24.07.2026 à 17:39
Sebastian Vandermeersch
Bellingcat has geolocated footage showing Shahed-136 type kamikaze drones in operation in Mali. Defence Blog and France 24 previously published reports that these drones were being deployed on the battlefield in northern Mali. But Bellingcat and Jeune Afrique subsequently verified two recent strikes using geolocation, satellite imagery and expert analysis to provide some of the […]
The post Shahed-Type Drones Filmed During Mali Village Attacks appeared first on bellingcat.
Bellingcat has geolocated footage showing Shahed-136 type kamikaze drones in operation in Mali.
Defence Blog and France 24 previously published reports that these drones were being deployed on the battlefield in northern Mali. But Bellingcat and Jeune Afrique subsequently verified two recent strikes using geolocation, satellite imagery and expert analysis to provide some of the clearest open-source evidence to date documenting their deployment.
The two strikes took place in the villages of Inafarak on July 12 and Talahandak on July 17. While the available evidence does not allow the exact variant to be identified, experts told Bellingcat it is quite likely the drones were manufactured in Russia given the deployment of the Kremlin-controlled Africa Corps group and the broader pattern of Russian military support to Mali.
Leo Jarry, a drone expert with Tungsten Strategies, told Bellingcat: “If the drones are Russian manufactured, they represent a visible demonstration of Russian support for Mali.”
Reports that Russian drones had been used in Mali first emerged in May, when Defence Blog published photographs of drone wreckage from strikes near the town of Savare.
Earlier this month, France 24 also identified debris from several Russian drone systems in Mali, pointing to an expanding Russian drone presence in the country. Until now, however, there has been no verified footage showing how Shahed-136 type drones in flight and hitting targets.
Mali has been mired in conflict since a rebellion erupted in the country’s north in 2012. In recent years, Russian forces, first through the Wagner Group and now through its successor, Africa Corps, have supported the Malian Armed Forces (FAMa) in operations against Tuareg rebel groups and jihadist organisations
On July 12, footage showing the aftermath of a drone strike in the village of Inafarak was published on X.
#حدود الجزائر ، مسيرة مالية ، انطلقت من قاعدة غاوا “
— محمدن أيب أيب (@EypeMohamedn) July 12, 2026
ضربت موقعا للتجار “ب” ( انفارغ ) الأضرار مادية”
تنبيه “
منطقة الضربة تبعد عن حدود الجزائر، 20 km ” pic.twitter.com/wpxWY7Qvz5
Bellingcat geolocated the footage to the town, which is close to the border with Algeria (21.32330, 0.72980) using satellite imagery. We confirmed the location by comparing a post-strike satellite image captured on July 15 with imagery from 2024. The comparison shows several buildings that were standing in 2024 had been destroyed by July, 15, 2026. This damage was consistent with that visible in the geolocated footage. The strike appears to have hit a commercial facility, with a damaged truck and numerous damaged fuel drums visible.

One of the videos shows the remains of an engine which appears consistent with an MD-550, a distinctive four-cylinder two-stroke engine which is found on the Shahed-136 family of drones. We showed the image of the engine to two weapons researchers – Trevor Ball, an independent weapons expert and former Bellingcat investigator, and Leo Jarry, a drone expert with Tungsten Strategies – who said the engine is consistent with the Shahed-136 family of drones.
The component also closely matches reference imagery of MD-550 engines published by the Open Source Munitions Portal (OSMP), an expert-reviewed database of documented weapons remnants, and on the war & sanctions component database.


Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
The footage we found on X was also republished by the Wagner- and Africa Corps-affiliated Telegram channel “White Uncles in Africa”, which regularly shares racist memes and graphic posts and which Bellingcat has previously reported on.
The channel captioned the videos: “Now the Azawadi ‘khokhols’ will be seeing Gerans all the time.” The use of “Geran” refers to a Russian-manufactured version of the Shahed-136. The post also uses the derogatory Russian slur “khokhol” for Ukrainians and applies it to people from Azawad, the name used by Tuareg separatists for northern Mali.
On July 17, graphic footage showing the aftermath of another Shahed-136 type drone strike was posted on X, showing one casualty as well as a burning truck. An additional video of the burning vehicle shows what appear to be bottles of cooking oil spilling from the truck indicating it may have been a commercial truck.
Bellingcat geolocated these videos to the village of Talahandak (20.26369, 1.80095), which is also close to the border with Algeria but around 100 miles southeast of Inafarak, by matching the surrounding buildings to satellite imagery.

Shortly afterwards, a Wagner-affiliated X account claimed that the drone responsible for the strike had been shot down by rebels before hitting the truck. The post showed one video where a Shahed-type drone could be seen in flight.
#أزواد“منطقة” تل هنداك “سقوط مسيرة إيرانية انتحارية ‘ pic.twitter.com/g0yqbpRO9C
— محمدن أيب أيب (@EypeMohamedn) July 17, 2026
We were able to geolocate where the footage that captured the drone’s final moments before impact was filmed to another area of Talahandak, nearly a kilometer away (20.266907, 1.792656) from the video that showed the impact site.

A distinctive smoke plume can be seen rising from the sight of impact in several other videos posted online shortly after the strike.
Bellingcat geolocated each of these videos and matched the plume of smoke adding further confirmation that the footage showing the drone in flight is authentic.
The video shows the drone descending directly towards the location where the person and truck were hit, and there appears to be no interception before impact.

The Shahed-136 is a series of long-range one-way attack drones originally developed in Iran and now also manufactured in Russia. Unlike the drones typically used by Mali’s Armed Forces- the Bayraktar TB2 , which launch relatively small precision-guided munitions before returning to base, one-way attack drones are designed to explode on impact, allowing them to attack over longer distances given they do not require recovery.
Leo Jarry, a drone expert with Tungsten Strategies, told Bellingcat that the drone provides Africa Corps and FAMa with an “expendable, cost-effective” long-range strike capability, allowing them to engage targets in Mali’s far north beyond the effective reach of the Bayraktar TB2. “The fact that these systems are relatively cheap and expendable changes the risk calculation for operators,” Jarry said. “They can be used more freely, potentially forcing insurgents in northern Mali to adapt their behaviour to a new aerial threat.”
However, Jarry said the system is inherently less precise than the Bayraktar TB2 because it cannot verify its targets during flight. Instead, it relies on separate surveillance assets to identify and track targets before launch. “In Mali, where armed groups are highly mobile and frequently operate among civilian populations, any gap between target identification and impact creates a risk of striking the wrong target.” Combined with the drone’s larger warhead, this increases the potential for civilian harm when employed in or near populated areas.
#Azawad
— mahmoud (@mahmoud_sahara_) July 17, 2026
un autre drone shahed russe a frappé un camion des marchandises à Talahandak. Ces marchandises une fois à Talahandak ils sont transité à Toumbouctou et Gao pour ravitailler ces villes,mais ces terroristes russes prefaireent terrorisés tout ce qui est dans l’Azawad. pic.twitter.com/y5E9ySC5RO
In Ukraine, Russian forces have used Shahed-136 type drones extensively in long-range strike campaigns that have repeatedly targeted civilian infrastructure, causing civilian casualties. Their appearance in Mali raises the possibility that the operational practices associated with these weapons are also being exported to this conflict.
The deployment also follows Bellingcat’s and Jeune Afrique’s recent investigation documenting the use of banned Russian cluster munitions in Mali.
Malian forces and Africa Corps currently face mounting pressure in northern Mali following a series of rebel offensives. Fighting has intensified in recent months, with rebels capturing several military bases and reportedly inflicting heavy losses on both FAMa and Africa Corps.
Jarry told Bellingcat that the relatively low cost and expendable nature of these new drones make them well suited to retaliatory strikes following attacks by rebels.
Bellingcat’s Carlos Gonzales contributed to this report as well as the following members of Bellingcat’s volunteer community: Nicole Kiess, Afton Briones, Riccardo Giannardi and Ziyu Wan.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
The post Shahed-Type Drones Filmed During Mali Village Attacks appeared first on bellingcat.
16.07.2026 à 18:00
Kolina Koltai
This investigation is a collaboration between Bellingcat and New Zealand news site The Press. You can read The Press’ piece here. Content warning: This article discusses non-consensual sexually explicit content and child sexual abuse material. In 2024, a former track and field coach in Boston, Massachusetts, was sentenced to five years in jail for attempting […]
The post Identifying the Crypto Entrepreneur Linked to Popular Forum Trading in ‘Leaked’ Nudes of Women appeared first on bellingcat.
This investigation is a collaboration between Bellingcat and New Zealand news site The Press. You can read The Press’ piece here.
Content warning: This article discusses non-consensual sexually explicit content and child sexual abuse material.
In 2024, a former track and field coach in Boston, Massachusetts, was sentenced to five years in jail for attempting to trick and extort more than 100 women, including student-athletes he coached, into sending him intimate photos.
According to the 2021 criminal complaint, Steve Waithe stole photos from some of the student-athletes’ phones under the pretence of “filming their form” at practices and meets. He also approached some victims via fake online accounts, telling them he had found their images on a forum site called “leakedbb.com” (“LeakedBB”) and offering to help them remove these photos if they provided more images for “reference”.
Authorities said Waithe also hired and paid another man in October 2020 to hack into the Snapchat accounts of women he coached or had other relationships with in an effort to steal and distribute nude images online.
In one post, according to the US Attorney’s Office, Waithe wrote: “Does anyone want to trade nudes? I’m talking girls you actually know. Could be exes or whatever. I have quite a few and [am] down to trade over snap[chat] or something.”
Legal documents do not name the sites on which Waithe distributed these images, but Bellingcat found a cached version of a November 2020 post with that exact wording on LeakedBB – the same site he allegedly used to try to trick victims. Another cached LeakedBB thread posted a few months later shows the same user offering to trade nudes of athletes, including “a lot that I actually know”.

Such posts were not unusual on the site: multiple archived pages show the forum’s users either requesting Snapchat hacks or offering to help others hack Snapchat accounts, sometimes for a fee.
In the criminal case against Waithe, the ownership of LeakedBB is never discussed, but a Bellingcat investigation can reveal that payment streams, company records and website domain information appear to lead back to one individual: Jitendra Maharaj, a Christchurch-based former pilot and co-founder of a cryptocurrency start-up, Pay It Now (PIN), which reportedly billed itself as the “Stripe of crypto payments”.

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
Our New Zealand publishing partner The Press sent an email to Maharaj on June 4 outlining our findings in detail and inviting him to respond. Maharaj did not reply to this.
However, by June 6, LeakedBB was down. As of publication, the website remains inaccessible.
The Press later received an email from a Christchurch-based lawyer representing Maharaj, who said their client was in Fiji for a family member’s funeral. The lawyer requested that we wait until his return on June 23.
When The Press visited his residence – a two-storey family home in Christchurch’s affluent Aidanfield suburb – on June 25, Maharaj said he did not know who was behind LeakedBB or operated it and that he was not sure if the website was down.
He said he did not respond to the email queries and had not spoken to his lawyers about them because “all the evidence against me just sounded really weird” and it seemed like there was “some kind of targeted attack out on me” based on “manufactured evidence or something that’s pointing me to this garbage”. However, he refused to comment on the record about most of the specific evidence linking him to the site and referred these questions to his lawyer.
He also claimed that he had been contacted by people “trying to harass me to get me to send them money”, but declined to provide details on the record.

Despite a further extension of the deadline until July 6 – more than a month after we first reached out – Maharaj and his lawyer had not provided any statement directly addressing the specific evidence linking him to the site as of publication.
PIN, the company Maharaj co-founded, did not respond to The Press’ requests for comment. However, there is no suggestion that PIN has any knowledge of or involvement in LeakedBB.
LeakedBB was set up in 2019 and built a sizeable following over the next seven years, averaging an estimated two million visits a month from March to May this year. The board statistics shown on LeakedBB’s homepage in May displayed 2.2 million registered users and more than 2.6 million posts.

Google’s Transparency Report shows it received more than 95,000 individual requests for over 350,000 pages on LeakedBB to be delisted from search results. This resulted in Google de-listing more than 169,000 pages from its search results, according to the report.
Shortly after the site went offline, a Reddit post noting the outage and asking for alternatives trended in the “hot” section of a piracy subreddit, accumulating almost 700 votes in a week. In response to a question by one commenter asking what the site was, another person replied: “Not only did it have ‘onlyfans’ content, also amateur, asian, arabic, celebrity and other hacked phone/icloud content from other sites.”
This comment accurately summarised some of the content on the site. In LeakedBB’s early days, it had sections for other types of “leaked” content such as computer programmes and eBooks. But within months, the forum’s discussions were almost exclusively about pornographic images and videos that members claimed had been leaked – implying that it was non-consensual, hacked or stolen content.
The most popular section on the forum contained content that claimed to be from sites such as OnlyFans and Fansly, which, if shared without the original creators’ consent, would be a violation of their intellectual property.
Reba Rocket, co-owner and chief operating officer of Takedown Piracy, a company that helps both adult performers and private individuals remove non-consensually shared explicit media, said sites like LeakedBB cause financial harm to legitimate content creators.
“People would not shove a DVD into their coat pocket and walk out of the store – that’s something tangible that they know they’re doing something wrong, whereas watching something on the internet for free doesn’t have that same connected moral,” she said.
Other sections on LeakedBB featured threads requesting or promoting content that often appeared to show women who did not have anything to do with the adult industry, which the posts claimed were leaked, hacked or even obtained through blackmail.
One post advertised images of girls from 29 US states: “There’s names and Facebook information if you want that,” the member, “Master Leaker”, posted. “There’s also two girls that got blackmailed into sending more nudes as well!”

In the “Requests” section, users shared clothed images of women or social media handles of potential victims, and asked if others had leaked content of them. In one recent post looking for a “Florida Milf”, a user wrote: “She may go by the name [redacted]. Looks like the daughter graduated from [redacted]. Anyone have content of her? Sex tapes?”
Some users also posted nude or intimate images of women they had found elsewhere, asking for help finding out their real identities. “Who is she?” or “Can anyone ID?” were some common questions in the posts.
Non-consensual intimate image sharing (NCII), colloquially referred to as “revenge porn”, is far from new. It is a known problem on Reddit, where, in 2022, a BBC investigation found “thousands” of such images being shared despite the platform’s attempts to crack down on the issue.
LeakedBB, however, seemed to take the opposite approach: instead of trying to moderate or prevent users from posting what appeared to be NCII, it sought to profit from and reward it.
Except for preview images, most of the content users shared in the “leaks” section was behind a paywall and could only be accessed with memberships costing up to US$99.99 or by redeeming credits.
The site rewarded members with credits for posting “leaked” content, as well as when other members spent credits to “unlock” their content. These credits could be used to access links that users could otherwise only view with a paid upgrade, or redeemed for cryptocurrency at varying rates (the most frequent contributors had the option to cash out the equivalent of up to $0.15 for each thread they posted).
There was also an annual Christmas contest, with last year’s total prizes worth over $4,000 in cryptocurrency for users who posted or liked the most threads.

Rocket said LeakedBB had “damaged many people”, including clients of her company. “Those specific clients are not in the adult industry,” she said, “but LeakedBB seemed more than happy to share their non-consensual content”.
The “leaks” were often posted with women’s purported real names, locations and social media accounts, as well as preview images showing their uncovered faces. One poster said sharing a woman’s social media details “adds to the experience”.
“For me, it makes my jerk-off sesh feel more personal, as if she’s an actual person I know rather than a moviestar/pornstar,” the post said.

There were more than 80 responses to this thread, mostly thanking the original poster for sharing the content. One of them, however, claimed to be the woman shown in the images: “Please remove this link. These photos were illegally stolen from me. This constitutes revenge porn and violates US law. Police are already involved. Not only is it illegal but just gross.”
Allison Mahoney, the founder and managing attorney at ALM Law in New York and Colorado, told Bellingcat she received calls about cases involving NCII “all the time”.
“It kind of amazes me, given the amount of media attention this has gotten over the years, that people are still engaging in this type of abuse so cavalierly,” said Mahoney, whose firm specialises in providing legal services for abuse survivors and children harmed in welfare systems.
Mahoney and Rocket agreed that sites sharing NCII often had real-world implications for victims, especially when images were posted alongside personal information, including names, contact information and professions.
“We have clients who … their children were kicked out of Catholic school, or they lost their mainstream job, or relationships ended, or families cut them off simply because content was posted online without their consent and viewed by others,” Rocket said.
Mahoney said online abuse can turn into offline abuse when victims have their personal information, like their name, profession and contact information, posted with their images. She has seen clients who had strangers show up at their homes or places of work, threatening their physical safety – a situation she said was “really terrifying”.
In July last year, LeakedBB closed a marketplace it had hosted for more than five years, which allowed users to sell leaks and services to each other. Lucifer NightStar, the administrator account on the site, said there were allegations of people selling “UA [underage] material”, which was “not something we want on [LeakedBB]”.

On one section of the forum, which was specifically for sharing content from other sites that hosted leaked pornographic content, LeakedBB had a disclaimer: “Please note that posting any content on any one below the legal age of 18 is against the law. We have a zero tolerance policy on such things and your account will immediately be banned / reported.”
But this warning did not appear on other sections of the forum, including those featuring threads of “amateur nudes” described as having been leaked. Some threads on the forum, which remained accessible shortly before the entire site was taken down, also described images of “young teens”.
While it is not known if those descriptions are accurate, in a recent post on Reddit a person asked for help taking down non-consensual photos they said were taken when they were a minor, hacked from Snapchat, and posted on LeakedBB, among other sites.
“I am in school to become a teacher and searched my name on google. If you go down a bit these websites come up,” they wrote. “I am so devastated and can’t believe this has happened to me.”
While speaking to The Press outside his residence on June 25, Maharaj said that when it came to publishing non-consensual pornography and child sexual abuse imagery, “It should be obvious anyone’s against that.”
Lucifer NightStar was the username for the only account with the title of “Administrator” on the LeakedBB forum. This user posted FAQs for the site and almost every forum announcement throughout its history.
The URL of this account’s profile page shows the user ID (UID) of “1”. According to documentation for MyBB, a free and open source forum software that LeakedBB has credited for powering the site, the first user of the forum is assigned the UID “1” and has super administrator privileges – meaning their account cannot be deleted, banned or otherwise altered by regular administrators.
While the profile did not state the user’s location, it did show a local timestamp based on the user’s timezone settings, which matched GMT+12 – a timezone used in several countries in Oceania, including New Zealand and Fiji.
Lucifer NightStar’s recent posts generally avoid mentioning non-consensual intimate imagery, focusing on administrative updates and issues, troubleshooting and the annual Christmas contest. However, in the first few months of the forum’s existence, the user posted a thread with a “LeakedBB Exclusive” of “leaked Kiwi girls”.

In another discussion thread from 2020, Lucifer NightStar vouched for a user’s ability to “influence” another member’s ex-girlfriend to share nudes.

Maharaj did not respond to The Press and Bellingcat’s question about whether he was Lucifer NightStar. However, one of the administrator’s posts led us to a clue pointing to Maharaj’s possible connection with LeakedBB.
In one post in May 2021, responding to a user reporting problems paying with Apple Pay, Lucifer NightStar shared a screenshot of what the payment screen should look like. A company name was visible in this image: “Logica LTD”.

New Zealand company records show that Logica Limited was registered by Maharaj in February 2021, just months before this post. The company address is also in Christchurch, where Maharaj lives.
(Note: This is a different company from Logica Partners Limited, based in Auckland, which has no apparent connection with Maharaj or LeakedBB and is unrelated to this investigation.)
The records from the New Zealand Companies Office show that Maharaj has been the sole director of Logica Limited since its incorporation. He stated on his LinkedIn profile that he was self-employed as the CEO of Logica NZ from May 2020 to August 2021.
(Maharaj’s LinkedIn profile appears to have been deleted between June 13 and June 15, after The Press and Bellingcat’s initial enquiries and during the period his lawyer said he was in Fiji attending a family member’s funeral.)

But that was not the only connection to Logica Limited. On May 4, 2022, a YouTube user with the display name “LeakedBB” uploaded a video on how to pay for memberships on the site. This video was also embedded on LeakedBB’s homepage.
The video showed how users could pay by credit card. When they clicked to purchase a membership, LeakedBB would redirect them to another website to buy a digital avatar pack with a price corresponding to their selected membership tier.
After purchasing this “referral product”, users were encouraged to leave a comment and a positive rating to receive an “extra bonus month”. Archived versions of the website show view counts in the tens of thousands for some of these avatar packs.
The thumbnails of the “digital avatars” as well as their price and description, as shown in the video, were identical to those shown on the archived version of a site, logica.nz, which is recorded as Logica Limited’s website on OpenCorporates. This site also lists “Logica LTD” in its copyright information at the bottom of its landing page.
(Bellingcat last accessed a live version of the video on June 15. By July 1, we noticed that the video had been removed by the uploader.)

In a forum thread on LeakedBB dedicated to explaining alternative ways to pay for membership, hundreds of users posted that they had just purchased the “Mystic Avatar Pack” or the “Pixel Avatar Pack” to gain access to the site. One user included screenshots of their purchase, showing the site URL to be “logica.nz”. Other users also stated that they had made the purchase on this website and were waiting to receive their upgrades.

This website’s landing page now displays only a note stating that it is under maintenance. However, according to archives captured by the Internet Archive, it was still selling “digital avatar packs” in March 2025.
This type of payment structure not only conceals the nature of the transaction from the payment processor (as non-consensual content violates most platforms’ terms of service), but it also hides the transactions for the user, as payments are not described as being made to “LeakedBB” on bank statements.
When asked about the links between LeakedBB and Logica Limited, Maharaj only told The Press at the doorstep interview on June 25 that “Logica was my company. I cannot say what happened there right now”.
According to the New Zealand Companies Register, Logica Limited is in good standing, with its most recent annual filing submitted by Maharaj in March 2026.
The Domain Name System (DNS) records of LeakedBB revealed another connection that seems to point back to Maharaj. Using online investigations tool DNSlytics, we viewed DNS records for the website and found that in 2020, the MX (mail exchange) record for LeakedBB.com was set to LeakedBB.net. An MX record is the mail server set up to accept emails for that domain. For LeakedBB.com, this was later changed to ProtonMail.
While the WHOIS ownership of LeakedBB.net is obscured, we found it on a list of sites that had DNS certificates issued by another site, mybbplugins.com. A DNS certificate is used to prove ownership of a domain and requires an administrator to validate that certificate.
According to WHOIS records from cyberthreat intelligence platform DomainTools, mybbplugins.com was publicly registered to Maharaj from December 2011 to February 2019, after which the registrant information was redacted.
The same site also issued a DNS certificate for a domain bearing Maharaj’s name (jitendramaharaj.com) as well as two domains that include part of his first name, jit-pay.cc and thejitshow.com. DNS certificates for these domains were issued between 2016 and 2021, according to free Certificate Transparency monitoring site crt.sh. Both “leakedbb” and the domain names linked to Maharaj’s name (i.e. “jitendramaharaj”, “jit-pay” and “thejitshow”) were also used as subdomains for mybbplugins.com, records from DomainTools show.
Another link appeared when we inspected the code of the oldest saved archive of the payment screen on LeakedBB, from November 2019, which showed a ProtonMail address associated with the PayPal form at the time with a string of seven digits as the username.
This string of seven digits is an exact match for what appears to be part of a Fiji-based phone number listed on WHOIS records for websites registered to Maharaj’s name including mybbplugins.com, from 2008 to 2011. It is unclear whether Maharaj was using this phone number in 2019, by the time LeakedBB was set up, and a different Fiji-based phone number was used with his name when the registration for mybbplugins.com was renewed in 2016.

Explore some of the links between Maharaj and LeakedBB:

Bellingcat also found several other apparent connections between Maharaj and other applications hosting adult content.
An account with the username “Jitendra M.” has been posting on the MyBB community forum since 2008, with the account ID originally using the username “Darkmew”. An archived capture of this account’s profile information showed a date of birth and a location in Fiji.
This date of birth matches the one listed on a Facebook profile Bellingcat found under Maharaj’s name. His LinkedIn profile also shows that prior to moving to Christchurch, he worked in Nadi, Fiji, and he has listed addresses in the city for some of the domains registered to his name, as well as an email with a Fijian domain. This user also mentions that they are a pilot.
Jitendra M.’s profile bears a “former staff” label, indicating that he used to work for MyBB. A previous commit (save) of a file containing details of MyBB team members shows that the full name associated with this account’s user ID and username was “Jitendra Maharaj”, and his website was listed as jitendra-maharaj.com.
Archived versions of this site show photos and details that match those from Maharaj’s public social media profiles and interviews. For example, a 2011 capture shows that he mentioned being a pilot at a company called Pacific Sun. Pacific Sun was later rebranded as Fiji Link, and Maharaj’s LinkedIn profile, before it was deleted, stated that he worked for Fiji Link from 2009 to 2015. A blog post on the site also refers to mybbplugins.com as the author’s “newest endeavour”.

Very shortly after joining the MyBB community forum in Feb 2008, Jitendra M. asked about using MyBB for “warez” (an internet slang term for pirated digital content) and/or adult content. He stated that he was “interested in using it for a [sic] adult forum”.
During this time, he also posted asking about streaming videos from a server and how to use a PayPal account without a credit card for “people putting money into my account for services I provide”. In late 2008, Jitendra M. purchased a web domain, reaperscrypt.info, which Wayback Machine archives show hosted pornographic content while it was online in 2009. This domain was publicly registered to Maharaj from November 2008 to January 2010.
In 2013, he posted about selling the mybbplugins.com domain. However, as previously mentioned, Maharaj’s name was still publicly registered as the owner of the domain until February 2019, when registration data was redacted.

Bellingcat was able to view Facebook and Instagram accounts under Maharaj’s name and showing his profile picture in early May. These accounts painted a picture of a family man, with his public photos mainly showing his wife and children. His Facebook account had been either deleted or made private by May, and his Instagram account, while still active, has not been updated since 2013.
Archives of an X account using the same username as Maharaj’s Facebook and Instagram accounts also show several posts from November 2019 promoting LeakedBB.

The “Darkmew” username that Jitendra M. originally used was also used for a GitHub account which hosts a repository described as the “official repository for Pay it Now – PIN Token”. This account, which now redirects to an account with the username “JitMaharaj”, has also forked (or copied) two apps created by other people: one to create a subscription platform “like onlyfans.com” that uses cryptocurrency for payments; the other designed to scrape and report illicit content from LeakedBB.

These forked repositories were among 38 visible on JitMaharaj’s account on June 17, but by July 1 – after a June 22 query from The Press asking Maharaj whether he owned this account – there were only 25 repositories listed on this account. The two repositories mentioned above were among those removed.
Maharaj did not respond to questions about whether he owned any of the accounts or domains mentioned in this section.
Mahoney said that successfully removing clients’ images from platforms like LeakedBB was a time-consuming task. “Some sites, usually the sites hosted overseas, will just ignore the request and won’t take them down,” she said.
In the US, which accounted for almost half (40 percent) of LeakedBB’s web traffic in May, the Take it Down Act recently came into effect. The new federal law requires platforms to quickly remove non-consensually shared intimate imagery when it is reported.
However, there has been little discussion of the law on LeakedBB. One user asked in the “Help” forum how this act would affect the site and its members back in October 2025, but Lucifer NightStar never responded to this post.

Rocket said having content removed for her US-based clients could be difficult when the platforms were based overseas: “A lot of it depends on where the platform is hosted, who runs their ad network and who is monetising – who their payment processors are,” she said.
LeakedBB accepted cryptocurrency payments through NOWPayments, a cryptocurrency payments gateway based in the Netherlands and Estonia. The purchase page for its subscription plans, which allowed users to gain unrestricted access to the site, redirected to a NOWPayments purchase screen to transfer cryptocurrency to LeakedBB.
In response to questions from Bellingcat, NOWPayments confirmed that LeakedBB’s activities violated its terms of service. The payments provider said it had deactivated LeakedBB’s account and blacklisted the platform immediately, as of June 4.
LeakedBB did have a form for people to request that their content be taken down under the Digital Millennium Copyright Act (DMCA), a US copyright law. However, this required victims to submit personal information such as a physical address and a business email address, and stated that it would reject requests that used email addresses from free services like Google and ProtonMail. Such details appear to go beyond those required for DMCA takedown requests on other sites: for example, Google only requires a first and last name, and an email address from any domain.
In one Reddit thread discussing the difficulty of removing content from LeakedBB under the DMCA, someone commented: “Some of this seems fairly standard, some of it seems like it’s designed to make people not request a takedown for fear of doxing [sic] themselves.”
On the page to submit DMCA takedown requests, LeakedBB also stated that successful requests would lead to them removing content hosted on their servers, but not links to third-party hosting providers – which is how a large portion of the content was made available to the website’s users.
In New Zealand, where Maharaj is based, posting intimate imagery without consent is illegal under the Harmful Digital Communications Act. People face up to two years imprisonment or a fine up to NZ$50,000 (US$29,200), while for a company, the fine can be as high as NZ$200,000.
Netsafe is the only approved body in the country that handles complaints under this act. The agency’s chief online safety officer Sean Lyons told The Press that the law was quite novel and other jurisdictions were “envious” when it was enacted – it was able to respond to generative AI technology that didn’t exist when it was written, and gave New Zealand courts powers to issue takedown orders, even in other countries.
Still, Lyons said the law had its limitations: it was mostly intended for use where one individual was harming another, and if the responsible party was overseas, the law’s efficacy largely relied on responsible platforms doing the right thing.
“There are times when within our process, we will have contacted platforms or hosts and they will have said, ‘Who the heck are you?’…[Or] ‘We know what we’re doing, we are quite comfortable with what we are doing, and we don’t give a stuff about what it is that you are telling us, or about New Zealand law, or about the harm.’”
Mahoney and Rocket agreed that current laws were limited in their effectiveness against sites like LeakedBB.
“The fact of the matter is there are places where … until there is an enforceable international law, that content is going to be available forever, which means there is a risk of it being shared forever,” Rocket said.
Mahoney said image-based abusers have also become more sophisticated over time: “Technology is advancing, and the law is always playing catch-up,” she said.
But she suggested that identifying those responsible for the abuse could have a deterrent effect: “The anonymity that people have hiding behind screens really contributes to this and emboldens people to act in ways that are very abusive to people.
“If people understand that there’s a risk that their identity and their bad behaviour will be revealed, the hope is that it will curtail some of this and dissuade people from engaging in this type of conduct, which is so, so harmful to the victims.”
If you are a victim or know anyone who is affected by image-based abuse, resources and support are available through StopNCII.org.
Galen Reich and Melissa Zhu from Bellingcat and Michael Wright from The Press contributed to this article.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
The post Identifying the Crypto Entrepreneur Linked to Popular Forum Trading in ‘Leaked’ Nudes of Women appeared first on bellingcat.
07.07.2026 à 00:19
Carlos Gonzales
Bellingcat has geolocated footage circulating on social media that appears to show coffins placed in newly dug trenches following the recent deadly earthquakes in Venezuela. The site identified extends over two hectares beside an existing cemetery in La Esperanza, a town near La Guaira on the country’s northern coast. It was visited by a representative of […]
The post Between Graves and Uncertainty: The Management of the Dead After Venezuela’s Earthquake appeared first on bellingcat.
Bellingcat has geolocated footage circulating on social media that appears to show coffins placed in newly dug trenches following the recent deadly earthquakes in Venezuela.
The site identified extends over two hectares beside an existing cemetery in La Esperanza, a town near La Guaira on the country’s northern coast.
It was visited by a representative of our Latin American reporting partners who captured pictures of work ongoing at the site. They also report speaking to a resident who said that refrigerated trucks with several bodies had been coming and going.

The location matches a site identified in July 6 reports by AFP and Deutsche Welle (DW), which detailed that 150 unidentified bodies had been buried in a long row of individual graves.
AFP and DW published pictures of individual crosses and stones, quoting a resident of the town who stated that the burials were “numbered by plots and also by the code” so they could be identified at a later date.
It is not known if the coffins visible in the social media footage relate to the 150 unidentified bodies later referred to by AFP and DW, or if they are separate burials at the same general location.
Reuters also published pictures of the site on July 6 and showed video of coffins arriving on the back of flat bed trucks.

More than 3,500 people are confirmed to have died as a result of the earthquakes so far. But that figure is expected to rise significantly, with the UN reporting that the death toll could reach 10,000.
Oran Finegan, Director of Forensic Action International and former Head of Forensics for the International Committee of the Red Cross (ICRC), told Bellingcat that, while it is best practice for the burial of deceased persons to take place in individual graves, it is not uncommon to see long trenches like those seen in the social media footage when there are high numbers of unidentified deceased and it is not practical to immediately provide individual graves.

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
He pointed to documentation from the ICRC that details best practices in such circumstances. He also made the important distinction between common graves, where bodies are temporarily kept until identification can take place, and mass graves, where bodies are dumped clandestinely without any care or process. What is seen in the footage appears to be the former, he said. There has been no evidence of the latter.
Finegan emphasised that it was vital that burials were mapped and recorded properly during any burial process so that identification could take place at a later date. Documenting where bodies were coming from, laying each body with enough distance from each other and ensuring each coffin or body bag had a unique number was key, he said.
While it has not been possible to ascertain the exact processes being followed at or preceding burials at the La Esperanza site, media reports in nearby La Guaira have recorded complications with identification and burial processes.
According to the BBC the scale of the disaster has overwhelmed local services, forcing institutions to improvise. Some bodies were being placed outside, exposed to the sun, at a port facility in La Guaira, the BBC reported.
A further complication is that many of the bodies recovered have reportedly been unrecognisable.
One woman told the independent Venezuelan publication RunRun.es that she was sent a tag and number for a body bag that did not match the bodies of her relatives. She was then told that her relatives’ bodies had been misidentified and sent for burial at a site in the town of Los Teques.
The New York Times reported last week that overwhelmed morgues were filling with unidentified bodies, forcing authorities to consider mass burials.
The Venezuelan Attorney General’s Office, the Judicial Police and National Service of Forensic Medicine Sciences did not respond to requests for comment for this article. However, President Delcy Rodriguez has previously stated that all bodies are being processed through a forensic identification system which includes fingerprints records, photographic documentation and forensic odontology.
Rodríguez has also said that “no one will go to a mass grave”.
The President of the Venezuelan Professional Funeral Sector Association (Asoproinfu), Davenio Velásquez, stated that there is a protocol for unidentified bodies to be buried temporarily in “five hundred individual burial niches” in Caracas. He added that they will be exhumed and cremated after six months if not identified.
Finegan added that exhuming and cremating bodies prevents identification and it is not a best practice. However, he said it is important to understand local cultural and religious customs. He also added that the six-month deadline for reclaiming remains is likely unrealistically short for such a major disaster.
Terrain features in the social media videos Bellingcat found are consistent with those seen beside a graveyard on the outskirts of La Esperanza, a town situated on Venezuela’s northwest coast near the La Guaira region that was significantly impacted by the earthquakes.
These features allowed us to geolocate the site seen in the footage.
Firstly, a video published on Facebook on July 1 by Colombian digital outlet RTV appears to show a large grave with approximately half a dozen coffins situated within it. The video (which we will refer to as Video 1) further shows a group of people in civilian clothes beside a truck with more coffins on the back. It was not possible to verify the contents of the coffins.

Another video (which we will refer to as Video 2) posted to Instagram by an independent creator who said it was shared by a source on the ground also shows a series of large holes on a plot of land that appears similar to the first video.

Bellingcat sought to identify where these videos were taken by first searching for any other potential reference images and footage we could compare them to.
We found one video posted by a former army Colonel and now Mayor of Vargas Municipality, José Manuel Suárez Maldonado, posing beside heavy machinery as it prepared a plot of land that was due to be given to the local community as a new cemetery plot. The video was first published in June 2024.

By comparing the footage in the mayor’s video with the RTV and independent creator video – as well as matching landmarks visible in the mountaineering app Peakvisor – we were able to verify that all were filmed on the same plot of land.
For example, a distinctive tree formation is visible in Video 1 and Video 2, suggesting they were filmed at the same site.

Mountain features and hillsides seen in the background of Video 2 match those seen in Video 3.

The rocky facade of one hillside visible in Video 2 also matches what can be seen in Video 3.

Combined, the visual comparisons allow us to ascertain that the three videos were filmed in the same place.
We then compared the hills and mountains visible in Video 2 to what can be seen in the mountaineering app, PeakVisor. This allowed us to confirm the location just outside La Esperanza.

Satellite imagery of this site taken on June 25 shows a patch of land that appears green, filled with vegetation. By June 27, a newly scraped area of approximately 1.5 acres – roughly the size of a football pitch – appeared in exactly the same place.

It is important to note that the recently cleared area appears to have been excavated or altered before.
Satellite imagery from 2022 and 2023 shows work being carried out in the same spot before it once again became overgrown.
However, Bellingcat identified a white marquee visible in Video 2, providing a temporal reference to show that at least one of the videos was filmed in 2026.
This marquee was visible in satellite imagery captured on June 27, 2026, at the exact spot visible in Video 2.

In footage posted to TikTok on July 2 (which we are labelling Video 4) the same tent appears to be visible.
The cleared sector of land matches the shape of the work visible in more recent satellite imagery of the site.
Satellite imagery from previous years also shows that the cleared area looks slightly different when viewed from above. This allows us to be confident that the social media footage aligns with the more recent satellite imagery rather than previous years when the area was also cleared.

Bellingcat’s reporting partners contacted the Venezuelan Attorney General’s Office, the Judicial Police and National Service of Forensic Medicine Sciences, the President of the Association of Funeral Industry Professionals (Asoproinfu) but did not receive a response before publication.
Finegan, the forensics expert, said that the current death toll was likely an underestimation and authorities are expecting it to rise.
But he said that even when families are unable to immediately identify their loved ones, it was vital to ensure that the deceased are buried respectfully and in a way that preserves the possibility of future identification. This he added can bring families a degree of comfort in the most difficult circumstances.
This investigation was the result of a collaborative effort with our Venezuelan and Latin American partners: Efecto Cocuyo, Alianza Rebelde Investiga (ARI)—comprising El Pitazo, Runrunes and TalCual—and the Latin American Center for Investigative Journalism (CLIP).
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
The post Between Graves and Uncertainty: The Management of the Dead After Venezuela’s Earthquake appeared first on bellingcat.