sextortion to target minors, including victims as young as 14. In these cases, offenders typically contacted minors through social media, established trust and persuaded them to share explicit images or videos. They then threatened to distribute the material to the victim's contacts unless a ransom was paid. Investigators also found that some criminal syndicates were procuring Crime-as-a-Service from external providers, including through the dark web. These services were used to outsource activities such as money laundering and other operational functions. While several cases from Operation Jackal IV remain under investigation, the preliminary results demonstrate the scale and international reach of the networks targeted during the eight-month operation. The participating countries were Austria, Argentina, Australia, Canada, Côte d'Ivoire, France, Germany, Indonesia, Ireland, Italy, Japan, Malaysia, the Netherlands, Nigeria, Portugal, South Africa, Spain, Sweden, Switzerland, the United Arab Emirates, the United Kingdom and the United States.

Tracking a Sanctioned Russian Vessel’s West African Odyssey

Sign up here to receive Bellingcat’s biggest investigations by email as soon as they are published.

A sanctioned vessel that was previously reported to have transported weapons destined for Russian mercenaries has been traversing ports on the west coast of Africa since March, exhibiting what experts told Bellingcat  was an unusual set of movements and behaviours.

Patria (IMO: 9159921) has been sanctioned by the US, Ukraine and Canada.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Radio France International (RFI) reported last year that it was one of two ships to deliver weapons to Conakry in Guinea that were intended for the Kremlin-controlled Africa Corps and their operations in Mali.

Satellite imagery and Automated Identification System (AIS) data from Lloyd’s List Intelligence shows Patria has shuttled between the Port of Douala in Cameroon and the Port of Owendo in Libreville, Gabon four times since March. 

It has also twice stopped in anchorage off the coast of Lagos, Nigeria: first in March and then again at the time of publication. Analysis shows the vessel also spent time in anchorage off the coast of Equatorial Guinea. 

The online news site, Modern Ghana, first reported Patria’s presence off the coast of Lagos in July after X-users @SONNAROW_OSINT and @RFNOSBlog picked up on Patria’s position.

It is not clear what Patria has delivered or picked up at these ports. Nor is it clear why it has spent so long going back and forth between them. But experts Bellingcat spoke to said the unusual patterns of behaviour raised numerous questions.

Charlie Brown, a former US Naval Officer and Senior Advisor at United Against Nuclear Iran said the combination of Patria’s repeated regional port calls, extended periods at anchor, and an apparent absence of a normal point-to-point trading cycle warranted scrutiny, especially as the ship is under sanction and is previously reported to have shipped arms. 

Tracking the Patria

Patria is a cargo vessel that has a distinct shape and features. Its bridge is located on the bow and it has a bright red deck that contrasts with its blue hull and two yellow cranes. 

At the end of the deck, the ship has a built-in ramp for vehicles (the Patria is a so-called roll on/roll off, or RoRo, vessel that is designed to transport wheeled vehicles). Its chimney is located next to the ramp.

Footage of the Patria, posted on Youtube on Jan 22, 2024. Credit: Hanro Shipping – Sakhalin Projects LLC / YouTube Channel @hanroship

This, in combination with the length of the ship (101 m), allowed Bellingcat to pick the vessel out in satellite imagery. AIS data helped us further track its long journey which began in the Sea of Japan, in Russia’s far-east, in January.

For the most part, we were able to match Patria’s AIS position with corresponding satellite imagery. We found no evidence of obvious spoofing incidents (where a ship intentionally broadcasts misleading AIS data) by the vessel during its months-long voyage, however, there were some instances where satellite images were not available and thus spoofing by the vessel cannot be completely ruled out.

MapLibre | Protomaps© OpenStreetMap contributors

Port of Olga, Russia

AIS data indicates that Patria loaded at the Port of Olga in the Sea of Japan between Jan. 21 and 23. Patria can also be seen on satellite imagery on these dates.

Credit: Planet Labs PBC.

Port of Douala, Cameroon

AIS data indicates that Patria unloaded some cargo in the Port of Douala between Mar. 11 and 12. Again, the ship can also be seen in satellite imagery on these dates.

Credit: Planet Labs PBC.

Lagos Anchorage, Nigeria

AIS data indicates Patria anchored off the coast of Lagos from Mar. 14 to 15.

A Sentinel-2 image from the 15th appears to show another ship next to Patria. AIS data indicates that this is JS Gratitude, a bunkering tanker. This close proximity suggests that Patria was refuelling.

Credit: Contains modified Copernicus Sentinel data 2026.

Bata Anchorage, Equatorial Guinea

AIS data and satellite imagery indicate Patria stayed off the coast of Equatorial Guinea for several days.

Credit: Planet Labs PBC.

Port of Owendo, Libreville, Gabon

AIS data and satellite imagery indicate Patria loaded at the Port of Owendo in Libreville after spending a few days off the coast.

Credit: Planet Labs PBC.

Port of Douala, Cameroon

AIS data and satellite imagery indicate Patria stayed at the Douala Anchorage from Apr. 6 to 14, before unloading at the Port of Douala between Apr. 14 and 18.

Credit: Planet Labs PBC.

Port of Owendo, Libreville, Gabon

AIS data suggests Patria loaded in Libreville again between Apr. 22 and 26.

Port of Douala, Cameroon

AIS data, supported by satellite imagery, indicates Patria stayed at the Douala Anchorage for nearly a month from Apr. 27 to May 21 before unloading in Douala from May 21 to 27.

Credit: Planet Labs PBC.

A third trip between the Port of Owendo, Libreville to Douala, Cameroon

AIS data indicates, after nearly a month’s wait in Douala anchorage, Patria again loaded at Owendo before returning to Douala to unload.

A fourth trip between the Port of Owendo, Libreville to Douala, Cameroon

AIS data indicates Patria again loaded at Owendo before returning to Douala to unload.

Lagos Anchorage, Nigeria

AIS data indicates, after a short visit to the Libreville anchorage, Patria anchored off the coast of Lagos where it remained at the time of publication.

Credit: Planet Labs PBC.

Examining the Patria’s Draught

We reviewed the draught of the ship at each port visit and found that the ship’s draught always dropped after a stay at the Port of Douala, suggesting it was unloading there.

A ship’s “draught” is the distance from the bottom of the hull (the keel) to the waterline. When loaded, a ship is heavier and sits lower in the water (e.g. a draught of six metres) than when it is unloaded (e.g. a draught of four metres).

Draught is the depth of a ship below the waterline. 

In the period from March to July, the Patria made five port calls to Douala and each time the draught decreased. Conversely, it called four times at the Port of Owendo in Libreville, each time the draught increased, meaning the ship became heavier, suggesting it was loading.

The draught is self-reported by ships but usually when it arrives at ports this kind of data is checked – reporting accurate draught is also a safety issue for ships arriving and departing at ports. 

Bellingcat asked the ship’s owners, managers and both ports if items were being transferred from Libreville to Douala but did not receive a response at time of publication.

Brown, the former US Naval Officer and now a Senior Advisor at United Against Nuclear Iran, said Patria’s movements were unusual.

“A sanctioned vessel linked to a prior military logistics shipment spending nearly six months operating between a small cluster of West African ports, Douala, and Owendo, without returning to a clear commercial trading pattern warrants scrutiny,” Brown told us.  


“While innocent explanations such as mechanical issues, commercial disputes, lack of cargo, chartering delays, or prolonged maintenance are possible, the combination of repeated regional port calls, extended periods at anchor, and an apparent absence of a normal point-to-point trading cycle is atypical for a merchant vessel.” 

He added that the current period of more than 30 days at the Lagos Anchorage, in particular, is noteworthy. 

David Soud, Head of Research and Analysis at I.R Consilium also told Bellingcat that Patria’s prolonged Lagos Anchorage could have innocent explanations such as its need for ongoing repairs, or that its operators were out of money, but added that there could also be more calculated reasons and it was laying low for a while.

Bellingcat analysed AIS data from Lagos Anchorage and found that while there has been high congestion, no other RoRo or container vessel waited longer than 10 days to enter the port in the period that Patria has been at Lagos Anchorage. At time of writing, Patria has been in anchorage for more than 30 days.

Regarding the Patria’s apparent deliveries of cargo between Libreville in Gabon, and Douala in Cameroon, Soud told Bellingcat:

“Given the vessel’s history of transporting military equipment to African seaports for overland delivery to Russian and allied forces in the Sahel, it’s not out of the question that some form of supplies for Russian or other forces could be picked up in Gabon, whose government has developed a closer relationship with Moscow, to be discharged in Douala, which is the main entry point for goods going to Central African Republic.”

Bellingcat asked the Nigerian Ports Authority why Patria had been in anchorage for so long, whether it had applied to dock and whether the port was aware of its sanctioned status but did not receive a response at time of publication.

The ports of Douala in Cameroon and Owendo in Libreville, Gabon did not respond to Bellingcat’s requests for comment about the Patria’s visits and the cargo it was carrying.

Bellingcat also contacted the two companies connected to the vessel – Hanro Shipping and Sakhalin Shipping Company which are listed as the vessel’s owner and manager respectively in sanctions documents. We also contacted the company connected to JS Gratitude. We did not receive a response at time of publication.


Youri van der Weide, Galen Reich, Yörük Işık contributed to this report.

Cover image: Planet Lab image shows the Patria at the Port of Douala, Cameroon, on April 17, 2026. Credit: Planet Labs PBC.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Tracking a Sanctioned Russian Vessel’s West African Odyssey appeared first on bellingcat.

Welcome to Dubai: Kinahan Cartel’s Visas Revealed

This article is the result of a collaboration with The Sunday Times. You can find their corresponding piece here.

The Kinahan cartel, led by Christy Kinahan (centre) and his sons Christopher Jr (left) and Daniel (right), controls one of the most powerful transnational crime groups in the world from the Emirates. Source: Supplied

A key leader of the Kinahan cartel who is wanted by authorities around the world and has been living in hiding in Dubai for a decade has just had his Emirates residence permit renewed.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

A Bellingcat and The Sunday Times review of public immigration records from the United Arab Emirates (UAE) has revealed that Christopher Kinahan Jr, the son of cartel founder Christy Kinahan, was issued with a new visa less than two weeks ago. 

This is despite his status as a sanctioned individual who is the subject of a $5 million reward from the US government for information leading to his arrest. 

Our analysis has also exposed the residence statuses of the crime gang’s other sanctioned leaders who remain at large in Dubai. The records include previously unknown companies where the cartel members are purportedly employed.

The US government has offered a $5 million reward for information leading to the arrest or conviction of Christopher Kinahan Jr for participating in transnational organised crime, namely narcotics trafficking and money laundering.

It comes after Christopher Jr’s older brother Daniel Kinahan lost his final appeal in Dubai last week to prevent being extradited back to Ireland. He is the second key figure of the crime group to be apprehended in the Emirates following his high-profile arrest in April.

The Kinahan Organised Crime Group is a $1.5 billion transnational network involved in drug trafficking, money laundering and arms smuggling. Investigators have connected it to Iran’s intelligence services and the Lebanon-based militant group Hezbollah.

The cartel’s senior leadership – Christy Kinahan, 69, and his sons Daniel, 49, and Christopher Jr, 45, their cousin Ian Dixon, 36, along with associates Sean McGovern, 40, Bernard Clancy, 48, and Johnny Morrissey, 66 – was sanctioned by the US government in 2022.

Christopher Kinahan Jr and his father Christy Kinahan, seen in the background of a photo posted to a Dubai restaurant’s social media in 2023.

The UAE reportedly banned the Kinahans from doing business in the wake of the sanctions and the Emiratis also claim to have frozen €200 million in Kinahan assets. However, our findings suggest the cartel is still doing business in the Emirates and its leadership has repeatedly engaged with immigration authorities in the years following the sanctions.

The visa records were accessed through publicly available UAE government websites. We entered data contained in the US government’s sanctions notice, including the gang members’ ID or passport number, birth date and nationality, to view their immigration files.

Action in Dubai

Six of the seven key cartel figures who were sanctioned by the US in 2022 lived in Dubai. Cartel lieutenant Sean McGovern was extradited to Ireland in 2025 and jailed in June.

Daniel Kinahan awaits extradition from Dubai.

Online Immigration Records

Our open source review of immigration records shows two members have active residence permits. The other two have expired permits.

Chris Kinahan Jr

Chris Kinahan Jr

Active Permit

Christopher Kinahan Jr’s residence permit was renewed on July 20 for a two-year period. His previous visa had expired in December 2024. The new residence card lists his employment as “sales officer” at a company named Island Star Tourism.

Bernard Clancy

Bernard Clancy

Active Permit

Bernard Clancy’s most recent two-year residence permit was renewed in January. Like Christopher Jr, Clancy’s stated profession is “sales officer”, but for a company named Al Matn Goods Wholesalers LLC.

Christy Kinahan

Christy Kinahan

Expired Permit
Ian Dixon

Ian Dixon

Expired Permit

Records for Christy Kinahan and Ian Dixon show the residence permits associated with their available passport numbers have expired.

Christy Kinahan

Christy Kinahan

Expired Permit

On his most recent visa, which expired on April 1, Christy Kinahan’s listed employer is OSA Management Consultancies DWC LLC. This firm is based at the same Dubai address as CV Aviation Consulting Services DWC LLC, another company reportedly linked to the cartel.

Ian Dixon

Ian Dixon

Expired Permit

Dixon’s employer listed on his most recent visa was Hoopoe Sports LLC, one of the firms sanctioned by the US for being “owned or controlled” by Dixon.

Christy Kinahan

Christy Kinahan

The UAE imposes a fine for each day a person stays in the country after their visa expires. A Dubai government portal shows Christy Kinahan owes the equivalent of more than USD $1,000 for an 81 day overstay.

Ian Dixon

Ian Dixon

Dixon, whose residency expired in 2024, owes more than USD $11,000 for an 852-day overstay.

Sanctioned
Christy Kinahan

Christy Kinahan

Dubai

Expired Permit
  • 81 days overstay
  • Fine: ~$1,000
Chris Kinahan Jr

Chris Kinahan Jr

Dubai

Active Permit
  • Renewed: Jul 2026
  • Island Star Tourism
Bernard Clancy

Bernard Clancy

Dubai

Active Permit
  • Renewed: Jan 2026
  • Al Matn Goods Wholesalers LLC
Ian Dixon

Ian Dixon

Dubai

Expired Permit
  • 852 days overstay
  • Fine: ~$11,000
Daniel Kinahan

Daniel Kinahan

Dubai

Sean McGovern

Sean McGovern

Dubai > IRE

Johnny Morrissey

Johnny Morrissey

Spain

Chris Kinahan Jr

Chris Kinahan Jr

Dubai

Active Permit
Residency Document
Residence permit for Christopher Kinahan Jr. Source: GDRFA Dubai
Bernard Clancy

Bernard Clancy

Dubai

Active Permit
Clancy Residency Document
Residence permit for Bernard Patrick Clancy under the name “Bernard Patrick”. Source: GDRFA Dubai
Christy Kinahan

Christy Kinahan

Dubai

Expired Permit
Father Residency Document
Ian Dixon

Ian Dixon

Dubai

Expired Permit
Dixon Residency Document
Expired residence permits for Christy Kinahan and Ian Dixon. Source: GDRFA Dubai
Christy Kinahan

Christy Kinahan

Dubai

Expired Permit
Father Residency Document
Expired residence permit for Christy Kinahan. Source: GDRFA Dubai
Ian Dixon

Ian Dixon

Dubai

Expired Permit
Dixon Residency Document
Expired residence permit for Ian Dixon. Source: GDRFA Dubai
Overstay Fines Document - Christy Kinahan
Screenshots of fine records for Christy Kinahan and Ian Dixon. Source: GDRFA Dubai
Overstay Fines Document - Ian Dixon
Screenshots of fine records for Christy Kinahan and Ian Dixon. Source: GDRFA Dubai

*Bellingcat searched the Dubai government’s identity and foreign affairs portal by inputting data about the cartel’s leadership that was contained in the US government’s sanctions notice. Searching the gang members’ ID or passport number, birth date and nationality returned a “Unified Number”, a unique identifier assigned to every UAE visa holder. This number, when entered with the other identity information on a UAE federal government portal, returned the visa holder’s current status, history and file number.

Roy McComb, a former deputy director of the UK’s National Crime Agency, told The Sunday Times it was preposterous to suggest that the UAE did not know the visa status of the cartel members in Dubai.

“How is Christy Kinahan in the UAE unlawfully and the authorities there are unwilling to take appropriate action? The Kinahans are not an unknown entity, they are at the very apex of organised crime,” he said. “For the UAE not to know their residency status beggars belief.”

David Haigh, a British solicitor who was imprisoned on fraud charges in Dubai and now assists victims of abuse in the region, said it was clear the cartel must be paying off officials. “If someone is living openly there for a long period of time with that level of heat, that to me shows there’s been corruption involved,” he said. “If they were using false passports to enter Dubai, that’s a serious federal offence.”

Daniel and Christy Kinahan – nicknamed “The Dapper Don” – at a Dubai sports arena last June. Source: WeCaptureYou, TrillerTV

The passport details publicly listed in the US sanctions provide an unprecedented glimpse into the timeline of the cartel leadership’s visa history, giving an overview of their initial entry and exit to the Emirates.

The records show that four of the six key gang members had entered the UAE long before the 2016 attempt on Daniel Kinahan’s life in Dublin and the ensuing deadly feud that led to the cartel’s full relocation to the UAE.

A passport number for Christopher Kinahan Jr is linked to short-term UAE visas issued as early as September 2013. A passport number listed for Daniel Kinahan, searched in combination with an alternative sanctions-listed date of birth that is not his real one, returned seven short-term UAE visas between 2013 and 2015. It is not known what name this passport was under, but Daniel Kinahan has reportedly held illegitimate passports in the past.

A short-term visa for details associated with Ian Dixon first appeared in 2015. Authorities allege that Dixon acted as a trusted lieutenant to Daniel Kinahan by helping move bulk cash across Europe, arranging payments and keeping tabs on money owed by a narco-trafficker. In June, we revealed that Dixon was the poster boy for a padel club in Dubai, where he has been captured playing the racquet sport on webcams. 

Left: Ian Dixon has been sanctioned by the US Treasury as part of its action against the Kinahan cartel. Right: Dixon at a racquet sports event post-sanctions. Source: US Treasury, sanddune_padel_dxb / Instagram

The earliest visas found for details associated with Sean McGovern and Bernard Clancy were from March and April 2016 respectively, the months after the 2016 attack in Dublin.

All key members of the group, with the exception of crime boss Christy Kinahan, gained residency in the UAE using Irish passports. The cartel founder’s British passport number is linked to his immigration file; both to his latest residence permit and four previous temporary visas. Records show the first visa associated with this passport was issued in February 2007 – the earliest known instance of Christy Kinahan entering the UAE. Another was issued in November 2009, and then two more in 2017. 

However, details for an Irish passport under one of Christy Kinahan’s aliases (“Christopher O’Brien”) return 31 separate records on the UAE’s visa inquiry portal between 2014 and 2017. Bellingcat confirmed this passport number was associated with the name Christopher O’Brien after discovering both in corporate documents for a now-defunct Hong Kong firm that was incorporated in February 2014. This suggests Kinahan may have been using a false passport to travel to and from the UAE in addition to traveling under his authentic document. A man was jailed in 2023 after admitting he supplied “fraudulently obtained genuine passports” to criminals, including Kinahan.

Details from sanctions against Christy Kinahan were found on publicly available corporate documents of a defunct Hong Kong firm (passport number blurred by Bellingcat). Source: US Treasury, Hong Kong Companies Registry

One short-term UAE visa issued for “Christopher O’Brien” ended on August 19, 2015. Posts on LinkedIn three days later showed Christy Kinahan – wearing black-framed glasses and named in the posts as “Christopher O’Brien” – surrounded by Iranian and Turkish businessmen in a high-rise company office in Ankara. These images, discovered by Bellingcat in posts under the name of the managing director of a now-defunct Turkish investment company, have since been deleted.

LinkedIn posts from August 2015 showing “Christopher O’Brien”, a.k.a Christy Kinahan, in an office in Turkey.

According to the Dubai government, employment-based residence visas are valid for two years and must be obtained by a company on its employee’s behalf. The employer is required to apply for a work permit through the UAE’s Ministry of Human Resources and Emiratization. The employee must pass a fitness test before their employer can apply for the residence permit.

The company names on Clancy and Kinahan Jr’s residence permits, Al Matn Goods Wholesalers and Island Star Tourism respectively, match existing firms in Dubai. However, Bellingcat was unable to confirm whether these entities are the same as the ones listed on the residence permits. It is also not known why Clancy’s residence permit only includes his first and middle names (“Bernard Patrick”) while the other cartel members’ visas used their full names. 

Wanted posters for Irish drugs smugglers Daniel, Christy and Christopher Kinahan Jr, released after the cartel leaders were sanctioned in 2022. Source: US Department of the Treasury

The firm named on Christy Kinahan’s permit, OSA Management Consultancies, is listed as an aviation consultancy on a Dubai government registry. In addition to sharing an address with cartel-linked firm CV Aviation Consulting Services, UAE company data accessed on Horizons, a platform created by Washington DC-based nonprofit C4ADS that aggregates public records, shows that both firms also have the same business licence number and date of incorporation, suggesting OSA may be a newer name for the same entity.

The managing director of Island Star Tourism told Bellingcat on the phone that Christopher Kinahan Jr was working as “commission-based staff, not in-office staff”. He confirmed he recognised Christopher Kinahan Jr’s name but said he had never met him. Asked how the company name appeared on his visa, he said “I don’t know”. He said if the UAE had any problem with Christopher Kinahan Jr, it would “not give permission”.

Al Matn Goods Wholesalers and OSA Management Consultancies did not respond to questions from Bellingcat.

The UAE foreign ministry has been approached for comment.


Connor Plunkett, Peter Barth, Beau Donelly and John Mooney contributed to this article. Scroll-driven interactive by Connor Plunkett and Miguel Ramalho. 

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Welcome to Dubai: Kinahan Cartel’s Visas Revealed appeared first on bellingcat.

Will Ronaldo Cry​? World Cup Fans Bet Billions Through Prediction Markets

Cristiano Ronaldo during Portugal’s losing game against Spain earlier this month. Source: Imagn Images via Reuters Connect

Football fans wagered more than US $14 billion on the FIFA World Cup through prediction markets Polymarket and Kalshi, a Bellingcat analysis has found.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

On the crypto-based Polymarket, which provides more information about individual trading accounts than its rival American site Kalshi, we also found that just 1% of users collected the vast majority of winnings during the tournament.

Users traded on almost 60,000 outcomes across both sites during the competition, betting on everything from the sponsor of the Golden Boot winner to whether Cristiano Ronaldo would shed a tear during a Portugal match. 

The World Cup, held in the US, Canada and Mexico over June and July, was forecast to be the biggest betting event in history, with a predicted $50 billion in wagers. 

Unlike traditional sports betting sites, prediction markets resemble stock exchanges where users trade, via an order book, on whether a real-world event will happen. Prices fluctuate based on what the market believes the probability of that event is. The sites charge fees on each sports trade.  

With 48 teams playing 104 games, the World Cup was slated to be the biggest gambling event of all time. Source: Polymarket

The prediction market industry has faced criticism over its vulnerability to insider trading, potential market manipulation and concerns about fueling unregulated gambling. The Wall Street Journal also reported in May that a small number of individuals using algorithmic trading models were taking home an outsized share of winnings.

This would appear to align with Bellingcat’s World Cup analysis, where a small percentage of accounts made most of the winnings. However, the level of detail we were able to obtain did not allow us to see accounts that had utilised algorithmic methods.

Both Polymarket and Kalshi make events and volume data available for programmatic extraction – making it useful for open source analysis. Bellingcat’s data analysis examined all 104 matches as well as the World Cup winner event that was hosted on each platform.

On Polymarket, users traded a total of $10 billion ($5.7 billion on individual games and $4.3 billion on which country would win). The largest game on Polymarket was the Spain vs Argentina final ($212 million), followed by the France vs Spain semi-final ($165 million) and the England vs Argentina semi-final ($142 million). 

On Kalshi, users traded a total of more than $4.3 billion ($4.1 billion on the games and $200 million on the winner).

Bellingcat’s analysis also found that 1% of Polymarket trading accounts collected 86% of all winnings during the World Cup, and the bottom 50% of winners shared just 0.1% of profits. The typical winning account on Polymarket made $21, while the typical losing account lost $32 (measured by the median, which is less affected by a handful of exceptionally large wins and losses). More than 12% of traders (14,500) who bet on two or more games lost every bet. The Polymarket account that won the most across all games made a profit of more than $13 million, while the biggest loser lost $11.6 million.

We were unable to run the same win-loss analysis for Kalshi because trading account overviews are not publicly available.

The top teams, by trading volume, across both sites were Argentina ($1.068 billion), Spain ($876 million) and France ($836 million). The top players were Argentina’s Lionel Messi ($40 million), France’s Kylian Mbappé ($36 million) and Norway’s Erling Haaland ($16 million).

How We Calculated the Volume

Polymarket displays the actual traded volume on its site, the total US dollar amount of shares bought and sold since the market started.

Kalshi does not display the traded volume. Instead, it shows the notional volume, which counts every contract traded at the maximum payout value of $1. This means that a token bought for $0.20 will be presented as $1 extra in a user’s displayed volume. This makes the total monetary volume appear higher on Kalshi’s website. To achieve a fair comparison between both platforms, we implemented a heuristic to reconstruct Kalshi’s markets’ volume. We used the daily average price for each market over their duration and multiplied it by the number of contracts traded on that day, the sum of which gives us the values used in this piece. We applied this formula for the more than 21,000 World Cup markets. 


Data scraping was supported by Oxylabs’ Project 4β.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Will Ronaldo Cry​? World Cup Fans Bet Billions Through Prediction Markets appeared first on bellingcat.

Shahed-Type Drones Filmed During Mali Village Attacks

Bellingcat has geolocated footage showing Shahed-136 type kamikaze drones in operation in Mali.

Defence Blog and France 24 previously published reports that these drones were being deployed on the battlefield in northern Mali. But Bellingcat and Jeune Afrique subsequently verified two recent strikes using geolocation, satellite imagery and expert analysis to provide some of the clearest open-source evidence to date documenting their deployment.

The two strikes took place in the villages of Inafarak on July 12 and Talahandak on July 17. While the available evidence does not allow the exact variant to be identified, experts told Bellingcat it is quite likely the drones were manufactured in Russia given the deployment of the Kremlin-controlled Africa Corps group and the broader pattern of Russian military support to Mali.

Leo Jarry, a drone expert with Tungsten Strategies, told Bellingcat: “If the drones are Russian manufactured, they represent a visible demonstration of Russian support for Mali.”

Reports that Russian drones had been used in Mali first emerged in May, when Defence Blog published photographs of drone wreckage from strikes near the town of Savare.

Earlier this month, France 24 also identified debris from several Russian drone systems in Mali, pointing to an expanding Russian drone presence in the country. Until now, however, there has been no verified footage showing how Shahed-136 type drones in flight and hitting targets. 

Mali has been mired in conflict since a rebellion erupted in the country’s north in 2012. In recent years, Russian forces, first through the Wagner Group and now through its successor, Africa Corps, have supported the Malian Armed Forces (FAMa) in operations against Tuareg rebel groups and jihadist organisations

Inafarak –  July 12, 2026

On  July 12, footage showing the aftermath of a drone strike in the village of Inafarak was published on X.


Bellingcat geolocated the footage to the town, which is close to the border with Algeria (21.32330, 0.72980) using satellite imagery. We confirmed the location by comparing a post-strike satellite image captured on July 15 with imagery from 2024. The comparison shows several buildings that were standing in 2024 had been destroyed by July, 15, 2026. This damage was consistent with that visible in the geolocated footage. The strike appears to have hit a commercial facility, with a damaged truck and numerous damaged fuel drums visible.

A geolocation diagram showing satellite imagery (top) and a screen grab from footage (bottom) that allowed us to match the site of the strike to Inafark. Satellite Image credit: Planet Labs PBC. Social footage from @EypeMohamedn.

One of the videos shows the remains of an engine which appears consistent with an MD-550, a distinctive four-cylinder two-stroke engine which is found on the Shahed-136 family of drones. We showed the image of the engine to two weapons researchers – Trevor Ball, an independent weapons expert and former Bellingcat investigator, and Leo Jarry, a drone expert with Tungsten Strategies – who said the engine is consistent with the Shahed-136 family of drones.

The component also closely matches reference imagery of MD-550 engines published by the Open Source Munitions Portal (OSMP), an expert-reviewed database of documented weapons remnants, and on the war & sanctions component database.

Left: Screengrab showing the MADO MD-550 engine found in Inafarak. Source: X/@EypeMohamedn. Right: Verified comparison image showing a MADO MD-550 engine. Source: OSMP.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

The footage we found on X was  also republished by the Wagner- and Africa Corps-affiliated Telegram channel “White Uncles in Africa”, which regularly shares racist memes and graphic posts  and which Bellingcat has previously reported on.

The channel captioned the videos: “Now the Azawadi ‘khokhols’ will be seeing Gerans all the time.” The use of “Geran” refers to a Russian-manufactured version of the Shahed-136. The post also uses the derogatory Russian slur “khokhol” for Ukrainians and applies it to people from Azawad, the name used by Tuareg separatists for northern Mali.

Talahandak –  July 17, 2026

On  July 17, graphic footage showing the aftermath of another Shahed-136 type drone strike was posted on X, showing one casualty as well as a burning truck. An additional video of the burning vehicle shows what appear to be bottles of cooking oil spilling from the truck indicating it may have been a commercial truck.

Bellingcat geolocated these videos to the village of Talahandak (20.26369, 1.80095), which is also close to the border with Algeria but around 100 miles southeast of Inafarak, by matching the surrounding buildings to satellite imagery.

A geolocation diagram showing satellite imagery (top) and a screen grab from footage (bottom) that allowed us to match the site of the strike to Talahandak. Satellite Image credit: Planet Labs PBC. Social footage from X/@mahmoud_sahara.

Shortly afterwards, a Wagner-affiliated X account claimed that the drone responsible for the strike had been shot down by rebels before hitting the truck. The post showed one video where a Shahed-type drone could be seen in flight.

We were able to geolocate where the footage that captured the drone’s final moments before impact was filmed to another area of Talahandak, nearly a kilometer away (20.266907, 1.792656) from the video that showed the impact site.

Geolocation diagram showing satellite imagery (right) and footage (right) showing Shahed-136 type drone in flight, using high-resolution Planet satellite image from July 23, 2026.

A distinctive smoke plume can be seen rising from the sight of impact in several other videos posted online shortly after the strike. 

Bellingcat geolocated each of these videos and matched the plume of smoke adding further confirmation that the footage showing the drone in flight is authentic. 

The video shows the drone descending directly towards the location where the person and truck were hit, and there appears to be no interception before impact.

Screengrabs showing matching smoke plume across verified imagery. Left – Source: X/@EypeMohamedn. Middle – Source: Facebook/Ali Ould Right – Source: Facebook/ⵢⵙⴰⵍⴰⵏ24اخبارNewS

A New Weapon Raises New Risks

The Shahed-136 is a series of long-range one-way attack drones originally developed in Iran and now also manufactured in Russia. Unlike the drones typically used by Mali’s Armed Forces- the  Bayraktar TB2 , which launch relatively small precision-guided munitions before returning to base, one-way attack drones are designed to explode on impact, allowing them to attack over longer distances given they do not require recovery.

Leo Jarry, a drone expert with Tungsten Strategies, told Bellingcat that the drone provides Africa Corps and FAMa with an “expendable, cost-effective” long-range strike capability, allowing them to engage targets in Mali’s far north beyond the effective reach of the Bayraktar TB2. “The fact that these systems are relatively cheap and expendable changes the risk calculation for operators,” Jarry said. “They can be used more freely, potentially forcing insurgents in northern Mali to adapt their behaviour to a new aerial threat.”

However, Jarry said the system is inherently less precise than the Bayraktar TB2 because it cannot verify its targets during flight. Instead, it relies on separate surveillance assets to identify and track targets before launch. “In Mali, where armed groups are highly mobile and frequently operate among civilian populations, any gap between target identification and impact creates a risk of striking the wrong target.” Combined with the drone’s larger warhead, this increases the potential for civilian harm when employed in or near populated areas.

From Ukraine to Sahel

In Ukraine, Russian forces have used Shahed-136 type drones extensively in long-range strike campaigns that have repeatedly targeted civilian infrastructure, causing civilian casualties. Their appearance in Mali raises the possibility that the operational practices associated with these weapons are also being exported to this conflict. 

The deployment  also follows Bellingcat’s and Jeune Afrique’s recent investigation documenting the use of banned Russian cluster munitions in Mali.

Malian forces and Africa Corps currently face mounting pressure in northern Mali following a series of rebel offensives. Fighting has intensified in recent months, with rebels capturing several military bases and reportedly inflicting heavy losses on both FAMa and Africa Corps. 

Jarry told Bellingcat that the relatively low cost and expendable nature of these new drones make them well suited to retaliatory strikes following attacks by rebels.


Bellingcat’s Carlos Gonzales contributed to this report as well as the following members of Bellingcat’s volunteer community: Nicole Kiess, Afton Briones, Riccardo Giannardi and Ziyu Wan.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Shahed-Type Drones Filmed During Mali Village Attacks appeared first on bellingcat.

Identifying the Crypto Entrepreneur Linked to Popular Forum Trading in ‘Leaked’ Nudes of Women

This investigation is a collaboration between Bellingcat and New Zealand news site The Press. You can read The Press’ piece here

Content warning: This article discusses non-consensual sexually explicit content and child sexual abuse material.

In 2024, a former track and field coach in Boston, Massachusetts, was sentenced to five years in jail for attempting to trick and extort more than 100 women, including student-athletes he coached, into sending him intimate photos. 

According to the 2021 criminal complaint, Steve Waithe stole photos from some of the student-athletes’ phones under the pretence of “filming their form” at practices and meets. He also approached some victims via fake online accounts, telling them he had found their images on a forum site called “leakedbb.com” (“LeakedBB”) and offering to help them remove these photos if they provided more images for “reference”. 

Authorities said Waithe also hired and paid another man in October 2020 to hack into the Snapchat accounts of women he coached or had other relationships with in an effort to steal and distribute nude images online. 

In one post, according to the US Attorney’s Office, Waithe wrote: “Does anyone want to trade nudes? I’m talking girls you actually know. Could be exes or whatever. I have quite a few and [am] down to trade over snap[chat] or something.” 

Legal documents do not name the sites on which Waithe distributed these images, but Bellingcat found a cached version of a November 2020 post with that exact wording on LeakedBB – the same site he allegedly used to try to trick victims. Another cached LeakedBB thread posted a few months later shows the same user offering to trade nudes of athletes, including “a lot that I actually know”.

Screengrab from LeakedBB, showing a user asking to trade nudes of “girls you actually know”; redaction by Bellingcat

Such posts were not unusual on the site: multiple archived pages show the forum’s users either requesting Snapchat hacks or offering to help others hack Snapchat accounts, sometimes for a fee. 

In the criminal case against Waithe, the ownership of LeakedBB is never discussed, but a Bellingcat investigation can reveal that payment streams, company records and website domain information appear to lead back to one individual: Jitendra Maharaj, a Christchurch-based former pilot and co-founder of a cryptocurrency start-up, Pay It Now (PIN), which reportedly billed itself as the “Stripe of crypto payments”. 

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Our New Zealand publishing partner The Press sent an email to Maharaj on June 4 outlining our findings in detail and inviting him to respond. Maharaj did not reply to this. 

However, by June 6, LeakedBB was down. As of publication, the website remains inaccessible. 

The Press later received an email from a Christchurch-based lawyer representing Maharaj, who said their client was in Fiji for a family member’s funeral. The lawyer requested that we wait until his return on June 23. 

When The Press visited his residence – a two-storey family home in Christchurch’s affluent Aidanfield suburb – on June 25, Maharaj said he did not know who was behind LeakedBB or operated it and that he was not sure if the website was down. 

He said he did not respond to the email queries and had not spoken to his lawyers about them because “all the evidence against me just sounded really weird” and it seemed like there was “some kind of targeted attack out on me” based on “manufactured evidence or something that’s pointing me to this garbage”. However, he refused to comment on the record about most of the specific evidence linking him to the site and referred these questions to his lawyer. 

He also claimed that he had been contacted by people “trying to harass me to get me to send them money”, but declined to provide details on the record.

Jitendra Maharaj at the entrance of his residence on June 25, 2026. Source: Iain McGregor/The Press

Despite a further extension of the deadline until July 6 – more than a month after we first reached out – Maharaj and his lawyer had not provided any statement directly addressing the specific evidence linking him to the site as of publication. 

PIN, the company Maharaj co-founded, did not respond to The Press’ requests for comment. However, there is no suggestion that PIN has any knowledge of or involvement in LeakedBB.

Profiting Off ‘Leaks’

LeakedBB was set up in 2019 and built a sizeable following over the next seven years, averaging an estimated two million visits a month from March to May this year. The board statistics shown on LeakedBB’s homepage in May displayed 2.2 million registered users and more than 2.6 million posts.

Screengrab of the board’s statistics as of May 26, 2026; personal information redacted by Bellingcat

Google’s Transparency Report shows it received more than 95,000 individual requests for over 350,000 pages on LeakedBB to be delisted from search results. This resulted in Google de-listing more than 169,000 pages from its search results, according to the report. 

Shortly after the site went offline, a Reddit post noting the outage and asking for alternatives trended in the “hot” section of a piracy subreddit, accumulating almost 700 votes in a week. In response to a question by one commenter asking what the site was, another person replied: “Not only did it have ‘onlyfans’ content, also amateur, asian, arabic, celebrity and other hacked phone/icloud content from other sites.”

This comment accurately summarised some of the content on the site. In LeakedBB’s early days, it had sections for other types of “leaked” content such as computer programmes and eBooks. But within months, the forum’s discussions were almost exclusively about pornographic images and videos that members claimed had been leaked – implying that it was non-consensual, hacked or stolen content.

The most popular section on the forum contained content that claimed to be from sites such as OnlyFans and Fansly, which, if shared without the original creators’ consent, would be a violation of their intellectual property

Reba Rocket, co-owner and chief operating officer of Takedown Piracy, a company that helps both adult performers and private individuals remove non-consensually shared explicit media, said sites like LeakedBB cause financial harm to legitimate content creators.

“People would not shove a DVD into their coat pocket and walk out of the store – that’s something tangible that they know they’re doing something wrong, whereas watching something on the internet for free doesn’t have that same connected moral,” she said. 

Other sections on LeakedBB featured threads requesting or promoting content that often appeared to show women who did not have anything to do with the adult industry, which the posts claimed were leaked, hacked or even obtained through blackmail. 

One post advertised images of girls from 29 US states: “There’s names and Facebook information if you want that,” the member, “Master Leaker”, posted. “There’s also two girls that got blackmailed into sending more nudes as well!”

LeakedBB user advertising a large file of “girls from 29 different states”; personal information redacted by Bellingcat

In the “Requests” section, users shared clothed images of women or social media handles of potential victims, and asked if others had leaked content of them. In one recent post looking for a “Florida Milf”, a user wrote: “She may go by the name [redacted]. Looks like the daughter graduated from [redacted]. Anyone have content of her? Sex tapes?” 

Some users also posted nude or intimate images of women they had found elsewhere, asking for help finding out their real identities. “Who is she?” or “Can anyone ID?” were some common questions in the posts. 

Non-consensual intimate image sharing (NCII), colloquially referred to as “revenge porn”, is far from new. It is a known problem on Reddit, where, in 2022, a BBC investigation found “thousands” of such images being shared despite the platform’s attempts to crack down on the issue. 

LeakedBB, however, seemed to take the opposite approach: instead of trying to moderate or prevent users from posting what appeared to be NCII, it sought to profit from and reward it. 

Except for preview images, most of the content users shared in the “leaks” section was behind a paywall and could only be accessed with memberships costing up to US$99.99 or by redeeming credits. 

The site rewarded members with credits for posting “leaked” content, as well as when other members spent credits to “unlock” their content. These credits could be used to access links that users could otherwise only view with a paid upgrade, or redeemed for cryptocurrency at varying rates (the most frequent contributors had the option to cash out the equivalent of up to $0.15 for each thread they posted). 

There was also an annual Christmas contest, with last year’s total prizes worth over $4,000 in cryptocurrency for users who posted or liked the most threads.

Screengrab of a forum announcement on LeakedBB posted on Dec. 7, 2025.

Rocket said LeakedBB had “damaged many people”, including clients of her company. “Those specific clients are not in the adult industry,” she said, “but LeakedBB seemed more than happy to share their non-consensual content”. 

The “leaks” were often posted with women’s purported real names, locations and social media accounts, as well as preview images showing their uncovered faces. One poster said sharing a woman’s social media details “adds to the experience”. 

“For me, it makes my jerk-off sesh feel more personal, as if she’s an actual person I know rather than a moviestar/pornstar,” the post said.

Screengrab of a post where a LeakedBB user shared content of a woman, including her socials; personal information redacted by Bellingcat

There were more than 80 responses to this thread, mostly thanking the original poster for sharing the content. One of them, however, claimed to be the woman shown in the images: “Please remove this link. These photos were illegally stolen from me. This constitutes revenge porn and violates US law. Police are already involved. Not only is it illegal but just gross.”

Allison Mahoney, the founder and managing attorney at ALM Law in New York and Colorado, told Bellingcat she received calls about cases involving NCII “all the time”. 

“It kind of amazes me, given the amount of media attention this has gotten over the years, that people are still engaging in this type of abuse so cavalierly,” said Mahoney, whose firm specialises in providing legal services for abuse survivors and children harmed in welfare systems.

Mahoney and Rocket agreed that sites sharing NCII often had real-world implications for victims, especially when images were posted alongside personal information, including names, contact information and professions. 

“We have clients who … their children were kicked out of Catholic school, or they lost their mainstream job, or relationships ended, or families cut them off simply because content was posted online without their consent and viewed by others,” Rocket said. 

Mahoney said online abuse can turn into offline abuse when victims have their personal information, like their name, profession and contact information, posted with their images.  She has seen clients who had strangers show up at their homes or places of work, threatening their physical safety – a situation she said was “really terrifying”. 

In July last year, LeakedBB closed a marketplace it had hosted for more than five years, which allowed users to sell leaks and services to each other. Lucifer NightStar, the administrator account on the site, said there were allegations of people selling “UA [underage] material”, which was “not something we want on [LeakedBB]”.

Screengrab of a post where Lucifer NightStar explained why the marketplace section had been shut down.

On one section of the forum, which was specifically for sharing content from other sites that hosted leaked pornographic content, LeakedBB had a disclaimer: “Please note that posting any content on any one below the legal age of 18 is against the law. We have a zero tolerance policy on such things and your account will immediately be banned / reported.”

But this warning did not appear on other sections of the forum, including those featuring threads of “amateur nudes” described as having been leaked. Some threads on the forum, which remained accessible shortly before the entire site was taken down, also described images of “young teens”. 

While it is not known if those descriptions are accurate, in a recent post on Reddit a person asked for help taking down non-consensual photos they said were taken when they were a minor, hacked from Snapchat, and posted on LeakedBB, among other sites. 

“I am in school to become a teacher and searched my name on google. If you go down a bit these websites come up,” they wrote. “I am so devastated and can’t believe this has happened to me.” 

While speaking to The Press outside his residence on June 25, Maharaj said that when it came to publishing non-consensual pornography and child sexual abuse imagery, “It should be obvious anyone’s against that.”

Who Is Lucifer NightStar?

Lucifer NightStar was the username for the only account with the title of “Administrator” on the LeakedBB forum. This user posted FAQs for the site and almost every forum announcement throughout its history. 

The URL of this account’s profile page shows the user ID (UID) of “1”. According to documentation for MyBB, a free and open source forum software that LeakedBB has credited for powering the site, the first user of the forum is assigned the UID “1” and has super administrator privileges – meaning their account cannot be deleted, banned or otherwise altered by regular administrators.

While the profile did not state the user’s location, it did show a local timestamp based on the user’s timezone settings, which matched GMT+12 – a timezone used in several countries in Oceania, including New Zealand and Fiji. 

Lucifer NightStar’s recent posts generally avoid mentioning non-consensual intimate imagery, focusing on administrative updates and issues, troubleshooting and the annual Christmas contest. However, in the first few months of the forum’s existence, the user posted a thread with a “LeakedBB Exclusive” of “leaked Kiwi girls”.

One of Lucifer NightStar’s first posts on LeakedBB, sharing content described as “leaked Kiwi girls”.

In another discussion thread from 2020, Lucifer NightStar vouched for a user’s ability to “influence” another member’s ex-girlfriend to share nudes.

(Top) LeakedBB user offering their services to obtain nudes from another user’s ex-partner; (Below) A response from Lucifer NightStar vouching for this user being a “premium collector”. Personal information redacted by Bellingcat

Maharaj did not respond to The Press and Bellingcat’s question about whether he was Lucifer NightStar. However, one of the administrator’s posts led us to a clue pointing to Maharaj’s possible connection with LeakedBB. 

Logica Ltd and MyBBplugins

In one post in May 2021, responding to a user reporting problems paying with Apple Pay, Lucifer NightStar shared a screenshot of what the payment screen should look like. A company name was visible in this image: “Logica LTD”.

Screenshot of a forum post by Lucifer NightStar on how to pay for a premium upgrade for LeakedBB using Apple Pay, showing the company name “Logica LTD”.

New Zealand company records show that Logica Limited was registered by Maharaj in February 2021, just months before this post. The company address is also in Christchurch, where Maharaj lives.

(Note: This is a different company from Logica Partners Limited, based in Auckland, which has no apparent connection with Maharaj or LeakedBB and is unrelated to this investigation.) 

The records from the New Zealand Companies Office show that Maharaj has been the sole director of Logica Limited since its incorporation. He stated on his LinkedIn profile that he was self-employed as the CEO of Logica NZ from May 2020 to August 2021. 

(Maharaj’s LinkedIn profile appears to have been deleted between June 13 and June 15, after The Press and Bellingcat’s initial enquiries and during the period his lawyer said he was in Fiji attending a family member’s funeral.)

Left: Screengrab of Jitendra’s work history from LinkedIn; right: Company registration information for Logica Limited (redaction by Bellingcat). Sources: LinkedIn, New Zealand Companies Office

But that was not the only connection to Logica Limited. On May 4, 2022, a YouTube user with the display name “LeakedBB” uploaded a video on how to pay for memberships on the site. This video was also embedded on LeakedBB’s homepage. 

The video showed how users could pay by credit card. When they clicked to purchase a membership, LeakedBB would redirect them to another website to buy a digital avatar pack with a price corresponding to their selected membership tier. 

After purchasing this “referral product”, users were encouraged to leave a comment and a positive rating to receive an “extra bonus month”. Archived versions of the website show view counts in the tens of thousands for some of these avatar packs. 

The thumbnails of the “digital avatars” as well as their price and description, as shown in the video, were identical to those shown on the archived version of a site, logica.nz, which is recorded as Logica Limited’s website on OpenCorporates. This site also lists “Logica LTD” in its copyright information at the bottom of its landing page

(Bellingcat last accessed a live version of the video on June 15. By July 1, we noticed that the video had been removed by the uploader.)

Left: YouTube video on how to purchase upgrades on LeakedBB. Right: Archived purchase screen of the same avatar pack on Logica.nz

In a forum thread on LeakedBB dedicated to explaining alternative ways to pay for membership, hundreds of users posted that they had just purchased the “Mystic Avatar Pack” or the “Pixel Avatar Pack” to gain access to the site. One user included screenshots of their purchase, showing the site URL to be “logica.nz”. Other users also stated that they had made the purchase on this website and were waiting to receive their upgrades.

Shared screenshot from a LeakedBB user who purchased a “Pixel Avatar” pack in exchange for membership, showing that they left a comment, like other users, on the purchase page on logica.nz. Personal information redacted by Bellingcat

This website’s landing page now displays only a note stating that it is under maintenance. However, according to archives captured by the Internet Archive, it was still selling “digital avatar packs” in March 2025.

This type of payment structure not only conceals the nature of the transaction from the payment processor (as non-consensual content violates most platforms’ terms of service), but it also hides the transactions for the user, as payments are not described as being made to “LeakedBB” on bank statements.

When asked about the links between LeakedBB and Logica Limited, Maharaj only told The Press at the doorstep interview on June 25 that “Logica was my company. I cannot say what happened there right now”.

According to the New Zealand Companies Register, Logica Limited is in good standing, with its most recent annual filing submitted by Maharaj in March 2026. 

The Domain Name System (DNS) records of LeakedBB revealed another connection that seems to point back to Maharaj. Using online investigations tool DNSlytics, we viewed DNS records for the website and found that in 2020, the MX (mail exchange) record for LeakedBB.com was set to LeakedBB.net. An MX record is the mail server set up to accept emails for that domain. For LeakedBB.com, this was later changed to ProtonMail. 

While the WHOIS ownership of LeakedBB.net is obscured, we found it on a list of sites that had DNS certificates issued by another site, mybbplugins.com. A DNS certificate is used to prove ownership of a domain and requires an administrator to validate that certificate. 

According to WHOIS records from cyberthreat intelligence platform DomainTools, mybbplugins.com was publicly registered to Maharaj from December 2011 to February 2019, after which the registrant information was redacted.

The same site also issued a DNS certificate for a domain bearing Maharaj’s name (jitendramaharaj.com) as well as two domains that include part of his first name, jit-pay.cc and thejitshow.com. DNS certificates for these domains were issued between 2016 and 2021, according to free Certificate Transparency monitoring site crt.sh. Both “leakedbb” and the domain names linked to Maharaj’s name (i.e. “jitendramaharaj”, “jit-pay” and “thejitshow”) were also used as subdomains for mybbplugins.com, records from DomainTools show. 

Another link appeared when we inspected the code of the oldest saved archive of the payment screen on LeakedBB, from November 2019, which showed a ProtonMail address associated with the PayPal form at the time with a string of seven digits as the username. 

This string of seven digits is an exact match for what appears to be part of a Fiji-based phone number listed on WHOIS records for websites registered to Maharaj’s name including mybbplugins.com, from 2008 to 2011. It is unclear whether Maharaj was using this phone number in 2019, by the time LeakedBB was set up, and a different Fiji-based phone number was used with his name when the registration for mybbplugins.com was renewed in 2016.

Top: The archived HTML code for LeakedBB’s payment page, with a ProtonMail email linked to its PayPal account. Bottom: The WHOIS domain registry for mybbplugins.com, registered to Maharaj in 2011, with a phone number matching the digits to the ProtonMail email. Graphic: Galen Reich

Explore some of the links between Maharaj and LeakedBB:

Graphic: Galen Reich

From MyBB to LeakedBB

Bellingcat also found several other apparent connections between Maharaj and other applications hosting adult content. 

An account with the username “Jitendra M.” has been posting on the MyBB community forum since 2008, with the account ID originally using the username “Darkmew”. An archived capture of this account’s profile information showed a date of birth and a location in Fiji. 

This date of birth matches the one listed on a Facebook profile Bellingcat found under Maharaj’s name. His LinkedIn profile also shows that prior to moving to Christchurch, he worked in Nadi, Fiji, and he has listed addresses in the city for some of the domains registered to his name, as well as an email with a Fijian domain. This user also mentions that they are a pilot

Jitendra M.’s profile bears a “former staff” label, indicating that he used to work for MyBB. A previous commit (save) of a file containing details of MyBB team members shows that the full name associated with this account’s user ID and username was “Jitendra Maharaj”, and his website was listed as jitendra-maharaj.com. 

Archived versions of this site show photos and details that match those from Maharaj’s public social media profiles and interviews. For example, a 2011 capture shows that he mentioned being a pilot at a company called Pacific Sun. Pacific Sun was later rebranded as Fiji Link, and Maharaj’s LinkedIn profile, before it was deleted, stated that he worked for Fiji Link from 2009 to 2015. A blog post on the site also refers to mybbplugins.com as the author’s “newest endeavour”.

Left: Archived profile of “Darkmew”’s profile on MyBB; Right: Screengrab of information from a Facebook profile under Maharaj’s name, which has either been made private or deleted as of publication.

Very shortly after joining the MyBB community forum in Feb 2008, Jitendra M. asked about using MyBB for “warez” (an internet slang term for pirated digital content) and/or adult content. He stated that he was “interested in using it for a [sic] adult forum”. 

During this time, he also posted asking about streaming videos from a server and how to use a PayPal account without a credit card for “people putting money into my account for services I provide”. In late 2008, Jitendra M. purchased a web domain, reaperscrypt.info, which Wayback Machine archives show hosted pornographic content while it was online in 2009. This domain was publicly registered to Maharaj from November 2008 to January 2010. 

In 2013, he posted about selling the mybbplugins.com domain. However, as previously mentioned, Maharaj’s name was still publicly registered as the owner of the domain until February 2019, when registration data was redacted.

Top: Post by Jitendra M. about using MyBB for warez and adult sites using MyBB; Bottom: Post about selling mybbplugins.com

Bellingcat was able to view Facebook and Instagram accounts under Maharaj’s name and showing his profile picture in early May. These accounts painted a picture of a family man, with his public photos mainly showing his wife and children. His Facebook account had been either deleted or made private by May, and his Instagram account, while still active, has not been updated since 2013.

Archives of an X account using the same username as Maharaj’s Facebook and Instagram accounts also show several posts from November 2019 promoting LeakedBB. 

Archived tweets from an account, using the same username as what appeared to be Maharaj’s former Facebook and Instagram accounts, which posted links to LeakedBB in November 2019. Personal information redacted by Bellingcat

The “Darkmew” username that Jitendra M. originally used was also used for a GitHub account which hosts a repository described as the “official repository for Pay it Now – PIN Token”. This account, which now redirects to an account with the username “JitMaharaj”, has also forked (or copied) two apps created by other people: one to create a subscription platform “like onlyfans.com” that uses cryptocurrency for payments; the other designed to scrape and report illicit content from LeakedBB.

Screengrabs from the “JitMaharaj” GitHub account, which forked repositories for an application designed to create a platform “like ‘onlyfans.com’, and another to report illicit content from LeakedBB.

These forked repositories were among 38 visible on JitMaharaj’s account on June 17, but by July 1 – after a June 22 query from The Press asking Maharaj whether he owned this account – there were only 25 repositories listed on this account. The two repositories mentioned above were among those removed.

Maharaj did not respond to questions about whether he owned any of the accounts or domains mentioned in this section.

‘Hiding Behind Screens’

Mahoney said that successfully removing clients’ images from platforms like LeakedBB was a time-consuming task. “Some sites, usually the sites hosted overseas, will just ignore the request and won’t take them down,” she said.

In the US, which accounted for almost half (40 percent) of LeakedBB’s web traffic in May, the Take it Down Act recently came into effect. The new federal law requires platforms to quickly remove non-consensually shared intimate imagery when it is reported.

However, there has been little discussion of the law on LeakedBB. One user asked in the “Help” forum how this act would affect the site and its members back in October 2025, but Lucifer NightStar never responded to this post.

LeakedBB user asking about the Take It Down Act

Rocket said having content removed for her US-based clients could be difficult when the platforms were based overseas: “A lot of it depends on where the platform is hosted, who runs their ad network and who is monetising – who their payment processors are,” she said. 

LeakedBB accepted cryptocurrency payments through NOWPayments, a cryptocurrency payments gateway based in the Netherlands and Estonia. The purchase page for its subscription plans, which allowed users to gain unrestricted access to the site, redirected to a NOWPayments purchase screen to transfer cryptocurrency to LeakedBB. 

In response to questions from Bellingcat, NOWPayments confirmed that LeakedBB’s activities violated its terms of service. The payments provider said it had deactivated LeakedBB’s account and blacklisted the platform immediately, as of June 4. 

LeakedBB did have a form for people to request that their content be taken down under the Digital Millennium Copyright Act (DMCA), a US copyright law. However, this required victims to submit personal information such as a physical address and a business email address, and stated that it would reject requests that used email addresses from free services like Google and ProtonMail. Such details appear to go beyond those required for DMCA takedown requests on other sites: for example, Google only requires a first and last name, and an email address from any domain.

In one Reddit thread discussing the difficulty of removing content from LeakedBB under the DMCA, someone commented: “Some of this seems fairly standard, some of it seems like it’s designed to make people not request a takedown for fear of doxing [sic] themselves.”

On the page to submit DMCA takedown requests, LeakedBB also stated that successful requests would lead to them removing content hosted on their servers, but not links to third-party hosting providers – which is how a large portion of the content was made available to the website’s users. 

In New Zealand, where Maharaj is based, posting intimate imagery without consent is illegal under the Harmful Digital Communications Act. People face up to two years imprisonment or a fine up to NZ$50,000 (US$29,200), while for a company, the fine can be as high as NZ$200,000. 

Netsafe is the only approved body in the country that handles complaints under this act. The agency’s chief online safety officer Sean Lyons told The Press that the law was quite novel and other jurisdictions were “envious” when it was enacted – it was able to respond to generative AI technology that didn’t exist when it was written, and gave New Zealand courts powers to issue takedown orders, even in other countries.

Still, Lyons said the law had its limitations: it was mostly intended for use where one individual was harming another, and if the responsible party was overseas, the law’s efficacy largely relied on responsible platforms doing the right thing. 

“There are times when within our process, we will have contacted platforms or hosts and they will have said, ‘Who the heck are you?’…[Or] ‘We know what we’re doing, we are quite comfortable with what we are doing, and we don’t give a stuff about what it is that you are telling us, or about New Zealand law, or about the harm.’”

Mahoney and Rocket agreed that current laws were limited in their effectiveness against sites like LeakedBB. 

“The fact of the matter is there are places where … until there is an enforceable international law, that content is going to be available forever, which means there is a risk of it being shared forever,” Rocket said. 

Mahoney said image-based abusers have also become more sophisticated over time: “Technology is advancing, and the law is always playing catch-up,” she said. 

But she suggested that identifying those responsible for the abuse could have a deterrent effect: “The anonymity that people have hiding behind screens really contributes to this and emboldens people to act in ways that are very abusive to people.

“If people understand that there’s a risk that their identity and their bad behaviour will be revealed, the hope is that it will curtail some of this and dissuade people from engaging in this type of conduct, which is so, so harmful to the victims.” 

If you are a victim or know anyone who is affected by image-based abuse, resources and support are available through StopNCII.org.


Galen Reich and Melissa Zhu from Bellingcat and Michael Wright from The Press contributed to this article. 

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Identifying the Crypto Entrepreneur Linked to Popular Forum Trading in ‘Leaked’ Nudes of Women appeared first on bellingcat.

Between Graves and Uncertainty: The Management of the Dead After Venezuela’s Earthquake

Bellingcat has geolocated footage circulating on social media that appears to show coffins placed in newly dug trenches following the recent deadly earthquakes in Venezuela.

The site identified extends over two hectares beside an existing cemetery in La Esperanza, a town near La Guaira on the country’s northern coast.

It was visited by a representative of our Latin American reporting partners who captured pictures of work ongoing at the site. They also report speaking to a resident who said that refrigerated trucks with several bodies had been coming and going.

Stills from a video published by Colombian outlet TV and showing a group of coffins in a dug trench. Source: RTV Facebook

The location matches a site identified in July 6 reports by AFP and Deutsche Welle (DW), which detailed that 150 unidentified bodies had been buried in a long row of individual graves.

AFP and DW published pictures of individual crosses and stones, quoting a resident of the town who stated that the burials were “numbered by plots and also by the code” so they could be identified at a later date.

It is not known if the coffins visible in the social media footage relate to the 150 unidentified bodies later referred to by AFP and DW, or if they are separate burials at the same general location.

Reuters also published pictures of the site on July 6 and showed video of coffins arriving on the back of flat bed trucks.

Top: A map highlighting the location of the site southwest  of Catia La Mar. Bottom: Stitched frames of TikTok video showing a panoramic view of the burial site. The satellite image (inset) captured on 30 June 2026 shows a matching sector of land approximately the size of two football pitches. The land began to be cleared on 27 June 2026 next to the Municipal cemetery La Esperanza in La Guaira State. Credit: Mapcreator, TikTok. Satellite: Copernicus Sentinel data (2026), processed by ESA

More than  3,500 people are confirmed to have died as a result of the earthquakes so far. But that figure is expected to rise significantly, with the UN reporting that the death toll could reach 10,000.

Oran Finegan, Director of Forensic Action International and former Head of Forensics for the International Committee of the Red Cross (ICRC), told Bellingcat that, while it is best practice for the burial of deceased persons to take place in individual graves, it is not uncommon to see long trenches like those seen in the social media footage when there are high numbers of unidentified deceased and it is not practical to immediately provide individual graves. 

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

He pointed to documentation from the ICRC that details best practices in such circumstances. He also made the important distinction between common graves, where bodies are temporarily kept until identification can take place, and mass graves, where bodies are dumped clandestinely without any care or process. What is seen in the footage appears to be the former, he said. There has been no evidence of the latter.

Finegan emphasised that it was vital that burials were mapped and recorded properly during any burial process so that identification could take place at a later date. Documenting where bodies were coming from, laying each body with enough distance from each other and ensuring each coffin or body bag had a unique number was key, he said. 

While it has not been possible to ascertain the exact processes being followed at or preceding burials at the La Esperanza site, media reports in nearby La Guaira have recorded complications with identification and burial processes.

According to the BBC  the scale of the disaster has overwhelmed local services, forcing institutions to improvise. Some bodies were being placed outside, exposed to the sun, at a port facility in La Guaira, the BBC reported.

A further complication is that many of the bodies recovered have reportedly been unrecognisable. 

One woman told the independent Venezuelan publication RunRun.es that she was sent a tag and number for a body bag that did not match the bodies of her relatives. She was then told that her relatives’ bodies had been misidentified and sent for burial at a site in the town of Los Teques.

The New York Times reported last week that overwhelmed morgues were filling with unidentified bodies, forcing authorities to consider mass burials.

The Venezuelan Attorney General’s Office, the Judicial Police and National Service of Forensic Medicine Sciences did not respond to requests for comment for this article. However, President Delcy Rodriguez has previously stated that all bodies are being processed through a forensic identification system which includes fingerprints records, photographic documentation and forensic odontology.

Rodríguez has also said that “no one will go to a mass grave”.

The President of the Venezuelan Professional Funeral Sector Association (Asoproinfu), Davenio Velásquez, stated that there is a protocol for unidentified bodies to be buried temporarily in “five hundred individual burial niches” in Caracas. He added that they will be exhumed and cremated after six months if not identified. 

Finegan added that exhuming and cremating bodies prevents identification and it is not a best practice. However, he said it is important to understand local cultural and religious customs. He also added that the six-month deadline for reclaiming remains is likely unrealistically short for such a major disaster.

Identifying the Burial Site

Terrain features in the social media videos Bellingcat found are consistent with those seen beside a graveyard on the outskirts of La Esperanza, a town situated on Venezuela’s northwest coast near the La Guaira region that was significantly impacted by the earthquakes.

These features allowed us to geolocate the site seen in the footage.

Firstly, a video published on Facebook on July 1 by Colombian digital outlet RTV appears to show a large grave with approximately half a dozen coffins situated within it. The video (which we will refer to as Video 1) further  shows a group of people in civilian clothes beside a truck with more coffins on the back. It was not possible to verify the contents of the coffins.

Stills from a video published by Colombian outlet TV and showing a group of coffins in a dug trench. Source: RTV Facebook

Another video (which we will refer to as Video 2) posted to Instagram by an independent creator who said it was shared by a source on the ground also shows a series of large holes on a plot of land that appears similar to the first video. 

Stills from a video published by an independent creator showing trenches at a site similar to video 1. Source: eylyngenv Instagram.

Bellingcat sought to identify where these videos were taken by first searching for any other potential reference images and footage we could compare them to.

We found one video posted by a former army Colonel and now Mayor of Vargas Municipality, José Manuel Suárez Maldonado, posing beside heavy machinery as it prepared a plot of land that was due to be given to the local community as a new cemetery plot. The video was first published in June 2024.

Video 3 Major of Vargas promoting future free plots at la Esperanza town municipal cemetery back in June 2023. Credit: Instagram

By comparing the footage in the mayor’s video with the RTV and independent creator video – as well as matching landmarks visible in the mountaineering app Peakvisor – we were able to verify that all were filmed on the same plot of land.

For example, a distinctive tree formation is visible in Video 1 and Video 2, suggesting they were filmed at the same site.

Matching trees in the background of Video 1 (left) and Video 2 (right) suggests they were filmed at the same site.

Mountain features and hillsides seen in the background of Video 2 match those seen in Video 3.

Stills from Video 2 (left) and Video 3 (right) the terrain in the background in both videos appear to be the same and are consistent with a mountain ridge seen from cemetery La Esperanza. Credit: Instagram

The rocky facade of one hillside visible in Video 2 also matches what can be seen in Video 3.

Stills from Video 2 (right) and Video 3 (left) the rocky formation of the hill  in the background appears to be the same.

Combined, the visual comparisons allow us to ascertain that the three videos were filmed in the same place.

We then compared the hills and mountains visible in Video 2 to what can be seen in the mountaineering app, PeakVisor. This allowed us to confirm the location just outside La Esperanza.

Comparison between the Video 2 (bottom) with a 3D landscape modeled in PeakVisor for the respective location.

Satellite imagery of this site taken on June 25 shows a patch of land that appears green, filled with vegetation. By June 27, a newly scraped area of approximately 1.5 acres – roughly the size of a football pitch – appeared in exactly the same place.

A GIF shows satellite imagery captured over the La Esperanza site on June 25, June 27 and June 29. Credit: Copernicus.

It is important to note that the recently cleared area appears to have been excavated or altered before.

Satellite imagery from 2022 and 2023 shows work being carried out in the same spot before it once again became overgrown.

However, Bellingcat identified a white marquee visible in Video 2, providing a temporal reference to show that at least one of the videos was filmed in 2026.

This marquee was visible in satellite imagery captured on June 27, 2026, at the exact spot visible in Video 2.

Top: GoogleEarth 3D view of the surrounding terrain. Center: Stills from video 2 stitched to build a panorama view of the site used to determine the point of view of the camera filming. A white marquee is visible in the footage. Bottom: This white marquee appears to be visible on land only on satellite Imagery from Planet captured in June 2026. Sources: GE Pro/LandSat/Copernicus/Airbus, Instagram, Planet Labs PBC.

In footage posted to TikTok on  July 2 (which we are labelling Video 4) the same tent appears to be visible. 

The cleared sector of land matches the shape of the work visible in more recent satellite imagery of the site.

Satellite imagery from previous years also shows that the cleared area looks slightly different when viewed from above. This allows us to be confident that the social media footage aligns with the more recent satellite imagery rather than previous years when the area was also cleared.

Stitched stills from a TikTok Video 4  posted on 2 July showing dug graves at la Esperanza Cemetery. The cleared area seen in social media footage aligns with the more recent satellite imagery rather than previous years when the area was also cleared.Credit: TikTok. Satellite (inset): Copernicus Sentinel data (2026), processed by ESA.

Bellingcat’s reporting partners contacted the Venezuelan Attorney General’s Office, the Judicial Police and National Service of Forensic Medicine Sciences, the President of the Association of Funeral Industry Professionals (Asoproinfu) but did not receive a response before publication.

Finegan, the forensics expert, said that the current death toll was likely an underestimation and authorities are expecting it to rise. 

But he said that even when families are unable to immediately identify their loved ones, it was vital to ensure  that the deceased are buried respectfully and in a way that preserves the possibility of future identification. This he added can bring families a degree of comfort in the most difficult circumstances.


This investigation was the result of a collaborative effort with our Venezuelan and Latin American partners: Efecto Cocuyo, Alianza Rebelde Investiga (ARI)—comprising El Pitazo, Runrunes and TalCual—and the Latin American Center for Investigative Journalism (CLIP).

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Between Graves and Uncertainty: The Management of the Dead After Venezuela’s Earthquake appeared first on bellingcat.

Rhino Horn, Leopard Skin and Tiger Claws Sold Openly on Facebook

Warning: Includes graphic descriptions of animal harm and images of animal parts from the outset.

A Bellingcat investigation has uncovered a Myanmar-based wildlife trafficker who has operated openly across social media for at least six years, claiming to have sold tiger bones, rhino horn, elephant skin and other products from protected and endangered species to customers in Myanmar, China and Thailand.

By analysing hundreds of adverts and customer conversations, Bellingcat traced more than US$21,000 in sales, identified cross-border shipments linked to multiple payment accounts, and geolocated the dealer’s home address. The seller frequently used graphic images to convince buyers that his wildlife products were genuine, sharing footage of animals before and after they were killed as proof of authenticity.

Following this investigation, Meta removed 10 Facebook accounts, WeChat suspended three accounts and revoked their payment functions, TikTok and YouTube each removed one account, and authorities in Myanmar and Thailand said they would examine the findings further.

On December 21 2022, a Facebook account shared a reel of a tiger cub lying unconscious beneath the caption: “Time for winemaking”, followed by several laughing face emojis. Four days later, the same account shared another reel, this time of an adult tiger lying motionless on an orange plastic sheet as a man approaches with a knife.

Two separate videos posted to Facebook by the account known as MB.

The account behind both videos belongs to Mei Ba (hereafter MB), a self-described Traditional Chinese Medicine (TCM) doctor based in Myanmar. In TCM, plants and animal products are used to prepare remedies based on established medicinal formulas. These remedies can take many forms, including herbal teas, simmered concoctions, ingredients steeped in wine, and pills. TCM is also sometimes associated with pseudoscientific beliefs, such as the idea that consuming an animal’s organ can nourish the corresponding organ in the human body.

A Bellingcat investigation has found that MB frequently advertises the trafficked parts of critically endangered and vulnerable species to customers in Myanmar, Thailand and China. An analysis of social media posts published by MB over six years found references to sales involving parts of bears, elephants, leopards, musk deer, otters, pangolins, rhinos, seahorses and tigers, all of which are protected species.

Screenshot of MB’s TikTok profile where he identifies himself as a TCM Doctor. Bottom: English translation by Bellingcat.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Profiting from Protected Species

For at least six years, MB has used ten different Facebook accounts under versions of his name to advertise animal parts and products for sale, including those derived from vulnerable and protected species. 

MB has advertised tiger body parts and products, including skins and wine made from bones. Myanmar’s wild tiger population was last estimated at a minimum of 22 animals (in a 2019 study published before the civil war). Licensed tiger farms, described as being similar to zoos, also operate in the country. However, Myanmar law prohibits the killing of any tiger, wild or captive. 

Bellingcat has also identified adverts offering leopard body parts, including skin, bones and gallbladders, as well as a product described as a “whip”, a euphemism for a penis. Many of the adverts explicitly stated that the body parts came from wild animals. The Indochinese leopard is classified as critically endangered, with fewer than 800 mature individuals believed to remain in the wild across mainland South-East Asia.

Products as advertised by MB on Facebook. Left: wild leopard skin, Dec 2024; top right: wild leopard bones, Dec 2025; bottom right: leopard gallbladder, Dec 2022. Descriptions added by Bellingcat.

MB has advertised body parts and other products derived from Asian elephants, an endangered species, including skin sold in pieces and powdered form, as well as their genitals.

One of MB’s more graphic posts showed a recently killed and butchered moon bear – a type of Asian black bear which is classified as a vulnerable species. MB has also advertised various bear body parts for sale, including paws, heads, gallbladders, bile and fat.

Whole rhino horns, as well as bracelets and medicinal products made from rhino horn, have been advertised by MB. Although rhinos have been extinct in Myanmar since the 1980s, the country remains a known transit route for rhino products moving from India to China and elsewhere in South-East Asia, suggesting the items advertised by MB originated outside Myanmar.

Rhino products as advertised by MB on Facebook. Labels added by Bellingcat.

Under Myanmar law, anyone convicted of killing, possessing or trading a “completely protected species,” or its parts, faces a minimum prison sentence of three years and a fine under a conservation law introduced in 2018. Completely protected species advertised by MB include Asiatic black bears, elephants, leopards and rhinos.

Bellingcat contacted multiple Myanmar government authorities for comment regarding MB’s wildlife trade. The Myanmar embassy in London confirmed receipt of Bellingcat’s request and said it would consult the relevant authorities in Myanmar. 

Convincing Customers

Counterfeits are common in the illegal wildlife trade. Buffalo horn is often carved to resemble rhino horn, while cattle penises are passed off as tiger parts. Much of MB’s promotional strategy therefore focuses on persuading buyers that his products are genuine. 

To market rhino horn, MB has posted images of the items on scales or held up against a light, which he claims demonstrates the texture of genuine horn. For tiger bones, in one post he said that a patch of skin would be left attached to demonstrate their authenticity. 

MB has also posted videos of recent leopard and tiger kills. He has shared footage of live tigers in cages followed by images of the same animals being butchered for their skins, bones, skulls, claws and fangs.

Video of a live tiger in a cage, posted by MB on Facebook on Nov, 14 2022. Translation of the accompanying text: “What the hell are you huffing about? Just wait, your turn is coming [Smug emoji]”.

Bellingcat only analysed open source evidence, including social posts, customer conversations, visible transactions and shipping receipts. Therefore, the authenticity and composition of the wildlife products advertised or sold could not be independently verified.

Nevertheless, given the volume and graphic nature of these posts, MB’s ability to operate on Facebook for at least six years raises questions about why his accounts remained active up until Bellingcat contacted Meta.

Evading Platform Moderation

For years, MB has openly advertised his business on Facebook, posting hundreds of adverts across ten profiles and various groups. He often uses coded language, including Chinese-language euphemisms in his comments. 

For example, he uses “eraser” (橡皮) to refer to “elephant skin” (象皮), a Mandarin homophone with characters that are also visually similar, shown below.

Screenshot of a Facebook advert posted by MB on Oct, 30 2024. Post refers to elephant skin as “eraser” and includes an elephant emoji. Annotations by Bellingcat. 

MB also uses pinyin, the phonetic system for spelling Mandarin Chinese words using Latin letters. For example, in one post, he abbreviates the pinyin word for “rhino” (xīniú) as “X”, advertising “X horn powder”, and uses “Y” (pinyin: yào) as shorthand for “medicine”. He also frequently uses animal emojis, including tiger, elephant, rhino, deer and bear, to refer to products derived from those animals without naming them directly.

Clockwise from top left, the emojis and text refer to products including rhino meat strips, African elephant skin, tiger bone paste (twice), wild deer antler and bear gallbladder.

Asked why MB had been able to operate for so long without being banned and how it detects common evasion tactics such as coded language, Meta responded: “Bad actors constantly evolve their tactics to avoid enforcement, which is why we partner with groups and invest in tools and technology to detect and remove violating content.”

Cross-Border Trade

To map the scale of MB’s business, Bellingcat analysed more than 500 screenshots of customer conversations spanning May 2021 to May 2026. Originally taking place on Facebook, Viber and WeChat, these exchanges were later reposted by MB on Facebook.

Often blurred or cropped, the material appears to have been shared as part of a strategy to present MB as a trusted seller who reliably delivers to customers. However, given the content frequently included shipping labels with names and addresses, product descriptions, and price discussions, Bellingcat was able to trace part of MB’s customer base and income. Notably, only content MB chose to repost was available for analysis, meaning the findings represent only a sample of his overall activity. 

Across the dataset, Bellingcat identified more than 150 transactions totalling US$21,000. The United Nations estimated Myanmar’s annual per capita income at between $300 and $430 in 2023.

hierarchy visualization

Bellingcat analysis of MB’s digital footprint showing revenue earned per species by MB. Currency in US$. Trade values are estimated based on yearly average black market exchange rates.

Based on delivery records, Bellingcat identified 119 deliveries within Myanmar, 27 to mainland China, and nine to Thailand. Within Myanmar, shipments were most often sent to shared pickup points in cities or towns, whereas those to China were more frequently sent directly to individual addresses. 

Shipments within Myanmar most often involved small quantities of powders or medicines, such as 3 to 7 g of rhino horn powder or 5 g of bear gall bladder. By contrast, deliveries to China more often included whole animal parts such as rhino horn or tiger bones, or larger quantities of products, including 500 g to 1 kg of elephant skin powder or 10 to 40 bottles of medicine.

Map of number of recorded sales to regions in Myanmar, China and Thailand, based on Bellingcat’s analysis of MB’s digital footprint between 2021 and 2026.

MB’s highest-value recorded transaction was to a customer in Yiyang, Hunan Province, China and involved two tiger femur bones weighing just over 2.5 kg. Sold in July 2022, the bones fetched 23,500 Chinese Yuan (US$3,494). The customer was asked to provide a screenshot as proof of payment. MB later reposted this on Facebook, alongside a photograph of the bones wrapped in cling film and a shipping label for Deppon Logistics attached. 

Bellingcat contacted Deppon Logistics for comment, sharing the image and tracking number shown below, but received no response at the time of publication.

Screenshot of a customer conversation in which MB offers several tiger femur bones for sale. Bottom: Photograph of the wrapped bones, showing a courier label and tracking number, posted on Facebook on July, 8 2022.

Under Chinese law, buying, transporting, or selling protected or endangered species can, in the most serious cases, carry prison sentences of more than 10 years. Asian elephants and wild tigers are listed as “Class 1” protected animals. A permit system does exist for the use of captive-bred tigers, although it remains controversial

Under the Convention on International Trade in Endangered Species of Wild Fauna and Flora (CITES) Appendix I, international trade in any endangered species, including Asian elephants and tigers, as well as their derivatives such as skin powder, scales and bones, is prohibited. China, Myanmar and Thailand are all parties to the treaty. 

Bellingcat contacted the General Administration of Customs of China for comment on MB’s wildlife sales to China but did not receive a response at the time of publication.

Related articles by Bellingcat

The Hunt for Malaysia’s Elusive Wildlife Trafficker
Asia-Pacific

The Hunt for Malaysia’s Elusive Wildlife Trafficker

Bellingcat also found evidence of nine deliveries to Thailand, including a tiger penis and several TCM powders said to contain dog, yak and seahorse, all species regulated by Thai law and protected under CITES.

The Thai Natural Resources and Environmental Crime Division told Bellingcat that it already monitors packages falsely declared as traditional medicine but found to contain protected wildlife parts or ingredients derived from them. Following Bellingcat’s findings on MB’s activities, the division said it would investigate further.

A large proportion of MB’s exports to all three countries were bottles of TCM powders or tablets. For example, a “kidney replenishing medicine” was purported to contain deer, dog, gecko, praying mantis, seahorse and yak, while a “prostate medicine” was said to include deer, seahorse and dog. 

Under Chinese law, all packaged TCMs must carry labels clearly displaying the manufacturer’s name, full ingredient list, production and expiry dates, and information on side effects and safety. None of these details were present on MB’s labels.

A shipment of “Elephant Treasure Digestive Medicine”, described by MB as containing rare and valuable ingredients and bearing the image of an elephant on the label. The ingredient list states only “skin powder”. Posted on Facebook in October 2025.

Multiple banks accounts

Over six years of reposted conversations with customers, Bellingcat observed MB requesting payments to at least 15 different accounts, including seven via WeChat Pay, two via Alipay and six via third-party bank accounts, which MB described as belonging to friends or family.

For example, in May 2022, a customer purchased 1kg of elephant skin powder to be shipped to Chiuchow, Guangdong Province, China. MB told the customer his WeChat account could not currently receive the payment and instructed them to send the funds to his “sis” [female associate], shown below.

Screenshots of a WeChat conversation between MB and a customer, reposted by MB on 29 May 2022. English translation by Bellingcat.

Both WeChat Pay and Alipay’s terms and conditions prohibit the use of their services to receive payments for illegal activities.

After being contacted by Bellingcat, WeChat suspended three accounts, revoking all payment functions and removing associated content. 

Alipay did not respond to Bellingcat’s request for comment.

Identifying MB

MB’s brazen online activities include operating at least ten Facebook profiles, two TikTok accounts, one WeChat account and one YouTube channel. He is the sole administrator of a Facebook group with nearly 1,000 members. Across these platforms, he has amassed some 12,000 followers. 

While using variations of “Mei Ba” (MB) across most of these accounts, he also uses the Chinese name “Mei Xiangfu” on his personal WeChat account. The name “May Kyin Phu” also appears alongside payment QR codes when customers are asked to transfer funds. Below is a QR code for Myanmar’s largest bank, KBZ, which includes what appears to be MB’s legal name: U May Kyin Phu, with “U” used as an honorific equivalent to Mr.

Screenshot from a WeChat conversation with a customer showing MB’s ID photograph and a bank QR code displaying the name “May Kyin Phu”. Reposted by MB to Facebook on Dec, 23 2024.

Since 2019, MB has used the same ID photo as his profile picture across multiple platforms, as well as his wedding photo as his TikTok profile picture and Facebook banner image. His wife, identified in the wedding photo and in other images posted by MB, has also been found advertising vulnerable and protected species via her Facebook account.

With more than 3,100 followers, she frequently reposts MB’s adverts while also sharing screenshots of conversations with customers. For example, in one WeChat exchange later reposted to Facebook, she discusses the cash sale of five “real” tiger penises.

From MB’s posts, Bellingcat geolocated a house in Lashio, eastern Myanmar, used to photograph animal parts for sale in his advertisements. MB has posted content from this property since 2020.

In the images below, what MB describes as “leopard gallbladders” can be seen hanging from a balcony, revealing the layout of the property’s backyard and the rooftops of adjacent buildings. Although Lashio is not covered by Street View, the distinctive roof visible in MB’s images matched with user-uploaded photographs on Google Maps.

Geolocation of photographs posted by MB to Facebook in Dec 2022, matching rooftops in Lashio, Myanmar, with Google Earth imagery from Sept 2022.

Bellingcat contacted both MB and his wife for comment on the findings of this report. Both were reached via WeChat and appear to have received the request, but did not reply at the time of publication.


Data visuals by Galen Reich, Graphics by Merel Zoet, Editor, Claire Press.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.


The post Rhino Horn, Leopard Skin and Tiger Claws Sold Openly on Facebook appeared first on bellingcat.

Satellite Imagery Shows Scale of Venezuela Earthquake Damage

At least 1,719 people are reported to have died after two devastating earthquakes struck northwestern Venezuela last week.

The final casualty count is expected to rise significantly.

Some media outlets report resident’s growing frustration with the Venezuelan government and its recovery efforts.

Sky News on June 29 reported that the United Nations Coordinator for Humanitarian Affairs in Venezuela was preparing for as many as 10,000 deaths. 

Social media posts, news reports and drone footage have been shared in recent days, proving vital sources for many Venezuelans (both in the country and living abroad) who are searching for information about loved ones who remain missing.

Social media pages have been set up listing many of those who are yet to be accounted for. Others have contacted Bellingcat asking if apartment blocks relatives were staying in are still standing. 

Bellingcat has received satellite imagery from Planet Labs PBC that shows one the worst affected areas in the country, including collapsed buildings and apartment blocks in La Guaira.

Readers can move laterally and vertically to observe the full image in the interactive below as well as zoom in on specific areas to assess the damage. A share button on the top right will copy a shareable link to the zoomed in area.

Scroll and zoom to see damage throughout the affected Venezuelan coast. Toggle between English and Spanish. Share a link to a specific location by clicking the button on the top right. The before imagery is from Jul 30, 2025 and Dec 12, 2023. After imagery is from Jun 27, 2026. SkySat imagery via Planet Labs PBC.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

The high resolution image covers a 14-mile stretch of Venezuela’s northern coast from the towns of Catia La Mar to Caraballeda, which have been among the worst impacted. 

Other areas to be significantly impacted but not included in the imagery above include Caracas, Maracay, Valencia, Barquisimeto and Yaracuy.

We have compared the satellite imagery we obtained with previous images captured before the earthquake to identify which parts of this 14-mile stretch of coastline to show changes since the quakes. 

Readers can toggle between the imagery captured on June 27 (five days after the Jun. 24 quakes) and a composite of reference images taken on Jul. 30, 2025 and Dec. 11, 2023 (before the quakes).

Zooming in on specific areas reveals the scale of the damage.

For example, several buildings seem to have been flattened in the below before and after images showing the Playa Grande area.

Before imagery (left) of Playa Grande is from Feb 27, 2026. Imagery from after the earthquake (right) is from Jun 26, 2026. SkySat imagery via Planet Labs PBC.

The Planet Labs imagery also confirms significant destruction in the town of Carabelleda.

Before imagery (left) of Carabelleda is from Jun. 19, 2026. Imagery from after the earthquake (right) is from Jun 27, 2026. SkySat imagery via Planet Labs PBC.

Another area, Macuto, has been significantly impacted as well.

Before imagery (left) of Macuto is from Mar 20, 2026. Imagery from after the earthquake (right) is from Jun 27, 2026. SkySat imagery via Planet Labs PBC.

Footage taken on the ground and posted to social media also displays the devastation.

A minute-long video filmed on a 500-meter section of José María España Avenue in Carabelleda shows as many as a dozen collapsed buildings, most of them high-rises. This drone footage gives an aerial look of the destruction of at least six apartment blocks in the same area.

Another video shared on social media showed a collapsed hotel in Macuto, between Carabelleda and La Guaira.

Other open source information about the damage in cities such as Caracas, Valencia and beyond can be found on this site where individuals are uploading images and videos detailing damage.

While international rescuers continue to arrive in Venezuela, the threat of aftershocks remains.

Reuters also reports that engineers fear many buildings that remain standing could be vulnerable and are requesting an audit of state housing.


Carlos Gonzales, Jake Godin and Miguel Ramalho contributed to this report.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

The post Satellite Imagery Shows Scale of Venezuela Earthquake Damage appeared first on bellingcat.

Poster Boy: Sanctioned Kinahan Cartel Lieutenant Found Playing Padel in Dubai

This article is the result of a collaboration with The Sunday Times. You can find their corresponding piece here.

Every Friday evening, the brochure says, players can compete to win cash prizes in one of the world’s fastest-growing racquet sports. The padel club in Dubai’s west is the picture of modern wellness culture: climate-controlled courts, a private sauna and ice bath, and one-on-one coaching. The promotional image shows a bearded man in mid-swing, eyes locked on the ball. He wears matching activewear and a golden tan. The poster boy for padel is a talented player who once finished runner-up at an international tournament. He has also spent the past decade living in the shadows.

Left: Ian Dixon has been sanctioned by the US Treasury as part of its action against the Kinahan cartel. Right: Dixon, who appears to live a carefree lifestyle in Dubai, at a racquet sports event post-sanctions. Source: US Treasury, sanddune_padel_dxb / Instagram, asiapacificpadeltour / Instagram

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Ian Thomas Dixon is a key figure in the Kinahan cartel, the Irish organised crime group that authorities say has evolved into a US$1.5 billion transnational network involved in drug trafficking, money laundering and arms smuggling. Investigators have connected the cartel to Iran’s intelligence services and the Lebanon-based militant group Hezbollah. Its feuds with rival gangs have been linked to at least 18 murders across four countries.

Dixon, 36, along with the Kinahan Organised Crime Group’s senior leadership – Christy Kinahan, 69, and his sons Daniel, 49, and Christopher Jr, 45 – was sanctioned by the US government in 2022. Authorities allege the Irishman acted as a trusted lieutenant to Daniel Kinahan, who is said to manage the cartel’s vast drug trafficking operation by helping move bulk cash across Europe, arranging payments and keeping tabs on money owed by a narco-trafficker.

Wanted posters for Irish drugs smugglers Daniel, Christy and Christopher Kinahan Jr, released after the cartel leaders were sanctioned along with four key associates in 2022. Source: US Department of the Treasury

Bellingcat and The Sunday Times can today reveal how Dixon’s racquet sport hobby has left behind a digital trail that led to the most recent footage of him since those sanctions were imposed – the first time he has been pictured publicly in almost a decade. This investigation also uncovers the alias Dixon has used in Dubai and exposes the first open source links to an underworld associate who was recently extradited from the Gulf state and jailed in Scotland.

It comes as cartel leader Daniel Kinahan awaits extradition to Ireland after his arrest in Dubai on foot of a warrant issued by Irish authorities. The arrest, in April, followed an extensive policing and diplomatic effort from international law enforcement.

Bellingcat recently published images of ex-UFC fighter Mounir Lazzez with Daniel and Christy Kinahan at a 2025 MMA event in Dubai. Our investigation also linked Lazzez to multimillion-dollar transactions for crude oil tankers that were later sanctioned by the US. Source: WeCaptureYou, C4ADS Horizons

In March, investigations by Bellingcat and The Sunday Times exposed the first photographs of Daniel Kinahan and his father in years and also revealed that the cartel’s “friend”, former UFC fighter Mounir Lazzez, was connected to US sanctions against Iran.

The latest findings give an unprecedented glimpse into the recent activity of a key cartel associate who, until now, has largely flown under the radar.

Family Ties

When cartel founder Christy Kinahan moved to Spain after his release from an Irish prison in 2001, it wasn’t long before his new home became a hub for the gang. His sons, Daniel and Christopher Jr, soon followed him to the Costa del Sol – as did their younger cousin, Dublin native Ian Dixon.

From the late 2000s onward, Dixon worked for businesses linked to the crime family in the south of Spain. One of these was The Auld Dubliner, a pub in Estepona that reportedly served as a base of operations for the cartel. In 2010, the pub was raided and temporarily closed by authorities as part of Operation Shovel, a years-long multi-national police investigation into the cartel’s drugs and arms-trafficking activities.

Left: Dixon pictured in 2011 behind the bar at The Auld Dubliner in Estepona. Right: Exterior of the pub in 2012 (image highlighted by Bellingcat). Source: Facebook, Google Street View

Dixon would also work as a trainer at MGM Marbella, the boxing gym co-founded by Daniel Kinahan that would go on to represent some of the biggest pro boxers in the world. The company, which was renamed MTK Global, shut down after the US sanctions on the Kinahans were imposed in April 2022.

Top left: Ian Dixon at MGM Marbella in 2013. Top right: Dixon running a pads training session at the gym in January 2015. Bottom: Dixon pictured with Daniel Kinahan and others in Spain in 2013. Source: X, MGM Marbella / YouTube

In 2016, Dixon was arrested by Spanish police investigating the murder of Irish criminal Gary Hutch. The previous year, Hutch had been gunned down while out for a morning jog in a gated community on the Costa del Sol.

Dixon was released without charge, and another Kinahan cartel associate was later sentenced to 22 years for his role in the murder. The killing sparked a feud between the Kinahans and the rival Irish Hutch gang  that resulted in at least 18 deaths. 

Dixon and other key Kinahan members fled to Dubai in the wake of the deadly feud.

CCTV footage of Gary Hutch being pursued by a gunman in southern Spain, moments before Hutch was cornered and shot dead in September 2015. Source: BBC, The Irish Sun

Ian Dixon has no known convictions. But his alleged role in the Kinahan Organised Crime Group was laid bare when the US sanctioned him. Authorities said Dixon managed finances and moved bulk currency for Daniel Kinahan and also kept tabs on the debt owed by a narco-trafficker. 

The sanctions notice also said Dixon controlled Hoopoe Sports LLC, a Dubai firm that listed a number of pro boxers among its clients and reportedly received more than $4 million for bouts involving former heavyweight champion Tyson Fury. Boxing promoter Bob Arum told Yahoo Sports the money was for consulting fees owed to Daniel Kinahan.

Screenshot from a 2022 archive of US-sanctioned Hoopoe Sports’ website, showing pro boxers Jamie Conlan, Billy Joe Saunders, Hughie Fury and Michael Conlan among its clients list. Dixon’s company email address is visible on the footer. Source: arejaywoof / X, archive.org

Dixon lived in an exclusive gated community in Dubai, according to the 2022 sanctions notice. Online listings show that properties like his Spanish-inspired villa are worth up to $2.7 million.

Passion for Padel

Padel is an increasingly popular racquet sport from Mexico best described as a combination of tennis and squash. According to the sport’s governing body, it has more than 17.5 million weekly players across 150 countries and the UAE, where Dixon lives, has the second-highest number of padel courts in Asia. It was on these courts in late 2024 that Dixon played in the master final of the Asia Pacific Padel Tour (APPT).

A pre-match group photo was captured on the APPT male amateur final live stream. The photo, posted to Facebook, shows Dixon was part of the lineup. Source: APPT / YouTube, Facebook, US Treasury

APPT rankings show Dixon registered for the tournament under the name “Ian Thomas”. Like his cartel leader relative Christy Kinahan, who used his first and middle names as an alias on his Google review profile, Dixon had dropped his surname.

Finding a Fugitive – How we Located Dixon

Bellingcat found the padel club promotion showing Ian Dixon after running images of the cartel associate through a publicly available facial recognition search engine. Among the results was a link to a graphic designer’s online portfolio, which included the advertisement for the padel competition. The original photo had been posted on the sports club’s Instagram page in late 2023, with the caption: “Elevating fun, one swing at a time!” Dixon was not named.

Left: The padel tournament ad discovered via a PimEyes search for Ian Dixon. Right: The original picture and caption from the sports club’s Instagram page, posted in October 2023. Source: sanddune_padel_dxb / Instagram

We searched for additional open source evidence and located online profiles for a 36-year-old Irish padel player named “Ian Thomas” who had taken part in a number of matches in Dubai in recent years. One profile shows he played 16 ranked matches between September 2024 and April 2026 – the most recent being the week after Daniel Kinahan’s arrest. But the accounts did not include profile pictures.

Left: Screenshots from an online profile for 36-year-old Irishman “Ian Thomas” & Christy Kinahan’s Google review profile under the name “Christopher Vincent”. Right: Dixon pictured at a padel centre in an Instagram post from August 2024. Source: Rankedin.com, Google Maps, Instagram

Bellingcat searched for footage showing the padel events and venues listed on the profiles. It returned multiple social media posts and live-streams clearly showing Ian Dixon at the same events where “Ian Thomas” was registered as playing. Dixon can also be heard speaking with a Dublin accent and at one point is seen with a close relative of Daniel Kinahan.

Dixon and his doubles partner played four games over the December 13-15 weekend, eventually placing second after losing in the final. The Irish cartel associate is captured on film after the match receiving a silver medal and commemorative racquet.

Clip showing “Ian Thomas” in the final position in the APPT Dubai 2024 male amateur rankings, followed by Dixon on court during the match and receiving a racquet after his silver-medal placement. Source: asiapacificpadeltour.com, asiapacificpadeltour / Instagram

The Asia Pacific Padel Tour was held a month after senior Kinahan cartel figure Sean McGovern was arrested in Dubai on foot of an Interpol red notice. McGovern was extradited to Ireland last year and earlier this month jailed for 24 years for directing the activities of a criminal organisation in relation to murder and attempted murder. 

The tournament was live-streamed to YouTube via webcams set up on two courts. Dixon was captured throughout the three-day event, both playing on the court and mingling with others in the background. The hour-long male amateur final, which Dixon lost, is viewable in its entirety.

Clips from the tournament on December 15 showing Dixon before, during and after the amateur male final. Source: APPT / YouTube

Dixon also posed for photos during the tournament, but it appears he did have some reticence about appearing on social media. In two images from a different padel event hosted at the same venue a few months later, Dixon’s face had been covered. However, a third photo was not edited, confirming that it was Ian Dixon.

Top: Dixon posed for a photo before beginning the APPT amateur male final. Bottom: Dixon’s face was covered with a grey oval and an emoji in two social media posts from a different event. One of the pictures was not censored in another post. Source: APPT / Facebook, isdpadel / Instagram, ISD Dubai Sports City / LinkedIn

Kingpin in the Crowd

Among the people Dixon was seen with at padel events in Dubai was Stephen Jamieson, a Scottish criminal who was recently jailed for his role in a multimillion-dollar drug trafficking operation.

Dixon (left) and Jamieson (right) seen arriving and meeting on a live stream of a Dubai racquet sport event in December 2024. Jamieson was arrested by authorities in the Gulf state the following July. Source: Police Scotland, The Scottish Sun, asiapacificpadeltour / Instagram, APPT / YouTube

Dixon greeted Jamieson with a fist pump during the Dubai APPT tournament in December 2024 on the day the Irishman played in the amateur final.

Left: Jamieson watching padel games on days one and three of the APPT in 2024, when Dixon was also in attendance. Right: Police mugshot of Jamieson. Source: asiapacificpadeltour / Instagram, Police Scotland

Dixon was also pictured with Jamieson at a family day padel event just weeks before the Scottish criminal’s arrest. (Bellingcat is not publishing details of that event to protect the identity of family members.)

Clips from day three of the tournament showing Dixon meeting Jamieson. Both men arrived and left separately at different times. Source:  APPT / YouTube, BBC, The Scottish Sun

Jamieson, who has multiple convictions, was extradited from Dubai last year and is serving a six-year prison sentence in Scotland on organised crime and drug charges. The case against him was built around intercepted messages he had sent via the defunct encrypted communication network EncroChat – a network the Kinahans have also usedto direct drug shipments.

The Sunday Times reports today on the Kinahan cartel’s deeply entrenched links to organised crime in the UK, where it is known to control much of the illicit drug market. It said the footage showing that Dixon and Jamieson know each other could indicate an underworld connection, since cartel cadres do not associate with rival operations.

Dixon is among the remaining cartel figures at large in Dubai, along with Christy Kinahan, Christopher Jr and gang lieutenant Bernard Clancy. Source: US Treasury

Three of the seven alleged key Kinahan cartel figures have been arrested since the US sanctions were imposed. Johnny Morrissey, arrested in Spain in 2022, was later bailed and subject to a travel ban. Sean McGovern was jailed earlier this month and Daniel Kinahan awaits extradition to Ireland after his recent arrest in Dubai. Garda Commissioner Justin Kelly, of Ireland’s police force, recently said the investigation into the Kinahan cartel was ongoing and that authorities were continuing to focus on the other members of the gang.

Ian Dixon did not respond to questions from Bellingcat.


Connor Plunkett, Peter Barth, Beau Donelly and John Mooney contributed to this article. 

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

The post Poster Boy: Sanctioned Kinahan Cartel Lieutenant Found Playing Padel in Dubai appeared first on bellingcat.

Super-Potent Synthetic Opioids Spread Across US Amid Fentanyl Crackdown

This article was co-published with Signal Ohio and STAT.

In high school, Ashley Delgado dreamed of becoming a doctor and one day buying her father a Rolls-Royce. “She wanted to heal people,” said her father, James Taylor. She had a high GPA, Taylor added, and did especially well in science and Latin.

In her mid-20s, Ashley suffered a leg injury and was prescribed OxyContin. The painkiller marked the beginning of a yearslong descent through addiction — from prescription opioids to methamphetamine, then heroin, and finally, fentanyl.

With her family’s support, Ashley spent time in a rehabilitation facility in her hometown of Cleveland, Ohio, and in recovery she moved into a sober living home. But on an early summer morning in 2023, Ashley’s body was found on a dead-end street just outside the city. One sandal was missing. Tucked inside her bra was a folded scrap of paper containing a tan powder. She was 29.

Ashley Delgado died in August 2023. Source: Supplied

“I have lost my father, my grandmother — that hurts,” Taylor said. “But when you lose your child, that’s the worst thing on the planet, because they’re not supposed to go before you.”

Toxicology tests would later show a mix of substances in Ashley’s system, including protonitazene and metonitazene, powerful synthetic opioids from a little-known class of drugs known as nitazenes. Her death was ruled accidental.

Before his daughter’s fatal overdose, Taylor had never heard of nitazenes. Developed in the 1950s as potential painkillers, the drugs never reached the market because they were deemed unsafe for medical use. He was shocked to learn they could be up to 40 times more potent than fentanyl and 500 times stronger than heroin.

Nitazenes are predominantly sold online, both on the clear web and dark web, and are often laced into other substances to increase their potency. Experts say this puts unsuspecting users seeking more common drugs, such as oxycodone, fentanyl, or stimulants like cocaine, at risk of fatal overdoses.

Left: Ashley, aged about 5, with her father James Taylor in Cleveland, Ohio. Right: Ashley and her dog, Gucci, after graduating from high school in 2012. Source: Supplied

The US Drug Enforcement Administration (DEA) started tracking nitazene-related seizures around 2014, but it wasn’t until 2019 that it saw a marked increase. Since then, federal authorities have scheduled dozens of nitazenes as illegal substances, launched undercover operations, filed indictments, and imposed tariffs on China, where many of the laboratories manufacturing and supplying nitazenes and fentanyl are known to reside.  

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Yet, figures provided to Bellingcat by the United Nations Office on Drugs and Crime (UNODC) show the United States has reported 26 different kinds of nitazenes since 2019 — the second highest number globally, after Canada.

And data from the Centers for Disease Control and Prevention (CDC) on nitazene-involved overdose deaths suggest that cases continue to rise. More than 1,100 fatalities have been confirmed through the CDC’s State Unintentional Drug Overdose Reporting System (SUDORS), but experts believe the number of Americans who have died from them since 2019 could be as high as 2,000. 

Alex Krotulski, the director of the Centre for Forensic Science Research and Education in Pennsylvania, told Bellingcat that deaths are underreported because nitazenes were not routinely tested for.

“There are only limited forensic toxicology labs that test for nitazenes, so if a nitazene was present and the lab didn’t test for it, the number wouldn’t appear in SUDORS,” he said. “Also, for labs that do test for nitazenes, they have missed cases prior to their testing.” The most recent years for which there is CDC data, 2023 and 2024, show they were the deadliest, with 747 confirmed deaths.

A Bellingcat investigation last year found more than 1,000 nitazenes advertisements populating online marketplaces, forums and the dark web. Source: Bellingcat

In this months-long open source investigation, Bellingcat combed through dozens of criminal court proceedings, filed national, state, and county-level Freedom of Information requests, and obtained scores of medical examiner reports to produce the most detailed account yet of how nitazenes are infiltrating US borders and destroying lives. 

The investigation found that, despite efforts to curb their spread across the country, nitazenes are proliferating online. It also shows that, by the time nitazenes reach American users, they are almost always mixed with several other drugs, including methamphetamines, cocaine and, most notably, fentanyl. 

As of this year, 48 of 50 US states have reported nitazene seizures.

Less Fentanyl, More Nitazenes

Fentanyl is by far the biggest opioid killer in the US. With more than a quarter of a million deaths since 2021 and about 200 fatalities a day, fentanyl is one of the country’s most urgent public health crises. But drug experts warn that nitazenes can be even more potent and are being mixed with fentanyl and other substances, creating increasingly lethal combinations.

The Faces of Fentanyl memorial exhibit, at the DEA’s headquarters in Arlington, Virginia, displays more than 7,000 photos of people who have lost their lives to fentanyl poisoning or overdose. Source: DEA

“We’re always concerned about fentanyl being mixed in with other drugs — cocaine, meth, heroin,” said Frank Tarentino, Associate Chief of Operations for the DEA’s Northeast Region. “You add nitazenes to that and it makes it exponentially more dangerous and frightening for drug law enforcement, parents, caregivers, educators, and the young.”

Data obtained from the DEA’s National Forensic Laboratory Information System (NFLIS) show reports of confirmed seizures of nitazenes rising sharply — from 43 positive tests in 2019 to almost 2,000 in 2024 (the most recent year for which figures are available). By March this year, more than 8,000 nitazene reports had been recorded since 2019. But experts said that not all laboratories can test for nitazenes — which come in many forms including powders, pills, and sprays — and many don’t feed into the NFLIS system, meaning these numbers are almost certainly an underestimate.

We asked the DEA for a breakdown of reports of nitazenes by state. Ashley Delgado’s home state of Ohio stands out. NFLIS data from 2019 to 2024 indicate that more than a third of all positive nitazene laboratory reports nationally are linked to Ohio. 

Separate data from the CDC shows Ohio has also recorded the highest number of nitazene-related overdose deaths in the US since 2021. In 2020, there were just four fatalities linked to the drug; in 2021 that number rose to 90. Between 2022 and 2024, according to government data, there were 200 more deaths.

“It is a risk to our community,” said AmandaLynn Reese, chief programme officer at Harm Reduction Ohio, a non-profit that supports people who use drugs. “There’s been several instances of nitazenes being reported within the community, and I think we’re going to see more of that, especially as we’re seeing less fentanyl.”

To learn more about what was happening in Ohio, Bellingcat filed a public records request for county-level figures to the state’s Bureau of Criminal Investigation (BCI). The data shows that the counties of Scioto, Butler and Cuyahoga — areas long affected by the opioid crisis — account for almost half of all nitazene detections across the state, by weight.

In the 2000s, Portsmouth in Scioto County became known as the “pill mill capital” of America due to widespread overprescribing of opioids. More recent data continue to show Scioto with one of the highest rates of drug overdose deaths in the state. In Cuyahoga County, which includes Cleveland, drug-related mortality rates tripled the national average in 2022. 

Two years ago, Ohio’s Governor Mike DeWine issued executive orders to schedule nine different nitazenes and legalised the use of tools to test for drugs including nitazenes. 

The reasons why Ohio has been so hard hit are still not fully understood. “Ohio’s geography has long been a suspected contributing factor,” said Erin Reed, director of RecoveryOhio, a statewide initiative coordinating Ohio’s response to addiction. The organisation cited a 2001 article pointing to Ohio’s unique geographic and infrastructural features — including vast land, air and sea transportation networks — as key reasons for the state being a hub for drug trafficking. 

Local organisations like Harm Reduction Ohio are pushing for more drug-checking services, education, and greater accessibility to testing strips and life-saving medications like Naloxone, a drug that is used to reverse an opioid overdose. “People are going to use drugs,” Reese said. “We don’t know the supply, but those are ways you can engage in your drug use to increase safety and reduce harm.”

Dealer’s Choice

Bellingcat obtained medical examiner reports from Cuyahoga County for all nitazene-related deaths in 2023 and 2024, which provide an insight into how the drugs are being consumed. The autopsy records show that 45 people — 31 men and 14 women aged 29 to 72 — died after taking nitazenes over the two-year period. Among them were university graduates and former athletes, an Army veteran, an ironworker and an addiction counselor.  

Just before Christmas in 2024, a young man from Cleveland died after taking drugs that included etonitazene. A couple of weeks earlier, the body of an elderly woman was found in her home after she ingested drugs that included metonitazene and protonitazene. In the summer, a mother of two children in her thirties consumed a similar lethal mix. All except one of the 45 deaths was ruled accidental. 

And in every instance, nitazenes were detected alongside fentanyl, and often with a cocktail of other drugs such as heroin, cocaine, methamphetamine and benzodiazepines. The reason for this wide variety, Tarentino, the DEA agent said, is that dealers often mix nitazenes into other drugs to make them more powerful and addictive, and ultimately to give them a competitive edge. 

“It becomes a brand,” he said. “The unfortunate circumstance that we find ourselves in is that the dealer’s choice becomes a deadly decision.” Not only are these mixtures deadly — they can also be highly profitable. 

“We used to see organisations that were predominantly selling and transporting cocaine or just heroin or just methamphetamine,” Tarentino said. “Now, we’re seeing organisations move coke, heroin, meth, fentanyl, pills, powder – everything. So we see these poly-drug organisations, and then we see these poly-drug mixtures.” Source: DEA 

Court records analysed by Bellingcat show nitazenes have been sold at prices ranging from roughly US $4,000 to $12,000 per kilogram. But Tarentino said the DEA’s internal estimate puts $12,000 at the lower end of the range, with prices going up to as much as $40,000. Given their potency, even small quantities can be diluted into hundreds of thousands — or potentially millions — of doses once mixed and pressed into pills. “A little bit can go a long way,” Tarentino said, “and they can make a lot of money.”

A Freedom of Information Act request to the US Customs and Border Protection (CBP) revealed that in 2024 and 2025 — the only years for which the agency has monitored nitazenes separately — 41 consignments of the drug were intercepted. The data shows that most of these shipments arrived by mail, primarily from mainland China, Hong Kong and the United Kingdom. The quantities tended to be small, ranging from less than 1 gram to almost 700 grams. 

The UK has also recorded an increase in high-strength nitazenes in recent years. John Fahey, a spokesman for the National Crime Agency, said criminals used the UK as a “transit point” for shipping illicit drugs and that officials were working closely with US law enforcement on nitazene-related cases. Source: DEA

But that’s not always the case. An analysis of US federal court records linked to prosecutions of nitazenes indicates that roughly 90 kilograms of material containing nitazenes in different forms (powder and pills) have been seized over the past three years. Nearly two-thirds of that amount, about 60 kilograms, stem from a single case.

In that case, prosecutors allege that a man named Valkar Singh drove a blue Maserati from Canada into the US carrying six industrial-sized buckets with more than 100,000 pills containing  isotonitazene. According to court filings, Singh transported the drugs to a Bronx, New York address, where he was arrested by undercover law enforcement officers. 

Tarentino, who is familiar with the Singh case but could not comment on it specifically, said a lot of work is being done to prevent drugs being smuggled across the Canadian border. “Canada has become a major concern, but also a major partner in trying to stop the synthetic opioids that are coming into the United States,” he said.

Lawyers for Singh, who has pleaded guilty and is awaiting sentencing, declined to comment.

Photos of buckets containing isotonitazenes in the trunk of Singh’s car. Pills only contain trace levels of active ingredients, meaning the exact quantity of nitazenes is unknown. Still, experts say this seizure was significant, considering the drug’s potency. Source: US District Court for the Southern District of New York

The scale of the alleged seizure makes this case an outlier. Of 46 federal cases identified by Bellingcat between 2021 and 2025, the next highest nitazenes seizure was about 9 kilograms. By comparison, data provided by the European Union Drugs Agency shows roughly 18 kilograms of nitazene-related seizures (pills, powder, liquid) across the EU between 2019 and 2023. 

“It’s very large,” said Jared Brown, scientific affairs officer at the UNODC. “One hundred thousand pills is probably at the limit of what we hear about in terms of maximum types of quantities that get seized.” 

The evidence suggests that most buyers are individual dealers who purchase relatively small quantities online, rather than organised criminal groups. “It’s street-level or mid-level dealers [in the US] that are introducing the nitazenes into the drug supply, not the big drug traffickers,” said Philip Berry, a visiting senior lecturer at King’s College London who formerly worked in counter-narcotics at the UK Home Office.

Court documents show that buyers can easily find nitazene suppliers online: on dark web marketplaces, standalone chemical supplier websites, or even on social media platforms. The suppliers often market the drugs by listing their chemical identifier and social media contact details. Often, the ads include an image of a young Asian woman striking a pose. 

Buyers are often individual dealers who contact sales representatives via encrypted channels and negotiate a deal. In those conversations, representatives will sometimes disclose how they claim to evade customs, for example by declaring the product as cosmetics or electronic accessories.

Ads for nitazenes — such as these ones Bellingcat viewed this month — are found on dozens of sites, from  social media platforms to prominent Asian-headquartered marketplaces that target international buyers. Source: Bellingcat

A detailed account that illustrates this modus operandi comes from the 2023 case against a man named Will Catis in Florida — the state with the second highest number of confirmed nitazene reports. Court documents show that a basic internet search led Catis to multiple nitazene advertisements listed by Jiangsu Bangdeya New Material Technology Co., LTD, a Chinese company sanctioned by the US Treasury for offering illicit substances for sale, including fentanyl and protonitazene.

Catis purchased approximately four kilograms of nitazenes from Jiangsu Bangdeya in batches no larger than 500 grams. The drugs were sent via the US Postal Service to Deerfield Beach, Florida. Once received, Catis mixed the nitazenes with other drugs, pressed the substance into a brick and sold it to other drug traffickers. Catis was jailed for 12 years after pleading guilty to possessing and intending to distribute nitazenes.  

One court case from Florida describes how a couple who lived in a converted garage bedroom in Hernando County bought nitazenes through the mail from Chinese companies they contacted online. Jacob Spinoza and his girlfriend Veronica Jo Barback regularly abused the drugs and distributed them locally, according to court documents. Both pleaded guilty. Spinoza was sentenced to nine years in prison, and Barback received a three-year sentence.

Jacob Spinoza and Veronica Jo Barback under the influence of nitazenes. Court records said Spinoza survived more than 20 overdoses in 2022. Source: US District Court Middle District of Florida

Another notable case reveals how a man allegedly ran a drug trafficking operation from a prison in Ohio. Investigators said Brian Lumbus Jr worked with a middleman, Giancarlo Miserotti, who contacted drug manufacturers in China to get nitazenes shipped through Italy to avoid custom checks. Once in Ohio, the plan was to distribute the drugs to other states, court documents said. 

But law enforcement agents were listening in on conversations between Lumbus and other members of the drug network, who expressed caution about the potency of nitazenes. “Man, we got to be careful … somebody died,” Lumbus said in one phone conversation, according to court documents. “Ohhh … it was too strong,” Miserotti responded. “I think the ratio of the pink [metonitazene] was thick.” 

Lumbus is awaiting trial. Miserotti was arrested in Italy in 2023 and sentenced to more than 13 years in prison. 

Arms Race

Enforcement actions have targeted the online marketplace ecosystem. In June 2025, Archetyp Market, a major dark web platform used to sell drugs, was dismantled in a coordinated operation involving Europol. US authorities have also indicted several China-based companies and individuals accused of offering nitazenes and related synthetic opioids for sale. Still, advertisements for nitazenes continue to litter online markets, constantly adapting to new regulatory regimes.

Nitazenes, such as this listing for etonitazene, which is up to 500 times stronger than heroin, are openly advertised online. Source: Bellingcat

In July 2025, China placed the majority of nitazenes under national control. Tightened regulations — both in China and the US — have tried to stem the flow of nitazenes. But drug experts warn that manufacturers are already exploiting loopholes in China’s regulations by marketing chemically similar synthetic opioids known as “orphines.” 

Jared Brown, of UNODC, said orphines are also thought to come from China and are about as powerful as fentanyl. “Orphines have just enough of the molecule difference that it isn’t covered by the core definition that China has made,” he said. 

This is not the first time Chinese synthetic opioid manufacturers have adapted to regulations. In 2019, China banned all fentanyl-related substances, including some major precursors. The number of distinct fentanyl analogues reported to the UNODC subsequently plummeted, while reports of nitazenes quickly picked up. Now that China is clamping down on nitazenes, orphines are on the rise. More than 150 cases involving orphines were reported in the US between 2024 and 2025, the majority of which are in Illinois.

“Always adapting, always changing – we call them ‘shape shifters’,” said Tarentino. “They’re this global Hydra that are always changing, evolving and adapting to their environment and taking full advantage of all of these different loopholes and vulnerabilities that exist.”


Reporting for this story was supported by the Fund for Investigative Journalism.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Super-Potent Synthetic Opioids Spread Across US Amid Fentanyl Crackdown appeared first on bellingcat.

Heading Off: New Technique Helps Track Grain Smuggling Expansion to Libya

On February 15, 2026, the bulk carrier, Grumant (IMO: 9385879) was pictured at the occupied Ukrainian Port of Feodosia on the Crimean peninsula. Satellite imagery suggests it had already been there for several days.  It appeared to stock up on grain before departing on a two-month-long journey eventually docking at the Port of Benghazi in Libya on April 18.

While there have been previous reports of grain shipments from occupied Ukraine arriving in Libya, this is only the second time a Russian ship has been observed delivering what the Ukrainian government describes as “stolen” grain to the country. The previous case involved the Damas Wave which travelled in January of last year to the port of Misrata which is under the control of the UN-recognised Government of National Unity (GNU). In addition to satellite imagery, Bellingcat deployed a new technique that analysed Grumant’s heading data which was contained in AIS information provided by Lloyd’s List Intelligence, to help confirm Grumant’s presence in Feodosia. 

Bellingcat has been tracking smuggled Ukrainian grain shipments as they find new markets, five of the ships we previously identified have since been sanctioned by the EU while another was sanctioned by the US Department of Treasury.

MapLibre | Protomaps© OpenStreetMap contributors

Bosphorus Strait

Grumant transits the Bosphorus Strait in the middle of the night.

Credit: Yörük Işık.

Black Sea

Grumant enters a region of the Black Sea known for GNSS interference, meaning that Grumant’s publicly reported Automated Identification System (AIS) position is unreliable.

Port of Feodosia

On February 15, a high resolution satellite image confirms the ship is docked at the port of Feodosia at berth No. 1 that is used for bulk and metal cargo. Matching features visible include Grumant’s grey decking, its seven hatches and bright yellow front mast. What appears to be leftover grain can be seen under the two port crates, immediately next to the ship.

Credit: Satellite image ©2026 Vantor.

Black Sea

Grumant exits the area of signal interference, meaning that its reported position on ship tracking services is now reliable again. Its AIS messages indicate it is travelling towards the Bosphorus.

Bosphorus Strait

Grumant transits the Bosphorus Strait towards the Sea of Marmara. Judging by the draft, with no visible red paint on its hull, the ship appears to be fully laden.

Credit: Yörük Işık.

Izmir Anchorage

Grumant arrives in Izmir, Turkey on February 23 and anchors off the coast until March 13.

Over the course of three weeks, Grumant never enters the Port of Izmir. It is not known if it was denied entry. Bellingcat asked the port operators but did not receive a response before publication.

Credit: Planet Labs PBC.

Aliağa

Grumant then loiters off the coast of Aliağa, about 50 km from Izmir. It stays here until March 16, never entering the port. It again is not known if it was denied entry. Bellingcat asked the port operators but did not receive a response before publication.

Near Benghazi

Grumant arrives in Libyan waters and stays off the coast of Benghazi until April 1.

Libyan Waters

Grumant briefly leaves the coast of Benghazi, but returns a few days later.

Benghazi

Grumant leaves the anchorage on April 18 and docks at the port of Benghazi where it unloads the grain. The ship was captured in a Vantor satellite image on April 20.

It leaves port on April 23, and heads back towards the Bosphorus.

Credit: Satellite image ©2026 Vantor.

Bosphorus Strait

After spending a few days off the coast of Tuzla, Grumant transits the Bosphorus towards the Black Sea.

Credit: Yörük Işık.

Lloyd’s List Intelligence has previously reported on the expansion of Russia’s grain smuggling operations, beyond the occupied port of Sevastopol to include Feodosia port

According to the Ukrainian activism, journalism and hacker group, Kiborg News, Grumant used deceptive shipping practices to deliver grain to Latakia, Syria in 2024. The report included several of Grumant’s shipping manifests, which showed it had repeatedly exported grain from Occupied Crimea to Syria. 

Heading Data Helps Locate Grumant

It is standard maritime practice that ships broadcast Automatic Identification System (AIS) messages which include a ship’s position, heading, and draught (among other information).

Because of longstanding Global Navigation Satellite System (GNSS) interference in parts of the Black Sea, the position data transmitted by an affected ship’s AIS system is often unreliable.

Between February 7 and February 19, 2026, data from Lloyd’s List Intelligence shows the Grumant transmitted 29 AIS messages, with unreliable positions in the vicinity of Feodosia. We know these positions are unreliable as they are erratic and some of them report the ship as being positioned on land.

Unreliable AIS positions – Grumant’s reported positions between February 7-19, 2026, via Lloyd’s List Seasearcher.

However, according to the IMO, the heading data transmitted by a ship’s AIS system must come from an onboard compass. A compass is unaffected by GNSS interference, meaning it is a more reliable source of information in these conditions.

Over the same dates, all 29 AIS messages reported the ship’s heading as 267 degrees or 268 degrees. The Port of Feodosia has a heading of 267.5 degrees. The close agreement between the ship’s heading and port heading strongly suggests that Grumant was moored at the port between February 7 and February 19, 2026.

We conducted an extra check of the heading data by reviewing satellite imagery available of berth 1 at Feodosia Port, which suggests that the same vessel was present on several days between February 6 and February 18. Imagery on Feb. 6 shows the port was empty in the morning and occupied in the afternoon. Grumant exited the area of GNSS interference on February 21, and berth 1 at the port was captured on satellite image on February 22 and appeared empty. The low resolution satellite imagery is only used as an additional check to see if a vessel is at the berth.

Timeline of open source observations related to Grumant’s presence (tick) or absence (cross) at Feodosia port. Empty entries indicate a lack of available data.
Sentinel-1 timelapse of Feodosia Port, Copernicus Sentinel data 2026. Annotations by Bellingcat.
PlanetScope timelapse of Feodosia Port, Planet Labs PBC. Annotations by Bellingcat.

Bellingcat checked all vessels transmitting AIS in the vicinity of Feodosia Port and found that Grumant was the only one that consistently transmitted a heading matching the Port of Feodosia over the period of interest.

We shared our research with Charlie Brown, a former US Naval Officer and Senior Advisor at United Against Nuclear Iran where he focuses on maritime sanctions enforcement and the tracking of illicit shipping. Brown told Bellingcat that while satellite imagery of vessels remained key for identification, when looking for reliable data in a spoofing environment it made sense to look at the various elements of AIS data to try and find some accurate information, despite GNSS spoofing.

“It’s quite standard for the independent gyro compass to be providing the heading […] I think the majority would not [be subject to spoofing] so it’s a good methodology to parse out the particular data and then make some inferences from that.”

“It’s neat to think of what can be derived from data that would otherwise be dirty or wrong. So there’s still some elements of use in there.”

He added that in theory there are probably some compasses that are subject to spoofing as well. 

He told Bellingcat that it was fair to say the heading data of the Grumant supported identification, but stressed the need to cross-reference with other data sources. 

While in this instance it has been possible to use AIS data to help verify the location of Grumant, it is relatively unusual to have access to this information. 

Ships that call to the occupied territories frequently disable their AIS transponders to do so.

This activity, known as “dark port calls”, is a common tactic for those engaging in illicit or sanctioned trades. 

Grumant does not transmit AIS messages from February 8 to 11, but this is the longest gap in data (see diagram above), with intermittent messages coming through after that point.

It is unclear why Grumant continued to transmit AIS during the period it was loading in Feodosia. 

A review of Lloyd’s List Intelligence data from January 2025 shows that on a previous voyage to the Black Sea the Grumant operated “dark” for 59 days.  

Visual Identification

On February 15, 2026, high resolution imagery showed Grumant docked in the Port of Feodosia. We compared it with other recent images of Grumant to confirm the match. 

The ship in the satellite image has a grey-coloured deck, which is uncommon enough for it to stand out. Many bulk carriers have cranes (including the ships we previously covered such as Krasnodar, Zafar and Zaid), Grumant does not have any. It also has seven hatches (openings for the grain) and a bright yellow front mast that matches the mast of Grumant (see the image of it transiting the Bosphorus). We can match the Grumant in the Feodosia image, not only to pictures of the Grumant shot from the ground, but also to the satellite image from Benghazi.

The length and breadth of the ship also matches that of the Grumant; 180 metres by 22.90 metres. 

Above: Image of the Grumant transiting the Bosphorus. (In yellow: the mast, red: the seven hatches, green: four vent masts, two on either side). Credit: Yörük Işık. Middle: Satellite image of the Grumant in Feodosia on February 15, 2026. (Matching elements are denoted in the same way as the image above). Bottom: Grumant captured at Benghazi port on April 20. Credit: Satellite image ©2026 Vantor. Annotations by Bellingcat.

Libya’s Relationship with Russia and Ukraine 

Libya has complicated internal dynamics with essentially two administrations in charge of different parts of the country – the Government of National Unity (GNU) in the west and the Libyan National Army (LNA) in the east.

In recent years, Russia has backed the LNA’s General Khalifa Haftar, based out of Benghazi, in the east of the country. But Jalel Harchaoui, a political scientist specialising in Libya with the Royal United Services Institute (RUSI), stressed that the two sides of this conflict, the LNA and the UN-recognised GNU, are not currently fighting. Instead they are in a flawed, multi-year truce.

Therefore, the east-west divide isn’t as clear-cut as during the civil war. While all shipments going to Benghazi and Tobruk are overseen by the LNA, not all shipments going to the city of Misrata (which is run by the GNU) are meant for the GNU-dominated part of the country. 

Harchaoui told Bellingcat: “the Tripoli government is in some regards pro-Ukraine, but if there’s business that can be done with Russia through the very opaque port of Misrata and all the right people get paid, the business is going to take place.”

That observation is potentially significant given at least one previously tracked vessel that went from occupied Ukraine to Libya docked in Misrata.

This was not the case of the Grumant, however, which arrived in an LNA-controlled part of the country. It is not known from open sources alone if the authorities in Libya or at the port in Benghazi knew the grain carried by Grumant had come from occupied Ukraine.

Bellingcat contacted the Benghazi-based LNA government and representatives of the Tripoli-based GNU government via the Libyan Embassy in The Netherlands. We also contacted the Port of Benghazi, Port of Imzir in Turkey as well as the Ukrainian and Russian authorities. Representatives of the LNA did not respond to requests for comment before publication, nor did the Port of Benghazi or Port of Izmir. The Libyan Embassy in The Netherlands replied to Bellingcat after publication, stating that Benghazi and eastern Libya are not under the authority or administrative control of the Government of National Unity and therefore they are not currently in a position to comment on Bellingcat’s findings.

Ukraine Continues to Pursue the “Shadow Grain Fleet”

“The port of Feodosia, located in the temporarily occupied Autonomous Republic of Crimea, is not under Ukrainian control, and any commercial activity conducted there is illegal,” the Ministry for Development of Communities and Territories of Ukraine and the Ministry of Foreign Affairs of Ukraine told Bellingcat in a joint response. 

They told us the loading of grain exported from the temporarily occupied territories is an illegal act and Russia was using ports as logistics centers to export stolen Ukrainian agricultural products.

“The expansion of such routes to third countries, in particular to North Africa, demonstrates Russia’s ongoing efforts to circumvent international sanctions and monetize resources stolen from the occupied Ukrainian territories.” 

The Ukrainian Ministry of Foreign Affairs sent information about Grumant’s (IMO: 9385879) “illegal activities” to the diplomatic missions in Great Britain, the Republic of Turkey and the Republic of Tunisia over the course of March to May this year, the ministries told Bellingcat. 

Ukraine is continuing to pursue legal action against Russia’s “shadow grain fleet” they told us. For instance, earlier this month a Swedish court approved the transfer of the Russian “shadow grain fleet” vessel CAFFA to Ukraine for investigation after it was arrested in Swedish waters. 

This case has set a new precedent, going beyond sanction and fines previously handed out to such vessels, and allowing for the detention and confiscation of a shadow fleet vessel in European jurisdictions, the ministries said.

According to Russian court documents Grumant’s previous owner Murmansk Shipping Company was dissolved and “Decision/Reshenie” LLC were listed as the International Safety Manager and operator of Grumant. Decision/Reshenie were also listed as the operator of Grumant in another court document, from an unrelated case. 

Bellingcat attempted to contact Decision/Reshenie to ask about Grumant’s grain shipment from Feodisia Port to Benghazi Port, but they had not responded at time of publication.


Youri van der Weide, Galen Reich, Yörük Işık and Bridget Diakun contributed to this report.

Cover image: Planet Lab image shows Grumant anchored off Izmir, Turkey on February 27. Credit: Planet Labs PBC.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.


The post Heading Off: New Technique Helps Track Grain Smuggling Expansion to Libya appeared first on bellingcat.

Tracing Digital Links Between Viory and Ruptly

“In the age of misinformation, the line between fact and fiction is blurrier than ever.”

“For those of us working in video news, verification isn’t a nice-to-have. It’s a necessity. It is how we protect the stories we help shape and how we earn and maintain trust in an increasingly chaotic information ecosystem,” Abu Dhabi-registered video news agency Viory posted on LinkedIn on April 9, 2026, offering training to help newsrooms and journalists sort fact from fiction. 

The self-described “video news agency of the Global South” has delivered journalism training to multiple national press agencies across Africa, Asia and the Middle East.

However, when it comes to Viory itself, the line between fact and fiction is very blurry indeed. 

Bellingcat has found multiple links between the digital infrastructure of Viory and Ruptly news agency, a branch of sanctioned Russian propaganda outlet Russia Today, including shared IP addresses, a Viory-linked site using a digital security certificate registered to Ruptly, and Ruptly sending site performance data to Viory. While there have been previous reports on suspected links between the two outlets, our investigation adds new evidence about Viory’s ties to Ruptly media. 

When contacted for comment, both Viory and Ruptly denied any connection with each other.

Composite Image created by Bellingcat.

‘Video News Agency of the Global South’

Viory’s main offering is raw video footage of news events provided via subscription. According to Viory, its clients include “major international news outlets, local media organisations, and independent creatives in more than 170 countries”.

If its own figures are to be believed, Viory was strikingly well established at its launch in November 2023, by which time it claimed to have a “pre-assembled team of over 150 full-time staff, and an established network of over 3,000 video journalists across the world”.

The name “Viory” is a trade name. The company’s legal name is Darpo Vision FZ LLC, according to its website, which also states that it is registered in Abu Dhabi. In August 2024, Darpo Vision FZ LLC filed for a trademark in the US for the name Viory, which was approved in December of 2025

As of May 2026, Bellingcat found press releases and news reports referencing at least 30 agreements between Viory and partners in more than 22 countries, as well as cooperation agreements with government agencies, training agreements with universities and regional journalism bodies. 

This includes:

Viory also sponsored a glitzy event for its inaugural Global South Video News Awards in December 2025 at Abu Dhabi’s first-ever BRIDGE Summit.

Ruptly Revisited

Ruptly is a video news agency formerly based in Berlin and ultimately controlled by Russia Today (RT), which is owned by Russian state media company ANO TV-Novosti. ANO TV-Novosti has been on the EU sanctions list since December 2022 for spreading “pro-Kremlin propaganda and disinformation” and supporting Russia’s war against Ukraine. 

RT launched Ruptly, which operated in Berlin via a German-registered subsidiary in 2013, with the goal of “becom[ing] the go-to alternative resource in a highly concentrated market of professional news video footage, and to deliver coverage of stories that other agencies miss.”

Sanctions imposed on RT following Russia’s 2022 invasion of Ukraine choked off Ruptly’s source of funds in Germany, leading the German company to begin insolvency proceedings in October 2024. Ruptly continues to operate from Moscow as of 2026.

As with Viory, Ruptly’s main offering is providing raw news footage to subscribers around the world. It relies on a large network of international freelancers and stringers. In 2016 RT claimed that Ruptly had “surpassed” newswire services AFP and Reuters on YouTube, and was serving more than 600 media organisations in 45 countries.

Felix Huesmann of the German outlet RedaktionsNetzwerk Deutschland (RND), was the first to outline links between Ruptly and Viory while covering the insolvency proceedings of Ruptly. He found that Darpo Vision’s original details on the Abu Dhabi Creative Media Authority’s site included an email address d.toktosunova@gmail.com. It has not been confirmed who this email address belongs to; however, the username matches the first name initial and surname of Dinara Toktosunova, the managing director of Ruptly. When asked about this email address by Huesmann  in 2024, Ruptly “explained that Toktosunova is focused on securing the future of the Ruptly team [in Moscow] and is not working anywhere else as a managing director.”The activist group, OSINT For Ukraine, also outlined links between Ruptly and Viory, including the movement of multiple key staff between the two organisations and strong similarities between the two organisations’ platforms and content.

Darpo Vision’s Security Certificate

The legal entity behind Viory, Darpo Vision, was set up in one of Abu Dhabi’s free zones – special economic areas that have business-friendly incentives such as tax exemptions and that allow 100 percent foreign ownership. The free zones also offer what some describe as high levels of “corporate privacy,”  which others assert has created a haven for shell companies and opaque corporate structures.

Darpo Vision initially had its own web domain, darpo.vision. The site has since been removed. Whois records show that the domain was registered by Darpo Vision FZ LLC in December 2022 to a PO Box in Abu Dhabi, using a Russian domain name registrar and a Moscow phone number. 

Initially, Darpo.vision had its own Secure Sockets Layer (SSL) certificate – a digital certificate that authenticates a website’s identity, allowing it to secure and encrypt data. However, VirusTotal data shows that as of at least June 2024, darpo.vision was using a wildcard SSL certificate registered to ruptly.video. A Wildcard SSL certificate is a single certificate with a wildcard character (*) in the domain name field. This allows the certificate to secure a single domain and multiple subdomains. You can see historical SSL certificates for darpo.vision.


James Wilson, a software and networking engineer with 20 years of experience and currently Enterprise Technology editor at Risky Business Media, told Bellingcat that to prevent unauthorised use or forgery of SSL certificates, a private key is needed to create and use a wildcard certificate across multiple domains. 

“The fact that darpo.vision was using a wildcard SSL certificate for ruptly.video indicates that whoever was running darpo.vision also had access to the private key for ruptly.video’s SSL certificate. Normally, only the people operating Ruptly’s web hosting infrastructure would be likely to have access to that,” Wilson explained. 

When asked by Bellingcat about whether there were alternative possible explanations, Wilson suggested that it was theoretically possible that someone may have hacked Ruptly and stolen their private SSL key. 

“However, using that wildcard SSL certificate on a domain that didn’t match the wildcard in the certificate defies explanation as the browser would alert the user to the certificate error,” he added.

Shared IP Addresses

Bellingcat also identified multiple shared IP addresses which appeared to be concurrently in use by both Ruptly and Viory between May 2025 and May 2026. 

From 2025 onwards, the Russian IP address 158.160.132.25 has been used concurrently by viory.video, ruptly.video, ruptly.agency and ruptly.tv, according to VirusTotal. Similarly, since the beginning of 2026, IP address 84.252.135.88 has been used concurrently by viory.video, viory.team, ruptly.video, ruptly.agency and ruptly.tv, according to VirusTotal. 

VirusTotal data shows that from 2025 onwards, IP address 158.160.166.22 has been used by ruptly.video and viory.video while from 2026 onwards, IP address 158.160.226.68 has been used by viory.video and ruptly.tv. The VirusTotal data appears to show these IP addresses being used exclusively by Ruptly and Viory as of 2025 and 2026. However, VirusTotal does not necessarily capture all domains which resolve to an IP, and other domains may also have resolved to these IP addresses, which were not observed by VirusTotal’s passive DNS replication service. It is also important to note that in some cases, unrelated domains use the same IP addresses.

Ruptly Sends Site Performance Data to Viory

Viory’s and Ruptly’s site infrastructure was also linked through data sent via Sentry, an internal error tracking and performance monitoring platform. 

An API scan of Ruptly’s main client login page, ruptly.agency, on March 26, 2026, shows that the page was sending data to a subdomain of viory.team. This domain appears to be used by Viory primarily for backend purposes, based on subdomains which appear to refer to common developer and site management tools such as Traefik and ArgoCD, in addition to Sentry.io. Notably, two subdomains also appear to refer to Ruptly. 

The purpose of one domain sending data to another domain’s Sentry project is generally to consolidate all of the relevant performance and error data in one place for in-house developers to monitor. 

The ruptly.agency page’s request to viory.team also includes an authentication key for Viory’s Sentry project. Ruptly.agency is not the only Ruptly domain sending Sentry data to viory.team. As of May 9, 2026 the login page for ruptly.video’s own Sentry project, sentry.ops.ruptly.video, automatically redirects to sentry.ops.ruptly.video/auth/login/viory/. Ruptly Video’s Sentry login page also features “Viory” as the title.

The ruptly.video Sentry login page is also sending data to the viory.team Sentry project, the ruptly.agency homepage and using a favicon hosted on viory.team.

A third Ruptly domain, ruptly.tv, also sends performance data to viory.team’s Sentry project via cms.dev.ruptly.tv. 

James Wilson noted that in each case, the Ruptly domains sending data to Viory appeared to be using a different Sentry key.

“If you look at each of these snippets sending telemetry data [from the Ruptly domains], the specific Sentry keys for sentry.ops.viory.team are different for each. I presume that someone with access to Viory’s Sentry keys has generated and included fresh Sentry keys in each of these instances in order to differentiate between the telemetry from this site versus others using the same Sentry instance,” Wilson said. 

“This cuts against the idea that this is, for example, a case of someone just lazily copy-pasting code on Ruptly’s domains. It suggests that each of these snippets was likely to have been deliberately included. The alternative explanation of changing these API keys to some arbitrary value seems much less plausible given the lack of diligence in ensuring other aspects of the content didn’t cross-reference the domains.”

‘Ruptly’ Page Title on Viory Test Page

Finally, Bellingcat found a page at frontend.dev.viory.video/en that appears likely to be a developer test page for the front page of Viory’s main domain viory.video.

Notably, however, the page title reads “Stream trending news | Ruptly.” The page description included in the source code also refers to Ruptly:  

“Follow breaking world news in real-time and stream the latest developments in politics, sports, finance, science, tech, and more from one of the top online news sites. Download and share international news today with award-winning news agency Ruptl” [sic].

Screenshot of frontend.dev.viory.video/en page, captured May 10th 2026. Archived source.

Wilson said that the use of the Ruply page title and text on the Viory test page “looks like a case of lazy copy and pasting”.

“That could potentially be done by someone outside of Ruptly, although it would be strange.”

While this particular piece lies on the lower end of the spectrum of proof, Wilson said that together with the other stronger pieces of evidence, including multiple Ruptly domains appearing to send data to Viory using different API keys, and Ruptly’s wildcard SSL certificate on Darpo Vision’s site, the weight of evidence for a connection between Ruptly and Viory adds up.

“None of the pieces of evidence are watertight on their own, but when you add them together it’s difficult to think of other plausible explanations for all of them being true at the same time,” he added.

“None of the pieces of evidence are watertight on their own, but when you add them together it’s difficult to think of other plausible explanations for all of them being true at the same time,”

-James Wilson

Bellingcat also found that Ruptly appears to have connections to a company in Hong Kong. Company records from July 2022 indicate that this company was originally named Ruptly Limited, but in September of that year, the company’s name was changed to Lotus Production Limited. 

The Hong Kong company remains registered as active and filed annual reports in September 2025.

Russian Slant in the ‘Global South’ 

Anna Hiller, a Bangkok-based Consultant Research Analyst for the Institute for Strategic Dialogue told Bellingcat that the resources provided by Viory can be an attractive pool of source material for smaller media outlets, governments and academic institutions with small budgets.

She told Bellingcat that Viory’s editorial choices are clear when looking at the site’s videos.

“When accessing Viory, the prominence of pro-Russian and pro-China content is immediately noticeable, including numerous articles focused on Vladimir Putin, Russia-China cooperation, and broader China-related narratives.”  

Bellingcat contacted Viory, Darpo Vision and Lotus Production Limited to ask about the connections we found between the Viory website and Ruptly and between Lotus Production Limited and Ruptly. 

Viory said that it had no connection with Ruptly. “Viory has no connection with Ruptly; any suggestion otherwise based on ordinary use of similar digital platforms, tools or cloud providers is poorly founded and inaccurate; Viory is a UAE-based, privately held, self-funded and 100% privately owned organisation, and receives no funding, direction or instructions from any state media,” the company said in an email response. 

Ruptly also said it was not connected to Viory. It declined to respond to Bellingcat’s questions, including about specific findings such as Ruptly’s domains sending technical performance and error data to Viory, calling these questions “irrelevant”.


Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Tracing Digital Links Between Viory and Ruptly appeared first on bellingcat.

The ‘Lost’ Villages of Myanmar’s Rakhine

A “river of blood” was how one survivor described the scene in western Myanmar. “I saw shooting. I saw mass killing.” Another told the UN High Commissioner for Human Rights (UNHRC) how 20 relatives, including three children, had been killed in the 2024 attack on Htan Shauk Khan village.

Human Rights Watch (HRW) said earlier this month that the Arakan Army (AA) “may have killed at least 170 Rohingya men, women, and children” in Hoyyar Siri (known as Htan Shauk Khan in Burmese) in Buthidaung Township. It described the May 2, 2024, attack as a “massacre”.

Buthidaung is one of the two townships in Rakhine State that is home to the majority of the Rohingya, a mainly Muslim ethnic minority in the predominantly Buddhist Myanmar.

At least 40 villages in Buthindaung were burned down in April and May 2024 amid clashes between the AA, an ethnic armed group fighting Myanmar’s military junta for control of Rakhine, and junta forces battling to retain their hold of the township.

Both sides committed abuses against civilians during the clashes, according to HRW. The military junta’s forced conscription of Rohingya to fight on its behalf has also intensified violence against them. 

The military and Rohingya armed groups began arson attacks in Buthidaung township in April 2024. By mid-May the AA had captured all junta bases, according to the think tank, the Australian Strategic Policy Institute. The destruction of Buthidaung has previously been documented by Bellingcat. 

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

The AA has denied accusations that it massacred civilians in Buthidaung, claiming that those killed were junta soldiers and Rohingya militants.

Bellingcat emailed the United League of Arakan, AA’s political wing, about the alleged attack on civilians but did not receive a response at the time of publication. The United League of Arakan’s humanitarian office responded to Bellingcat after publication disputing the Human Rights Watch report and the allegation that Arakan Army personnel massacred Muslim civilians. Instead describing that the village became part of an intense military confrontation involving several armed groups, rather than a one-sided assault. Myanmar’s Ministry of Defence also did not respond to our questions. 

Evidence of civilian harm in Myanmar is slow to emerge and difficult to obtain due to the military’s strict control of the region and the tight grip of armed groups such as the AA in areas they control. 

“The mass killing could only be confirmed more than a year later,” the recent HRW report said, “when survivors eventually crossed into Bangladesh and found their way to the Rohingya refugee camps in Cox’s Bazar.” 

Aerial imagery shows that Htan Shauk Khan was almost entirely destroyed in May 2024.

False-colour infrared map from Copernicus on Planet Insights Browser shows exposed ground in grey or tan, indicative of possible damage, in the village.

Erasing Homes

A new investigation by Bellingcat has identified 115 villages in Rakhine State, similar to Htan Shauk Khan, as partially or completely destroyed since the February 2021 military coup that overthrew Myanmar’s democratically elected government.

The data points to a pattern of violence that leaves civilian areas uninhabitable and in some cases, erases them completely.

MapLibre | Protomaps | Planet Labs © OpenStreetMap contributors

Several buildings were set on fire when the junta allegedly dropped a bomb on the Muslim village of Zu La on Nov. 3, 2024. The fire was captured nearby on NASA FIRMS.

Satellite imagery indicates that it was attacked again on Dec. 9, 2024. Visible smoke can be seen rising from the village.

Zu La is located in Maungdaw Township. Along with neighbouring Buthidaung, Maungdaw is home to the majority of Myanmar’s persecuted Rohingya.

Zu La, and the neighbouring village of Gone Nar, previously faced violence during the 2017 Rohingya genocide.

Satellite imagery from that year shows them completely burned to the ground.

They show signs of reconstruction after 2017.

But repeated attacks in 2024 destroyed the villages again.

Neither of the villages appears on the latest maps from 2024. These are produced by the United Nations mapping unit, based on Myanmar government maps.

Steve Ross, Senior Fellow at the US nonprofit Stimson Center who is leading the ‘Crisis in Myanmar’s Rakhine State’ project, told Bellingcat this is part of the military’s broader campaign to deny the existence of the Rohingya and erase identity in Rakhine.

Bellingcat contacted the Myanmar government but had received no response by the time of publication.

Villages in Mungdaw are inured to cycles of violence. Ywar Haung, a village south of Zu La, has stood barren since 2017.

So has Kan Kya, where the military built the Border Guard Police Battalion No. 5 (BGP5).

All four villages are among the growing number of Rakhine’s lost settlements.

Six of the 10 villages we found partially or totally destroyed in Maungdaw in 2024 aren’t marked on the UN’s township map.

Removing more villages from the map remains a possibility, Ross said. However, following this April’s elections, which critics dismissed as a sham, the military is eager to restore international credibility and avoid actions that might be seen as provocative, the expert told Bellingcat.

The AA announced the capture of Maungdaw when it seized BGP5 on Dec. 8, 2024.

And with that the armed group gained full control of Myanmar’s entire border with Bangladesh.

Shortly afterwards, the AA took control of the strategically important Ann Township in central Rakhine.

The armed group announced it had captured the headquarters of the Western Regional Military Command on Dec. 18, 2024.

It shared a video of the headquarters and nearby military installations burning.

Local residents in and around the township were trapped, displaced or forced to flee their homes due to the months-long fight for Ann.

According to reports, the military entered Pyaung Chaung village and burned it down on Oct. 31, 2024.

Satellite imagery from Nov. 1, 2024, shows large-scale damage in the village. There were reports that the military warned residents to evacuate the village a week before the attack.

Ross believes that the military’s intention has been to try to make Rakhine as ungovernable as possible if the AA gains full control of the state.

Nearby villages of Yat Thar Ywar Thit

and Pyaung Thay show similar evidence of destruction.

Sittwe city, the capital of Rakhine State, has become a focal area of fighting since late 2025. The city is in Sittwe township, one of the three townships still under junta control.

Su Mon Thant, Asia-Pacific analyst at Armed Conflict Location and Event Data Project (ACLED), said capturing Sittwe would be highly symbolic for the AA as no non-state actor has yet taken control of a state capital in the country.

The AA already controls areas along an India-backed transport corridor in Myanmar that includes a port in Sittwe.

Sittwe is surrounded by water on three sides. Capturing it would be challenging, with the military maintaining naval superiority and building defences in and around the city to deter a potential AA offensive, Ross said.

On Dec. 27, 2024, the AA attacked the Kyauk Tan checkpoint near Sittwe on the highway linking the capital to Yangon, the largest city to the south of Rakhine.

There are many villages near the checkpoint.

Like Taw Kan

where, according to local reports, junta forces carried out an arson attack that destroyed 80 houses on Jan. 15, 2024.

Bellingcat found at least 13 villages near the checkpoint that had been destroyed, with only a few remaining structures. All but one of them were attacked in 2024-2025.

Less than 4km from the checkpoint is Yar Tan

which appears intact in a March 2024 Google Earth image

but several buildings look destroyed in high-resolution satellite image on Google Earth from March 2025.

Trenches and military outposts began appearing near the village around Nov-Dec 2024.

They grew as the months passed. However, due to a lack of updated high-resolution satellite images, we cannot tell whether these are currently in use or to what extent.

There are also villages that appear to have been replaced with defensive structures. For example, Kan Pyin Ywar Haung, for which the latest available high-resolution satellite image shows trenches on both sides.

Although such structures are clearly visible in high-resolution satellite imagery, lower-quality images can also help indicate whether a village was replaced with fortifications.

Kan Pyin Ywar Thit, located just south of Kan Pyin Ywar Haung, appears to have been completely destroyed; however, the same criss-crossing lines are not visible across the village.

Similar fortifications appear in other villages.

Defence infrastructure has replaced villages on the outskirts of Sittwe, making it more difficult for AA to advance towards the city, said Ross.

Bellingcat also found at least 10 villages partially or totally destroyed in Kyaukpyu Township since fighting intensified in February 2025.

Kyaukpyu, which has abundant oil, natural gas and marine resources, is also home to a junta naval base

As well as Chinese infrastructure projects that the AA fully or partially controls.

Nearly all the villages we found to be destroyed or damaged are within a 10km radius of the naval base.

In early March this year, clashes took place between the AA and the military near Say Maw village, located less than 5km from the base.

NASA FIRMS detected fire in the village and the surrounding areas on March 23, 2026.

The latest high resolution satellite image on Planet from April 2026 shows flattened buildings in the village.

A month earlier Saing Chon Dwein village, also less than 5km from the base, was reportedly burned down by the military.

The fire was caught on a Feb. 9, 2026 lower resolution satellite image

with burnt areas distinguishable the next day.

Like Sittwe, Kyaukpyu is surrounded by water, making it difficult for the Arakan Army, which lacks naval capabilities, to seize control. “AA has some advanced drones reportedly, but these areas also have jamming technology,” said Thant.

Methodology

The data was compiled using news reports, including social media channels, ACLED, satellite imagery and NASA FIRMS. The names of the villages were corroborated using the UN’s Myanmar Information Management Unit (MIMU), news reports and Planet Labs. 

We only included areas where the destruction was clearly visible in high-resolution satellite imagery or significant enough to be detected in mid-resolution images. Our data is not exhaustive and the true number of affected villages is likely to be higher.

While it is difficult to ascertain whether the villages we found damaged or destroyed showed signs of reconstruction, at least five of them appear to show some buildings rebuilt in latest available satellite imagery.

Military Control Is Slipping

Last month, in the first election since Myanmar’s 2021 coup, the pro-military parliament chose junta chief Min Aung Hlaing to be the next president.  

Subscribe to the Bellingcat newsletter

Subscribe to our newsletter for first access to our published content and events that our staff and contributors are involved with, including interviews and training workshops.

According to research group Data for Myanmar, at least 65 townships were excluded from voting, including the 14 in the AA’s control. In Rakhine’s 17 townships, voting was held in only three still under junta control – Kyaukpyu, Sittwe and Manaung.

The AA resumed attacks against the junta in Rakhine in November 2023, ending a year-long ceasefire.

Data published by the Armed Conflict Location and Event Data Project (ACLED) and analysed by Bellingcat reveals a sharp increase in the military’s air and drone strikes in Rakhine. After the AA resumed its offensive, strikes rose from 30 in 2023 to 461 in 2024. By the end of 2024, the AA had captured all but three townships in the state.

Bellingcat found that strikes were then concentrated in the townships where the junta is fighting to maintain control. They decreased in 13 townships captured by the AA and remained unchanged in one during 2025. By contrast, attacks increased in Kyaukpyu and Sittwe, yet to be captured by the AA. Data for Manaung is unavailable.

ACLED’s data comes from multiple sources, including news reports and social media. While the data is not exhaustive, a broad trend can be identified. You can read further details and caveats about the data here.

Su Mon Thant, Asia-Pacific analyst at ACLED,explained that the military conducts clearance operations to prevent the AA from using villages as buffers or shelters – a tactic employed across the country. “At the same time, it’s a warning sign for other villages,” she said, adding that when one village is set ablaze, it sends a signal to other villages not to “accept, shelter or harbor” armed groups. Thant also noted that people are displaced when their village is destroyed, eroding support for armed groups as locals suffer the consequences of the fighting. 

The AA has vowed to take control of all of Rakhine by 2027 and success may bring a geopolitical shift in the region. The armed group’s control over Kyaukpyu and Sittwe will give it significant leverage, with both India and China having infrastructure projects in the townships, Steve Ross of the Stimson Center told Bellingcat.

But neither side can control the state without further alleviation of civilian suffering, Ross said. According to UNHRC data, there are almost half a million internally displaced people (IDPs) in Rakhine as of March 30, 2026.

Estimated total IDPs in March-April of each year. Data prior to 2022 is unavailable. Source: United Nations Human Rights Council. Chart: Created on Datawrapper, edited on Adobe Illustrator by Pooja Chaudhuri/Bellingcat

In Sittwe township alone, about 120,000 Rohingya have been displaced by communal conflict since 2012. 

“People displaced from other parts of Rakhine State during the war are in Sittwe, hundreds of thousands of civilians,” said Thant, adding that neither side can control the capital without significant loss of life.

There are also 1 million Rohingya refugees in Bangladesh. The futures of both the refugees and IDPs remain uncertain. 

“Nobody can go home yet at this stage,” said Thant.


Editor’s note: This article was updated on July 6, 2026 to include response from representatives of the United League of Arakan.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post The ‘Lost’ Villages of Myanmar’s Rakhine appeared first on bellingcat.

💾

Banned Russian Submunitions Found After Mali’s Military Announces Airstrikes

This investigation is a collaboration between Bellingcat and Jeune Afrique. You can read Jeune Afrique’s article in French here.

Unexploded Russian-made cluster munition bomblets, as well as damage consistent with bomblet impacts, have been found in a village in northern Mali – despite the West African country being a state party to the Convention on Cluster Munitions (CCM) which prohibits their use. 

The deployment of cluster munitions in northern Mali was first reported by Radio France International last week, citing local sources yet without showing images of the munitions or strikes in the reporting. However, social media footage posted on May 17, and since analysed by Bellingcat and our publishing partner, Jeune Afrique, shows unexploded Russian manufactured ShOAB-0.5 submunitions (bomblets).

Bellingcat geolocated a video showing the unexploded ShOAB-0.5 bomblets in the village of Tadjmart (18.977305, 0.86072), located approximately 55-kilometers (34-miles) south of the larger town of Aguelhok in northern Mali. This matches the location of airstrikes announced by the Malian Armed Forces (FAMa) on May 17. FAMa claimed it had identified armed groups in the area.

A map detailing where the Tadjmart strike, signified by the red flame, was recorded. Courtesy MapCreator.

Russia’s paramilitary Africa Corps group, which is controlled by the Russian government and which replaced the Wagner mercenary group in the country, has been supporting Malian military operations.

Mali’s civil war has been ongoing since 2012. But the conflict has spiked in recent weeks as Tuareg separatists from the Azawad Liberation Front (FLA) and militants from the al-Qaeda affiliated Jama’at Nusrat al-Islam wal-Muslimin (JNIM) seized control of parts of the country in coordinated attacks against Malian and Africa Corps forces.

Les mercenaires continuent de larguer des bombes sur des maisons et certains diront pourquoi se révolter contre ces genres des pratiques inhumaines ne respectant aucun Droit. https://t.co/5jynKwUgeW pic.twitter.com/nB3ym4yooc

— Mohamed Lilly (@MedLilly1) May 17, 2026

The footage geolocated by Bellingcat shows the unexploded submunitions near buildings, alongside multiple small craters, consistent with submunition explosions.

Left: Unexploded ShOAB-0.5 submunition found approximately 55 km south of Aguelhok. Right: ShOAB-0.5 Submunition. Sources: X and Armament Research Services.

The buildings and landmarks visible in the footage allowed us to geolocate where it was taken.

Geolocation of the video showing unexploded ShOAB-0.5 submunitions and the craters to the village of Tadjmart (18.977305, 0.86072). Sources: Airbus Imagery via Google Earth and X.

Additional footage geolocated by Bellingcat to nearby coordinates 18.97954, 0.85989 shows destroyed and burning buildings several hundred meters away, although this damage is not consistent with cluster munition use. The damage appears more significant than that which would be caused by submunition impacts.

Geolocation of the additional footage showing destruction several hundred meters away from where the submunitions were geolocated. Sources: Airbus Imagery via Google Earth and X.

Cluster munitions are explosive weapons which open mid-air to release large numbers of submunitions. They are prohibited from being used by signatories of the Convention on Cluster Munitions (CCM) because they are indiscriminate, saturate a wide area and can leave behind highly volatile unexploded bomblets which can kill civilians long after deployment. 

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

While Mali is a signatory to the CCM, Russia is not a state party to the agreement. 

Brian Finucane, a senior adviser with the US Program at the International Crisis Group, told Bellingcat that as a party to the CCM, Mali is “subject to its prohibitions and requirements. These include not only prohibitions on the use of cluster munitions, but also obligations to clear and destroy such munitions on its territory.”

ShOAB-0.5 submunitions are carried by the Russian RBK-500 cluster munition dispenser. A single RBK-500 dispenser can deploy about 565 ShOAB-0.5 submunitions. There is as yet no footage posted online showing a spent dispenser linked to this incident.Footage did circulate online on May 16 showing the remnants of an RBK-500. It was claimed to have been used in a separate cluster munition strike in the Timbuktu region of Mali. However, this footage was not geolocatable, given it only shows a close up of the dispenser at night, nor was it possible to tell when the footage was taken.

A second video appears to show the same dispenser, but shows the side with visible Russian markings denoting the model: “РБК-500; ШОАБ-0.5; ТГ-30”. This identifies the dispenser, RBK-500, the submunition inside, ShOAB-0.5, and the explosive filler, TG-30.

Left: Markings visible on RBK-500 ShOAB-0.5 dispenser reportedly found in Mali. Right: Reference image of RBK-500 ShOAB-0.5 cluster munitions loaded onto an aircraft. Sources: محمدن أيب أيب and Telegram.

RBK-500 dispensers are deployed by Russian-made aircraft including several MiG and Su models. According to the 2024 IISS Military Balance report, Mali does not have any known operational Russian fixed-wing attack aircraft. Two Russian Su-25 aircraft delivered to Mali – one in 2022 and another in 2023 – are reported to have crashed and been out of service since late 2023.

An Su-24M model has since appeared in satellite imagery captured at Modibo Keita International Airport in Bamako. The imagery was first published by France 24 in April 2025, although it was unclear if this aircraft was, or has been, operated by Africa Corps or Malian forces.

Bellingcat contacted the Malian military and Russian Ministry of Defence requesting comment, and asking which force was responsible for deploying cluster munitions. We did not receive a substantive response by publication time beyond the initial statement made by the FAMa which detailed it was responsible for the May 17 strike.

A video posted on May 17, by an account linked to Azawad rebels in Northern Mali, shows a person handling components of a ShOAB-0.5 submunition, seemingly unaware of the danger. However, as the video shows only a close up of the submunition, it has not been possible to geolocate the video or confirm when it was taken.

Les Azawadiens ne fabriquent pas les armes au contraire ils les démontent ! pic.twitter.com/0tqOb6ut9G

— Oumayya AG Ambeiry (@AgOumayya) May 17, 2026

The FLA condemned the use of cluster munitions in a statement published on May 18. 

Bellingcat has previously reported on the use of cluster munitions in Syria and Ukraine and the danger they pose to civilians.


Youri van der Weide contributed to this report.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Banned Russian Submunitions Found After Mali’s Military Announces Airstrikes appeared first on bellingcat.

Satellite Imagery Shows Ongoing Demolitions Across Southern Lebanon

The fragile ceasefire agreed between Israel and Hezbollah last month is holding. 

But satellite imagery shows that at least 46 of 54 towns and villages within the Israel Defense Forces (IDF) “Yellow Line” in southern Lebanon have been heavily damaged or, in some cases, entirely flattened

Much of the destruction and demolition has taken place in recent weeks.

Bellingcat’s satellite imagery analysis examined towns and villages identified on OpenStreetMap, a community-driven map database. Medium resolution PlanetScope satellite imagery covering each of the locations was provided by Planet Labs, a US company that recently restricted some of its imagery in the Middle East.

Bellingcat is sharing the annotated PlanetScope imagery for the dates of March 2 and May 8, 2026, showing the scale of damage that has occurred during roughly the first two months of the US-Israeli war against Iran.

The towns and villages detailed in the map are colour coded. Red shows locations  that have suffered varying degrees of damage or destruction, while yellow shows locations that were damaged prior to the US-Israeli war with Iran. White shows locations that have not been significantly damaged at time of publication.

Scroll and zoom to see damage throughout southern Lebanon in each of the date tabs. The first image is from March 2, 2026, shortly after the US and Israel attacked Iran. The second image is from May 8, 2026, more than two months after the start of the war and amid a fragile ceasefire between Israel and Hezbollah. PlanetScope imagery via Planet Labs PBC.

Israel’s Defence Minister, Israel Katz, is reported to have stated that “all homes in Lebanese villages near the border will be destroyed — in accordance with the Rafah and Beit Hanoun model in Gaza”. The aim, Katz said, is to “remove, once and for all, the threats near the border”. Israel has adopted similar methods of flattening buildings and homes close to Israel’s border in Gaza.

The large-scale destruction in southern Lebanon has been reported by multiple outlets including the BBC, CNN, SkyNews and The New York Times. These reports have shared images from several towns and villages, but Bellingcat is publishing satellite imagery for the entirety of southern Lebanon. The changes between the two dates show the scale and pace of destruction.

Take our survey

Help shape the future of our collective.

Within the Yellow Line  — the area occupied by the IDF since a ceasefire was agreed between Hezbollah and Israel on April 16 —  some towns were reported already destroyed or heavily damaged during the 2024 Israeli invasion of southern Lebanon. Some — like the coastal border town of Naqoura or the southeastern border town of Kfar Kila — have now been largely demolished. This is visible in both the medium-resolution PlanetScope imagery, and in high-resolution imagery obtained from Airbus by the BBC.   

Everything south of Lebanon’s Litani and Zahrani Rivers has been under evacuation orders issued by the IDF since early March, with regular updates warning residents to leave ahead of airstrikes. 

Much of the destruction within the “Yellow Line” appears to be from either controlled demolitions using explosives or construction vehicles. The IDF has shared numerous videos showing large-scale demolitions conducted in the towns and villages in southern Lebanon, while videos shared elsewhere on social media show the aftermath — large parts of towns like Beit Lif or Kheim reduced to rubble. 

One particularly large explosion took place in the small village of Qantara, where the IDF says it found two large tunnel systems built by Hezbollah. 

The tunnels were detonated with 450 tonnes of explosives, leaving large parts of the village obliterated. Another video released by the IDF showed some of the few remaining buildings in the nearby village of Aadashit being demolished with explosives. The IDF claimed the buildings were “Hezbollah infrastructure”.

Before and after imagery from Planet Labs shows the villages of Qantara and Aadshit in southern Lebanon on March 2 and April 30, 2026. The April imagery shows the aftermath of two large demolitions conducted by the IDF. Large parts of both villages have also been demolished. The UNP 7-1 label details the position of a UN peacekeepers facility.

Bellingcat contacted the IDF for comment on the details in this story but did not receive a response before publication. 

A full size version of the map can be found here.


Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Satellite Imagery Shows Ongoing Demolitions Across Southern Lebanon appeared first on bellingcat.

DRC’s Coltan Belt: Verifying Deadly Landslides at Mines Under M23 Control

Since the beginning of 2026, at least four landslides are reported to have killed hundreds of people at the Rubaya mines in the Democratic Republic of Congo (DRC), a major global source of coltan. Coltan is widely used in smartphones, laptops and e-vehicles.

An estimated 10,000 to 11,000 miners work in treacherous conditions for as little as a few dollars a day. Image: Reuters.

With the mines currently under the control of the Rwandan-backed group M23, and access restricted to journalists and many NGOs, the true number of casualties remains unclear. Frequent cellular network disruptions have also been reported across the region.

In the absence of reliable on-the-ground coverage, Bellingcat used open source methods to examine statements from the authorities and media reports. Bellingcat confirmed several incidents in which villages were engulfed in the landslide and residents living near the mine were among those killed.

Estimated area affected by M23 activity in 2026, based on ACLED incident data.

Landslide No.1 – January 28

Reports of a deadly landslide killing more than 200 people began appearing in international media in late January and early February. 

Three days after the incident, the DRC government made a statement on Facebook outlining that at least 200 people had been killed. They said the landslide was “a consequence of the rampant and illegal mining by Rwanda and the M23/AFC”.

Screenshot of a Facebook post by the DRC government, translated by Bellingcat.

In response, the M23-appointed local governor, Lumumba Muyisa, told Reuters that at least 200 people had been killed, but attributed the landslide to heavy rains. 

Landslides are common in small-scale mines, especially during the rainy season, which in Rubaya spans from September to May and peaks between March and April. 

According to local journalists, it took several days for the injured to reach Goma due to poor road conditions and cellular network problems. Image: Screenshot from Le Journal Afrique TV package.

Bellingcat cross-checked local media reports against one of the few social media posts about the incident, geolocating the phone footage to a mining pit south-east of Rubaya. In the video, the narrator speaking in Kinyarwanda (the national language of Rwanda, also spoken in eastern DRC) pans from the top to the bottom of the slope. Filmed at a distance, no bodies are visible in the footage.

Left: Layered frames from phone footage. White box highlights the tree line. Yellow box highlights a cluster of buildings. Right: Pre-landslide image from Google Earth Pro (March 14, 2025) with aligned white and yellow boxes.

Satellite imagery captured before and after the first landslide shows how the mud advanced down the slope.

Satellite imagery before (left) and after (right) the first landslide. Affected area highlighted by white box. Source: Planet Labs PBC

Landslide No.2 – March 3

Just over a month later, a second landslide was reported. On Facebook, the DR Congo Ministry of Mines released a statement including a provisional death toll of more than 200 people:

Screenshot of a Facebook post by the DRC government. Translation by Bellingcat. 

However, senior M23 official Fanny Kaj, speaking to AP, rejected the DRC government’s claims, stating: 

“I can confirm what people are publishing is not true. There was no landslide; there were bombings, and the death toll isn’t what people are saying. It’s simply about five people who died,” Kaj said. 

The same day the second landslide was reported, another M23 spokesperson, Lawrence Kanyuka, announced an attack involving “combat drones and heavy artillery”, at a location more than 250km from Rubaya.

Speaking to eyewitnesses at the mines, international media reported a landslide triggered by heavy rains, with no mention of bombings – only of workers buried under the earth. 

Bellingcat verified several social media videos of the second incident, in which dozens of people are seen digging for those buried under the mud. The clip below is an edited excerpt that excludes graphic images of bodies.

Edited video clip (left) geolocated to the camera icon (right). The white line (right) shows the camera’s movement as it pans across the slope. Source: Planet Labs PBC, March 26, 2026.

Later in the video, as the camera zooms in on several bodies, the narrator speaking in Kinyarwanda says: “Those you can see here have just been pulled out. These people are dead, but others are continuing to the search operations.” 

Due to the low quality of the footage, an accurate body count was not possible. 

Bellingcat geolocated footage of landslide No. 2 to the same location as landslide No. 1, shown in the satellite imagery below.

Satellite imagery before (left) and after (right) the first landslide. Affected area highlighted by white box. Source: Planet Labs PBC, Copernicus Sentinel Data / Browser.

M23 did not respond to a request for comment on findings contradicting senior official Fanny Kaj’s claim that no landslide occurred on 3 March.

Landslide No.3 – March 7

Four days later, a third landslide was reported, with estimates of more than 300 people killed, according to civil society official Telesphore Nitendike. Speaking to EFE, Nitendike said the landslide had affected “more than 40 families” as houses were “swept away” by the mud.

Satellite imagery shows the landslide advancing from east to west as mud surged down the slope.

Before and after the third landslide on March, 3. Source: Planet Labs PBC.

Bellingcat verified more than a dozen social media videos from the third incident, the majority posted on X by local media accounts. Almost all contained highly distressing content, including the bodies of young children. In one video, the narrator walks through a crowd of more than a hundred people, then stops and pans across several bodies covered with blankets, saying: 

“These bodies were found here in Gatabi [name of village], inside houses. You can see how the houses were swallowed. The search for residents is still ongoing. It is truly a tragedy.”

As he continues filming, at least seven unclothed bodies, all young children, are seen being carried down the slope.

“You see, there, that’s another child’s body. These are children who were sleeping in their homes. Some were still in bed when they were swallowed by the landslide.”

Left: Video clip shows a body covered with a blanket on a stretcher. Right: Video clip shows the community-led rescue effort. The background satellite image shows geolocated pins marking the videos. Source: Planet Labs PBC, 16 February 2026.

Bellingcat geolocated 12 social media videos of the third landslide to a location southwest of Rubaya town.

Landslide No.4 – March 27

A fourth landslide was reported at the end of March by local outlets, describing the collapse of two mining shafts and the death of at least nine workers. 

Satellite analysis, combined with the geolocation of one social media video, indicates the fourth incident took place at the same location as landslides No.1 and No.2.

Before and after the fourth landslide on March 27. Yellow box highlights houses engulfed in the mud. Source: Planet Labs PBC.

Despite repeated attempts by Bellingcat to contact the DRC government and M23 for updated casualty figures across all four incidents, neither party responded. 

In February of this year, human rights group Global Witness called on companies and governments using or trading DRC’s coltan to ensure mine operators adhere to international human rights and environmental standards.

Take our survey

Help shape the future of our collective.

Bellingcat also contacted the DRC government spokesman and minister for communication and media, Patrick Muyaya, regarding a post he made on X that Bellingcat found to be promoting misinformation about the rate of expansion of the mines while under M23 control.

In the post, Muyaya urges followers to watch a video that presents itself as an open source report but includes satellite imagery falsely attributed to Bellingcat and “Planet Labs Inc.” We can confirm that this is not our work. The imagery also appears not to be from Planet Labs PBC, but from Google Earth Pro (illustrated below). 

The fabricated video was originally posted in 2025 by the Facebook account, Congo Kinshasa.

Left: Screenshot from Congo Kinshasa’s video, mislabelled ‘Avril 2024’ (April). Yellow box highlights false attribution to Bellingcat and “Planet Labs Inc.” Top Right: Satellite imagery from Google Earth Pro, 2019, matching fake video on left (minus a colour filter). Bottom right: Authentic Planet Labs image from 2024, April 19.

Contacted by Bellingcat, Congo Kinshasa confirmed that they were the creator of the video. Asked to explain why the satellite images were mislabeled and the analysis wrongly attributed to Bellingcat, they responded: “I don’t understand you. What exactly is your problem?”

Minister Patrick Muyaya did not respond to our request for comment on his post promoting false information.


Claire Press contributed to this report.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post DRC’s Coltan Belt: Verifying Deadly Landslides at Mines Under M23 Control appeared first on bellingcat.

Unearthing a Colombian Politician’s Connections to Neo-Nazi Active Club Group

This investigation is a collaboration between Bellingcat and Colombian media outlet Cerosetenta. You can read Cerosetenta’s piece in Spanish here.

A video posted on Feb. 26 shows several men painting over graffiti in Restrepo, a neighbourhood in Bogota, Colombia, and replacing them with images of their own: a logo used by Colombian political candidate and businessman Jorge Rodriguez, who is one of the men shown in the footage.

“Today we are defending public space to stop generating hatred in future generations!” said the caption posted on Instagram by Rodriguez, who unsuccessfully ran for office in the March 2026 congressional elections as part of Centro Democratico, the country’s largest right-wing party. 

But at least one of the graffiti-ed pieces they painted over carried a message critical of, rather than promoting, hate: “Creole Nazis will not pass” – using a term that refers to Nazi sympathisers in Latin America. 

A screenshot of Rodriguez’s Feb. 26, 2026 video showing men painting over graffiti with the words “Nazis Criollos no pasaran”, or “Creole Nazis will not pass”. Source: Instagram

And although the faces of most of the men shown in the video were pixelated, the tattoos visible on one of them have multiple similarities with a prominent member of neo-Nazi group Active Club Bogota – an individual known as Javier “Orlik” Ruiz, whom Rodriguez follows on Instagram and who “liked” the video.

In response to Bellingcat and Cerosetenta’s queries via Instagram, Rodriguez did not answer questions about his relationship with Active Club Bogota or the individual we identified as appearing in his videos, but said he was “not obligated to respond to any interview or request without a court order”. He also threatened legal action if we used his image or name in this investigation, saying that this would violate his rights to privacy, reputation and data protection, as well as the right to his own image. 

Take our survey

Help shape the future of our collective.

Similarly, Ruiz did not reply to questions that Bellingcat sent via email, including on his role in Active Club Bogota, but responded to our query by threatening legal action if we used his name, image or background information about him without his “prior, express and informed authorisation”. Ruiz said in his email that, among other things, processing his personal data without authorisation could be considered a violation of personal data under Colombian law.

After Bellingcat replied to both Rodriguez and Ruiz, noting that they did not answer our questions and inviting them again to do so, Ruiz responded with another legal threat referencing data laws – again without answering any questions related to this investigation. 

Bellingcat and Cerosetenta have consulted legal experts in both the Netherlands, where Bellingcat is headquartered, and in Colombia on the question of how privacy laws in both countries are balanced against the right to freedom of expression. In light of (amongst other factors) the public interest in this information and the fact that both Rodriguez and Ruiz qualify as “public figures” (persons who have, through their acts or their position, entered the public arena), the reporting in this article and the editorial choices made by Bellingcat are protected by the freedom of expression.

Both Rodriguez’s and Ruiz’s full responses are included at the end of this article.

Active Club Bogota is the local branch of the international Active Club movement. It hosted celebrations of Adolf Hitler’s birthday at a Bogota community centre in 2025 and 2026. At the 2025 event, the group hosted a Nazi-inspired book burning. This year, the group celebrated with Nazi swastika cupcakes, a swastika-emblazoned birthday cake and the screening of a 1940 Nazi propaganda film.

A still from an April 2025 video posted by Active Club Bogota, showing a Spanish translation of Jewish Holocaust victim Anne Frank’s diary, placed in a charcoal barbecue to be burned outside a Bogota community centre. A Spanish-language translation of a book of essays by physicist Albert Einstein, who was Jewish, was also burned.
An April 2026 photo posted on Active Club Bogota’s Telegram channel showing a portrait of Hitler and cupcakes decorated with swastikas.
A photo of an event held at the same community centre commemorating Hitler’s birthday in 2026, posted on Active Club Bogota’s public Telegram channel. Blurring in the original posted image.

Bellingcat and our Colombian partner Cerosetenta reached out multiple times via email and phone to the president of the relevant Community Action Board managing the community centre where these events were held, using contact information listed in a document by the local mayor’s office. As of publication, we have not received a response to our emails, and calls to the president of the community centre have gone unanswered.

Active Club Bogota, which has had an online presence since early 2024, appears to be the only officially recognised South American chapter of the neo-Nazi network started in the US by white supremacist Robert Rundo. The international movement, which Bellingcat has covered extensively, is known for using fitness, fighting and fashion to recruit young men and boys into the far right, normalise fascist ideas and prepare them for physical violence against perceived enemies. 

Active Club Bogota’s official Instagram account followed just over 60 accounts earlier this year. Rodriguez’s public Instagram account was, and continues to be, one of them. In March this year, Rodriguez also “liked” a March 2026 post from the group that featured a flag for a neo-Nazi movement. 

A March 15, 2026 Instagram post from Active Club Bogota, showing Jorge Rodriguez’s “like” on the post. Bellingcat has obscured account details in the photo.

While Rodriguez was unsuccessful in his bid for a seat in parliament, garnering just 4,401 votes, he presents himself as a prominent member of Centro Democratico and claims to have founded the party’s largest youth group. 

He has appeared in photos and events on his social media alongside notable figures from the party, such as former Vice Minister of Justice Rafael Nieto Loaiza, party director Gabriel Vallejo, presidential candidate Paloma Valencia and the party’s founder, Alvaro Uribe Velez.

Alexander Ritzmann, a senior advisor with the Counter-Extremism Project (CEP), told Bellingcat that an affiliation between Active Club Bogota and a political actor like Rodriguez should be taken seriously.

Heidi Beirich, co-founder of Global Project Against Hate and Extremism (GPAHE), said that any sort of legitimacy lent to an outwardly neo-Nazi group, like those that make up the Active Club movement, “sets a dangerous precedent”.

Bellingcat’s investigation into Active Club Bogota also suggests that the group has connections with the international far-right, with allies and “brothers” from Brazil to Spain, as well as apparent links with Combat 18, a violent neo-Nazi network accused of being an “international criminal organisation” and terrorist group. There is no evidence to suggest that Rodriguez has any connections to these other groups.

Centro Democratico was the biggest challenger to Colombian President Gustavo Petro’s left-wing coalition Pacto Historico in the March elections, securing 17 seats in the Senate, up from 13 in 2022, and a majority of 32 seats in the House of Representatives, double the 16 it won in the previous elections.

Subscribe to the Bellingcat newsletter

Subscribe to our newsletter for first access to our published content and events that our staff and contributors are involved with, including interviews and training workshops.

In response to Bellingcat’s queries, Centro Democratico National Director Gabriel Vallejo said the party was unaware of any proven links between Rodriguez and far-right, neo-Nazi, or extremist groups. 

Vallejo said that the Party’s candidates retain the right to exercise their freedom of expression and define their ideological affinities within the limits of the Constitution and the law. 

However, Vallejo said that Centro Democratico does not support or endorse any type of link with organisations or movements that incite hate speech, violence or the glorification of crime. 

“The Party maintains a firm stance in defence of the Constitution, the law, democratic institutions, and respect for human dignity, as well as in the protection of the public interest and fundamental rights,” he said. “In this regard, any conduct that contravenes these principles is contrary to the Party’s guidelines and will be subject to the corresponding actions in accordance with the Statutes and applicable regulations.”

Tattoo Identifications

In Rodriguez’s Feb. 26 video, the former political candidate can be clearly seen. However, several others had their identities obscured, with one particular individual being completely pixelated from head to toe in almost every frame he appeared in, even where only part of his arm was visible. 

Screenshots from the Feb. 26 video showing a heavily pixelated individual

But thanks to a few frames where parts of the individual’s arms or hands are briefly unpixelated, or where colouration shows through the pixelation, Bellingcat was able to match the person shown in the video to a prominent Active Club Bogota member and possible leader – an individual who goes by Javier or “Orlik” Ruiz – who Rodriguez follows on Instagram and vice versa. 

Between April and May 2024, the first few weeks after Active Club Bogota’s Telegram channel was set up, eight posts listed an author who went by “Orlik Ruiz”. 

Bellingcat searched online for social media accounts and information related to “Orlik Ruiz” and quickly found numerous public social media accounts that appear to belong to the same individual, with posts showing photos of his face and tattoos. Several of these accounts used the name Javier Ruiz. These accounts included a YouTube account featuring 2022 video clips showing Ruiz and other men at a shooting range, holding what appear to be automatic rifles.

Screenshots from Javier or “Orlik” Ruiz’s Telegram and social media accounts. Source: Telegram, Instagram, YouTube; redaction of handles by Bellingcat

In most of these social media accounts, Ruiz posted numerous photos exposing his face and, more frequently, his tattoos from multiple angles, allowing Bellingcat to confirm that the same individual appears in the vast majority of Active Club Bogota’s online content.

Active Club Bogota’s Telegram channel listed an account with the name “Javi” as the group’s main contact. There were more than 30 posts on this account’s own profile page, and though the face of the person shown in the photos posted from this account was obscured, the matching tattoos in many of these posts all pointed to the same person.

Left: A screenshot of an August 2025 video posted by Active Club Bogota showing Javier Ruiz, identifiable by his tattoos including a Nazi swastika flag tattoo and blue band on his left arm. Right: A cropped photo of Ruiz, the same blue band tattoo visible on his left arm, posted on one of his VKontakte accounts in 2020.

Ruiz’s tattoos had several distinctive features that appeared across multiple photos. The backs of both of his hands are tattooed up to the base knuckles. He also has an arrow tattoo on his left middle finger, pointing down towards the base knuckle, and a red design that circles his left wrist. 

These match several features of tattoos on the individual’s left hand that can be made out despite the pixelation, including what appears to be red colouration on the individual’s wrist, heavy dark hand tattooing, and also discolouration on the left middle finger, suggesting tattoos on that finger.

A pixelated left hand in the Feb. 26 video at 0:37, with colouration of tattoos showing through the pixelation. The brightness of the photo has been adjusted by Bellingcat
A cropped photo of Ruiz from his own Telegram account, showing red tattooing on his left wrist, similar heavy left hand tattoos and two dark left middle finger tattoos, like the individual in the Feb. 26 video

While blurred footage alone is not enough to confirm matching tattoos, several other significantly more detailed and clearer comparisons could be made. 

In one frame, a very similar arrow to that seen in photos of Ruiz appears on the left middle finger of the individual shown in the video.

Left: An arrow tattoo visible on Ruiz’s left middle finger in a photo from his Telegram account. Right: A similar-looking mark visible on the left middle finger of the pixelated individual in Rodriguez’s Feb. 26 video (at 0:43). Annotations by Bellingcat
The screengrab showing the mark on the pixelated individual’s left middle finger overlaid on the photo from Ruiz’s Telegram account in a GIF created and annotated by Bellingcat. The images have been rotated, and the lighting of the screengrab has been adjusted for clearer comparison. 

In addition, there are gaps in the tattoos and a rounded shape visible on his left arm that are consistent in position with photos of Ruiz’s tattoos.

A gap in the tattoos (red arrow) and rounded shape (blue arrow) visible on the unidentified man’s left arm in a screengrab of the Feb. 26 video at 0:19 (left), is consistent with images of Ruiz’s tattooed left arm posted on Telegram (centre and right).

There are also several frames in the video where the individual’s right hand is visible. These unpixelated, although still blurry, frames show the individual has heavy tattooing on their right hand that forms a curved shape between their knuckles. This is consistent with the shape of the tattoos on the right hand of Active Club Bogota’s Ruiz as seen in photos posted on the group’s Telegram channel and on social media.

Top left and right: Cropped frames from the Feb. 26 video (at 0:41) showing the individual’s right hand and heavy right-hand tattooing; brightness adjusted by Bellingcat. Bottom left and right: Cropped screenshots from a Jan. 2025 Active Club Bogota video (left) and a Dec. 2025 Instagram video by an Active Club Bogota member (right) showing Ruiz’s right hand and his hand tattoo

Another frame shows a small red tattoo visible on the middle-right finger as well as a detail between the index finger and right pinky. This matches with other, clearer images of Ruiz’s tattoos visible on his private Instagram.

Left: A screenshot of a photo from Ruiz’s private Instagram account. Right: a photo of the right hand from the Feb. 26 video (at 0:41). A small anchor tattoo below the knuckle and a detail in his hand tattoo can be seen in the same position.

Furthermore, in several frames of the video, the pixelated individual’s upper-right arm is visible, showing red colouration that is consistent in size and shape with images of Ruiz’s tattooed right arm.

A screenshot from the Feb. 26 video (at 0:44), showing red and black tattooing on the pixelated individual’s upper right arm. The brightness of the photo has been adjusted by Bellingcat
A cropped photo of Ruiz from his own Telegram account, showing very similar red and black tattooing on his upper right arm as the individual in the Feb. 26 video

Promoting Fascist Ideas in the Region

The first sign we could find online of Active Club Bogota’s appearance on the city’s neo-Nazi scene was in early 2024, when its official Telegram channel was created. 

The official Active Club website that Rundo, the American founder of the Active Club movement, has openly promoted in several podcasts features a map of “official” Active Clubs around the world. As of the time of publication, Active Club Bogota is the only one in South America on the map.

A screenshot of South America from a map on the official Active Club website, featuring the only “official” group on the continent, Active Club Bogota.

But social media posts from Active Club Bogota suggest that the Colombia-based group has been attempting to promote the development of other Active Clubs in Latin America, with mixed results.

In September 2025, Active Club Bogota promoted a new Active Club in Brazil, boasting that “our brothers … have also taken a big step forward.” 

A screenshot of a September 2025 post from Active Club Bogota

This Brazilian Active Club Telegram channel no longer exists as of February 2026. 

Also in September 2025, Active Club Bogota promoted the Telegram channel of a new Active Club in Argentina, which they referred to as “our Argentinian friends”. This Telegram channel, like the Brazilian Active Club Telegram channel, no longer exists as of February 2026.

In December 2025, Active Club Bogota promoted the Telegram channel of another new Active Club based in Mexico City, which the Colombian channel referred to as “our Mexican brothers, who are joining this great movement that seeks to reclaim our identity and heritage”.

Beirich, the co-founder of GPAHE, said that Active Clubs are a concerted effort to market the far right to a new generation of young people. 

“Active Clubs can and do serve as a bridge between older generations of neo-Nazis and the current wave of youth engaging with the movement,” she said.

“Groups like the one in Bogota are hyper-local enterprises that also connect its members to a transnational extremist network of other Active Clubs and white supremacist groups that share a similar worldview,” she added.

Ritzmann, from CEP, also said that the threat posed by the group should not only be measured by its size. “Even a small local chapter can function as a recruitment hub, a training environment, and a bridge into wider transnational extremist networks,” he said.

International Connections

Our identification of Ruiz also led to evidence of links between Active Club Bogota and international neo-Nazi networks Blood & Honour and Combat 18.

In a May 2024 photo posted on his public Telegram account, a man whose face is covered by a cloth mask and further obscured with a digital image was pictured standing next to two neo-Nazi musicians who were in Bogota to perform at a concert that Ruiz had promoted on his Telegram account. One of the musicians is British neo-Nazi Ken McLellan, who has long been associated with Blood & Honour. 

The tattoos on the lower left leg and right hand of the man whose face was obscured appear to be the same as Ruiz’s – matching the shape, colour and position – based on photos publicly posted on Active Club Bogota’s Telegram channel.

Ruiz, identifiable by his tattoos on his lower left leg and right hand (shown in photos in the “Tattoos Identification” section), posing with Michael Grosch, a member of a German neo-Nazi band (centre) and British neo-Nazi Ken McLellan (right)
Left: The lower leg tattoo of a man shown in Ruiz’s photo. Right: The same tattoo on Ruiz’s left leg, from public Telegram posts on Active Club Bogota’s Telegram channel.

Blood & Honour is an international neo-Nazi network founded in the United Kingdom in 1987; McLellan and his band were present at this founding meeting and still regularly perform at Blood & Honour-affiliated concerts. Blood & Honour’s affiliate group Combat 18, described as the “armed branch” of Blood & Honour, was founded in 1992. 

Members and associates of Blood & Honour and Combat 18 have been accused of crimes including possessing explosives and drug trafficking. Individuals associated with both groups have been convicted of crimes including attempted murder, murder and terrorism. Both groups have been designated terrorist organisations in Canada since 2019 and have been subject to financial counter-terrorism sanctions in the United Kingdom since January 2025. 

Screenshots from videos posted by Active Club Bogota in October 2024 (left) and January 2025 (right), both featuring a flag commonly associated with international neo-Nazi networks Blood & Honour and Combat 18. The individual speaking is wearing a t-shirt in support of Active Club founder Robert Rundo.
Above: A cropped version of a photo posted by Active Club Bogota in March 2026, showing Blood & Honour and Combat 18 insignia on a table of merchandise and literature. Below: A rotated close-up of the Blood & Honour/C18 merchandise.

A Colombia-based neo-Nazi fashion retailer that sells t-shirts with Combat 18 symbolism and branding also lists Ruiz as the main contact on its Telegram channel (Bellingcat is not naming the retailer to avoid amplification). 

On its WhatsApp Business account, this retailer advertises neo-Nazi clothing and paraphernalia, including content with Combat 18’s name, symbolism and branding, as well as content promoting bands with documented links to Combat 18. Active Club Bogota has also promoted this retailer on its own Telegram channel. After reaching out to Meta, the parent company of WhatsApp, a spokesperson told Bellingcat that “this account breaks our terms of service and we have banned it”. As of publication, the WhatsApp Business account has been blocked.

Screenshots of t-shirts sold by a Colombian-based retailer featuring Combat 18 content. This retailer lists Active Club Bogota’s Ruiz as its main contact and has been promoted on Active Club Bogota’s Telegram channel.

After a series of arrests of alleged members in Spain in October 2023, Spanish authorities publicly called Combat 18 an “international criminal organisation” and claimed the Spanish wing of the group has relations with Combat 18 members in South America. 

Spanish media outlet El Periodico further reported that this police operation against Combat 18 in October 2023, according to their sources, “was mounted to pursue organised crime and other related offences, including drug trafficking”. 

Bellingcat established another link between the two groups through another individual associated with Active Club Bogota. 

In a 2015 post on one of Ruiz’s public Facebook accounts, an individual (in red below) who at the time was a bassist with a neo-Nazi band that sang songs praising and promoting Combat 18, is visible with a black tattoo on his left bicep.

 A March 2015 photo from one of Ruiz’s Facebook accounts; the caption indicates that Ruiz was posing “with the members” (“con los socios”) of a Bogota neo-Nazi band.

Almost a decade later, in January 2025, Active Club Bogota posted a video that featured an individual with a tattoo that appeared to be in the same shape and placement.

Above: Zoomed-in view of the neo-Nazi bassist’s left arm from Ruiz’s 2015 photo. Below: The tattoo of an individual shown in a January 2025 Active Club Bogota video practising jiu-jitsu (screengrab rotated for comparison).

The bassist’s name was mentioned in two posts by Juan de Dios Osuna Montanez, the alleged leader of Combat 18 in Spain, on Instagram in May 2024. 

Both posts featured a photo of what Montanez described as “little gifts directly from Colombia,” with Montanez thanking an account under this individual’s name, calling him his “brother.” These posts occurred during the same time period during which Active Club Bogota posted content from Catalonia, in northeastern Spain.

The photos Montanez posted of the apparent gifts are nearly identical, with the only difference being that the second photo is more zoomed in than the first. The photo shows a sticker with Active Club Bogota’s logo and branding, a t-shirt reading “Blood & Honour Colombia Division,” a sticker featuring both Blood & Honour and Combat 18’s logo, as well as packages of candy and coffee that Bellingcat was able to identify as being from small Colombian brands. 

“Little gifts directly from Colombia. Thanks brother and family.” The Instagram account belonging to the individual tagged in the post has since become inaccessible.

Montanez did not respond to Bellingcat’s request for comment via Instagram and Facebook, but we were blocked by his Instagram account after we reached out. We were unable to find any other public contact information for Montanez.

Ritzmann of CEP said that Active Club Bogota’s repeated display of the Combat 18 flag on its Telegram channel signals identification with one of the most explicitly militant neo-Nazi traditions in Europe.

He added that while some Active Clubs avoid overtly antisemitic references to avoid scrutiny by law enforcement, reduce negative media attention and attract new recruits without frightening them away, Active Club Bogota “appears to sit at the more explicit edge of the Active Club strategy” with its open celebration of Hitler’s birthday and its antisemitic messaging. 

“The network wants to appear harmless enough to avoid scrutiny, but radical enough to attract militants. Active Club Bogota is an example of how that balance can shift toward overt neo-Nazi mobilisation while still remaining inside the wider transnational Active Club ecosystem,” he said.

Full Response from Jorge Rodriguez to Bellingcat’s Queries

[April 24, 2026]

Translated to English
“In response to your questions, I would like to inform you that I am not obligated to respond to any interview or request without a court order. Therefore, I will not respond to any interviews. Furthermore, should you decide to use my name or image, I wish to state that I DO NOT AUTHORISE THE USE OF MY NAME, SOCIAL MEDIA ACCOUNTS OR ANY RELATED CONTENT.

Likewise, if you use my image or name, it constitutes a violation of my fundamental rights to privacy, reputation, habeas data, and the right to my own image, the latter of which has been repeatedly recognised and protected by the jurisprudence of the Constitutional Court.

The unauthorised use of my image or name may constitute a punishable offence, and I will be authorised to initiate the corresponding legal actions to restore my rights.

Sincerely,

Jorge Rodríguez”

In Spanish (Original)

“De conformidad con sus preguntas, me permito indicarle que no estoy obligado a responder ninguna entrevista o requerimiento sin que medie orden judicial. Por lo anterior, no responderé ninguna entrevista, asimismo, en caso de que ustedes decidan utilizar mi nombre o imagen me permito indicar que NO AUTORIZO LA UTILIZACIÓN DE MI NOMBRE O IMAGEN, REDES SOCIALES Y DEMÁS.

De igual manera, si ustedes utilizan mi imagen o nombre es una transgresión de mis derechos fundamentales a la intimidad, al buen nombre, al habeas data y al derecho a la propia imagen, este último reconocido y protegido de manera reiterada por la jurisprudencia de la Corte Constitucional.

Incluso la utilización de imagen o nombre sin autorización puede constituir una conducta punible y estaré autorizado de iniciar las acciones legales correspondientes en aras del restablecimiento de mis derechos.

Cordialmente,

Jorge Rodríguez”

First Response from Javier Ruiz to Bellingcat’s Queries

[April 21, 2026]

Translated to English
“As the data subject of the aforementioned personal data, I hereby submit this formal request regarding the use of my name, image, and background information in an interview request, without my prior, express, and informed consent.

The described conduct constitutes a potential violation of my fundamental rights to privacy, reputation, habeas data, and the right to my own image, the latter repeatedly recognised and protected by the jurisprudence of the Constitutional Court.

Likewise, the processing of my personal data without authorisation contravenes the provisions of Law 1581 of 2012 and its implementing decrees and could constitute the offence of personal data violation under Article 269F of the Colombian Penal Code.

Therefore, through this document, I expressly and immediately request:

– The suspension of any use, processing, circulation, or dissemination of my name, image, and other personal data.

– The permanent deletion of any content, file, record or publication in which my personal information has been used without my authorisation.

– A precise indication of the origin of the information, the purposes of its processing, and the third parties with whom it has been shared.

For the purposes of the foregoing, I grant a maximum period of forty-eight (48) hours from the receipt of this communication to demonstrate compliance with the requirement.

In case of non-compliance, I will be obligated to initiate the corresponding legal actions, including filing a writ of protection for the violation of my fundamental rights, as well as administrative proceedings before the Superintendency of Industry and Commerce and any applicable criminal actions.

This communication is understood as a formal prior request.

Sincerely,

J.R.”

In Spanish (Original)

“En mi calidad de titular de los datos personales referidos, me permito formular el presente requerimiento formal en relación con el uso de mi nombre, imagen y antecedentes dentro de una solicitud de entrevista, sin que medie autorización previa, expresa e informada de mi parte.

La conducta descrita constituye una posible vulneración de mis derechos fundamentales a la intimidad, al buen nombre, al habeas data y al derecho a la propia imagen, este último reconocido y protegido de manera reiterada por la jurisprudencia de la Corte Constitucional.

De igual forma, el tratamiento de mis datos personales sin autorización contraviene lo dispuesto en la Ley 1581 de 2012 y sus decretos reglamentarios, y podría adecuarse a la conducta tipificada como violación de datos personales conforme al artículo 269F del Código Penal Colombiano.

En virtud de lo anterior, por medio del presente escrito requiero de manera expresa e inmediata:

– La suspensión de cualquier uso, tratamiento, circulación o difusión de mi nombre, imagen y demás datos personales.

– La eliminación definitiva de cualquier contenido, archivo, registro o publicación en la que se haya hecho uso de los mismos sin mi autorización.

– La indicación precisa del origen de la información, las finalidades del tratamiento y los terceros con quienes haya sido compartida.

Para efectos de lo anterior, otorgo un plazo máximo de cuarenta y ocho (48) horas contadas a partir de la recepción de la presente comunicación, a fin de que se acredite el cumplimiento de lo requerido.

En caso de incumplimiento, me veré en la obligación de iniciar las acciones legales correspondientes, incluyendo la interposición de acción de tutela por la vulneración de mis derechos fundamentales, así como las actuaciones administrativas ante la Superintendencia de Industria y Comercio y las acciones penales a que haya lugar.La presente comunicación se entiende como requerimiento previo formal.

Cordialmente,

J.R.”

Second Response from Javier Ruiz to Bellingcat’s Queries

[May 7, 2026]

In English

“SUBJECT: FORMAL REQUEST FOR CESSATION AND WITHDRAWAL – NOTIFICATION OF VIOLATION OF FUNDAMENTAL RIGHTS AND DATA PROTECTION REGIME (LAW 1581 OF 2012)

In my capacity as a fully identified [Colombian] citizen and exercising my legal rights as the owner of personal data, I hereby submit this prior and peremptory request based on the following factual and legal grounds:

1. Lack of Consent and Legal Basis:

The unauthorised use of my name, image, and biographical information has been established within the framework of your informational activities. I declare that there has been no prior, express, informed, or qualified authorisation for the processing of said data, contravening the principle of legality and purpose established in Article 4 of Law 1581 of 2012.

2. Autonomy of the Right to One’s Own Image (Judgment T-040 of 2013): I hereby notify you that, in accordance with the jurisprudence of the Constitutional Court in its Judgment T-040 of 2013, the right to one’s own image is an autonomous and independent right. Therefore, the capture, use, or dissemination of my image and name requires my express consent, and journalistic practice does not grant an open licence for its exploitation without prior authorisation, especially when there is no public interest that proportionally justifies it.

3. Violation of Fundamental Rights:

Your actions constitute an arbitrary interference that affects my right to Habeas Data, my right to a good name (Art. 15 of the Colombian Penal Code), and, specifically, my right to my own image. According to the jurisprudence of the Honourable Constitutional Court, the use of a person’s image without their consent constitutes an overreach of journalistic practice that is not protected by freedom of information when it affects the private sphere.

4. Criminal and Administrative Liability: I hereby warn you that the processing of personal data without proper authorisation could constitute the conduct defined in Article 269F of the Colombian Penal Code (Violation of Personal Data), in addition to the fines imposed by the Superintendency of Industry and Commerce (SIC) for non-compliance with data protection regulations. 

LEGAL CLAIMS:

• IMMEDIATE CESSATION: The suspension of any act of processing, restricted circulation, or dissemination of my identity, image, or sensitive data.

• PERMANENT DELETION: The removal of any record from your databases or digital platforms containing information whose collection has not been authorised.

• TRACEABILITY REPORT: Submission of certification detailing the origin of my data and the identification of third parties to whom it has been transferred or transmitted.

TERM AND WARNING: You have a non-extendable term of forty-eight (48) hours to demonstrate compliance with the requests made herein. Silence or a negative response will authorise the initiation of a tutela action for the immediate protection of my fundamental rights, as well as the corresponding Administrative Complaint before the Office of the Superintendent Delegate for the Protection of Personal Data of the Superintendency of Industry and Commerce (SIC) and criminal proceedings before the Office of the Attorney General of Colombia.

1) Freedom of expression cannot infringe upon the right to privacy and honour.

2) The right to receive information, or rather, to inform, cannot supersede the duty not to disseminate defamatory information about a person or organisation.

3) A request for information from an independent, foreign media outlet cannot be based on erroneous presumptions regarding rulings, orders, and precedents pertaining to the Colombian judicial system. I thank you in advance for your attention, but I wish to clarify that I do not desire any response, understanding that you are complying with the order I have given and established.”

In Spanish (Original)

“ASUNTO: REQUERIMIENTO FORMAL DE CESE Y DESISTIMIENTO – NOTIFICACIÓN DE VULNERACIÓN DE DERECHOS FUNDAMENTALES Y RÉGIMEN DE PROTECCIÓN DE DATOS (LEY 1581 DE 2012)

En mi condición de ciudadano(a) plenamente identificado(a) y en ejercicio de mis facultades legales como titular de datos personales, presento ante ustedes este requerimiento previo y perentorio con base en los siguientes fundamentos de hecho y de derecho:

1. Ausencia de Consentimiento y Base Legal:

Se ha evidenciado el uso no autorizado de mi nombre, imagen y antecedentes biográficos en el marco de su actividad informativa. Manifiesto que no ha mediado autorización previa, expresa, informada ni calificada para el tratamiento de dichos datos, contraviniendo el principio de legalidad y finalidad establecido en el Artículo 4 de la Ley 1581 de 2012.

2. Autonomía del Derecho a la Propia Imagen (Sentencia T-040 de 2013):

Les notifico que, conforme a la jurisprudencia de la Corte Constitucional en su Sentencia T-040 de 2013, el derecho a la propia imagen es un derecho autónomo e independiente. Por tanto, la captura, uso o difusión de mi imagen y nombre requiere de mi consentimiento expreso, sin que el ejercicio periodístico otorgue una licencia abierta para su explotación sin autorización previa, especialmente cuando no existe un interés público que lo justifique de manera proporcional.

3. Vulneración de Derechos de Carácter Fundamental:

Su actuación constituye una injerencia arbitraria que afecta mi derecho al Habeas Data, al Buen Nombre (Art. 15 C.P.) y, de manera específica, al Derecho a la Propia Imagen. Según la jurisprudencia de la Honorable Corte Constitucional, el uso de la imagen de una persona sin su anuencia es una extralimitación del ejercicio periodístico que no encuentra amparo en la libertad de información cuando se afecta la esfera privada.

4. Responsabilidad Penal y Administrativa:

Les advierto que el tratamiento de datos personales sin la debida autorización podría configurar la conducta tipificada en el Artículo 269F del Código Penal Colombiano (Violación de datos personales), además de las sanciones pecuniarias que la Superintendencia de Industria y Comercio (SIC) impone por el incumplimiento del régimen de protección de datos.

PRETENSIONES LEGALES:

• CESE INMEDIATO: La suspensión de cualquier acto de tratamiento, circulación restringida o difusión de mi identidad, imagen o datos sensibles.

• SUPRESIÓN DEFINITIVA: La eliminación de cualquier registro en sus bases de datos o plataformas digitales que contenga información cuya recolección no haya sido autorizada.

• INFORME DE TRAZABILIDAD: Remitir certificación detallando el origen de mis datos y la identificación de terceros a quienes les hayan sido transferidos o transmitidos.

TÉRMINO Y ADVERTENCIA:

Cuentan con un término improrrogable de cuarenta y ocho (48) horas para acreditar el cumplimiento de lo aquí solicitado. El silencio o la respuesta negativa facultará el inicio de la Acción de Tutela para la protección inmediata de mis derechos fundamentales, así como la respectiva Denuncia Administrativa ante la Delegatura para la Protección de Datos Personales de la SIC y las acciones penales ante la Fiscalía General de la Nación.

1) La libertad de expresión no puede coartar el derecho a la privacidad y a la honra. 

2)El derecho a recibir información o más bien; a informar no puede supeditar el deber de no difundir información calumniosa sobre una persona u organización 

3) Un requerimiento de información por un medio independiente y extranjero no puede basarse en presunciones erróneas sobre sentencias, órdenes y antecedentes correspondientes al sistema judicial colombiano

De ante mano agradezco la atención prestada, sin antes aclarar que no deseo respuesta alguna, teniendo claro que acatan la orden dada y establecida de mi parte.”


Carlos Gonzales and Pooja Chaudhuri contributed research to this piece.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Unearthing a Colombian Politician’s Connections to Neo-Nazi Active Club Group appeared first on bellingcat.

“Make Iran Ungovernable” – Tracking Efforts To Destroy Iran’s Police Infrastructure

Bellingcat has identified at least 80 police stations or infrastructure related to law enforcement agencies and the Basij paramilitary group that has been damaged or destroyed in the first three weeks of the United States and Israel’s war against Iran. Experts told Bellingcat that both countries aim to degrade the Iranian regime’s “repressive capacity”.

Combined, the US and Israel have conducted thousands of strikes during the course of the 2026 war in Iran. Targets range from Islamic Revolutionary Guard Corps (IRGC) sites, Navy vessels to Iranian weapons manufacturers.

In early March, a Bellingcat analysis using satellite imagery and available photos and videos identified police stations as another apparent target, with at least 15 damaged or destroyed in the capital, Tehran.

We also identified multiple strikes against police infrastructure in the country’s north and west; these areas were targeted by the Israel Defence Forces according to a map released by the IDF on March 31.

“We are providing the brave people of Iran with the conditions to take their destiny into their own hands,” declared the Israeli Ministry of Foreign Affairs official X account, along with a photo of a destroyed police station.

اینجا کلانتری ۱۲۱ سلیمانیه در خیابان نبرد تهران بود.

ما شرایطی را برای مردم شجاع ایران فراهم می‌کنیم تا سرنوشت خود را در دست بگیرند. pic.twitter.com/VSm6YVvIwZ

— اسرائیل به فارسی (@IsraelPersian) March 5, 2026

In all, the majority of strikes Bellingcat analysed focused on police stations (30 incidents) and command centers or headquarters (29 incidents). Locations also include sites related to Basij, a plainclothes paramilitary organisation (9) affiliated with the IRGC that were “involved in the deadly crackdown” of protests in January 2026, others are associated with special forces (3) and traffic (2) or diplomatic (2) police compounds.

Related articles by Bellingcat

Satellite Imagery Reveals Strikes on Iranian Police Stations
Investigations

Satellite Imagery Reveals Strikes on Iranian Police Stations

Due to commercial satellite companies limiting access to imagery over Iran and neighbouring countries we relied on Sentinel-2 imagery data to help verify the incidents, as well as videos and photos, some of which were also verified by independent geolocators and contributors to the Geoconfirmed volunteer community and confirmed by Bellingcat researchers. 

Location data was partly determined using open source mapping data either from Wikimapia, OpenStreetMap or Google Maps. When video footage or photos were available for incidents reportedly targeting police stations, the location was verified with geolocation and satellite imagery analysis using either Planet Labs medium resolution PlanetScope data (restricted to imagery collected by March 9) or low resolution Sentinel-2 data.

Some locations were discovered utilising location data taken from OpenStreetMap using Overpass Turbo and comparing that with available Sentinel-2 data throughout Iran.

Map showing geolocated incidents in Iran. Click the markers to view the coordinates, sources, and verification notes. Map: Bellingcat/Miguel Ramalho

A Problem of Scale

Israel has released multiple videos showing the targeting of bases and checkpoints belonging to the Basij. In mid-March, the IDF announced the killing of the paramilitary group’s commander, Gholamreza Soleimani. 

Targeting the Basij is part of Israel’s and the US’ agenda “to degrade the regime’s repressive capacity,” Ali Vaez, the director of International Crisis Group Iran Project, told Bellingcat. Police stations are “not involved in repression in the way that crowd control police or Basij centers are”, so targeting them “appears more aimed at preventing the Islamic Republic from being able to maintain control internally,” he said.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Vaez told Bellingcat that, when considered alongside the broader range of targets, including industrial factories, the widespread targeting of police stations is part of a strategy “to make Iran ungovernable for the existing regime or whatever comes after”. 

Vaez was skeptical about the short term effects: “It’s a problem of scale. Iran is such a large country, even if you are able to completely destroy, not just degrade, the capacity of the regime in policing, oppressing, etc – it really requires not just maybe weeks but maybe months if not years.”

The Risk of Civilian Casualties

As of April 7, the Iranian Human Rights Activists News Agency estimates there’ve been more than 1,700 civilian fatalities during the war. 

Several police stations are situated in densely populated urban areas such as Tehran. Stations are used by civilians for various reasons including renewing driving licences, so if these buildings are targeted “during working hours and not in the middle of the night then risk is higher for these people,” Vaez said.

Map showing geolocated incidents in Tehran. Click the markers to view the coordinates, sources, and verification notes. Map: Bellingcat/Miguel Ramalho

A recent joint Airwars, Center for Civilians in Conflict and Human Rights Activists in Iran report detailing the first month of civilian casualties included a section on the worsening situation for detainees in Iranian prisons — including police stations that have been targeted. 

“I was detained in the holding cell of [Police Station 148] for ten days, along with four other activists. Now it looks like nothing is left of that station but ruins. I can’t even recognize where the detention area was. I keep wondering what happened to the people who were being held there during the attack. – Activist, told HRA upon seeing photos of the police station after recent US/Israeli airstrikes.”

Footage shared and geolocated by the BBC’s Shayan Sardarizadeh showed Police Station 148 damaged after an apparent strike in mid-March.

The main building of Tehran’s 148 police station and its courtyard, located on Enghelab Street, has been severely damaged in air strikes conducted on Friday.

The adjacent Hamoon Theatre also sustained some damage.

Video: @Vahid

Location: 35.700812, 51.402163@GeoConfirmed pic.twitter.com/9sdOtHd2XN

— Shayan Sardarizadeh (@Shayan86) March 14, 2026

One destroyed police station identified by Bellingcat in the city of Mahabad in northwestern Iran led to apparent damage to an Iranian Red Crescent Society building located next door. According to Iran’s Tasnim News agency (an IRGC-affiliated media outlet sanctioned by the EU, the US and Canada), one Red Crescent employee was injured in the attack.

The police station adjacent to the Red Crescent building isn’t identified on any mapping services, though there are reports “Police Station 11” was targeted the same day.

Annotated Google Earth image showing the location of a destroyed police station and partially destroyed Red Crescent building in Mahabad, West Azerbaijan Province, Iran. A video shared on Telegram by mamlekate on March 6 shows the view of the destruction from the ground. Buildings behind the destroyed police station match with those seen in the Google Earth imagery.

Israel has also targeted checkpoints operated by Basij members.

Bellingcat examined two cases showing Israeli strikes on checkpoints while civilians were passing. In one video, a strike hits a checkpoint as five motorbikes and a vehicle go by.

View of a Basij checkpoint in Tehran targeted by the IDF. Immediately before the explosion is visible in the video, there are five motorbikes and a car next to the checkpoint. Source: YouTube/IDF

In another IDF video, a yellow bus is immediately adjacent to the checkpoint when it is hit. It is unclear how many people were on the bus at the time of the strike or if anyone was injured.

View of a Basij checkpoint in Tehran targeted by the IDF. Immediately before the explosion, there is a yellow bus visible next to the targeted checkpoint. Source: IDF

According to the Open Source Munitions Portal (OSMP), Israeli drones commonly employ the Mikholit bomb. A variant of this bomb has 890 grams of explosives, an amount that creates hazardous fragmentation up to 104 meters away. 

“I have been watching the reporting on these Basij strikes and the use of the Mikholit in particular in open urban areas. It is IDF standard—using precision munitions and even sometimes “low collateral” munitions but in a reckless manner that still puts the civilian population at risk,” Wes J. Bryant, a defence and national security analyst formerly with the Pentagon’s Civilian Protection Center of Excellence told Bellingcat.

Questions Over Legality

International Humanitarian Law defines civilians as “persons who are not members of the armed forces”. Police officers fall under that definition, according to Adil Haque, Professor of Law at Rutgers University and Executive Editor at Just Security.  “As a rule, police are civilians and may not be attacked unless they take a direct part in hostilities,” Haque told Bellingcat. National security analyst Bryant agreed, adding that targeting police “does not stand up to legal scrutiny”.

Subscribe to the Bellingcat newsletter

Subscribe to our newsletter for first access to our published content and events that our staff and contributors are involved with, including interviews and training workshops.

In an email to Bellingcat, the IDF noted “that the police form part of Iran’s internal security apparatus, which also forms part of Iran’s armed forces, under Iran’s own domestic legislation. In every strike, the IDF takes feasible precautions in order to mitigate incidental harm to civilians and civilian objects to the extent possible under the circumstances.”

Police are indeed “part of the country’s armed forces. By that logic, anything with a flag on it is a legitimate target,” Ali Vaez, the director of International Crisis Group Iran Project, said.

Although Basij is a paramilitary group, any strikes against it would require precautions to minimise harm to civilians, Haque told Bellingcat. “Since the hostilities almost entirely involve aerial bombardment, the concrete and direct military advantage anticipated from strikes on Basij members who qualify as combatants is extremely low, so significant harm to nearby civilians would be disproportionate and illegal,” he said.

When asked about potential civilian casualties in the checkpoint strikes, the IDF told Bellingcat that since the Basij are subordinate to the IRGC and are therefore part of the armed forces, they are regarded as lawful military targets. Regarding the checkpoint strikes specifically, they stated “precision munitions and surveillance means were used in the strikes, as part of the precautions taken under the circumstances to mitigate expected incidental harm”.

Bellingcat reached out to US Central Command (CENTCOM) to ask if the US had any role in the police station strikes identified but received no official comment at the time of publication. 

The data collected so far for these sites can be found here.


Miguel Ramalho and Felix Matteo Lommerse contributed to this report.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post “Make Iran Ungovernable” – Tracking Efforts To Destroy Iran’s Police Infrastructure appeared first on bellingcat.

❌