16.07.2026 à 18:00
Kolina Koltai
This investigation is a collaboration between Bellingcat and New Zealand news site The Press. You can read The Press’ piece here. Content warning: This article discusses non-consensual sexually explicit content and child sexual abuse material. In 2024, a former track and field coach in Boston, Massachusetts, was sentenced to five years in jail for attempting […]
The post Identifying the Crypto Entrepreneur Linked to Popular Forum Trading in ‘Leaked’ Nudes of Women appeared first on bellingcat.
This investigation is a collaboration between Bellingcat and New Zealand news site The Press. You can read The Press’ piece here.
Content warning: This article discusses non-consensual sexually explicit content and child sexual abuse material.
In 2024, a former track and field coach in Boston, Massachusetts, was sentenced to five years in jail for attempting to trick and extort more than 100 women, including student-athletes he coached, into sending him intimate photos.
According to the 2021 criminal complaint, Steve Waithe stole photos from some of the student-athletes’ phones under the pretence of “filming their form” at practices and meets. He also approached some victims via fake online accounts, telling them he had found their images on a forum site called “leakedbb.com” (“LeakedBB”) and offering to help them remove these photos if they provided more images for “reference”.
Authorities said Waithe also hired and paid another man in October 2020 to hack into the Snapchat accounts of women he coached or had other relationships with in an effort to steal and distribute nude images online.
In one post, according to the US Attorney’s Office, Waithe wrote: “Does anyone want to trade nudes? I’m talking girls you actually know. Could be exes or whatever. I have quite a few and [am] down to trade over snap[chat] or something.”
Legal documents do not name the sites on which Waithe distributed these images, but Bellingcat found a cached version of a November 2020 post with that exact wording on LeakedBB – the same site he allegedly used to try to trick victims. Another cached LeakedBB thread posted a few months later shows the same user offering to trade nudes of athletes, including “a lot that I actually know”.

Such posts were not unusual on the site: multiple archived pages show the forum’s users either requesting Snapchat hacks or offering to help others hack Snapchat accounts, sometimes for a fee.
In the criminal case against Waithe, the ownership of LeakedBB is never discussed, but a Bellingcat investigation can reveal that payment streams, company records and website domain information appear to lead back to one individual: Jitendra Maharaj, a Christchurch-based former pilot and co-founder of a cryptocurrency start-up, Pay It Now (PIN), which reportedly billed itself as the “Stripe of crypto payments”.

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
Our New Zealand publishing partner The Press sent an email to Maharaj on June 4 outlining our findings in detail and inviting him to respond. Maharaj did not reply to this.
However, by June 6, LeakedBB was down. As of publication, the website remains inaccessible.
The Press later received an email from a Christchurch-based lawyer representing Maharaj, who said their client was in Fiji for a family member’s funeral. The lawyer requested that we wait until his return on June 23.
When The Press visited his residence – a two-storey family home in Christchurch’s affluent Aidanfield suburb – on June 25, Maharaj said he did not know who was behind LeakedBB or operated it and that he was not sure if the website was down.
He said he did not respond to the email queries and had not spoken to his lawyers about them because “all the evidence against me just sounded really weird” and it seemed like there was “some kind of targeted attack out on me” based on “manufactured evidence or something that’s pointing me to this garbage”. However, he refused to comment on the record about most of the specific evidence linking him to the site and referred these questions to his lawyer.
He also claimed that he had been contacted by people “trying to harass me to get me to send them money”, but declined to provide details on the record.

Despite a further extension of the deadline until July 6 – more than a month after we first reached out – Maharaj and his lawyer had not provided any statement directly addressing the specific evidence linking him to the site as of publication.
PIN, the company Maharaj co-founded, did not respond to The Press’ requests for comment. However, there is no suggestion that PIN has any knowledge of or involvement in LeakedBB.
LeakedBB was set up in 2019 and built a sizeable following over the next seven years, averaging an estimated two million visits a month from March to May this year. The board statistics shown on LeakedBB’s homepage in May displayed 2.2 million registered users and more than 2.6 million posts.

Google’s Transparency Report shows it received more than 95,000 individual requests for over 350,000 pages on LeakedBB to be delisted from search results. This resulted in Google de-listing more than 169,000 pages from its search results, according to the report.
Shortly after the site went offline, a Reddit post noting the outage and asking for alternatives trended in the “hot” section of a piracy subreddit, accumulating almost 700 votes in a week. In response to a question by one commenter asking what the site was, another person replied: “Not only did it have ‘onlyfans’ content, also amateur, asian, arabic, celebrity and other hacked phone/icloud content from other sites.”
This comment accurately summarised some of the content on the site. In LeakedBB’s early days, it had sections for other types of “leaked” content such as computer programmes and eBooks. But within months, the forum’s discussions were almost exclusively about pornographic images and videos that members claimed had been leaked – implying that it was non-consensual, hacked or stolen content.
The most popular section on the forum contained content that claimed to be from sites such as OnlyFans and Fansly, which, if shared without the original creators’ consent, would be a violation of their intellectual property.
Reba Rocket, co-owner and chief operating officer of Takedown Piracy, a company that helps both adult performers and private individuals remove non-consensually shared explicit media, said sites like LeakedBB cause financial harm to legitimate content creators.
“People would not shove a DVD into their coat pocket and walk out of the store – that’s something tangible that they know they’re doing something wrong, whereas watching something on the internet for free doesn’t have that same connected moral,” she said.
Other sections on LeakedBB featured threads requesting or promoting content that often appeared to show women who did not have anything to do with the adult industry, which the posts claimed were leaked, hacked or even obtained through blackmail.
One post advertised images of girls from 29 US states: “There’s names and Facebook information if you want that,” the member, “Master Leaker”, posted. “There’s also two girls that got blackmailed into sending more nudes as well!”

In the “Requests” section, users shared clothed images of women or social media handles of potential victims, and asked if others had leaked content of them. In one recent post looking for a “Florida Milf”, a user wrote: “She may go by the name [redacted]. Looks like the daughter graduated from [redacted]. Anyone have content of her? Sex tapes?”
Some users also posted nude or intimate images of women they had found elsewhere, asking for help finding out their real identities. “Who is she?” or “Can anyone ID?” were some common questions in the posts.
Non-consensual intimate image sharing (NCII), colloquially referred to as “revenge porn”, is far from new. It is a known problem on Reddit, where, in 2022, a BBC investigation found “thousands” of such images being shared despite the platform’s attempts to crack down on the issue.
LeakedBB, however, seemed to take the opposite approach: instead of trying to moderate or prevent users from posting what appeared to be NCII, it sought to profit from and reward it.
Except for preview images, most of the content users shared in the “leaks” section was behind a paywall and could only be accessed with memberships costing up to US$99.99 or by redeeming credits.
The site rewarded members with credits for posting “leaked” content, as well as when other members spent credits to “unlock” their content. These credits could be used to access links that users could otherwise only view with a paid upgrade, or redeemed for cryptocurrency at varying rates (the most frequent contributors had the option to cash out the equivalent of up to $0.15 for each thread they posted).
There was also an annual Christmas contest, with last year’s total prizes worth over $4,000 in cryptocurrency for users who posted or liked the most threads.

Rocket said LeakedBB had “damaged many people”, including clients of her company. “Those specific clients are not in the adult industry,” she said, “but LeakedBB seemed more than happy to share their non-consensual content”.
The “leaks” were often posted with women’s purported real names, locations and social media accounts, as well as preview images showing their uncovered faces. One poster said sharing a woman’s social media details “adds to the experience”.
“For me, it makes my jerk-off sesh feel more personal, as if she’s an actual person I know rather than a moviestar/pornstar,” the post said.

There were more than 80 responses to this thread, mostly thanking the original poster for sharing the content. One of them, however, claimed to be the woman shown in the images: “Please remove this link. These photos were illegally stolen from me. This constitutes revenge porn and violates US law. Police are already involved. Not only is it illegal but just gross.”
Allison Mahoney, the founder and managing attorney at ALM Law in New York and Colorado, told Bellingcat she received calls about cases involving NCII “all the time”.
“It kind of amazes me, given the amount of media attention this has gotten over the years, that people are still engaging in this type of abuse so cavalierly,” said Mahoney, whose firm specialises in providing legal services for abuse survivors and children harmed in welfare systems.
Mahoney and Rocket agreed that sites sharing NCII often had real-world implications for victims, especially when images were posted alongside personal information, including names, contact information and professions.
“We have clients who … their children were kicked out of Catholic school, or they lost their mainstream job, or relationships ended, or families cut them off simply because content was posted online without their consent and viewed by others,” Rocket said.
Mahoney said online abuse can turn into offline abuse when victims have their personal information, like their name, profession and contact information, posted with their images. She has seen clients who had strangers show up at their homes or places of work, threatening their physical safety – a situation she said was “really terrifying”.
In July last year, LeakedBB closed a marketplace it had hosted for more than five years, which allowed users to sell leaks and services to each other. Lucifer NightStar, the administrator account on the site, said there were allegations of people selling “UA [underage] material”, which was “not something we want on [LeakedBB]”.

On one section of the forum, which was specifically for sharing content from other sites that hosted leaked pornographic content, LeakedBB had a disclaimer: “Please note that posting any content on any one below the legal age of 18 is against the law. We have a zero tolerance policy on such things and your account will immediately be banned / reported.”
But this warning did not appear on other sections of the forum, including those featuring threads of “amateur nudes” described as having been leaked. Some threads on the forum, which remained accessible shortly before the entire site was taken down, also described images of “young teens”.
While it is not known if those descriptions are accurate, in a recent post on Reddit a person asked for help taking down non-consensual photos they said were taken when they were a minor, hacked from Snapchat, and posted on LeakedBB, among other sites.
“I am in school to become a teacher and searched my name on google. If you go down a bit these websites come up,” they wrote. “I am so devastated and can’t believe this has happened to me.”
While speaking to The Press outside his residence on June 25, Maharaj said that when it came to publishing non-consensual pornography and child sexual abuse imagery, “It should be obvious anyone’s against that.”
Lucifer NightStar was the username for the only account with the title of “Administrator” on the LeakedBB forum. This user posted FAQs for the site and almost every forum announcement throughout its history.
The URL of this account’s profile page shows the user ID (UID) of “1”. According to documentation for MyBB, a free and open source forum software that LeakedBB has credited for powering the site, the first user of the forum is assigned the UID “1” and has super administrator privileges – meaning their account cannot be deleted, banned or otherwise altered by regular administrators.
While the profile did not state the user’s location, it did show a local timestamp based on the user’s timezone settings, which matched GMT+12 – a timezone used in several countries in Oceania, including New Zealand and Fiji.
Lucifer NightStar’s recent posts generally avoid mentioning non-consensual intimate imagery, focusing on administrative updates and issues, troubleshooting and the annual Christmas contest. However, in the first few months of the forum’s existence, the user posted a thread with a “LeakedBB Exclusive” of “leaked Kiwi girls”.

In another discussion thread from 2020, Lucifer NightStar vouched for a user’s ability to “influence” another member’s ex-girlfriend to share nudes.

Maharaj did not respond to The Press and Bellingcat’s question about whether he was Lucifer NightStar. However, one of the administrator’s posts led us to a clue pointing to Maharaj’s possible connection with LeakedBB.
In one post in May 2021, responding to a user reporting problems paying with Apple Pay, Lucifer NightStar shared a screenshot of what the payment screen should look like. A company name was visible in this image: “Logica LTD”.

New Zealand company records show that Logica Limited was registered by Maharaj in February 2021, just months before this post. The company address is also in Christchurch, where Maharaj lives.
(Note: This is a different company from Logica Partners Limited, based in Auckland, which has no apparent connection with Maharaj or LeakedBB and is unrelated to this investigation.)
The records from the New Zealand Companies Office show that Maharaj has been the sole director of Logica Limited since its incorporation. He stated on his LinkedIn profile that he was self-employed as the CEO of Logica NZ from May 2020 to August 2021.
(Maharaj’s LinkedIn profile appears to have been deleted between June 13 and June 15, after The Press and Bellingcat’s initial enquiries and during the period his lawyer said he was in Fiji attending a family member’s funeral.)

But that was not the only connection to Logica Limited. On May 4, 2022, a YouTube user with the display name “LeakedBB” uploaded a video on how to pay for memberships on the site. This video was also embedded on LeakedBB’s homepage.
The video showed how users could pay by credit card. When they clicked to purchase a membership, LeakedBB would redirect them to another website to buy a digital avatar pack with a price corresponding to their selected membership tier.
After purchasing this “referral product”, users were encouraged to leave a comment and a positive rating to receive an “extra bonus month”. Archived versions of the website show view counts in the tens of thousands for some of these avatar packs.
The thumbnails of the “digital avatars” as well as their price and description, as shown in the video, were identical to those shown on the archived version of a site, logica.nz, which is recorded as Logica Limited’s website on OpenCorporates. This site also lists “Logica LTD” in its copyright information at the bottom of its landing page.
(Bellingcat last accessed a live version of the video on June 15. By July 1, we noticed that the video had been removed by the uploader.)

In a forum thread on LeakedBB dedicated to explaining alternative ways to pay for membership, hundreds of users posted that they had just purchased the “Mystic Avatar Pack” or the “Pixel Avatar Pack” to gain access to the site. One user included screenshots of their purchase, showing the site URL to be “logica.nz”. Other users also stated that they had made the purchase on this website and were waiting to receive their upgrades.

This website’s landing page now displays only a note stating that it is under maintenance. However, according to archives captured by the Internet Archive, it was still selling “digital avatar packs” in March 2025.
This type of payment structure not only conceals the nature of the transaction from the payment processor (as non-consensual content violates most platforms’ terms of service), but it also hides the transactions for the user, as payments are not described as being made to “LeakedBB” on bank statements.
When asked about the links between LeakedBB and Logica Limited, Maharaj only told The Press at the doorstep interview on June 25 that “Logica was my company. I cannot say what happened there right now”.
According to the New Zealand Companies Register, Logica Limited is in good standing, with its most recent annual filing submitted by Maharaj in March 2026.
The Domain Name System (DNS) records of LeakedBB revealed another connection that seems to point back to Maharaj. Using online investigations tool DNSlytics, we viewed DNS records for the website and found that in 2020, the MX (mail exchange) record for LeakedBB.com was set to LeakedBB.net. An MX record is the mail server set up to accept emails for that domain. For LeakedBB.com, this was later changed to ProtonMail.
While the WHOIS ownership of LeakedBB.net is obscured, we found it on a list of sites that had DNS certificates issued by another site, mybbplugins.com. A DNS certificate is used to prove ownership of a domain and requires an administrator to validate that certificate.
According to WHOIS records from cyberthreat intelligence platform DomainTools, mybbplugins.com was publicly registered to Maharaj from December 2011 to February 2019, after which the registrant information was redacted.
The same site also issued a DNS certificate for a domain bearing Maharaj’s name (jitendramaharaj.com) as well as two domains that include part of his first name, jit-pay.cc and thejitshow.com. DNS certificates for these domains were issued between 2016 and 2021, according to free Certificate Transparency monitoring site crt.sh. Both “leakedbb” and the domain names linked to Maharaj’s name (i.e. “jitendramaharaj”, “jit-pay” and “thejitshow”) were also used as subdomains for mybbplugins.com, records from DomainTools show.
Another link appeared when we inspected the code of the oldest saved archive of the payment screen on LeakedBB, from November 2019, which showed a ProtonMail address associated with the PayPal form at the time with a string of seven digits as the username.
This string of seven digits is an exact match for what appears to be part of a Fiji-based phone number listed on WHOIS records for websites registered to Maharaj’s name including mybbplugins.com, from 2008 to 2011. It is unclear whether Maharaj was using this phone number in 2019, by the time LeakedBB was set up, and a different Fiji-based phone number was used with his name when the registration for mybbplugins.com was renewed in 2016.

Explore some of the links between Maharaj and LeakedBB:

Bellingcat also found several other apparent connections between Maharaj and other applications hosting adult content.
An account with the username “Jitendra M.” has been posting on the MyBB community forum since 2008, with the account ID originally using the username “Darkmew”. An archived capture of this account’s profile information showed a date of birth and a location in Fiji.
This date of birth matches the one listed on a Facebook profile Bellingcat found under Maharaj’s name. His LinkedIn profile also shows that prior to moving to Christchurch, he worked in Nadi, Fiji, and he has listed addresses in the city for some of the domains registered to his name, as well as an email with a Fijian domain. This user also mentions that they are a pilot.
Jitendra M.’s profile bears a “former staff” label, indicating that he used to work for MyBB. A previous commit (save) of a file containing details of MyBB team members shows that the full name associated with this account’s user ID and username was “Jitendra Maharaj”, and his website was listed as jitendra-maharaj.com.
Archived versions of this site show photos and details that match those from Maharaj’s public social media profiles and interviews. For example, a 2011 capture shows that he mentioned being a pilot at a company called Pacific Sun. Pacific Sun was later rebranded as Fiji Link, and Maharaj’s LinkedIn profile, before it was deleted, stated that he worked for Fiji Link from 2009 to 2015. A blog post on the site also refers to mybbplugins.com as the author’s “newest endeavour”.

Very shortly after joining the MyBB community forum in Feb 2008, Jitendra M. asked about using MyBB for “warez” (an internet slang term for pirated digital content) and/or adult content. He stated that he was “interested in using it for a [sic] adult forum”.
During this time, he also posted asking about streaming videos from a server and how to use a PayPal account without a credit card for “people putting money into my account for services I provide”. In late 2008, Jitendra M. purchased a web domain, reaperscrypt.info, which Wayback Machine archives show hosted pornographic content while it was online in 2009. This domain was publicly registered to Maharaj from November 2008 to January 2010.
In 2013, he posted about selling the mybbplugins.com domain. However, as previously mentioned, Maharaj’s name was still publicly registered as the owner of the domain until February 2019, when registration data was redacted.

Bellingcat was able to view Facebook and Instagram accounts under Maharaj’s name and showing his profile picture in early May. These accounts painted a picture of a family man, with his public photos mainly showing his wife and children. His Facebook account had been either deleted or made private by May, and his Instagram account, while still active, has not been updated since 2013.
Archives of an X account using the same username as Maharaj’s Facebook and Instagram accounts also show several posts from November 2019 promoting LeakedBB.

The “Darkmew” username that Jitendra M. originally used was also used for a GitHub account which hosts a repository described as the “official repository for Pay it Now – PIN Token”. This account, which now redirects to an account with the username “JitMaharaj”, has also forked (or copied) two apps created by other people: one to create a subscription platform “like onlyfans.com” that uses cryptocurrency for payments; the other designed to scrape and report illicit content from LeakedBB.

These forked repositories were among 38 visible on JitMaharaj’s account on June 17, but by July 1 – after a June 22 query from The Press asking Maharaj whether he owned this account – there were only 25 repositories listed on this account. The two repositories mentioned above were among those removed.
Maharaj did not respond to questions about whether he owned any of the accounts or domains mentioned in this section.
Mahoney said that successfully removing clients’ images from platforms like LeakedBB was a time-consuming task. “Some sites, usually the sites hosted overseas, will just ignore the request and won’t take them down,” she said.
In the US, which accounted for almost half (40 percent) of LeakedBB’s web traffic in May, the Take it Down Act recently came into effect. The new federal law requires platforms to quickly remove non-consensually shared intimate imagery when it is reported.
However, there has been little discussion of the law on LeakedBB. One user asked in the “Help” forum how this act would affect the site and its members back in October 2025, but Lucifer NightStar never responded to this post.

Rocket said having content removed for her US-based clients could be difficult when the platforms were based overseas: “A lot of it depends on where the platform is hosted, who runs their ad network and who is monetising – who their payment processors are,” she said.
LeakedBB accepted cryptocurrency payments through NOWPayments, a cryptocurrency payments gateway based in the Netherlands and Estonia. The purchase page for its subscription plans, which allowed users to gain unrestricted access to the site, redirected to a NOWPayments purchase screen to transfer cryptocurrency to LeakedBB.
In response to questions from Bellingcat, NOWPayments confirmed that LeakedBB’s activities violated its terms of service. The payments provider said it had deactivated LeakedBB’s account and blacklisted the platform immediately, as of June 4.
LeakedBB did have a form for people to request that their content be taken down under the Digital Millennium Copyright Act (DMCA), a US copyright law. However, this required victims to submit personal information such as a physical address and a business email address, and stated that it would reject requests that used email addresses from free services like Google and ProtonMail. Such details appear to go beyond those required for DMCA takedown requests on other sites: for example, Google only requires a first and last name, and an email address from any domain.
In one Reddit thread discussing the difficulty of removing content from LeakedBB under the DMCA, someone commented: “Some of this seems fairly standard, some of it seems like it’s designed to make people not request a takedown for fear of doxing [sic] themselves.”
On the page to submit DMCA takedown requests, LeakedBB also stated that successful requests would lead to them removing content hosted on their servers, but not links to third-party hosting providers – which is how a large portion of the content was made available to the website’s users.
In New Zealand, where Maharaj is based, posting intimate imagery without consent is illegal under the Harmful Digital Communications Act. People face up to two years imprisonment or a fine up to NZ$50,000 (US$29,200), while for a company, the fine can be as high as NZ$200,000.
Netsafe is the only approved body in the country that handles complaints under this act. The agency’s chief online safety officer Sean Lyons told The Press that the law was quite novel and other jurisdictions were “envious” when it was enacted – it was able to respond to generative AI technology that didn’t exist when it was written, and gave New Zealand courts powers to issue takedown orders, even in other countries.
Still, Lyons said the law had its limitations: it was mostly intended for use where one individual was harming another, and if the responsible party was overseas, the law’s efficacy largely relied on responsible platforms doing the right thing.
“There are times when within our process, we will have contacted platforms or hosts and they will have said, ‘Who the heck are you?’…[Or] ‘We know what we’re doing, we are quite comfortable with what we are doing, and we don’t give a stuff about what it is that you are telling us, or about New Zealand law, or about the harm.’”
Mahoney and Rocket agreed that current laws were limited in their effectiveness against sites like LeakedBB.
“The fact of the matter is there are places where … until there is an enforceable international law, that content is going to be available forever, which means there is a risk of it being shared forever,” Rocket said.
Mahoney said image-based abusers have also become more sophisticated over time: “Technology is advancing, and the law is always playing catch-up,” she said.
But she suggested that identifying those responsible for the abuse could have a deterrent effect: “The anonymity that people have hiding behind screens really contributes to this and emboldens people to act in ways that are very abusive to people.
“If people understand that there’s a risk that their identity and their bad behaviour will be revealed, the hope is that it will curtail some of this and dissuade people from engaging in this type of conduct, which is so, so harmful to the victims.”
If you are a victim or know anyone who is affected by image-based abuse, resources and support are available through StopNCII.org.
Galen Reich and Melissa Zhu from Bellingcat and Michael Wright from The Press contributed to this article.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
The post Identifying the Crypto Entrepreneur Linked to Popular Forum Trading in ‘Leaked’ Nudes of Women appeared first on bellingcat.
07.07.2026 à 00:19
Carlos Gonzales
Bellingcat has geolocated footage circulating on social media that appears to show coffins placed in newly dug trenches following the recent deadly earthquakes in Venezuela. The site identified extends over two hectares beside an existing cemetery in La Esperanza, a town near La Guaira on the country’s northern coast. It was visited by a representative of […]
The post Between Graves and Uncertainty: The Management of the Dead After Venezuela’s Earthquake appeared first on bellingcat.
Bellingcat has geolocated footage circulating on social media that appears to show coffins placed in newly dug trenches following the recent deadly earthquakes in Venezuela.
The site identified extends over two hectares beside an existing cemetery in La Esperanza, a town near La Guaira on the country’s northern coast.
It was visited by a representative of our Latin American reporting partners who captured pictures of work ongoing at the site. They also report speaking to a resident who said that refrigerated trucks with several bodies had been coming and going.

The location matches a site identified in July 6 reports by AFP and Deutsche Welle (DW), which detailed that 150 unidentified bodies had been buried in a long row of individual graves.
AFP and DW published pictures of individual crosses and stones, quoting a resident of the town who stated that the burials were “numbered by plots and also by the code” so they could be identified at a later date.
It is not known if the coffins visible in the social media footage relate to the 150 unidentified bodies later referred to by AFP and DW, or if they are separate burials at the same general location.
Reuters also published pictures of the site on July 6 and showed video of coffins arriving on the back of flat bed trucks.

More than 3,500 people are confirmed to have died as a result of the earthquakes so far. But that figure is expected to rise significantly, with the UN reporting that the death toll could reach 10,000.
Oran Finegan, Director of Forensic Action International and former Head of Forensics for the International Committee of the Red Cross (ICRC), told Bellingcat that, while it is best practice for the burial of deceased persons to take place in individual graves, it is not uncommon to see long trenches like those seen in the social media footage when there are high numbers of unidentified deceased and it is not practical to immediately provide individual graves.

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
He pointed to documentation from the ICRC that details best practices in such circumstances. He also made the important distinction between common graves, where bodies are temporarily kept until identification can take place, and mass graves, where bodies are dumped clandestinely without any care or process. What is seen in the footage appears to be the former, he said. There has been no evidence of the latter.
Finegan emphasised that it was vital that burials were mapped and recorded properly during any burial process so that identification could take place at a later date. Documenting where bodies were coming from, laying each body with enough distance from each other and ensuring each coffin or body bag had a unique number was key, he said.
While it has not been possible to ascertain the exact processes being followed at or preceding burials at the La Esperanza site, media reports in nearby La Guaira have recorded complications with identification and burial processes.
According to the BBC the scale of the disaster has overwhelmed local services, forcing institutions to improvise. Some bodies were being placed outside, exposed to the sun, at a port facility in La Guaira, the BBC reported.
A further complication is that many of the bodies recovered have reportedly been unrecognisable.
One woman told the independent Venezuelan publication RunRun.es that she was sent a tag and number for a body bag that did not match the bodies of her relatives. She was then told that her relatives’ bodies had been misidentified and sent for burial at a site in the town of Los Teques.
The New York Times reported last week that overwhelmed morgues were filling with unidentified bodies, forcing authorities to consider mass burials.
The Venezuelan Attorney General’s Office, the Judicial Police and National Service of Forensic Medicine Sciences did not respond to requests for comment for this article. However, President Delcy Rodriguez has previously stated that all bodies are being processed through a forensic identification system which includes fingerprints records, photographic documentation and forensic odontology.
Rodríguez has also said that “no one will go to a mass grave”.
The President of the Venezuelan Professional Funeral Sector Association (Asoproinfu), Davenio Velásquez, stated that there is a protocol for unidentified bodies to be buried temporarily in “five hundred individual burial niches” in Caracas. He added that they will be exhumed and cremated after six months if not identified.
Finegan added that exhuming and cremating bodies prevents identification and it is not a best practice. However, he said it is important to understand local cultural and religious customs. He also added that the six-month deadline for reclaiming remains is likely unrealistically short for such a major disaster.
Terrain features in the social media videos Bellingcat found are consistent with those seen beside a graveyard on the outskirts of La Esperanza, a town situated on Venezuela’s northwest coast near the La Guaira region that was significantly impacted by the earthquakes.
These features allowed us to geolocate the site seen in the footage.
Firstly, a video published on Facebook on July 1 by Colombian digital outlet RTV appears to show a large grave with approximately half a dozen coffins situated within it. The video (which we will refer to as Video 1) further shows a group of people in civilian clothes beside a truck with more coffins on the back. It was not possible to verify the contents of the coffins.

Another video (which we will refer to as Video 2) posted to Instagram by an independent creator who said it was shared by a source on the ground also shows a series of large holes on a plot of land that appears similar to the first video.

Bellingcat sought to identify where these videos were taken by first searching for any other potential reference images and footage we could compare them to.
We found one video posted by a former army Colonel and now Mayor of Vargas Municipality, José Manuel Suárez Maldonado, posing beside heavy machinery as it prepared a plot of land that was due to be given to the local community as a new cemetery plot. The video was first published in June 2024.

By comparing the footage in the mayor’s video with the RTV and independent creator video – as well as matching landmarks visible in the mountaineering app Peakvisor – we were able to verify that all were filmed on the same plot of land.
For example, a distinctive tree formation is visible in Video 1 and Video 2, suggesting they were filmed at the same site.

Mountain features and hillsides seen in the background of Video 2 match those seen in Video 3.

The rocky facade of one hillside visible in Video 2 also matches what can be seen in Video 3.

Combined, the visual comparisons allow us to ascertain that the three videos were filmed in the same place.
We then compared the hills and mountains visible in Video 2 to what can be seen in the mountaineering app, PeakVisor. This allowed us to confirm the location just outside La Esperanza.

Satellite imagery of this site taken on June 25 shows a patch of land that appears green, filled with vegetation. By June 27, a newly scraped area of approximately 1.5 acres – roughly the size of a football pitch – appeared in exactly the same place.

It is important to note that the recently cleared area appears to have been excavated or altered before.
Satellite imagery from 2022 and 2023 shows work being carried out in the same spot before it once again became overgrown.
However, Bellingcat identified a white marquee visible in Video 2, providing a temporal reference to show that at least one of the videos was filmed in 2026.
This marquee was visible in satellite imagery captured on June 27, 2026, at the exact spot visible in Video 2.

In footage posted to TikTok on July 2 (which we are labelling Video 4) the same tent appears to be visible.
The cleared sector of land matches the shape of the work visible in more recent satellite imagery of the site.
Satellite imagery from previous years also shows that the cleared area looks slightly different when viewed from above. This allows us to be confident that the social media footage aligns with the more recent satellite imagery rather than previous years when the area was also cleared.

Bellingcat’s reporting partners contacted the Venezuelan Attorney General’s Office, the Judicial Police and National Service of Forensic Medicine Sciences, the President of the Association of Funeral Industry Professionals (Asoproinfu) but did not receive a response before publication.
Finegan, the forensics expert, said that the current death toll was likely an underestimation and authorities are expecting it to rise.
But he said that even when families are unable to immediately identify their loved ones, it was vital to ensure that the deceased are buried respectfully and in a way that preserves the possibility of future identification. This he added can bring families a degree of comfort in the most difficult circumstances.
This investigation was the result of a collaborative effort with our Venezuelan and Latin American partners: Efecto Cocuyo, Alianza Rebelde Investiga (ARI)—comprising El Pitazo, Runrunes and TalCual—and the Latin American Center for Investigative Journalism (CLIP).
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
The post Between Graves and Uncertainty: The Management of the Dead After Venezuela’s Earthquake appeared first on bellingcat.
30.06.2026 à 10:25
Galen Reich
If you’ve seen reports of a wildfire in your region and you’re looking for open source data, NASA’s fire-tracking tool is often the first place to start. It provides a heat signature and an approximate location. But detection is only the first step in understanding what’s happened. In this guide, we explore ways to analyse […]
The post Burning Forests: Tools for Tracking and Reporting Wildfire Damage appeared first on bellingcat.
If you’ve seen reports of a wildfire in your region and you’re looking for open source data, NASA’s fire-tracking tool is often the first place to start. It provides a heat signature and an approximate location. But detection is only the first step in understanding what’s happened. In this guide, we explore ways to analyse and report on the scale and severity of wildfires, including those in protected areas where ecosystems are often most fragile. We also examine how often fires recur in the same region over multiple seasons, helping to identify patterns in fire activity as climate change reshapes fire risk around the world.
Satellite imagery from Copernicus Browser will be used to visualise the spread of the fire, and vegetation health indices to assess burn severity. The datasets will then be combined in QGIS for more in-depth analysis. At each stage, suggestions will be offered for turning the data into clear, reportable findings.
Throughout this guide, a single case study will be used: Sicily’s Zingaro Nature Reserve. In 2025, wildfires swept across the region, destroying forests, grasslands and croplands. Located on the Capo San Vito peninsula, the reserve was so severely affected that sections remain closed today.
When investigating a wildfire, it’s important to narrow down when it occurred and where it spread. The Landsat and Sentinel-2 missions are well-suited to this task, providing regular free imagery of most of the Earth’s landmass.
Below are two sets of Sentinel-2 imagery showing conditions shortly before and after a fire on July 25, 2025, near Capo San Vito, Sicily. The top two images are true-colour, similar to what would be seen from an aeroplane window. The image on the top right shows an area of scorched earth on the eastern side of the peninsula, but the exact extent of the fire is difficult to determine because the colour of the ground has changed only slightly.


Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
The bottom two images are false-colour and highlight the difference between healthy vegetation and burned areas. Such imagery is possible because Sentinel-2 captures bands of light outside the visible range, a technique known as multispectral imaging. In these images, the near-infrared (NIR) band is coloured green, and the shortwave infrared (SWIR) band is coloured red. Healthy vegetation mainly reflects NIR light, so it appears green, while burned areas mainly reflect SWIR light, so they appear red.
These images were created with Copernicus Browser, a free browser-based tool from the European Space Agency for accessing and working with Sentinel imagery. It allows users to browse the Sentinel-2 catalogue by date and visualise different band combinations. You don’t need an account to use the browser, but signing in enables additional features.
If you’d like to try Copernicus Browser without further explanation, you can go straight to the false-colour post-fire image here.
To follow along step by step, first open Copernicus Browser. Then to visualise Sentinel-2 imagery:

By identifying the last available image before the fire and the earliest image after it in which the full burn area is visible, it’s possible to establish the location and timeline of the fire.
This allows us to report the following finding: “Satellite imagery reveals the extent of the damage caused by wildfires across the Capo San Vito peninsula on Sicily’s northern coast between July 20 and July 27, 2025.”
Extra exercise: Look up a recent fire (e.g., wildfires near Penco, Chile in January 2026), navigate to the affected location and try to visualise the burned area using Copernicus Browser.
The visibly scorched area can be measured using the Area of Interest tool (highlighted below), which allows users to draw a polygon on the map and calculate the total area in square kilometres. (Once drawn, keep the polygon in the editor, as it will be used again later.)

Reportable finding: “The wildfire that swept across Sicily’s Capo San Vito peninsula in 2025 burned more than 50 km2 of the peninsula, according to Sentinel-2 data.”
Repeatedly measuring the burned area over time allows you to follow the progression of a fire. This method was used by Bellingcat when covering the Etosha National Park wildfire in late September 2025.
Extra exercise: Replicate the analysis of the Etosha National Park fire from this Bellingcat article.
Some fires only affect surface vegetation, while others scorch the ground and cause long-lasting damage. Burn severity can be measured using an index called the Normalised Burn Ratio (NBR).
The spectral response of a material describes how reflective it is to different types of light. The graph below shows the difference between healthy vegetation and bare soil in terms of the amount and types of light they reflect.

By focusing on the NIR and SWIR bands, where reflectivity differs significantly between healthy vegetation and bare soil left after a burn, an index can be calculated:
NBR = (NIR – SWIR) / (NIR + SWIR)
A high NBR indicates healthy vegetation, while a low NBR indicates burned areas.
Copernicus Browser doesn’t include a default NBR layer, but it can be added via a custom script, as shown in the screenshot below:
Alternatively, you can skip these steps and go straight to the custom NBR post-fire image here.

The NBR layer displays positive values in green (healthy vegetation) and negative values in purple (burned areas), making the boundary of the scorched area much clearer than before.
To calculate the change in NBR in Copernicus Browser, use the Statistical Information tool (a free account is required to access this feature).


In this example, the pre-fire image had an average NBR of 0.11 and the post-fire image had an average NBR of -0.18. The NBR decreased by 0.29, which represents a moderate burn.
| Severity Level | Change in NBR |
| Unburned | Less than 0.100 |
| Low | 0.100 – 0.269 |
| Moderate | 0.270 – 0.659 |
| High | 0.660 or greater |
Reportable finding: In late July, the fire, which scorched more than 50km2 of Sicily’s Capo San Vito peninsula, was deemed moderately severe according to the US Forest Service guidelines.
Extra exercise: Find a custom visualisation script of interest from this repository and explore what it does.
By focusing on protected sites such as nature reserves and national parks, we can begin to assess how wildfires affect areas of high conservation value. Controlled burns are widely used in agriculture and land management, but unchecked fires in protected areas risk eroding fragile ecosystems.
The proportion of the Zingaro Nature Reserve that was damaged by the fire can be estimated by combining the NBR image created in Copernicus Browser with a dataset from Protected Planet, a global map of protected areas that includes nature reserves.
QGIS, a program for working with geographic data, is well-suited for this type of analysis. Download and install QGIS on your computer. For help with this step, refer to the QGIS installation guide.
To download the NBR image from Copernicus Browser:

Once the image has downloaded, rename it to NBR.tiff to make it easier to work with.
Next, open QGIS and click ‘New Project’ in the upper left.
Load the image from Copernicus Browser by dragging and dropping the downloaded file into QGIS.
CRS – The Coordinate Reference System describes how the world should be measured and projected. Two of the most common are:
EPSG:4326 – WGS 84, which uses latitude and longitude as the unit of measurement.
EPSG:3857 – WGS 84 / Pseudo-Mercator, which uses metres as the unit of measurement.
Raster – a type of data that uses pixels to represent information (such as satellite imagery)
Vector – a type of data that uses points, lines, and polygons to represent information (such as a burn area polygon).
Next, we categorise each pixel in the NBR image as burned or unburned.
Previous analysis in Copernicus Browser showed that the Zingaro Nature Reserve’s NBR value dropped below zero only after the fire (before image: mean NBR value on July 20, 0.11; after image: mean NBR value on July 27, -0.18).
We can use this analysis to set a threshold; anything below zero will be categorised as burned.
The QGIS Raster Calculator lets us apply our threshold to the NBR image and create a new layer.
Open the Raster Calculator by selecting ‘Raster > Raster Calculator…’ from the menu bar at the top.

The Raster Calculator lists the raster bands available in the project. In this example, there are five. These bands are set by the custom script we used in Copernicus Browser and are numbered as follows:
To create a new raster layer that applies our threshold on the NBR index band:
The expression NBR@5 < 0 tells QGIS to categorise NBR index values as burned if they are less than zero.
The new layer shows burned areas as white (a value of 1), and unburned areas as black (a value of 0).

Extra exercise: Download an NBR image captured before the fire. Use the Raster Calculator to create a new layer that shows burn severity.
Download the Zingaro Nature Reserve dataset from Protected Planet by selecting ‘Download > File Geodatabase’.
As before, drag and drop the downloaded file into QGIS. This time, the download is a zip file and contains many PDF files as well as the geodatabase file of interest. Scroll down to the bottom of the list and select the ‘gdbtable’ file with a polygon icon on the left side (see the blue highlighted row below), then press ‘Add Layers’.

This adds the nature reserve polygon as a layer in QGIS (and gives it an arbitrary colour). The nature reserve is almost completely contained within the white burned area, indicating it was heavily affected by the wildfire.

To measure the proportion of the nature reserve that was burned by the wildfire, we will use the Zonal Histogram tool from the QGIS Processing Toolbox to count the number of unburned and burned pixels within the reserve polygon.
Open the toolbox with ‘Processing > Toolbox’, and a pane should open to the right. In the Processing Toolbox search field, look up ‘Zonal Histogram’ and double-click the result to open the tool.
To create a new layer:

This will create a new layer called ‘Output zones’, which is a copy of the nature reserve polygon with pixel counts added.
Select the output layer in the lower left and click ‘Attribute Table’ in the upper right. (The attribute table is a spreadsheet-like view of the data contained in a layer.)
For the output layer, there is just one row because there is only one polygon. If the layer contained many polygons, there would be many rows.
The newly calculated counts are added to the end of the table, so scroll all the way to the right. Look for fields starting with ‘HISTO_’. Here, HISTO_0 is the count of unburned pixels (value of 0), and HISTO_1 is the count of burned pixels (value of 1).

To calculate the proportion of burned area, the number of burned pixels is divided by the total number of pixels.
Proportion = 57413 / (57413 + 2195) = 0.96318…
A value of 0.96318 means that just over 96.3% of the nature reserve burned.
Reportable finding: In late July, more than 95% of the Zingaro Nature Reserve burned in a wildfire, according to Sentinel-2 satellite imagery and Protected Planet data.
To assess the significance of an ongoing wildfire, it is important to place it in historical context. How does it compare with previous fires in the same area? Is it part of a seasonal pattern, or does it represent an unusually severe event?
With coverage dating back to 2008, the European Forest Fire Information System (EFFIS) automatically maps wildfires across Europe, North Africa, and parts of the Middle East.
Fire data can be requested directly from EFFIS using web form, with results delivered by email. For ease, you can also download Bellingcat’s archived copy of EFFIS wildfire data for Italy covering 2015–2025.
For this section, it is best to open a new QGIS project.
To view and analyse historic wildfires in the Zingaro Nature Reserve using EFFIS data:

The Intersection tool creates a new layer containing only the fires that affected the Zingaro Nature Reserve. To create the new layer:

QGIS functionality can be extended through plugins, including Data Plotly, which adds data visualisation tools. To install Data Plotly, open the Plugin Manager by selecting ‘Plugins > Manage and Install Plugins…’ from the menu bar, then:

Once installed, open the Data Plotly panel with ‘View > Panels > DataPlotly’. The panel should appear on the right-hand side of the QGIS window.
To plot a graph of historic wildfire activity within the nature reserve, configure Data Plotly as follows:
Note: EFFIS data provide initial and final dates for each fire, which are approximate because they depend on the availability of satellite imagery. These dates should be treated as bounds for when a fire occurred, rather than as the dates when it started and ended.
Next, switch to the Layout tab in Data Plotly:

The chart shows that the Zingaro Nature Reserve has experienced several significant wildfires over time. However, in 2025, the data show that the fire burned a larger area within the reserve than the major fires recorded in 2020 and 2017.

Reportable finding: The Zingaro Nature Reserve has experienced three major wildfires since 2015. Of these, the 2025 fire burned a larger area within the reserve than those recorded in 2020 and 2017.
The tools and methods in this guide can be applied to wildfires in many other regions. By combining satellite imagery with environmental and historical datasets, it’s possible to move beyond detection and begin to quantify a fire’s impact. In doing so, you can also place individual incidents in context, revealing whether they are part of a recurring pattern or an unusually severe event.
To learn more about fire detection, see Bellingcat’s guide to NASA FIRMS.
To explore QGIS further, visit the Bellingcat toolkit entry on QGIS.
Merel Zoet and Claire Press contributed to this report.
This guide contains modified Copernicus Sentinel data (2025), processed with Copernicus Browser, as well as data from the European Forest Fire Information System (EFFIS) of the European Commission Joint Research Centre.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
The post Burning Forests: Tools for Tracking and Reporting Wildfire Damage appeared first on bellingcat.
30.06.2026 à 00:34
Conflict and Human Rights Team
At least 1,719 people are reported to have died after two devastating earthquakes struck northwestern Venezuela last week. The final casualty count is expected to rise significantly. Some media outlets report resident’s growing frustration with the Venezuelan government and its recovery efforts. Sky News on June 29 reported that the United Nations Coordinator for Humanitarian […]
The post Satellite Imagery Shows Scale of Venezuela Earthquake Damage appeared first on bellingcat.
At least 1,719 people are reported to have died after two devastating earthquakes struck northwestern Venezuela last week.
The final casualty count is expected to rise significantly.
Some media outlets report resident’s growing frustration with the Venezuelan government and its recovery efforts.
Sky News on June 29 reported that the United Nations Coordinator for Humanitarian Affairs in Venezuela was preparing for as many as 10,000 deaths.
Social media posts, news reports and drone footage have been shared in recent days, proving vital sources for many Venezuelans (both in the country and living abroad) who are searching for information about loved ones who remain missing.
Social media pages have been set up listing many of those who are yet to be accounted for. Others have contacted Bellingcat asking if apartment blocks relatives were staying in are still standing.
Bellingcat has received satellite imagery from Planet Labs PBC that shows one the worst affected areas in the country, including collapsed buildings and apartment blocks in La Guaira.
Readers can move laterally and vertically to observe the full image in the interactive below as well as zoom in on specific areas to assess the damage. A share button on the top right will copy a shareable link to the zoomed in area.
Scroll and zoom to see damage throughout the affected Venezuelan coast. Toggle between English and Spanish. Share a link to a specific location by clicking the button on the top right. The before imagery is from Jul 30, 2025 and Dec 12, 2023. After imagery is from Jun 27, 2026. SkySat imagery via Planet Labs PBC.

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
The high resolution image covers a 14-mile stretch of Venezuela’s northern coast from the towns of Catia La Mar to Caraballeda, which have been among the worst impacted.
Other areas to be significantly impacted but not included in the imagery above include Caracas, Maracay, Valencia, Barquisimeto and Yaracuy.
We have compared the satellite imagery we obtained with previous images captured before the earthquake to identify which parts of this 14-mile stretch of coastline to show changes since the quakes.
Readers can toggle between the imagery captured on June 27 (five days after the Jun. 24 quakes) and a composite of reference images taken on Jul. 30, 2025 and Dec. 11, 2023 (before the quakes).
Zooming in on specific areas reveals the scale of the damage.
For example, several buildings seem to have been flattened in the below before and after images showing the Playa Grande area.
Before imagery (left) of Playa Grande is from Feb 27, 2026. Imagery from after the earthquake (right) is from Jun 26, 2026. SkySat imagery via Planet Labs PBC.
The Planet Labs imagery also confirms significant destruction in the town of Carabelleda.
Before imagery (left) of Carabelleda is from Jun. 19, 2026. Imagery from after the earthquake (right) is from Jun 27, 2026. SkySat imagery via Planet Labs PBC.
Another area, Macuto, has been significantly impacted as well.
Before imagery (left) of Macuto is from Mar 20, 2026. Imagery from after the earthquake (right) is from Jun 27, 2026. SkySat imagery via Planet Labs PBC.
Footage taken on the ground and posted to social media also displays the devastation.
A minute-long video filmed on a 500-meter section of José María España Avenue in Carabelleda shows as many as a dozen collapsed buildings, most of them high-rises. This drone footage gives an aerial look of the destruction of at least six apartment blocks in the same area.
Another video shared on social media showed a collapsed hotel in Macuto, between Carabelleda and La Guaira.
Other open source information about the damage in cities such as Caracas, Valencia and beyond can be found on this site where individuals are uploading images and videos detailing damage.
While international rescuers continue to arrive in Venezuela, the threat of aftershocks remains.
Reuters also reports that engineers fear many buildings that remain standing could be vulnerable and are requesting an audit of state housing.
Carlos Gonzales, Jake Godin and Miguel Ramalho contributed to this report.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
The post Satellite Imagery Shows Scale of Venezuela Earthquake Damage appeared first on bellingcat.
27.06.2026 à 20:02
Financial Investigations Team
This article is the result of a collaboration with The Sunday Times. You can find their corresponding piece here. Every Friday evening, the brochure says, players can compete to win cash prizes in one of the world’s fastest-growing racquet sports. The padel club in Dubai’s west is the picture of modern wellness culture: climate-controlled courts, […]
The post Poster Boy: Sanctioned Kinahan Cartel Lieutenant Found Playing Padel in Dubai appeared first on bellingcat.
This article is the result of a collaboration with The Sunday Times. You can find their corresponding piece here.
Every Friday evening, the brochure says, players can compete to win cash prizes in one of the world’s fastest-growing racquet sports. The padel club in Dubai’s west is the picture of modern wellness culture: climate-controlled courts, a private sauna and ice bath, and one-on-one coaching. The promotional image shows a bearded man in mid-swing, eyes locked on the ball. He wears matching activewear and a golden tan. The poster boy for padel is a talented player who once finished runner-up at an international tournament. He has also spent the past decade living in the shadows.


Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
Ian Thomas Dixon is a key figure in the Kinahan cartel, the Irish organised crime group that authorities say has evolved into a US$1.5 billion transnational network involved in drug trafficking, money laundering and arms smuggling. Investigators have connected the cartel to Iran’s intelligence services and the Lebanon-based militant group Hezbollah. Its feuds with rival gangs have been linked to at least 18 murders across four countries.
Dixon, 36, along with the Kinahan Organised Crime Group’s senior leadership – Christy Kinahan, 69, and his sons Daniel, 49, and Christopher Jr, 45 – was sanctioned by the US government in 2022. Authorities allege the Irishman acted as a trusted lieutenant to Daniel Kinahan, who is said to manage the cartel’s vast drug trafficking operation by helping move bulk cash across Europe, arranging payments and keeping tabs on money owed by a narco-trafficker.

Bellingcat and The Sunday Times can today reveal how Dixon’s racquet sport hobby has left behind a digital trail that led to the most recent footage of him since those sanctions were imposed – the first time he has been pictured publicly in almost a decade. This investigation also uncovers the alias Dixon has used in Dubai and exposes the first open source links to an underworld associate who was recently extradited from the Gulf state and jailed in Scotland.
It comes as cartel leader Daniel Kinahan awaits extradition to Ireland after his arrest in Dubai on foot of a warrant issued by Irish authorities. The arrest, in April, followed an extensive policing and diplomatic effort from international law enforcement.

In March, investigations by Bellingcat and The Sunday Times exposed the first photographs of Daniel Kinahan and his father in years and also revealed that the cartel’s “friend”, former UFC fighter Mounir Lazzez, was connected to US sanctions against Iran.
The latest findings give an unprecedented glimpse into the recent activity of a key cartel associate who, until now, has largely flown under the radar.
When cartel founder Christy Kinahan moved to Spain after his release from an Irish prison in 2001, it wasn’t long before his new home became a hub for the gang. His sons, Daniel and Christopher Jr, soon followed him to the Costa del Sol – as did their younger cousin, Dublin native Ian Dixon.
From the late 2000s onward, Dixon worked for businesses linked to the crime family in the south of Spain. One of these was The Auld Dubliner, a pub in Estepona that reportedly served as a base of operations for the cartel. In 2010, the pub was raided and temporarily closed by authorities as part of Operation Shovel, a years-long multi-national police investigation into the cartel’s drugs and arms-trafficking activities.

Dixon would also work as a trainer at MGM Marbella, the boxing gym co-founded by Daniel Kinahan that would go on to represent some of the biggest pro boxers in the world. The company, which was renamed MTK Global, shut down after the US sanctions on the Kinahans were imposed in April 2022.

In 2016, Dixon was arrested by Spanish police investigating the murder of Irish criminal Gary Hutch. The previous year, Hutch had been gunned down while out for a morning jog in a gated community on the Costa del Sol.
Dixon was released without charge, and another Kinahan cartel associate was later sentenced to 22 years for his role in the murder. The killing sparked a feud between the Kinahans and the rival Irish Hutch gang that resulted in at least 18 deaths.
Dixon and other key Kinahan members fled to Dubai in the wake of the deadly feud.
Ian Dixon has no known convictions. But his alleged role in the Kinahan Organised Crime Group was laid bare when the US sanctioned him. Authorities said Dixon managed finances and moved bulk currency for Daniel Kinahan and also kept tabs on the debt owed by a narco-trafficker.
The sanctions notice also said Dixon controlled Hoopoe Sports LLC, a Dubai firm that listed a number of pro boxers among its clients and reportedly received more than $4 million for bouts involving former heavyweight champion Tyson Fury. Boxing promoter Bob Arum told Yahoo Sports the money was for consulting fees owed to Daniel Kinahan.

Dixon lived in an exclusive gated community in Dubai, according to the 2022 sanctions notice. Online listings show that properties like his Spanish-inspired villa are worth up to $2.7 million.
Padel is an increasingly popular racquet sport from Mexico best described as a combination of tennis and squash. According to the sport’s governing body, it has more than 17.5 million weekly players across 150 countries and the UAE, where Dixon lives, has the second-highest number of padel courts in Asia. It was on these courts in late 2024 that Dixon played in the master final of the Asia Pacific Padel Tour (APPT).
APPT rankings show Dixon registered for the tournament under the name “Ian Thomas”. Like his cartel leader relative Christy Kinahan, who used his first and middle names as an alias on his Google review profile, Dixon had dropped his surname.
Bellingcat found the padel club promotion showing Ian Dixon after running images of the cartel associate through a publicly available facial recognition search engine. Among the results was a link to a graphic designer’s online portfolio, which included the advertisement for the padel competition. The original photo had been posted on the sports club’s Instagram page in late 2023, with the caption: “Elevating fun, one swing at a time!” Dixon was not named.

We searched for additional open source evidence and located online profiles for a 36-year-old Irish padel player named “Ian Thomas” who had taken part in a number of matches in Dubai in recent years. One profile shows he played 16 ranked matches between September 2024 and April 2026 – the most recent being the week after Daniel Kinahan’s arrest. But the accounts did not include profile pictures.

Bellingcat searched for footage showing the padel events and venues listed on the profiles. It returned multiple social media posts and live-streams clearly showing Ian Dixon at the same events where “Ian Thomas” was registered as playing. Dixon can also be heard speaking with a Dublin accent and at one point is seen with a close relative of Daniel Kinahan.
Dixon and his doubles partner played four games over the December 13-15 weekend, eventually placing second after losing in the final. The Irish cartel associate is captured on film after the match receiving a silver medal and commemorative racquet.
The Asia Pacific Padel Tour was held a month after senior Kinahan cartel figure Sean McGovern was arrested in Dubai on foot of an Interpol red notice. McGovern was extradited to Ireland last year and earlier this month jailed for 24 years for directing the activities of a criminal organisation in relation to murder and attempted murder.
The tournament was live-streamed to YouTube via webcams set up on two courts. Dixon was captured throughout the three-day event, both playing on the court and mingling with others in the background. The hour-long male amateur final, which Dixon lost, is viewable in its entirety.
Dixon also posed for photos during the tournament, but it appears he did have some reticence about appearing on social media. In two images from a different padel event hosted at the same venue a few months later, Dixon’s face had been covered. However, a third photo was not edited, confirming that it was Ian Dixon.

Among the people Dixon was seen with at padel events in Dubai was Stephen Jamieson, a Scottish criminal who was recently jailed for his role in a multimillion-dollar drug trafficking operation.
Dixon greeted Jamieson with a fist pump during the Dubai APPT tournament in December 2024 on the day the Irishman played in the amateur final.

Dixon was also pictured with Jamieson at a family day padel event just weeks before the Scottish criminal’s arrest. (Bellingcat is not publishing details of that event to protect the identity of family members.)
Jamieson, who has multiple convictions, was extradited from Dubai last year and is serving a six-year prison sentence in Scotland on organised crime and drug charges. The case against him was built around intercepted messages he had sent via the defunct encrypted communication network EncroChat – a network the Kinahans have also used – to direct drug shipments.
The Sunday Times reports today on the Kinahan cartel’s deeply entrenched links to organised crime in the UK, where it is known to control much of the illicit drug market. It said the footage showing that Dixon and Jamieson know each other could indicate an underworld connection, since cartel cadres do not associate with rival operations.

Three of the seven alleged key Kinahan cartel figures have been arrested since the US sanctions were imposed. Johnny Morrissey, arrested in Spain in 2022, was later bailed and subject to a travel ban. Sean McGovern was jailed earlier this month and Daniel Kinahan awaits extradition to Ireland after his recent arrest in Dubai. Garda Commissioner Justin Kelly, of Ireland’s police force, recently said the investigation into the Kinahan cartel was ongoing and that authorities were continuing to focus on the other members of the gang.
Ian Dixon did not respond to questions from Bellingcat.
Connor Plunkett, Peter Barth, Beau Donelly and John Mooney contributed to this article.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
The post Poster Boy: Sanctioned Kinahan Cartel Lieutenant Found Playing Padel in Dubai appeared first on bellingcat.
25.06.2026 à 15:59
Miguel Ramalho
Between February 2022 and September 2025, Bellingcat staff and volunteers collected, geolocated, and shared more than 2,500 incidents of civilian harm following Russia’s full-scale invasion of Ukraine. As part of this effort, Bellingcat tested a new machine learning model intended to rank Telegram social media posts on their likelihood of containing incidents of civilian harm. […]
The post How to Use AI to Help Find Civilian Harm appeared first on bellingcat.
Between February 2022 and September 2025, Bellingcat staff and volunteers collected, geolocated, and shared more than 2,500 incidents of civilian harm following Russia’s full-scale invasion of Ukraine.
As part of this effort, Bellingcat tested a new machine learning model intended to rank Telegram social media posts on their likelihood of containing incidents of civilian harm.
This novel methodology dramatically reduced the search and selection time required, freeing researchers to focus on verifying incidents of civilian harm – not just searching for them.
This piece documents our methodology, ethical considerations and lessons learned in the hope that others researching similar topics can benefit from our work.
Open source research into civilian harm is still a relatively new field and it presents many challenges – one of the biggest is organising and sorting through the huge volume of user generated content being produced to find what is relevant.
Machine learning, a form of artificial intelligence that uses algorithms to identify patterns from large amounts of data and make predictions, can make this task more efficient.
With ongoing conflicts involving large amounts of civilian harm occurring in Sudan, and much of the Middle East, this guide aims to offer those covering these conflicts an example of how machine learning can be used to help find and sort incidents. You can also access the Code Notebook for our model here.
We defined “civilian harm” not just as civilian deaths or injuries resulting from armed conflict, but also the broader and delayed effects on civilians from mental trauma, loss of livelihood, displacement, destruction of infrastructure and more. This definition was informed by the Protection of Civilians book on civilian harm.
Each Telegram post containing civilian harm which had already been manually verified by researchers was used to build an initial dataset of confirmed cases of civilian harm, which data scientists call positive instances. We collected a total of 5,848 unique URLs for these Telegram posts. For our manual collection we reviewed posts on relevant Telegram channels, working through oldest to newest posts each day. Assuming that a given post made it to our geolocated incidents list, it meant the researcher who flagged it also looked at the posts that appeared before and after it on Telegram and did not flag those ones, so we selected the 10 posts surrounding the verified civilian harm post as our additional dataset of posts that did not contain civilian harm. After excluding any deleted or duplicate posts, we ended up with 48,545 non-civilian harm posts, our negative instances.

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
The choice to overrepresent negative instances aims at better reflecting the real world and increasing data available for model training.
We enriched each URL with metadata from the Telegram API, such as the time of publication, reactions or textual content. As some of these posts had been deleted, we completed the missing data points with previously preserved versions from our Auto Archiver database, only available for the positive instances.
Training a machine learning model requires numerical data, as these models compute a prediction score based on mathematical operations.
We built these by converting raw data from our initial dataset, such as keywords signalling potential civilian harm, into numerical scores (or “features”) that the model could interpret, with the aim of increasing the model’s ability to identify patterns. This process, known as feature engineering, can significantly improve model results because it allows data scientists to suggest explicit context knowledge.
A full list of features we used to train the model can be found in the code notebook accompanying this piece. Many features were directly inspired by researchers’ input from their experiences manually screening cases of civilian harm by sorting through a set number of Telegram channels and inspecting each post individually.

Several of the features used were directly built from the metadata contained in each Telegram post including media_type, day_of_week; or binary ones: forwarded, edited and reply_to.
Other features included engagement information: views, forwards, total_reactions, and even individual features for most used emojis including the reaction_crying_face to count
emoji.
To embed the experience from the manual collection process, researchers put together a list of keywords both in Ukrainian and Russian that, to them, signalled posts likely to show civilian harm. For instance, “Шахед” and “КАБ” translated to “Shahed” and “Guided aerial bomb” respectively. We created a numerical feature to count their frequency.
In addition, we included several generic English-language keywords which meaningfully signalled potential civilian harm, such as “injured”, “school affected” and “hospital affected” that were only used for generating semantic similarity scores.
A semantic similarity score is a calculation used to determine the proximity in meaning between different words and phrases. To get the semantic similarity between the post text and each of our keywords, we represented each in a list of numbers via a Sentence Transformer model, which converts words into numerical representations called vectors that a computer can understand.
We then calculated the level of similarity between each vector using cosine similarity, one of the most popular methods for measuring similarity between two pieces of text.

Due to how embeddings work, this calculation results in a figure on a scale from -1 (no semantic proximity) to 1 (same meaning). For example, the words “hurt” and “injured” would have a high similarity score, while “residential” and “injured” would have a negative score as the words are not semantically similar.
Finally, to enable the model to identify the relevance of each post to civilian harm in Ukraine, we used a multilingual text transformer from the BERT family of language models to represent the entire post’s text as a vector of 768 numerical values. This model can efficiently represent text from many languages in a way that captures meaning: the same sentence in different languages will generate similar embeddings, and trained machine learning models can detect patterns in the embeddings.
It is important to note that for this initial prototype of a civilian harm detection model, we did not include any features derived from media content such as photos and videos, although that would be a logical next step in attempting to improve model performance.
With 54,393 rows of 893 numerical features each, we selected four machine learning algorithms to train our predictive models.
We chose Logistic Regression as a baseline algorithm due to its simplicity. We also selected three other “best in class” models, Random Forest, XGBoost, and LightGBM. These choices centred on the interpretability of the models and their ability to work on tabular data of this size. For example, we avoided neural networks due to a lack of interpretability and because those models work best with a larger dataset.
To genuinely assess the performance of the trained models, we split our dataset into three parts:
We used a stratified split to divide the dataset instead of a random split. This method ensured the proportion of positive instances (i.e. confirmed cases of civilian harm) remained consistent across all three sets at about 11 percent.

To measure the performance of machine learning models, we ran them through the test set and measured the number of correct and incorrect predictions. Models output a likelihood between 0 and 1 that each Telegram post contains civilian harm, and we tried to find a cut-off threshold that leads to a good balance between flagging almost every post (0.1) or flagging very few (0.9).
There are two main types of evaluation metrics to gauge a model’s prediction power. Recall asserts what fraction of positive instances (i.e. known civilian harm posts) were correctly flagged as such. Precision measures the fraction of posts flagged as civilian harm that are indeed civilian harm posts.

During the training phase, we tuned the models to maximise average precision (PR-AUC), a metric that summarises precision across all recall levels. While this method also accounts for precision, it prioritises recall, which is preferable for this use case as it steers model selection to reduce the number of civilian harm posts that are skipped.
The following table sorts models from best to worst PR-AUC against a baseline of a coin-flip predictor. ROC-AUC and F1 are two other evaluation metrics included as sanity checks. Simply put, ROC-AUC measures the probability of ranking two instances, one negative and one positive, correctly; F1 balances precision and recall equally and its best cut-off threshold value.

From these results, we selected XGBoost as our final model as it had the best scores when compared across all metrics.

Because these models are interpretable, we can understand which features are the most useful when predicting whether a post includes civilian harm. The above table shows the top 10 features that most strongly signal the XGBoost model to make a decision:
These results generally tally with what you might expect when selecting Telegram posts for instances of civilian harm, including that posts that generate a lot of emotional engagement and posts using keywords about civilian harm were among those most likely to contain content related to this topic. Not all models had the same top features as XGBoost. In fact, for the Random Forest model the most important feature was the number of crying face emojis present in a post, a soft pattern highlighted by researchers when this methodology was first imagined.

Retroactively, we decided to run a sample of the same test dataset through different large language models (LLMs) to gauge their ability to make these same predictions.
We aimed to include an LLM-generated score as an extra feature for our trained models, which would be captured as relevant if it correlated with the correct predictions.
To start, we selected two local models, the 1B and 4B variants of Gemma 3 from Google DeepMind, and two cloud-hosted models, Gemini 2.5 flash and Gemini 3.5 flash. With this selection, we hoped to compare results across a wide range of models’ expected performance.
We generated a 400-row stratified sample (preserving the same proportion of real civilian harm instances) from the test dataset used for the custom models. For each of the four LLM models, we ran two tests: one where only the Telegram post message was sent, and another including both the message and the engineered features (excluding the text embeddings, as the model had direct access to the text). In the prompt for each model, we asked for a score between 0 and 1. We then evaluated the results as we did for the custom models.

The above table shows that LLMs can indeed extract value from the engineered features. All four LLMs surpassed the baseline Logistic Regression model in our tests, yet none of them performed better than the other custom-trained models, and XGBoost remained the one with the highest PR-AUC.
Still, Gemini 2.5 Flash performed better than its newer version 3.5 and even achieved a slightly higher best F1 score than any other model. While this is a good result, for the flagging of civilian harm posts, the PR-AUC remains the crucial metric, as it captures the model’s ability to identify infrequent instances of civilian harm while minimising false positives.
Introducing an instrument of automated decision-making into a process of detecting civilian harm brings inherent ethical questions. These include automation bias, or how humans tend to blindly place faith in machine-generated recommendations; algorithmic bias, or how the results of these models echo the same patterns present in the training data, including under- or over-representation of types of civilian harm.
The decision to test an automated methodology for this particular project came from the fact that there were limited resources for both steps in the process – the detection of potential civilian harm and its actual verification. Historically, we built an enormous backlog of unverified incidents because a lot of time had to be spent on monitoring the most recent events so that potential evidence would be captured and preserved as soon as possible.
The automation of this process also reduced the exposure of researchers to a significant amount of unpleasant and distressing visual and text content, reducing the burden of exposure to traumatic content.
For this project, we tried to ameliorate the ethical challenges with a number of strategies including randomly flagging posts not captured by any model, monitoring which features models relied on to make decisions, and by doing historical comparisons of patterns in data.
Additionally, as stated above, for this initial prototype of a civilian harm detection model we did not include any features derived from the media content itself. In the future, it would be a logical next step in attempting to improve the model performance, to include the media from the posts – but using AI to review actual media comes with additional ethical challenges such as model bias.
Because of the opaque ownership of many LLM companies and their generative nature, the use of LLMs for an extra feature presented additional ethical challenges including privacy and safety concerns considering the sensitive nature of the data. Our model did not rely on LLMs, though we retroactively ran a sample through it.
After selecting this model, we created a user interface where researchers could view a list of Telegram posts sorted from most to least likely to contain indications of civilian harm. The user interface was designed for quick triage and integration, where a positive confirmation from researchers would instantly send the post to the Auto Archiver (Bellingcat’s tool for preserving digital content) and then transfer it to ATLOS (our internal collaborative verification platform). Bellingcat staff and volunteers could then manually verify incidents. Researcher input was constantly stored so that this data could be used to improve the model in the future.
Preliminary feedback indicated that the AI model was useful. Not only were we able to reduce time and harm from scouring through dozens of war reporting Telegram channels, researchers also reported that the stream of new posts being added to the verification backlog were capturing real and diverse cases of civilian harm.
We recognise this model has much room for improvement and is a work in progress. Even though it can illicit diverse civilian harm posts, further tests and improvements (such as improved feature engineering and continuous evaluation) are needed before it can confidently be deployed.
Despite the focus on civilian harm and Telegram (highly popular in Ukraine and Russia), this pipeline is generic and can be adapted to other conflict monitoring tasks. How easily this can be done does depend on how open the social media platform is and whether it is possible to scrape posts from it. Apart from that, it is easy to incorporate new features and data, and cheap to automatically retrain, test and deploy models as the system receives more human input.
Looking forward, sorting through overwhelming amounts of data in a conflict will continue to be challenging. Hopefully, this methodology can help newsrooms, conflict monitoring organisations, and others find the balance between ethical considerations and resources in order to carry out open source investigations on civilian harm and human rights violations.
Editor’s note: This article was updated on July 3, 2026, to include a line outlining that the model described is a work in progress.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
The post How to Use AI to Help Find Civilian Harm appeared first on bellingcat.
24.06.2026 à 14:05
Ziyu Wan
Warning: Includes graphic descriptions of animal harm and images of animal parts from the outset. A Bellingcat investigation has uncovered a Myanmar-based wildlife trafficker who has operated openly across social media for at least six years, claiming to have sold tiger bones, rhino horn, elephant skin and other products from protected and endangered species to […]
The post Rhino Horn, Leopard Skin and Tiger Claws Sold Openly on Facebook appeared first on bellingcat.
Warning: Includes graphic descriptions of animal harm and images of animal parts from the outset.
A Bellingcat investigation has uncovered a Myanmar-based wildlife trafficker who has operated openly across social media for at least six years, claiming to have sold tiger bones, rhino horn, elephant skin and other products from protected and endangered species to customers in Myanmar, China and Thailand.
By analysing hundreds of adverts and customer conversations, Bellingcat traced more than US$21,000 in sales, identified cross-border shipments linked to multiple payment accounts, and geolocated the dealer’s home address. The seller frequently used graphic images to convince buyers that his wildlife products were genuine, sharing footage of animals before and after they were killed as proof of authenticity.
Following this investigation, Meta removed 10 Facebook accounts, WeChat suspended three accounts and revoked their payment functions, TikTok and YouTube each removed one account, and authorities in Myanmar and Thailand said they would examine the findings further.
On December 21 2022, a Facebook account shared a reel of a tiger cub lying unconscious beneath the caption: “Time for winemaking”, followed by several laughing face emojis. Four days later, the same account shared another reel, this time of an adult tiger lying motionless on an orange plastic sheet as a man approaches with a knife.
Two separate videos posted to Facebook by the account known as MB.
The account behind both videos belongs to Mei Ba (hereafter MB), a self-described Traditional Chinese Medicine (TCM) doctor based in Myanmar. In TCM, plants and animal products are used to prepare remedies based on established medicinal formulas. These remedies can take many forms, including herbal teas, simmered concoctions, ingredients steeped in wine, and pills. TCM is also sometimes associated with pseudoscientific beliefs, such as the idea that consuming an animal’s organ can nourish the corresponding organ in the human body.
A Bellingcat investigation has found that MB frequently advertises the trafficked parts of critically endangered and vulnerable species to customers in Myanmar, Thailand and China. An analysis of social media posts published by MB over six years found references to sales involving parts of bears, elephants, leopards, musk deer, otters, pangolins, rhinos, seahorses and tigers, all of which are protected species.


Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
For at least six years, MB has used ten different Facebook accounts under versions of his name to advertise animal parts and products for sale, including those derived from vulnerable and protected species.
MB has advertised tiger body parts and products, including skins and wine made from bones. Myanmar’s wild tiger population was last estimated at a minimum of 22 animals (in a 2019 study published before the civil war). Licensed tiger farms, described as being similar to zoos, also operate in the country. However, Myanmar law prohibits the killing of any tiger, wild or captive.
Bellingcat has also identified adverts offering leopard body parts, including skin, bones and gallbladders, as well as a product described as a “whip”, a euphemism for a penis. Many of the adverts explicitly stated that the body parts came from wild animals. The Indochinese leopard is classified as critically endangered, with fewer than 800 mature individuals believed to remain in the wild across mainland South-East Asia.

MB has advertised body parts and other products derived from Asian elephants, an endangered species, including skin sold in pieces and powdered form, as well as their genitals.
One of MB’s more graphic posts showed a recently killed and butchered moon bear – a type of Asian black bear which is classified as a vulnerable species. MB has also advertised various bear body parts for sale, including paws, heads, gallbladders, bile and fat.
Whole rhino horns, as well as bracelets and medicinal products made from rhino horn, have been advertised by MB. Although rhinos have been extinct in Myanmar since the 1980s, the country remains a known transit route for rhino products moving from India to China and elsewhere in South-East Asia, suggesting the items advertised by MB originated outside Myanmar.
Rhino products as advertised by MB on Facebook. Labels added by Bellingcat.
Under Myanmar law, anyone convicted of killing, possessing or trading a “completely protected species,” or its parts, faces a minimum prison sentence of three years and a fine under a conservation law introduced in 2018. Completely protected species advertised by MB include Asiatic black bears, elephants, leopards and rhinos.
Bellingcat contacted multiple Myanmar government authorities for comment regarding MB’s wildlife trade. The Myanmar embassy in London confirmed receipt of Bellingcat’s request and said it would consult the relevant authorities in Myanmar.
Counterfeits are common in the illegal wildlife trade. Buffalo horn is often carved to resemble rhino horn, while cattle penises are passed off as tiger parts. Much of MB’s promotional strategy therefore focuses on persuading buyers that his products are genuine.
To market rhino horn, MB has posted images of the items on scales or held up against a light, which he claims demonstrates the texture of genuine horn. For tiger bones, in one post he said that a patch of skin would be left attached to demonstrate their authenticity.
MB has also posted videos of recent leopard and tiger kills. He has shared footage of live tigers in cages followed by images of the same animals being butchered for their skins, bones, skulls, claws and fangs.

Bellingcat only analysed open source evidence, including social posts, customer conversations, visible transactions and shipping receipts. Therefore, the authenticity and composition of the wildlife products advertised or sold could not be independently verified.
Nevertheless, given the volume and graphic nature of these posts, MB’s ability to operate on Facebook for at least six years raises questions about why his accounts remained active up until Bellingcat contacted Meta.
For years, MB has openly advertised his business on Facebook, posting hundreds of adverts across ten profiles and various groups. He often uses coded language, including Chinese-language euphemisms in his comments.
For example, he uses “eraser” (橡皮) to refer to “elephant skin” (象皮), a Mandarin homophone with characters that are also visually similar, shown below.

MB also uses pinyin, the phonetic system for spelling Mandarin Chinese words using Latin letters. For example, in one post, he abbreviates the pinyin word for “rhino” (xīniú) as “X”, advertising “X horn powder”, and uses “Y” (pinyin: yào) as shorthand for “medicine”. He also frequently uses animal emojis, including tiger, elephant, rhino, deer and bear, to refer to products derived from those animals without naming them directly.

Asked why MB had been able to operate for so long without being banned and how it detects common evasion tactics such as coded language, Meta responded: “Bad actors constantly evolve their tactics to avoid enforcement, which is why we partner with groups and invest in tools and technology to detect and remove violating content.”
To map the scale of MB’s business, Bellingcat analysed more than 500 screenshots of customer conversations spanning May 2021 to May 2026. Originally taking place on Facebook, Viber and WeChat, these exchanges were later reposted by MB on Facebook.
Often blurred or cropped, the material appears to have been shared as part of a strategy to present MB as a trusted seller who reliably delivers to customers. However, given the content frequently included shipping labels with names and addresses, product descriptions, and price discussions, Bellingcat was able to trace part of MB’s customer base and income. Notably, only content MB chose to repost was available for analysis, meaning the findings represent only a sample of his overall activity.
Across the dataset, Bellingcat identified more than 150 transactions totalling US$21,000. The United Nations estimated Myanmar’s annual per capita income at between $300 and $430 in 2023.
Bellingcat analysis of MB’s digital footprint showing revenue earned per species by MB. Currency in US$. Trade values are estimated based on yearly average black market exchange rates.
Based on delivery records, Bellingcat identified 119 deliveries within Myanmar, 27 to mainland China, and nine to Thailand. Within Myanmar, shipments were most often sent to shared pickup points in cities or towns, whereas those to China were more frequently sent directly to individual addresses.
Shipments within Myanmar most often involved small quantities of powders or medicines, such as 3 to 7 g of rhino horn powder or 5 g of bear gall bladder. By contrast, deliveries to China more often included whole animal parts such as rhino horn or tiger bones, or larger quantities of products, including 500 g to 1 kg of elephant skin powder or 10 to 40 bottles of medicine.

MB’s highest-value recorded transaction was to a customer in Yiyang, Hunan Province, China and involved two tiger femur bones weighing just over 2.5 kg. Sold in July 2022, the bones fetched 23,500 Chinese Yuan (US$3,494). The customer was asked to provide a screenshot as proof of payment. MB later reposted this on Facebook, alongside a photograph of the bones wrapped in cling film and a shipping label for Deppon Logistics attached.
Bellingcat contacted Deppon Logistics for comment, sharing the image and tracking number shown below, but received no response at the time of publication.

Under Chinese law, buying, transporting, or selling protected or endangered species can, in the most serious cases, carry prison sentences of more than 10 years. Asian elephants and wild tigers are listed as “Class 1” protected animals. A permit system does exist for the use of captive-bred tigers, although it remains controversial.
Under the Convention on International Trade in Endangered Species of Wild Fauna and Flora (CITES) Appendix I, international trade in any endangered species, including Asian elephants and tigers, as well as their derivatives such as skin powder, scales and bones, is prohibited. China, Myanmar and Thailand are all parties to the treaty.
Bellingcat contacted the General Administration of Customs of China for comment on MB’s wildlife sales to China but did not receive a response at the time of publication.
Bellingcat also found evidence of nine deliveries to Thailand, including a tiger penis and several TCM powders said to contain dog, yak and seahorse, all species regulated by Thai law and protected under CITES.
The Thai Natural Resources and Environmental Crime Division told Bellingcat that it already monitors packages falsely declared as traditional medicine but found to contain protected wildlife parts or ingredients derived from them. Following Bellingcat’s findings on MB’s activities, the division said it would investigate further.
A large proportion of MB’s exports to all three countries were bottles of TCM powders or tablets. For example, a “kidney replenishing medicine” was purported to contain deer, dog, gecko, praying mantis, seahorse and yak, while a “prostate medicine” was said to include deer, seahorse and dog.
Under Chinese law, all packaged TCMs must carry labels clearly displaying the manufacturer’s name, full ingredient list, production and expiry dates, and information on side effects and safety. None of these details were present on MB’s labels.

Over six years of reposted conversations with customers, Bellingcat observed MB requesting payments to at least 15 different accounts, including seven via WeChat Pay, two via Alipay and six via third-party bank accounts, which MB described as belonging to friends or family.
For example, in May 2022, a customer purchased 1kg of elephant skin powder to be shipped to Chiuchow, Guangdong Province, China. MB told the customer his WeChat account could not currently receive the payment and instructed them to send the funds to his “sis” [female associate], shown below.

Both WeChat Pay and Alipay’s terms and conditions prohibit the use of their services to receive payments for illegal activities.
After being contacted by Bellingcat, WeChat suspended three accounts, revoking all payment functions and removing associated content.
Alipay did not respond to Bellingcat’s request for comment.
MB’s brazen online activities include operating at least ten Facebook profiles, two TikTok accounts, one WeChat account and one YouTube channel. He is the sole administrator of a Facebook group with nearly 1,000 members. Across these platforms, he has amassed some 12,000 followers.
While using variations of “Mei Ba” (MB) across most of these accounts, he also uses the Chinese name “Mei Xiangfu” on his personal WeChat account. The name “May Kyin Phu” also appears alongside payment QR codes when customers are asked to transfer funds. Below is a QR code for Myanmar’s largest bank, KBZ, which includes what appears to be MB’s legal name: U May Kyin Phu, with “U” used as an honorific equivalent to Mr.

Since 2019, MB has used the same ID photo as his profile picture across multiple platforms, as well as his wedding photo as his TikTok profile picture and Facebook banner image. His wife, identified in the wedding photo and in other images posted by MB, has also been found advertising vulnerable and protected species via her Facebook account.
With more than 3,100 followers, she frequently reposts MB’s adverts while also sharing screenshots of conversations with customers. For example, in one WeChat exchange later reposted to Facebook, she discusses the cash sale of five “real” tiger penises.
From MB’s posts, Bellingcat geolocated a house in Lashio, eastern Myanmar, used to photograph animal parts for sale in his advertisements. MB has posted content from this property since 2020.
In the images below, what MB describes as “leopard gallbladders” can be seen hanging from a balcony, revealing the layout of the property’s backyard and the rooftops of adjacent buildings. Although Lashio is not covered by Street View, the distinctive roof visible in MB’s images matched with user-uploaded photographs on Google Maps.

Bellingcat contacted both MB and his wife for comment on the findings of this report. Both were reached via WeChat and appear to have received the request, but did not reply at the time of publication.
Data visuals by Galen Reich, Graphics by Merel Zoet, Editor, Claire Press.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
The post Rhino Horn, Leopard Skin and Tiger Claws Sold Openly on Facebook appeared first on bellingcat.
18.06.2026 à 10:59
Jonathan Moens
This article was co-published with Signal Ohio and STAT. In high school, Ashley Delgado dreamed of becoming a doctor and one day buying her father a Rolls-Royce. “She wanted to heal people,” said her father, James Taylor. She had a high GPA, Taylor added, and did especially well in science and Latin. In her mid-20s, […]
The post Super-Potent Synthetic Opioids Spread Across US Amid Fentanyl Crackdown appeared first on bellingcat.
This article was co-published with Signal Ohio and STAT.
In high school, Ashley Delgado dreamed of becoming a doctor and one day buying her father a Rolls-Royce. “She wanted to heal people,” said her father, James Taylor. She had a high GPA, Taylor added, and did especially well in science and Latin.
In her mid-20s, Ashley suffered a leg injury and was prescribed OxyContin. The painkiller marked the beginning of a yearslong descent through addiction — from prescription opioids to methamphetamine, then heroin, and finally, fentanyl.
With her family’s support, Ashley spent time in a rehabilitation facility in her hometown of Cleveland, Ohio, and in recovery she moved into a sober living home. But on an early summer morning in 2023, Ashley’s body was found on a dead-end street just outside the city. One sandal was missing. Tucked inside her bra was a folded scrap of paper containing a tan powder. She was 29.

“I have lost my father, my grandmother — that hurts,” Taylor said. “But when you lose your child, that’s the worst thing on the planet, because they’re not supposed to go before you.”
Toxicology tests would later show a mix of substances in Ashley’s system, including protonitazene and metonitazene, powerful synthetic opioids from a little-known class of drugs known as nitazenes. Her death was ruled accidental.
Before his daughter’s fatal overdose, Taylor had never heard of nitazenes. Developed in the 1950s as potential painkillers, the drugs never reached the market because they were deemed unsafe for medical use. He was shocked to learn they could be up to 40 times more potent than fentanyl and 500 times stronger than heroin.
Nitazenes are predominantly sold online, both on the clear web and dark web, and are often laced into other substances to increase their potency. Experts say this puts unsuspecting users seeking more common drugs, such as oxycodone, fentanyl, or stimulants like cocaine, at risk of fatal overdoses.

The US Drug Enforcement Administration (DEA) started tracking nitazene-related seizures around 2014, but it wasn’t until 2019 that it saw a marked increase. Since then, federal authorities have scheduled dozens of nitazenes as illegal substances, launched undercover operations, filed indictments, and imposed tariffs on China, where many of the laboratories manufacturing and supplying nitazenes and fentanyl are known to reside.

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
Yet, figures provided to Bellingcat by the United Nations Office on Drugs and Crime (UNODC) show the United States has reported 26 different kinds of nitazenes since 2019 — the second highest number globally, after Canada.
And data from the Centers for Disease Control and Prevention (CDC) on nitazene-involved overdose deaths suggest that cases continue to rise. More than 1,100 fatalities have been confirmed through the CDC’s State Unintentional Drug Overdose Reporting System (SUDORS), but experts believe the number of Americans who have died from them since 2019 could be as high as 2,000.
Alex Krotulski, the director of the Centre for Forensic Science Research and Education in Pennsylvania, told Bellingcat that deaths are underreported because nitazenes were not routinely tested for.
“There are only limited forensic toxicology labs that test for nitazenes, so if a nitazene was present and the lab didn’t test for it, the number wouldn’t appear in SUDORS,” he said. “Also, for labs that do test for nitazenes, they have missed cases prior to their testing.” The most recent years for which there is CDC data, 2023 and 2024, show they were the deadliest, with 747 confirmed deaths.

In this months-long open source investigation, Bellingcat combed through dozens of criminal court proceedings, filed national, state, and county-level Freedom of Information requests, and obtained scores of medical examiner reports to produce the most detailed account yet of how nitazenes are infiltrating US borders and destroying lives.
The investigation found that, despite efforts to curb their spread across the country, nitazenes are proliferating online. It also shows that, by the time nitazenes reach American users, they are almost always mixed with several other drugs, including methamphetamines, cocaine and, most notably, fentanyl.
As of this year, 48 of 50 US states have reported nitazene seizures.
Fentanyl is by far the biggest opioid killer in the US. With more than a quarter of a million deaths since 2021 and about 200 fatalities a day, fentanyl is one of the country’s most urgent public health crises. But drug experts warn that nitazenes can be even more potent and are being mixed with fentanyl and other substances, creating increasingly lethal combinations.

“We’re always concerned about fentanyl being mixed in with other drugs — cocaine, meth, heroin,” said Frank Tarentino, Associate Chief of Operations for the DEA’s Northeast Region. “You add nitazenes to that and it makes it exponentially more dangerous and frightening for drug law enforcement, parents, caregivers, educators, and the young.”
Data obtained from the DEA’s National Forensic Laboratory Information System (NFLIS) show reports of confirmed seizures of nitazenes rising sharply — from 43 positive tests in 2019 to almost 2,000 in 2024 (the most recent year for which figures are available). By March this year, more than 8,000 nitazene reports had been recorded since 2019. But experts said that not all laboratories can test for nitazenes — which come in many forms including powders, pills, and sprays — and many don’t feed into the NFLIS system, meaning these numbers are almost certainly an underestimate.
We asked the DEA for a breakdown of reports of nitazenes by state. Ashley Delgado’s home state of Ohio stands out. NFLIS data from 2019 to 2024 indicate that more than a third of all positive nitazene laboratory reports nationally are linked to Ohio.
Separate data from the CDC shows Ohio has also recorded the highest number of nitazene-related overdose deaths in the US since 2021. In 2020, there were just four fatalities linked to the drug; in 2021 that number rose to 90. Between 2022 and 2024, according to government data, there were 200 more deaths.
“It is a risk to our community,” said AmandaLynn Reese, chief programme officer at Harm Reduction Ohio, a non-profit that supports people who use drugs. “There’s been several instances of nitazenes being reported within the community, and I think we’re going to see more of that, especially as we’re seeing less fentanyl.”
To learn more about what was happening in Ohio, Bellingcat filed a public records request for county-level figures to the state’s Bureau of Criminal Investigation (BCI). The data shows that the counties of Scioto, Butler and Cuyahoga — areas long affected by the opioid crisis — account for almost half of all nitazene detections across the state, by weight.
In the 2000s, Portsmouth in Scioto County became known as the “pill mill capital” of America due to widespread overprescribing of opioids. More recent data continue to show Scioto with one of the highest rates of drug overdose deaths in the state. In Cuyahoga County, which includes Cleveland, drug-related mortality rates tripled the national average in 2022.
Two years ago, Ohio’s Governor Mike DeWine issued executive orders to schedule nine different nitazenes and legalised the use of tools to test for drugs including nitazenes.
The reasons why Ohio has been so hard hit are still not fully understood. “Ohio’s geography has long been a suspected contributing factor,” said Erin Reed, director of RecoveryOhio, a statewide initiative coordinating Ohio’s response to addiction. The organisation cited a 2001 article pointing to Ohio’s unique geographic and infrastructural features — including vast land, air and sea transportation networks — as key reasons for the state being a hub for drug trafficking.
Local organisations like Harm Reduction Ohio are pushing for more drug-checking services, education, and greater accessibility to testing strips and life-saving medications like Naloxone, a drug that is used to reverse an opioid overdose. “People are going to use drugs,” Reese said. “We don’t know the supply, but those are ways you can engage in your drug use to increase safety and reduce harm.”
Bellingcat obtained medical examiner reports from Cuyahoga County for all nitazene-related deaths in 2023 and 2024, which provide an insight into how the drugs are being consumed. The autopsy records show that 45 people — 31 men and 14 women aged 29 to 72 — died after taking nitazenes over the two-year period. Among them were university graduates and former athletes, an Army veteran, an ironworker and an addiction counselor.
Just before Christmas in 2024, a young man from Cleveland died after taking drugs that included etonitazene. A couple of weeks earlier, the body of an elderly woman was found in her home after she ingested drugs that included metonitazene and protonitazene. In the summer, a mother of two children in her thirties consumed a similar lethal mix. All except one of the 45 deaths was ruled accidental.
And in every instance, nitazenes were detected alongside fentanyl, and often with a cocktail of other drugs such as heroin, cocaine, methamphetamine and benzodiazepines. The reason for this wide variety, Tarentino, the DEA agent said, is that dealers often mix nitazenes into other drugs to make them more powerful and addictive, and ultimately to give them a competitive edge.
“It becomes a brand,” he said. “The unfortunate circumstance that we find ourselves in is that the dealer’s choice becomes a deadly decision.” Not only are these mixtures deadly — they can also be highly profitable.

Court records analysed by Bellingcat show nitazenes have been sold at prices ranging from roughly US $4,000 to $12,000 per kilogram. But Tarentino said the DEA’s internal estimate puts $12,000 at the lower end of the range, with prices going up to as much as $40,000. Given their potency, even small quantities can be diluted into hundreds of thousands — or potentially millions — of doses once mixed and pressed into pills. “A little bit can go a long way,” Tarentino said, “and they can make a lot of money.”
A Freedom of Information Act request to the US Customs and Border Protection (CBP) revealed that in 2024 and 2025 — the only years for which the agency has monitored nitazenes separately — 41 consignments of the drug were intercepted. The data shows that most of these shipments arrived by mail, primarily from mainland China, Hong Kong and the United Kingdom. The quantities tended to be small, ranging from less than 1 gram to almost 700 grams.

But that’s not always the case. An analysis of US federal court records linked to prosecutions of nitazenes indicates that roughly 90 kilograms of material containing nitazenes in different forms (powder and pills) have been seized over the past three years. Nearly two-thirds of that amount, about 60 kilograms, stem from a single case.
In that case, prosecutors allege that a man named Valkar Singh drove a blue Maserati from Canada into the US carrying six industrial-sized buckets with more than 100,000 pills containing isotonitazene. According to court filings, Singh transported the drugs to a Bronx, New York address, where he was arrested by undercover law enforcement officers.
Tarentino, who is familiar with the Singh case but could not comment on it specifically, said a lot of work is being done to prevent drugs being smuggled across the Canadian border. “Canada has become a major concern, but also a major partner in trying to stop the synthetic opioids that are coming into the United States,” he said.
Lawyers for Singh, who has pleaded guilty and is awaiting sentencing, declined to comment.

The scale of the alleged seizure makes this case an outlier. Of 46 federal cases identified by Bellingcat between 2021 and 2025, the next highest nitazenes seizure was about 9 kilograms. By comparison, data provided by the European Union Drugs Agency shows roughly 18 kilograms of nitazene-related seizures (pills, powder, liquid) across the EU between 2019 and 2023.
“It’s very large,” said Jared Brown, scientific affairs officer at the UNODC. “One hundred thousand pills is probably at the limit of what we hear about in terms of maximum types of quantities that get seized.”
The evidence suggests that most buyers are individual dealers who purchase relatively small quantities online, rather than organised criminal groups. “It’s street-level or mid-level dealers [in the US] that are introducing the nitazenes into the drug supply, not the big drug traffickers,” said Philip Berry, a visiting senior lecturer at King’s College London who formerly worked in counter-narcotics at the UK Home Office.
Court documents show that buyers can easily find nitazene suppliers online: on dark web marketplaces, standalone chemical supplier websites, or even on social media platforms. The suppliers often market the drugs by listing their chemical identifier and social media contact details. Often, the ads include an image of a young Asian woman striking a pose.
Buyers are often individual dealers who contact sales representatives via encrypted channels and negotiate a deal. In those conversations, representatives will sometimes disclose how they claim to evade customs, for example by declaring the product as cosmetics or electronic accessories.

A detailed account that illustrates this modus operandi comes from the 2023 case against a man named Will Catis in Florida — the state with the second highest number of confirmed nitazene reports. Court documents show that a basic internet search led Catis to multiple nitazene advertisements listed by Jiangsu Bangdeya New Material Technology Co., LTD, a Chinese company sanctioned by the US Treasury for offering illicit substances for sale, including fentanyl and protonitazene.
Catis purchased approximately four kilograms of nitazenes from Jiangsu Bangdeya in batches no larger than 500 grams. The drugs were sent via the US Postal Service to Deerfield Beach, Florida. Once received, Catis mixed the nitazenes with other drugs, pressed the substance into a brick and sold it to other drug traffickers. Catis was jailed for 12 years after pleading guilty to possessing and intending to distribute nitazenes.
One court case from Florida describes how a couple who lived in a converted garage bedroom in Hernando County bought nitazenes through the mail from Chinese companies they contacted online. Jacob Spinoza and his girlfriend Veronica Jo Barback regularly abused the drugs and distributed them locally, according to court documents. Both pleaded guilty. Spinoza was sentenced to nine years in prison, and Barback received a three-year sentence.

Another notable case reveals how a man allegedly ran a drug trafficking operation from a prison in Ohio. Investigators said Brian Lumbus Jr worked with a middleman, Giancarlo Miserotti, who contacted drug manufacturers in China to get nitazenes shipped through Italy to avoid custom checks. Once in Ohio, the plan was to distribute the drugs to other states, court documents said.
But law enforcement agents were listening in on conversations between Lumbus and other members of the drug network, who expressed caution about the potency of nitazenes. “Man, we got to be careful … somebody died,” Lumbus said in one phone conversation, according to court documents. “Ohhh … it was too strong,” Miserotti responded. “I think the ratio of the pink [metonitazene] was thick.”
Lumbus is awaiting trial. Miserotti was arrested in Italy in 2023 and sentenced to more than 13 years in prison.
Enforcement actions have targeted the online marketplace ecosystem. In June 2025, Archetyp Market, a major dark web platform used to sell drugs, was dismantled in a coordinated operation involving Europol. US authorities have also indicted several China-based companies and individuals accused of offering nitazenes and related synthetic opioids for sale. Still, advertisements for nitazenes continue to litter online markets, constantly adapting to new regulatory regimes.

In July 2025, China placed the majority of nitazenes under national control. Tightened regulations — both in China and the US — have tried to stem the flow of nitazenes. But drug experts warn that manufacturers are already exploiting loopholes in China’s regulations by marketing chemically similar synthetic opioids known as “orphines.”
Jared Brown, of UNODC, said orphines are also thought to come from China and are about as powerful as fentanyl. “Orphines have just enough of the molecule difference that it isn’t covered by the core definition that China has made,” he said.
This is not the first time Chinese synthetic opioid manufacturers have adapted to regulations. In 2019, China banned all fentanyl-related substances, including some major precursors. The number of distinct fentanyl analogues reported to the UNODC subsequently plummeted, while reports of nitazenes quickly picked up. Now that China is clamping down on nitazenes, orphines are on the rise. More than 150 cases involving orphines were reported in the US between 2024 and 2025, the majority of which are in Illinois.
“Always adapting, always changing – we call them ‘shape shifters’,” said Tarentino. “They’re this global Hydra that are always changing, evolving and adapting to their environment and taking full advantage of all of these different loopholes and vulnerabilities that exist.”
Reporting for this story was supported by the Fund for Investigative Journalism.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
The post Super-Potent Synthetic Opioids Spread Across US Amid Fentanyl Crackdown appeared first on bellingcat.
12.06.2026 à 10:51
Bellingcat Investigation Team
On February 15, 2026, the bulk carrier, Grumant (IMO: 9385879) was pictured at the occupied Ukrainian Port of Feodosia on the Crimean peninsula. Satellite imagery suggests it had already been there for several days. It appeared to stock up on grain before departing on a two-month-long journey eventually docking at the Port of Benghazi in […]
The post Heading Off: New Technique Helps Track Grain Smuggling Expansion to Libya appeared first on bellingcat.
On February 15, 2026, the bulk carrier, Grumant (IMO: 9385879) was pictured at the occupied Ukrainian Port of Feodosia on the Crimean peninsula. Satellite imagery suggests it had already been there for several days. It appeared to stock up on grain before departing on a two-month-long journey eventually docking at the Port of Benghazi in Libya on April 18.
While there have been previous reports of grain shipments from occupied Ukraine arriving in Libya, this is only the second time a Russian ship has been observed delivering what the Ukrainian government describes as “stolen” grain to the country. The previous case involved the Damas Wave which travelled in January of last year to the port of Misrata which is under the control of the UN-recognised Government of National Unity (GNU). In addition to satellite imagery, Bellingcat deployed a new technique that analysed Grumant’s heading data which was contained in AIS information provided by Lloyd’s List Intelligence, to help confirm Grumant’s presence in Feodosia.
Bellingcat has been tracking smuggled Ukrainian grain shipments as they find new markets, five of the ships we previously identified have since been sanctioned by the EU while another was sanctioned by the US Department of Treasury.
Grumant transits the Bosphorus Strait in the middle of the night.

Credit: Yörük Işık.
Grumant enters a region of the Black Sea known for GNSS interference, meaning that Grumant’s publicly reported Automated Identification System (AIS) position is unreliable.
On February 15, a high resolution satellite image confirms the ship is docked at the port of Feodosia at berth No. 1 that is used for bulk and metal cargo. Matching features visible include Grumant’s grey decking, its seven hatches and bright yellow front mast. What appears to be leftover grain can be seen under the two port crates, immediately next to the ship.

Credit: Satellite image ©2026 Vantor.
Grumant exits the area of signal interference, meaning that its reported position on ship tracking services is now reliable again. Its AIS messages indicate it is travelling towards the Bosphorus.
Grumant transits the Bosphorus Strait towards the Sea of Marmara. Judging by the draft, with no visible red paint on its hull, the ship appears to be fully laden.

Credit: Yörük Işık.
Grumant arrives in Izmir, Turkey on February 23 and anchors off the coast until March 13.
Over the course of three weeks, Grumant never enters the Port of Izmir. It is not known if it was denied entry. Bellingcat asked the port operators but did not receive a response before publication.

Credit: Planet Labs PBC.
Grumant then loiters off the coast of Aliağa, about 50 km from Izmir. It stays here until March 16, never entering the port. It again is not known if it was denied entry. Bellingcat asked the port operators but did not receive a response before publication.
Grumant arrives in Libyan waters and stays off the coast of Benghazi until April 1.
Grumant briefly leaves the coast of Benghazi, but returns a few days later.
Grumant leaves the anchorage on April 18 and docks at the port of Benghazi where it unloads the grain. The ship was captured in a Vantor satellite image on April 20.
It leaves port on April 23, and heads back towards the Bosphorus.

Credit: Satellite image ©2026 Vantor.
After spending a few days off the coast of Tuzla, Grumant transits the Bosphorus towards the Black Sea.

Credit: Yörük Işık.
Lloyd’s List Intelligence has previously reported on the expansion of Russia’s grain smuggling operations, beyond the occupied port of Sevastopol to include Feodosia port.
According to the Ukrainian activism, journalism and hacker group, Kiborg News, Grumant used deceptive shipping practices to deliver grain to Latakia, Syria in 2024. The report included several of Grumant’s shipping manifests, which showed it had repeatedly exported grain from Occupied Crimea to Syria.
It is standard maritime practice that ships broadcast Automatic Identification System (AIS) messages which include a ship’s position, heading, and draught (among other information).
Because of longstanding Global Navigation Satellite System (GNSS) interference in parts of the Black Sea, the position data transmitted by an affected ship’s AIS system is often unreliable.
Between February 7 and February 19, 2026, data from Lloyd’s List Intelligence shows the Grumant transmitted 29 AIS messages, with unreliable positions in the vicinity of Feodosia. We know these positions are unreliable as they are erratic and some of them report the ship as being positioned on land.

However, according to the IMO, the heading data transmitted by a ship’s AIS system must come from an onboard compass. A compass is unaffected by GNSS interference, meaning it is a more reliable source of information in these conditions.
Over the same dates, all 29 AIS messages reported the ship’s heading as 267 degrees or 268 degrees. The Port of Feodosia has a heading of 267.5 degrees. The close agreement between the ship’s heading and port heading strongly suggests that Grumant was moored at the port between February 7 and February 19, 2026.
We conducted an extra check of the heading data by reviewing satellite imagery available of berth 1 at Feodosia Port, which suggests that the same vessel was present on several days between February 6 and February 18. Imagery on Feb. 6 shows the port was empty in the morning and occupied in the afternoon. Grumant exited the area of GNSS interference on February 21, and berth 1 at the port was captured on satellite image on February 22 and appeared empty. The low resolution satellite imagery is only used as an additional check to see if a vessel is at the berth.



Bellingcat checked all vessels transmitting AIS in the vicinity of Feodosia Port and found that Grumant was the only one that consistently transmitted a heading matching the Port of Feodosia over the period of interest.
We shared our research with Charlie Brown, a former US Naval Officer and Senior Advisor at United Against Nuclear Iran where he focuses on maritime sanctions enforcement and the tracking of illicit shipping. Brown told Bellingcat that while satellite imagery of vessels remained key for identification, when looking for reliable data in a spoofing environment it made sense to look at the various elements of AIS data to try and find some accurate information, despite GNSS spoofing.
“It’s quite standard for the independent gyro compass to be providing the heading […] I think the majority would not [be subject to spoofing] so it’s a good methodology to parse out the particular data and then make some inferences from that.”
“It’s neat to think of what can be derived from data that would otherwise be dirty or wrong. So there’s still some elements of use in there.”
He added that in theory there are probably some compasses that are subject to spoofing as well.
He told Bellingcat that it was fair to say the heading data of the Grumant supported identification, but stressed the need to cross-reference with other data sources.
While in this instance it has been possible to use AIS data to help verify the location of Grumant, it is relatively unusual to have access to this information.
Ships that call to the occupied territories frequently disable their AIS transponders to do so.
This activity, known as “dark port calls”, is a common tactic for those engaging in illicit or sanctioned trades.
Grumant does not transmit AIS messages from February 8 to 11, but this is the longest gap in data (see diagram above), with intermittent messages coming through after that point.
It is unclear why Grumant continued to transmit AIS during the period it was loading in Feodosia.
A review of Lloyd’s List Intelligence data from January 2025 shows that on a previous voyage to the Black Sea the Grumant operated “dark” for 59 days.
On February 15, 2026, high resolution imagery showed Grumant docked in the Port of Feodosia. We compared it with other recent images of Grumant to confirm the match.
The ship in the satellite image has a grey-coloured deck, which is uncommon enough for it to stand out. Many bulk carriers have cranes (including the ships we previously covered such as Krasnodar, Zafar and Zaid), Grumant does not have any. It also has seven hatches (openings for the grain) and a bright yellow front mast that matches the mast of Grumant (see the image of it transiting the Bosphorus). We can match the Grumant in the Feodosia image, not only to pictures of the Grumant shot from the ground, but also to the satellite image from Benghazi.
The length and breadth of the ship also matches that of the Grumant; 180 metres by 22.90 metres.



Libya has complicated internal dynamics with essentially two administrations in charge of different parts of the country – the Government of National Unity (GNU) in the west and the Libyan National Army (LNA) in the east.
In recent years, Russia has backed the LNA’s General Khalifa Haftar, based out of Benghazi, in the east of the country. But Jalel Harchaoui, a political scientist specialising in Libya with the Royal United Services Institute (RUSI), stressed that the two sides of this conflict, the LNA and the UN-recognised GNU, are not currently fighting. Instead they are in a flawed, multi-year truce.
Therefore, the east-west divide isn’t as clear-cut as during the civil war. While all shipments going to Benghazi and Tobruk are overseen by the LNA, not all shipments going to the city of Misrata (which is run by the GNU) are meant for the GNU-dominated part of the country.
Harchaoui told Bellingcat: “the Tripoli government is in some regards pro-Ukraine, but if there’s business that can be done with Russia through the very opaque port of Misrata and all the right people get paid, the business is going to take place.”
That observation is potentially significant given at least one previously tracked vessel that went from occupied Ukraine to Libya docked in Misrata.
This was not the case of the Grumant, however, which arrived in an LNA-controlled part of the country. It is not known from open sources alone if the authorities in Libya or at the port in Benghazi knew the grain carried by Grumant had come from occupied Ukraine.
Bellingcat contacted the Benghazi-based LNA government and representatives of the Tripoli-based GNU government via the Libyan Embassy in The Netherlands. We also contacted the Port of Benghazi, Port of Imzir in Turkey as well as the Ukrainian and Russian authorities. Representatives of the LNA did not respond to requests for comment before publication, nor did the Port of Benghazi or Port of Izmir. The Libyan Embassy in The Netherlands replied to Bellingcat after publication, stating that Benghazi and eastern Libya are not under the authority or administrative control of the Government of National Unity and therefore they are not currently in a position to comment on Bellingcat’s findings.
“The port of Feodosia, located in the temporarily occupied Autonomous Republic of Crimea, is not under Ukrainian control, and any commercial activity conducted there is illegal,” the Ministry for Development of Communities and Territories of Ukraine and the Ministry of Foreign Affairs of Ukraine told Bellingcat in a joint response.
They told us the loading of grain exported from the temporarily occupied territories is an illegal act and Russia was using ports as logistics centers to export stolen Ukrainian agricultural products.
“The expansion of such routes to third countries, in particular to North Africa, demonstrates Russia’s ongoing efforts to circumvent international sanctions and monetize resources stolen from the occupied Ukrainian territories.”
The Ukrainian Ministry of Foreign Affairs sent information about Grumant’s (IMO: 9385879) “illegal activities” to the diplomatic missions in Great Britain, the Republic of Turkey and the Republic of Tunisia over the course of March to May this year, the ministries told Bellingcat.
Ukraine is continuing to pursue legal action against Russia’s “shadow grain fleet” they told us. For instance, earlier this month a Swedish court approved the transfer of the Russian “shadow grain fleet” vessel CAFFA to Ukraine for investigation after it was arrested in Swedish waters.
This case has set a new precedent, going beyond sanction and fines previously handed out to such vessels, and allowing for the detention and confiscation of a shadow fleet vessel in European jurisdictions, the ministries said.
According to Russian court documents Grumant’s previous owner Murmansk Shipping Company was dissolved and “Decision/Reshenie” LLC were listed as the International Safety Manager and operator of Grumant. Decision/Reshenie were also listed as the operator of Grumant in another court document, from an unrelated case.
Bellingcat attempted to contact Decision/Reshenie to ask about Grumant’s grain shipment from Feodisia Port to Benghazi Port, but they had not responded at time of publication.
Youri van der Weide, Galen Reich, Yörük Işık and Bridget Diakun contributed to this report.
Cover image: Planet Lab image shows Grumant anchored off Izmir, Turkey on February 27. Credit: Planet Labs PBC.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
The post Heading Off: New Technique Helps Track Grain Smuggling Expansion to Libya appeared first on bellingcat.