bellingcatRussian - English - Français - Espagnol - Deutsch
Bellingcat est un groupe international indépendant de chercheurs, d’enquêteurs et de journalistes citoyens utilisant à la fois enquêtes open source et réseaux sociaux ▷ BELLINGCAT FRANÇAIS
Sign up here to receive Bellingcat’s biggest investigations by email as soon as they are published. On a June night in 1996, in a basement apartment in Boston’s Chinatown, a killer put a pistol to the back of a young man’s head and pulled the trigger. The victim’s body was wrapped in quilts, lowered into the trunk of […]
Sign up here to receive Bellingcat’s biggest investigations by emailas soon as they are published.
Illustration by Oisín Mac Con Iomaire
On a June night in 1996, in a basement apartment in Boston’s Chinatown, a killer put a pistol to the back of a young man’s head and pulled the trigger. The victim’s body was wrapped in quilts, lowered into the trunk of a car and driven about 20 miles southwest of the city, where it was dumped in the woods. It lay undiscovered through two New England winters until a dog walked home carrying a human bone.
For three decades, authorities did not release the victim’s name to the public. He is listed in the National Missing and Unidentified Persons System (NamUs) as #UP12385, one of 202 unidentified people recorded in the state of Massachusetts. The circumstances of his discovery are reduced to five words: “Skeletal remains found in woods.” The case remains unsolved.
Bellingcat spent more than a year investigating in an effort to put a name to the victim. Using open sources, including freedom-of-information requests and newspaper archives, as well as interviews with investigators who worked on the case, we pieced together the story of the man’s life and death in an era before the internet kept a digital record. In total, we submitted 27 public records requests to 18 local, state and federal law enforcement agencies. We also contacted more than two dozen investigators, prosecutors, crime victims, journalists, experts and community groups connected to the case, though most said they did not recall the 30-year-old murder.
We learned that authorities identified the victim as Fu Chun Wang, a 26-year-old undocumented Chinese immigrant who did not speak English. We also learned of a sweeping investigation into Chinese organised crime in New England in the late 1990s. Authorities suspected Wang was a member of the Fukienese Flying Dragons, a gang the FBI described at the time as a “violent offshoot” of the larger Flying Dragons crime ring.
Fu Chun Wang’s mugshot. Source: Released by Sharon Police Department
Based in New York’s Chinatown, the Fukienese Flying Dragons were active across much of the East Coast. The gang trafficked migrants, extorted and robbed businesses, kidnapped for ransom and murdered rivals. Authorities believed Wang belonged to the Boston faction of the group, which was suspected of carrying out home invasions targeting Asian and Asian-American restaurant owners and staff across New England in 1996.
Heavily redacted FBI documents and correspondence between local and state authorities show that a federal operation investigating the home invasions uncovered information about Wang’s murder and other crimes. The operation, whose name is redacted, was led by the US Attorney for the District of New Hampshire.
Authorities suspected that the Boston-based members of the Fukienese Flying Dragons were also involved in prostitution, illegal gambling and kidnappings in multiple states. Investigators examined possible ties between the gang and a suspect in one of Boston’s deadliest mass killings: the 1991 Chinatown Massacre.
According to these newly released files, investigators received information that Wang had been murdered by members of his own gang shortly after Boston Police arrested and charged him for using credit cards stolen in one of the home invasions. While some gang members were identified as suspects and investigated, none were ever charged and convicted for the murder.
A Dog with a Bone
On April 10, 1998, a resident in Sharon, an affluent suburb southwest of Boston, called the police. Their black Labrador retriever had returned from the woods carrying a large bone. Four days later, testing by the coroner’s office in Boston determined it was a human femur likely belonging to an adult male. Police searched the woods, where a detective uncovered more bones near a bundle of quilts. Inside, they found a decomposed skeleton.
A coroner ruled that the victim was a man in his twenties or thirties who was possibly Asian or Native American. He had long black hair with blonde streaks. There were at least two overlapping bullet holes in the back of his skull. Local media reported at the time that the victim had been shot “execution style”. A single, corroded .380 calibre shell casing was found inside the quilt. The victim was wearing a green-and-white striped rugby shirt, denim jeans and white leather sneakers on the night he died. Loose change, a pocket knife and a tarnished set of keys were found nearby on the forest floor.
Blurred
Crime scene photos showing remains found in the woods, near the intersection of Walpole Street and Bluff Head Road, in April 1998. Source: Sharon Police Department
A botanist from Harvard University determined the body had likely been in the woods for at least 18 months. Experts from The Smithsonian Institution told police that forensic facial reconstruction would be “of questionable value” due to the damage caused by the gunshot injuries.
Before his murder, open source records of Wang’s life amounted to a few scattered data points: interactions with authorities, apartment rentals, a loan application and a hospitalisation following a car accident.
Police reports after his death show investigators pieced together a patchy collection of biographical data. He was from a family of five in Dongshan, a village in the southeastern Chinese province of Fujian, and was likely born into poverty. During his autopsy, it was noted that his teeth showed signs he had been “undernourished” as a child. He moved to the US to work in the restaurant industry and eventually joined a gang.
A January 1994 Immigration and Naturalisation Service (INS) record containing Wang’s fingerprints. Source: Released by Sharon Police Department
Wang migrated at a time when thousands of Fujianese were arriving in the US every month in search of a better life. Like many migrants at the time, he entered the country without documentation. By 1994, when Wang met with immigration authorities in Boston, he gave his address as an apartment on East Broadway in New York’s Chinatown. Two years later, he was issued an employment authorisation card. Boston Police would learn from the Immigration and Naturalisation Service (INS) that Wang had been granted political asylum.
Search results on Ancestry.com suggest that prior to living in Massachusetts, Wang had also lived in Virginia and Vermont. Records from the Sharon Police Department corroborate these findings. In Virginia, police learned that he worked in restaurants and had applied for a loan to buy a car, a 1994 green Mitsubishi Mirage.
In Vermont, Wang worked at a Chinese restaurant called Men-at-Wok until he was injured in a car accident in May 1996. After he was reported missing a month later, his car sat unclaimed in an auto body shop in Vermont until a bank sought to reclaim it.
Wang’s INS employment authorisation card. Source: Released by Sharon Police Department
Unclaimed checking and savings accounts at Fleet National Bank are listed under Wang’s name and the Quincy address in the Massachusetts unclaimed property database. The amount of money in these accounts is not publicly available, but the presence of unclaimed funds in his name, along with his abandoned car, are some of the many indicators that he met with foul play.
‘We’ll Kill Your Family’
In the summer of 1996, Chinese restaurant owners and their staff in suburban Boston and New Hampshire were terrorised by a wave of violent home invasions and robberies. Police described the suspects as “an organised group of Asian individuals”.
Composite sketches of two suspects in a July 1996 home invasion in Merrimack, NH based on witness descriptions. Source: Merrimack Police Department
The modus operandi was often the same. In the early morning hours, young men barged into rooming houses while Chinese restaurant workers slept. Sometimes they robbed the business owners’ homes. Armed with guns and knives, the intruders tied up their victims before stealing cash and valuables. One woman who was attacked at knifepoint told police an assailant threatened: “Shut up or I will kill you”. In another case, a victim was stabbed.
The assailants were described as young men or teenagers. In several cases, victims reported that they spoke Fuzhou, also known as Foochow, a language originating from eastern Fujian Province.
Jim Keating, a retired Sharon Police detective, told Bellingcat that many Asian gang extortions and robberies in the Boston area at the time were not reported. “They were all afraid of these guys, because they said, ‘We’ll come back and we’ll kill your family.’ And they would.”
In the span of a few months in 1996, similar robberies occurred in the Massachusetts towns of Bedford and Westborough, as well as Malden, a city about 10 kilometres north of Boston. These were followed by home invasions in the bordering state of New Hampshire, in Wolfeboro, Merrimack, Lebanon and Manchester. It is unclear if the home invasions and robberies were connected, but Bellingcat’s review of historic newspaper clippings and newly released police documents suggest that at least one other gang may have been responsible for some of the crimes.
In response to the crime spree, local, state and federal law enforcement agencies coordinated investigative efforts. Bellingcat obtained files detailing a federal operation led by the US Attorney for the District of New Hampshire. It included agents from the FBI, INS, Drug Enforcement Administration, Bureau of Alcohol, Tobacco, Firearms and Explosives, Customs Service, Border Patrol and Royal Canadian Mounted Police, along with officers from state, county, and local law enforcement agencies in New England.
Local media coverage of the home invasions in 1996. Source: Janet Wilson, The Boston Globe
Ben Leong, a retired Boston Police detective, said Asian gangs committing robberies, extortion and home invasions against restaurant owners and their staff were common in the 1990s. He said many of these crimes went unreported for cultural reasons, over fears of gang retaliation, and because victims did not trust law enforcement.
“Back then there were many factions of gangs,” he said. “The gang members were recruited throughout the country, nationally and internationally. Law enforcement was always playing catch up to identify the prevalent groups, and the individual members and leaders committing illegal activity.”
Leong, who is president of the International Organisation of Asian Crime Investigators and Specialists (IOACIS), said authorities had a better understanding of gang culture in Boston by around 1996 when local, state and federal agencies began sharing information.
Murdered in Chinatown
On June 9, 1996, one day after a home invasion in Wolfeboro, New Hampshire, Boston police were called to a Macy’s department store when a man tried to use credit cards stolen in the robbery to buy jewellery and electronics. He was arrested and booked on charges of receiving stolen property. The man was Fu Chun Wang.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
In Sharon Police records, Wang was described as “very depressed” and “possibly suicidal”. He told a Boston Police detective that he urgently needed to send $1,000 to his family in China. Other records said his father was ill and needed money. Files found on Judyrecords.com, a free database that purports to include more than 770 million US court case records, show that Wang was arraigned and a court appointed a defence attorney to him. He was bailed out after pleading not guilty.
Less than two weeks later, on June 21, Wang was reported missing to the Quincy Police Department in Massachusetts. The police report said Wang was last seen in Boston’s Chinatown on June 13, two days after he left jail. Police records indicate that a female friend of Wang’s had asked an attorney to file the missing persons report. The attorney who reported him missing told Bellingcat that he did not remember Wang.
The Sharon Police Department’s murder case file notes that within weeks of finding the human remains in the woods, they received information from Boston Police and the FBI that “Wang was murdered in Chinatown” in June 1996 and “his body [was] never found”.
Investigator’s handwritten notes about Wang’s case. Source: Sharon Police Department
Not all documents were released to Bellingcat, and some names were redacted. Fragmentary notes and witness statements provide the only clues to Wang’s final days. In handwritten records, Sharon Police said a man who was described as the “head of [an] Asian gang in Boston” had Wang killed over the New Hampshire breaking-and-entering incident.
A note in the Sharon Police file described a witness to Wang’s murder as a “Flying Dra” and a “NY gangster”. Retired detective Jim Keating confirmed to Bellingcat that Wang, along with his associates and killer, were suspected members of the Fukienese Flying Dragons. He said he believed Wang was murdered because he posed a risk to the gang following his arrest.
Investigator’s notes describing a witness as a gang member. Source: Sharon Police Department
Documents released by the Merrimack Police Department and Sharon Police Department said that an inmate in New York who, in 1997, was serving a 25-year sentence for attempted kidnapping, offered to share information about Wang’s murder with the FBI in return “for a reduction (sentence)”. The inmate implicated the gang in at least two 1996 New Hampshire home invasions and also gave authorities information about the murder.
The account is heavily redacted but includes a note that the US Attorney for New Hampshire was making arrangements to interview the man. Police in New Hampshire said they believed the inmate “was truthful in his statements and has knowledge about the murder of Mr Wang”. Keating confirmed to Bellingcat that he and investigators from other law enforcement agencies traveled to New York to interview the man. He said the inmate, a suspected member of the Fukienese Flying Dragons, gave a statement on Wang’s murder.
Keating said that investigators had learned of a dispute on the night of the murder between Wang and the gang’s leader. He said Wang had planned to run an illegal gambling operation at an apartment, which the gang boss was using as a prostitution venue. This led to an argument at another location, and when Wang left for the apartment the boss followed him.
But Keating said that based on the information gathered throughout the investigation, he believes the primary motive for Wang’s murder was his arrest over the use of credit cards stolen in the Wolfeboro home invasion. With that arrest, Wang presented a risk to the rest of the gang because investigators could tie them to the home invasions. “Wang broke the basic rules by taking something that was identifiable and using it, and that’s what the whole damn thing was about,” Keating said.
Crime scene photos of the basement unit on Oxford Place in Boston’s Chinatown where Wang was murdered. Source: Sharon Police Department
Keating told Bellingcat that the crime scene had been damaged by flooding after the murder. He said he used a power saw to cut off the bottom of a door in the unit and that lab testing revealed the presence of Wang’s blood.
Investigators also worked to confirm Wang’s identity by testing the DNA of the remains found in the woods. In a 1999 case summary written by a Massachusetts State Police Trooper, it was noted that the FBI was attempting to locate Wang’s parents through police in China.
Three months later, the FBI’s Hong Kong office sent a communique to Boston confirming that the Chinese Ministry of Public Security and Interpol had located Wang’s parents. Wang’s mother, it said, was willing to provide a DNA sample for comparison.
The FBI communique is the final document in the newly released files that details the efforts to confirm Wang’s identity with DNA. However, Keating told Bellingcat that a DNA sample was obtained from Wang’s mother in China. It was brought back to the US for testing and confirmed to be a match, he said. “I don’t know when the DNA was collected or who did it. But I know that they did that,” Keating said. “There is no question about who he was.”
Bellingcat contacted both the Norfolk and the Suffolk County District Attorneys to confirm the DNA match, but did not receive a response to questions about DNA testing or the victim’s identity. Other former law enforcement officers named in the files released to Bellingcat have not responded to requests for comment.
One document included in the murder file references discussions between homicide investigators and the FBI about charging Wang’s killer with home invasion offences. The note discusses the potential to have a witness testify against Wang’s suspected killer. It is unknown whether he was ever charged.
The Shooter
The man authorities suspected of shooting Wang, or ordering his killing, was described in the documents as the head of the Fukienese Flying Dragons in Boston. Police said he was an undocumented immigrant from Fujian Province who ran a sex trafficking ring.
A redacted note in the Sharon Police Department murder file references Wang’s suspected killer as “a player” in the Chinatown Massacre, an infamous 1991 case in which five men were shot dead in a basement gambling parlour in Boston. In another note in the case file, investigators wrote that he was “thought to be a federal informant”.
The name of the gang boss was redacted in the police file released to Bellingcat.
Keating said Wang’s identity was confirmed by DNA and that blood evidence, corroborated by witness statements, placed his killing in the Boston Chinatown apartment. The retired Sharon detective said at that point, the Boston Police Department and the Suffolk County District Attorney’s Office should have, respectively, taken over the investigation and prosecution of the case.
The Boston Police Department did not respond to questions from Bellingcat. It does not include the killing in its list of unsolved homicides.
The Suffolk County District Attorney’s Office said it did not have records for Wang’s murder. “Unfortunately, after a thorough search with assistance from our homicide unit, no responsive records could be located,” it said.
In response to Bellingcat’s original public records request, the Norfolk County District Attorney’s office, which covers Sharon, said the files were exempt from public disclosure because they pertained to “an active and ongoing criminal investigation”.
A spokesman for the office said last week that the circumstances surrounding the remains of an adult male discovered in Sharon in April 1998 “remain under investigation” by a state police detective assigned to the Norfolk District Attorney’s Unsolved Case Unit.
The FBI confirmed that the agency assisted state and local partners in an operation investigating home invasions in the late 1990s but did not answer questions about Wang’s murder or his suspected killer. “Given that we’re not the lead, we’ll refer you to Massachusetts State Police,” a spokeswoman said.
Massachusetts State Police referred questions to the Suffolk and Norfolk County District Attorney’s offices.
It remains a mystery why Wang’s killer was never charged and prosecuted for his murder. “They got away with so much. Blatantly got away with so much,” Keating said of the gang. “Killing people for these guys was like … these guys were all expendable.”
The Norfolk District Attorney’s Office encouraged anyone with any information about the case to contact the Massachusetts State Police Tip Line or the Sharon Police Department.
Melissa Zhu contributed research to this article.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
Sign up here to receive Bellingcat’s biggest investigations by email as soon as they are published. A sanctioned vessel that was previously reported to have transported weapons destined for Russian mercenaries has been traversing ports on the west coast of Africa since March, exhibiting what experts told Bellingcat was an unusual set of movements and behaviours. Patria (IMO: […]
Sign up here to receive Bellingcat’s biggest investigations by emailas soon as they are published.
A sanctioned vessel that was previously reported to have transported weapons destined for Russian mercenaries has been traversing ports on the west coast of Africa since March, exhibiting what experts told Bellingcat was an unusual set of movements and behaviours.
Patria (IMO: 9159921) has been sanctioned by the US, Ukraine and Canada.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
Radio France International (RFI) reported last year that it was one of two ships to deliver weapons to Conakry in Guinea that were intended for the Kremlin-controlled Africa Corps and their operations in Mali.
Satellite imagery and Automated Identification System (AIS) data from Lloyd’s List Intelligence shows Patria has shuttled between the Port of Douala in Cameroon and the Port of Owendo in Libreville, Gabon four times since March.
It has also twice stopped in anchorage off the coast of Lagos, Nigeria: first in March and then again at the time of publication. Analysis shows the vessel also spent time in anchorage off the coast of Equatorial Guinea.
The online news site, Modern Ghana, first reported Patria’s presence off the coast of Lagos in July after X-users @SONNAROW_OSINT and @RFNOSBlog picked up on Patria’s position.
It is not clear what Patria has delivered or picked up at these ports. Nor is it clear why it has spent so long going back and forth between them. But experts Bellingcat spoke to said the unusual patterns of behaviour raised numerous questions.
Charlie Brown, a former US Naval Officer and Senior Advisor at United Against Nuclear Iran said the combination of Patria’s repeated regional port calls, extended periods at anchor, and an apparent absence of a normal point-to-point trading cycle warranted scrutiny, especially as the ship is under sanction and is previously reported to have shipped arms.
Tracking the Patria
Patria is a cargo vessel that has a distinct shape and features. Its bridge is located on the bow and it has a bright red deck that contrasts with its blue hull and two yellow cranes.
At the end of the deck, the ship has a built-in ramp for vehicles (the Patria is a so-called roll on/roll off, or RoRo, vessel that is designed to transport wheeled vehicles). Its chimney is located next to the ramp.
Footage of the Patria, posted on Youtube on Jan 22, 2024. Credit: Hanro Shipping – Sakhalin Projects LLC / YouTube Channel @hanroship
This, in combination with the length of the ship (101 m), allowed Bellingcat to pick the vessel out in satellite imagery. AIS data helped us further track its long journey which began in the Sea of Japan, in Russia’s far-east, in January.
For the most part, we were able to match Patria’s AIS position with corresponding satellite imagery. We found no evidence of obvious spoofing incidents (where a ship intentionally broadcasts misleading AIS data) by the vessel during its months-long voyage, however, there were some instances where satellite images were not available and thus spoofing by the vessel cannot be completely ruled out.
AIS data indicates that Patria loaded at the Port of Olga in the Sea of Japan between Jan. 21 and 23. Patria can also be seen on satellite imagery on these dates.
AIS data indicates that Patria unloaded some cargo in the Port of Douala between Mar. 11 and 12. Again, the ship can also be seen in satellite imagery on these dates.
AIS data indicates Patria anchored off the coast of Lagos from Mar. 14 to 15.
A Sentinel-2 image from the 15th appears to show another ship next to Patria. AIS data indicates that this is JS Gratitude, a bunkering tanker. This close proximity suggests that Patria was refuelling.
AIS data and satellite imagery indicate Patria stayed at the Douala Anchorage from Apr. 6 to 14, before unloading at the Port of Douala between Apr. 14 and 18.
AIS data suggests Patria loaded in Libreville again between Apr. 22 and 26.
Port of Douala, Cameroon
AIS data, supported by satellite imagery, indicates Patria stayed at the Douala Anchorage for nearly a month from Apr. 27 to May 21 before unloading in Douala from May 21 to 27.
A third trip between the Port of Owendo, Libreville to Douala, Cameroon
AIS data indicates, after nearly a month’s wait in Douala anchorage, Patria again loaded at Owendo before returning to Douala to unload.
A fourth trip between the Port of Owendo, Libreville to Douala, Cameroon
AIS data indicates Patria again loaded at Owendo before returning to Douala to unload.
Lagos Anchorage, Nigeria
AIS data indicates, after a short visit to the Libreville anchorage, Patria anchored off the coast of Lagos where it remained at the time of publication.
We reviewed the draught of the ship at each port visit and found that the ship’s draught always dropped after a stay at the Port of Douala, suggesting it was unloading there.
A ship’s “draught” is the distance from the bottom of the hull (the keel) to the waterline. When loaded, a ship is heavier and sits lower in the water (e.g. a draught of six metres) than when it is unloaded (e.g. a draught of four metres).
Draught is the depth of a ship below the waterline.
In the period from March to July, the Patria made five port calls to Douala and each time the draught decreased. Conversely, it called four times at the Port of Owendo in Libreville, each time the draught increased, meaning the ship became heavier, suggesting it was loading.
The draught is self-reported by ships but usually when it arrives at ports this kind of data is checked – reporting accurate draught is also a safety issue for ships arriving and departing at ports.
Bellingcat asked the ship’s owners, managers and both ports if items were being transferred from Libreville to Douala but did not receive a response at time of publication.
Brown, the former US Naval Officer and now a Senior Advisor at United Against Nuclear Iran, said Patria’s movements were unusual.
“A sanctioned vessel linked to a prior military logistics shipment spending nearly six months operating between a small cluster of West African ports, Douala, and Owendo, without returning to a clear commercial trading pattern warrants scrutiny,” Brown told us.
“While innocent explanations such as mechanical issues, commercial disputes, lack of cargo, chartering delays, or prolonged maintenance are possible, the combination of repeated regional port calls, extended periods at anchor, and an apparent absence of a normal point-to-point trading cycle is atypical for a merchant vessel.”
He added that the current period of more than 30 days at the Lagos Anchorage, in particular, is noteworthy.
David Soud, Head of Research and Analysis at I.R Consilium also told Bellingcat that Patria’s prolonged Lagos Anchorage could have innocent explanations such as its need for ongoing repairs, or that its operators were out of money, but added that there could also be more calculated reasons and it was laying low for a while.
Bellingcat analysed AIS data from Lagos Anchorage and found that while there has been high congestion, no other RoRo or container vessel waited longer than 10 days to enter the port in the period that Patria has been at Lagos Anchorage. At time of writing, Patria has been in anchorage for more than 30 days.
Regarding the Patria’s apparent deliveries of cargo between Libreville in Gabon, and Douala in Cameroon, Soud told Bellingcat:
“Given the vessel’s history of transporting military equipment to African seaports for overland delivery to Russian and allied forces in the Sahel, it’s not out of the question that some form of supplies for Russian or other forces could be picked up in Gabon, whose government has developed a closer relationship with Moscow, to be discharged in Douala, which is the main entry point for goods going to Central African Republic.”
Bellingcat asked the Nigerian Ports Authority why Patria had been in anchorage for so long, whether it had applied to dock and whether the port was aware of its sanctioned status but did not receive a response at time of publication.
The ports of Douala in Cameroon and Owendo in Libreville, Gabon did not respond to Bellingcat’s requests for comment about the Patria’s visits and the cargo it was carrying.
Bellingcat also contacted the two companies connected to the vessel – Hanro Shipping and Sakhalin Shipping Company which are listed as the vessel’s owner and manager respectively in sanctions documents. We also contacted the company connected to JS Gratitude. We did not receive a response at time of publication.
Youri van der Weide, Galen Reich, Yörük Işık contributed to this report.
Cover image: Planet Lab image shows the Patria at the Port of Douala, Cameroon, on April 17, 2026. Credit: Planet Labs PBC.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
Sign up here to receive Bellingcat’s biggest investigations by email as soon as they are published. Satellite images obtained and analysed by Bellingcat show over five miles of new road constructed in Big Bend National Park in southwestern Texas, part of a US Customs and Border Protection (CBP) “Smart Wall” installation, which includes roads, barriers, […]
Sign up here to receive Bellingcat’s biggest investigations by emailas soon as they are published.
Satellite images obtained and analysed by Bellingcat show over five miles of new road constructed in Big Bend National Park in southwestern Texas, part of a US Customs and Border Protection (CBP) “Smart Wall” installation, which includes roads, barriers, lighting and cameras.
The project was paused earlier this week after pushback from local residents, politicians and environmental groups.
The roads have been built adjacent to the Rio Grande, through the river’s floodplain and riparian forest, and include construction adjacent to Cottonwood Campground, Santa Elena Canyon, and Mariscal Canyon in the National Park.
Planet Labs satellite imagery captured on August 15 and August 19 shows new roads cleared through the riparian forest around the Rio Grande in Big Bend National Park.
The map above traces the new road construction in yellow. An unannotated version of the satellite image showing the new road can be found here while a before image of the same area where no road is visible can be seen here.
The new road extends to Cottonwood Campground, one of four campgrounds in Big Bend National Park.
The road can be seen crossing the riparian forest and smaller drainages before joining the campground access road. Imagery also appears to show bright yellow construction equipment staging in the campground area, where bulldozers were previously seen.
Planet Labs satellite imagery captured on August 19 shows a new road near Cottonwood Campground in Big Bend National Park. Hover to compare to Planet satellite imagery from September 2022. Note that the removal of cottonwood trees in the campground is unrelated to CBP construction activity.
In the southernmost part of Big Bend National Park, additional new road construction is also visible near Mariscal Canyon and connecting to Talley Road.
CBP planning documents indicate that this section of the border will receive a four-to-six foot tall vehicle barrier in addition to the “smart wall” lighting and camera systems. Talley Road currently provides access to riverside backcountry campsites and hiking and boating access to Mariscal Canyon on the Rio Grande.
Planet Labs satellite imagery captured on August 18 shows a new road near Mariscal Canyon in the southernmost part of Big Bend National Park.
The map above traces the new road construction in yellow. An unannotated version of the satellite image showing the new road can be found here. A before image of the same area where no road is visible can be seen here.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
CBP Commissioner Rodney Scott described the construction activities as “survey and design work” in an August 13 statement. He also stated that CBP is “building one new access road, improving existing roads, installing detection technology, and placing vehicle barriers in limited, strategic locations.”
The Big Bend Border Patrol Sector sees the fewest migrant apprehensions of any part of the US southern border, according to CBP’s own data.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
This article is the result of a collaboration with The Sunday Times. You can find their corresponding piece here. A key leader of the Kinahan cartel who is wanted by authorities around the world and has been living in hiding in Dubai for a decade has just had his Emirates residence permit renewed. A Bellingcat […]
This article is the result of a collaboration with The Sunday Times. You can find their corresponding piece here.
The Kinahan cartel, led by Christy Kinahan (centre) and his sons Christopher Jr (left) and Daniel (right), controls one of the most powerful transnational crime groups in the world from the Emirates. Source: Supplied
A key leader of the Kinahan cartel who is wanted by authorities around the world and has been living in hiding in Dubai for a decade has just had his Emirates residence permit renewed.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
A Bellingcat and The Sunday Times review of public immigration records from the United Arab Emirates (UAE) has revealed that Christopher Kinahan Jr, the son of cartel founder Christy Kinahan, was issued with a new visa less than two weeks ago.
This is despite his status as a sanctioned individual who is the subject of a $5 million reward from the US government for information leading to his arrest.
Our analysis has also exposed the residence statuses of the crime gang’s other sanctioned leaders who remain at large in Dubai. The records include previously unknown companies where the cartel members are purportedly employed.
The US government has offered a $5 million reward for information leading to the arrest or conviction of Christopher Kinahan Jr for participating in transnational organised crime, namely narcotics trafficking and money laundering.
It comes after Christopher Jr’s older brother Daniel Kinahan lost his final appeal in Dubai last week to prevent being extradited back to Ireland. He is the second key figure of the crime group to be apprehended in the Emirates following his high-profile arrest in April.
The Kinahan Organised Crime Group is a $1.5 billion transnational network involved in drug trafficking, money laundering and arms smuggling. Investigators have connected it to Iran’s intelligence services and the Lebanon-based militant group Hezbollah.
The cartel’s senior leadership – Christy Kinahan, 69, and his sons Daniel, 49, and Christopher Jr, 45, their cousin Ian Dixon, 36, along with associates Sean McGovern, 40, Bernard Clancy, 48, and Johnny Morrissey, 66 – was sanctioned by the US government in 2022.
Christopher Kinahan Jr and his father Christy Kinahan, seen in the background of a photo posted to a Dubai restaurant’s social media in 2023.
The UAE reportedly banned the Kinahans from doing business in the wake of the sanctions and the Emiratis also claim to have frozen €200 million in Kinahan assets. However, our findings suggest the cartel is still doing business in the Emirates and its leadership has repeatedly engaged with immigration authorities in the years following the sanctions.
The visa records were accessed through publicly available UAE government websites. We entered data contained in the US government’s sanctions notice, including the gang members’ ID or passport number, birth date and nationality, to view their immigration files.
Action
in Dubai
Six of the seven key cartel figures who were sanctioned by
the US in 2022 lived in Dubai. Cartel lieutenant Sean McGovern was extradited
to Ireland in 2025 and jailed in June.
Daniel Kinahan awaits
extradition from Dubai.
Online
Immigration Records
Our open source review of immigration records shows two members
have active residence
permits. The other two have expired permits.
Chris Kinahan Jr
Active
Permit
Christopher Kinahan Jr’s residence permit was renewed on July 20
for a two-year period. His previous visa had expired in December
2024. The new residence card lists his employment as “sales
officer” at a company named Island Star Tourism.
Bernard Clancy
Active
Permit
Bernard Clancy’s most recent two-year residence permit was
renewed in January. Like Christopher Jr, Clancy’s stated
profession is “sales officer”, but for a company named Al Matn
Goods Wholesalers LLC.
Christy Kinahan
Expired
Permit
Ian
Dixon
Expired
Permit
Records for Christy Kinahan and Ian Dixon show the residence
permits associated with their available passport numbers have
expired.
Christy Kinahan
Expired
Permit
On his most recent visa, which expired on April 1, Christy
Kinahan’s listed employer is OSA Management Consultancies DWC
LLC. This firm is based at the same Dubai
address as CV Aviation Consulting Services DWC LLC,
another company reportedly
linked to the cartel.
Ian Dixon
Expired
Permit
Dixon’s employer listed on his most recent visa was Hoopoe
Sports LLC, one of the firms sanctioned by the US for being
“owned or controlled” by Dixon.
Christy
Kinahan
The UAE imposes a
fine for each day a person stays in the country after
their visa expires. A Dubai government portal shows Christy
Kinahan owes the equivalent of more than USD $1,000 for an 81
day overstay.
Ian Dixon
Dixon, whose residency expired in 2024, owes more than USD
$11,000 for an 852-day overstay.
Sanctioned
Christy
Kinahan
Dubai
Expired Permit
81 days overstay
Fine: ~$1,000
Chris
Kinahan Jr
Dubai
Active Permit
Renewed: Jul 2026
Island Star Tourism
Bernard
Clancy
Dubai
Active Permit
Renewed: Jan 2026
Al Matn Goods Wholesalers LLC
Ian Dixon
Dubai
Expired Permit
852 days overstay
Fine: ~$11,000
Daniel
Kinahan
Dubai
Sean
McGovern
Dubai > IRE
Johnny
Morrissey
Spain
Chris Kinahan Jr
Dubai
Active Permit
Residence permit for Christopher Kinahan Jr. Source: GDRFA Dubai
Bernard Clancy
Dubai
Active Permit
Residence permit for Bernard Patrick Clancy under the name
“Bernard Patrick”. Source: GDRFA Dubai
Christy Kinahan
Dubai
Expired Permit
Ian Dixon
Dubai
Expired Permit
Expired residence permits for Christy Kinahan and Ian Dixon.
Source: GDRFA Dubai
Christy Kinahan
Dubai
Expired Permit
Expired residence permit for Christy Kinahan. Source: GDRFA
Dubai
Ian Dixon
Dubai
Expired Permit
Expired residence permit for Ian Dixon. Source: GDRFA Dubai
Screenshots of fine records for Christy Kinahan and Ian Dixon.
Source: GDRFA Dubai
Screenshots of fine records for Christy Kinahan and Ian Dixon.
Source: GDRFA Dubai
*Bellingcat searched the Dubai government’s identity and foreign affairs portal by inputting data about the
cartel’s leadership that was contained in the US government’s sanctions notice. Searching the gang
members’ ID or passport number, birth date and nationality returned a
“Unified Number”, a unique identifier assigned to every UAE visa holder.
This number, when entered with the other identity information on a UAE federal government portal, returned
the visa holder’s current status, history and file number.
Roy McComb, a former deputy director of the UK’s National Crime Agency, told The Sunday Times it was preposterous to suggest that the UAE did not know the visa status of the cartel members in Dubai.
“How is Christy Kinahan in the UAE unlawfully and the authorities there are unwilling to take appropriate action? The Kinahans are not an unknown entity, they are at the very apex of organised crime,” he said. “For the UAE not to know their residency status beggars belief.”
David Haigh, a British solicitor who was imprisoned on fraud charges in Dubai and now assists victims of abuse in the region, said it was clear the cartel must be paying off officials. “If someone is living openly there for a long period of time with that level of heat, that to me shows there’s been corruption involved,” he said. “If they were using false passports to enter Dubai, that’s a serious federal offence.”
Daniel and Christy Kinahan – nicknamed “The Dapper Don” – at a Dubai sports arena last June. Source: WeCaptureYou, TrillerTV
The passport details publicly listed in the US sanctions provide an unprecedented glimpse into the timeline of the cartel leadership’s visa history, giving an overview of their initial entry and exit to the Emirates.
The records show that four of the six key gang members had entered the UAE long before the 2016 attempt on Daniel Kinahan’s life in Dublin and the ensuing deadly feud that led to the cartel’s full relocation to the UAE.
A passport number for Christopher Kinahan Jr is linked to short-term UAE visas issued as early as September 2013. A passport number listed for Daniel Kinahan, searched in combination with an alternative sanctions-listed date of birth that is not his real one, returned seven short-term UAE visas between 2013 and 2015. It is not known what name this passport was under, but Daniel Kinahan has reportedly held illegitimate passports in the past.
A short-term visa for details associated with Ian Dixon first appeared in 2015. Authorities allege that Dixon acted as a trusted lieutenant to Daniel Kinahan by helping move bulk cash across Europe, arranging payments and keeping tabs on money owed by a narco-trafficker. In June, we revealed that Dixon was the poster boy for a padel club in Dubai, where he has been captured playing the racquet sport on webcams.
Left: Ian Dixon has been sanctioned by the US Treasury as part of its action against the Kinahan cartel. Right: Dixon at a racquet sports event post-sanctions. Source: US Treasury, sanddune_padel_dxb / Instagram
The earliest visas found for details associated with Sean McGovern and Bernard Clancy were from March and April 2016 respectively, the months after the 2016 attack in Dublin.
All key members of the group, with the exception of crime boss Christy Kinahan, gained residency in the UAE using Irish passports. The cartel founder’s British passport number is linked to his immigration file; both to his latest residence permit and four previous temporary visas. Records show the first visa associated with this passport was issued in February 2007 – the earliest known instance of Christy Kinahan entering the UAE. Another was issued in November 2009, and then two more in 2017.
However, details for an Irish passport under one of Christy Kinahan’s aliases (“Christopher O’Brien”) return 31 separate records on the UAE’s visa inquiry portal between 2014 and 2017. Bellingcat confirmed this passport number was associated with the name Christopher O’Brien after discovering both in corporate documents for a now-defunct Hong Kong firm that was incorporated in February 2014. This suggests Kinahan may have been using a false passport to travel to and from the UAE in addition to traveling under his authentic document. A man was jailed in 2023 after admitting he supplied “fraudulently obtained genuine passports” to criminals, including Kinahan.
Details from sanctions against Christy Kinahan were found on publicly available corporate documents of a defunct Hong Kong firm (passport number blurred by Bellingcat). Source: US Treasury, Hong Kong Companies Registry
One short-term UAE visa issued for “Christopher O’Brien” ended on August 19, 2015. Posts on LinkedIn three days later showed Christy Kinahan – wearing black-framed glasses and named in the posts as “Christopher O’Brien” – surrounded by Iranian and Turkish businessmen in a high-rise company office in Ankara. These images, discovered by Bellingcat in posts under the name of the managing director of a now-defunct Turkish investment company, have since been deleted.
LinkedIn posts from August 2015 showing “Christopher O’Brien”, a.k.a Christy Kinahan, in an office in Turkey.
According to the Dubai government, employment-based residence visas are valid for two years and must be obtained by a company on its employee’s behalf. The employer is required to apply for a work permit through the UAE’s Ministry of Human Resources and Emiratization. The employee must pass a fitness test before their employer can apply for the residence permit.
The company names on Clancy and Kinahan Jr’s residence permits, Al Matn Goods Wholesalers and Island Star Tourism respectively, match existing firms in Dubai. However, Bellingcat was unable to confirm whether these entities are the same as the ones listed on the residence permits. It is also not known why Clancy’s residence permit only includes his first and middle names (“Bernard Patrick”) while the other cartel members’ visas used their full names.
Wanted posters for Irish drugs smugglers Daniel, Christy and Christopher Kinahan Jr, released after the cartel leaders were sanctioned in 2022. Source: US Department of the Treasury
The firm named on Christy Kinahan’s permit, OSA Management Consultancies, is listed as an aviation consultancy on a Dubai government registry. In addition to sharing an address with cartel-linked firm CV Aviation Consulting Services, UAE company data accessed on Horizons, a platform created by Washington DC-based nonprofit C4ADS that aggregates public records, shows that both firms also have the same business licence number and date of incorporation, suggesting OSA may be a newer name for the same entity.
The managing director of Island Star Tourism told Bellingcat on the phone that Christopher Kinahan Jr was working as “commission-based staff, not in-office staff”. He confirmed he recognised Christopher Kinahan Jr’s name but said he had never met him. Asked how the company name appeared on his visa, he said “I don’t know”. He said if the UAE had any problem with Christopher Kinahan Jr, it would “not give permission”.
Al Matn Goods Wholesalers and OSA Management Consultancies did not respond to questions from Bellingcat.
The UAE foreign ministry has been approached for comment.
Connor Plunkett, Peter Barth, Beau Donelly and John Mooney contributed to this article. Scroll-driven interactive by Connor Plunkett and Miguel Ramalho.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
Football fans wagered more than US $14 billion on the FIFA World Cup through prediction markets Polymarket and Kalshi, a Bellingcat analysis has found. On the crypto-based Polymarket, which provides more information about individual trading accounts than its rival American site Kalshi, we also found that just 1% of users collected the vast majority of […]
Cristiano Ronaldo during Portugal’s losing game against Spain earlier this month. Source: Imagn Images via Reuters Connect
Football fans wagered more than US $14 billion on the FIFA World Cup through prediction markets Polymarket and Kalshi, a Bellingcat analysis has found.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
On the crypto-based Polymarket, which provides more information about individual trading accounts than its rival American site Kalshi, we also found that just 1% of users collected the vast majority of winnings during the tournament.
Users traded on almost 60,000 outcomes across both sites during the competition, betting on everything from the sponsor of the Golden Boot winner to whether Cristiano Ronaldo would shed a tear during a Portugal match.
The World Cup, held in the US, Canada and Mexico over June and July, was forecast to be the biggest betting event in history, with a predicted $50 billion in wagers.
Unlike traditional sports betting sites, prediction markets resemble stock exchanges where users trade, via an order book, on whether a real-world event will happen. Prices fluctuate based on what the market believes the probability of that event is. The sites charge fees on each sports trade.
With 48 teams playing 104 games, the World Cup was slated to be the biggest gambling event of all time. Source: Polymarket
The prediction market industry has faced criticism over its vulnerability to insider trading, potential market manipulation and concerns about fueling unregulated gambling. The Wall Street Journal also reported in May that a small number of individuals using algorithmic trading models were taking home an outsized share of winnings.
This would appear to align with Bellingcat’s World Cup analysis, where a small percentage of accounts made most of the winnings. However, the level of detail we were able to obtain did not allow us to see accounts that had utilised algorithmic methods.
Both Polymarket and Kalshi make events and volume data available for programmatic extraction – making it useful for open source analysis. Bellingcat’s data analysis examined all 104 matches as well as the World Cup winner event that was hosted on each platform.
On Polymarket, users traded a total of $10 billion ($5.7 billion on individual games and $4.3 billion on which country would win). The largest game on Polymarket was the Spain vs Argentina final ($212 million), followed by the France vs Spain semi-final ($165 million) and the England vs Argentina semi-final ($142 million).
On Kalshi, users traded a total of more than $4.3 billion ($4.1 billion on the games and $200 million on the winner).
Bellingcat’s analysis also found that 1% of Polymarket trading accounts collected 86% of all winnings during the World Cup, and the bottom 50% of winners shared just 0.1% of profits. The typical winning account on Polymarket made $21, while the typical losing account lost $32 (measured by the median, which is less affected by a handful of exceptionally large wins and losses). More than 12% of traders (14,500) who bet on two or more games lost every bet. The Polymarket account that won the most across all games made a profit of more than $13 million, while the biggest loser lost $11.6 million.
We were unable to run the same win-loss analysis for Kalshi because trading account overviews are not publicly available.
The top teams, by trading volume, across both sites were Argentina ($1.068 billion), Spain ($876 million) and France ($836 million). The top players were Argentina’s Lionel Messi ($40 million), France’s Kylian Mbappé ($36 million) and Norway’s Erling Haaland ($16 million).
How We Calculated the Volume
Polymarket displays the actual traded volume on its site, the total US dollar amount of shares bought and sold since the market started.
Kalshi does not display the traded volume. Instead, it shows the notional volume, which counts every contract traded at the maximum payout value of $1. This means that a token bought for $0.20 will be presented as $1 extra in a user’s displayed volume. This makes the total monetary volume appear higher on Kalshi’s website. To achieve a fair comparison between both platforms, we implemented a heuristic to reconstruct Kalshi’s markets’ volume. We used the daily average price for each market over their duration and multiplied it by the number of contracts traded on that day, the sum of which gives us the values used in this piece. We applied this formula for the more than 21,000 World Cup markets.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
Bellingcat has geolocated footage showing Shahed-136 type kamikaze drones in operation in Mali. Defence Blog and France 24 previously published reports that these drones were being deployed on the battlefield in northern Mali. But Bellingcat and Jeune Afrique subsequently verified two recent strikes using geolocation, satellite imagery and expert analysis to provide some of the […]
Bellingcat has geolocated footage showing Shahed-136 type kamikaze drones in operation in Mali.
Defence Blog and France 24 previously published reports that these drones were being deployed on the battlefield in northern Mali. But Bellingcat and Jeune Afrique subsequently verified two recent strikes using geolocation, satellite imagery and expert analysis to provide some of the clearest open-source evidence to date documenting their deployment.
The two strikes took place in the villages of Inafarak on July 12 and Talahandak on July 17. While the available evidence does not allow the exact variant to be identified, experts told Bellingcat it is quite likely the drones were manufactured in Russia given the deployment of the Kremlin-controlled Africa Corps group and the broader pattern of Russian military support to Mali.
Leo Jarry, a drone expert with Tungsten Strategies, told Bellingcat: “If the drones are Russian manufactured, they represent a visible demonstration of Russian support for Mali.”
Reports that Russian drones had been used in Mali first emerged in May, when Defence Blog published photographs of drone wreckage from strikes near the town of Savare.
Earlier this month, France 24 also identified debris from several Russian drone systems in Mali, pointing to an expanding Russian drone presence in the country. Until now, however, there has been no verified footage showing how Shahed-136 type drones in flight and hitting targets.
Mali has been mired in conflict since a rebellion erupted in the country’s north in 2012. In recent years, Russian forces, first through the Wagner Group and now through its successor, Africa Corps, have supported the Malian Armed Forces (FAMa) in operations against Tuareg rebel groups and jihadist organisations
Inafarak – July 12, 2026
On July 12, footage showing the aftermath of a drone strike in the village of Inafarak was published on X.
Bellingcat geolocated the footage to the town, which is close to the border with Algeria (21.32330, 0.72980) using satellite imagery. We confirmed the location by comparing a post-strike satellite image captured on July 15 with imagery from 2024. The comparison shows several buildings that were standing in 2024 had been destroyed by July, 15, 2026. This damage was consistent with that visible in the geolocated footage. The strike appears to have hit a commercial facility, with a damaged truck and numerous damaged fuel drums visible.
A geolocation diagram showing satellite imagery (top) and a screen grab from footage (bottom) that allowed us to match the site of the strike to Inafark. Satellite Image credit: Planet Labs PBC. Social footage from @EypeMohamedn.
One of the videos shows the remains of an engine which appears consistent with an MD-550, a distinctive four-cylinder two-stroke engine which is found on the Shahed-136 family of drones. We showed the image of the engine to two weapons researchers – Trevor Ball, an independent weapons expert and former Bellingcat investigator, and Leo Jarry, a drone expert with Tungsten Strategies – who said the engine is consistent with the Shahed-136 family of drones.
The component also closely matches reference imagery of MD-550 engines published by the Open Source Munitions Portal (OSMP), an expert-reviewed database of documented weapons remnants, and on the war & sanctions component database.
Left: Screengrab showing the MADO MD-550 engine found in Inafarak. Source: X/@EypeMohamedn. Right: Verified comparison image showing a MADO MD-550 engine. Source: OSMP.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
The footage we found on X was also republished by the Wagner- and Africa Corps-affiliated Telegram channel “White Uncles in Africa”, which regularly shares racist memes and graphic posts and which Bellingcat has previously reported on.
The channel captioned the videos: “Now the Azawadi ‘khokhols’ will be seeing Gerans all the time.” The use of “Geran” refers to a Russian-manufactured version of the Shahed-136. The post also uses the derogatory Russian slur “khokhol” for Ukrainians and applies it to people from Azawad, the name used by Tuareg separatists for northern Mali.
Talahandak – July 17, 2026
On July 17, graphic footage showing the aftermath of another Shahed-136 type drone strike was posted on X, showing one casualty as well as a burning truck. An additional video of the burning vehicle shows what appear to be bottles of cooking oil spilling from the truck indicating it may have been a commercial truck.
Bellingcat geolocated these videos to the village of Talahandak (20.26369, 1.80095), which is also close to the border with Algeria but around 100 miles southeast of Inafarak, by matching the surrounding buildings to satellite imagery.
A geolocation diagram showing satellite imagery (top) and a screen grab from footage (bottom) that allowed us to match the site of the strike to Talahandak. Satellite Image credit: Planet Labs PBC. Social footage from X/@mahmoud_sahara.
Shortly afterwards, a Wagner-affiliated X account claimed that the drone responsible for the strike had been shot down by rebels before hitting the truck. The post showed one video where a Shahed-type drone could be seen in flight.
We were able to geolocate where the footage that captured the drone’s final moments before impact was filmed to another area of Talahandak, nearly a kilometer away (20.266907, 1.792656) from the video that showed the impact site.
Geolocation diagram showing satellite imagery (right) and footage (right) showing Shahed-136 type drone in flight, using high-resolution Planet satellite image from July 23, 2026.
A distinctive smoke plume can be seen rising from the sight of impact in several other videos posted online shortly after the strike.
Bellingcat geolocated each of these videos and matched the plume of smoke adding further confirmation that the footage showing the drone in flight is authentic.
The video shows the drone descending directly towards the location where the person and truck were hit, and there appears to be no interception before impact.
The Shahed-136 is a series of long-range one-way attack drones originally developed in Iran and now also manufactured in Russia. Unlike the drones typically used by Mali’s Armed Forces- the Bayraktar TB2 , which launch relatively small precision-guided munitions before returning to base, one-way attack drones are designed to explode on impact, allowing them to attack over longer distances given they do not require recovery.
Leo Jarry, a drone expert with Tungsten Strategies, told Bellingcat that the drone provides Africa Corps and FAMa with an “expendable, cost-effective” long-range strike capability, allowing them to engage targets in Mali’s far north beyond the effective reach of the Bayraktar TB2. “The fact that these systems are relatively cheap and expendable changes the risk calculation for operators,” Jarry said. “They can be used more freely, potentially forcing insurgents in northern Mali to adapt their behaviour to a new aerial threat.”
However, Jarry said the system is inherently less precise than the Bayraktar TB2 because it cannot verify its targets during flight. Instead, it relies on separate surveillance assets to identify and track targets before launch. “In Mali, where armed groups are highly mobile and frequently operate among civilian populations, any gap between target identification and impact creates a risk of striking the wrong target.” Combined with the drone’s larger warhead, this increases the potential for civilian harm when employed in or near populated areas.
From Ukraine to Sahel
In Ukraine, Russian forces have used Shahed-136 type drones extensively in long-range strike campaigns that have repeatedly targeted civilian infrastructure, causing civilian casualties. Their appearance in Mali raises the possibility that the operational practices associated with these weapons are also being exported to this conflict.
Malian forces and Africa Corps currently face mounting pressure in northern Mali following a series of rebel offensives. Fighting has intensified in recent months, with rebels capturing several military bases and reportedly inflicting heavy losses on both FAMa and Africa Corps.
Jarry told Bellingcat that the relatively low cost and expendable nature of these new drones make them well suited to retaliatory strikes following attacks by rebels.
Bellingcat’s Carlos Gonzales contributed to this report as well as the following members of Bellingcat’s volunteer community: Nicole Kiess, Afton Briones, Riccardo Giannardi and Ziyu Wan.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
This investigation is a collaboration between Bellingcat and New Zealand news site The Press. You can read The Press’ piece here. Content warning: This article discusses non-consensual sexually explicit content and child sexual abuse material. In 2024, a former track and field coach in Boston, Massachusetts, was sentenced to five years in jail for attempting […]
This investigation is a collaboration between Bellingcat and New Zealand news site The Press. You can read The Press’ piece here.
Content warning: This article discusses non-consensual sexually explicit content and child sexual abuse material.
In 2024, a former track and field coach in Boston, Massachusetts, was sentenced to five years in jail for attempting to trick and extort more than 100 women, including student-athletes he coached, into sending him intimate photos.
According to the 2021 criminal complaint, Steve Waithe stole photos from some of the student-athletes’ phones under the pretence of “filming their form” at practices and meets. He also approached some victims via fake online accounts, telling them he had found their images on a forum site called “leakedbb.com” (“LeakedBB”) and offering to help them remove these photos if they provided more images for “reference”.
Authorities said Waithe also hired and paid another man in October 2020 to hack into the Snapchat accounts of women he coached or had other relationships with in an effort to steal and distribute nude images online.
In one post, according to the US Attorney’s Office, Waithe wrote: “Does anyone want to trade nudes? I’m talking girls you actually know. Could be exes or whatever. I have quite a few and [am] down to trade over snap[chat] or something.”
Legal documents do not name the sites on which Waithe distributed these images, but Bellingcat found a cached version of a November 2020 post with that exact wording on LeakedBB – the same site he allegedly used to try to trick victims. Another cached LeakedBB thread posted a few months later shows the same user offering to trade nudes of athletes, including “a lot that I actually know”.
Screengrab from LeakedBB, showing a user asking to trade nudes of “girls you actually know”; redaction by Bellingcat
Such posts were not unusual on the site: multiple archived pages show the forum’s users either requesting Snapchat hacks or offering to help others hack Snapchat accounts, sometimes for a fee.
In the criminal case against Waithe, the ownership of LeakedBB is never discussed, but a Bellingcat investigation can reveal that payment streams, company records and website domain information appear to lead back to one individual: Jitendra Maharaj, a Christchurch-based former pilot and co-founder of a cryptocurrency start-up, Pay It Now (PIN), which reportedly billed itself as the “Stripe of crypto payments”.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
Our New Zealand publishing partner The Press sent an email to Maharaj on June 4 outlining our findings in detail and inviting him to respond. Maharaj did not reply to this.
However, by June 6, LeakedBB was down. As of publication, the website remains inaccessible.
The Press later received an email from a Christchurch-based lawyer representing Maharaj, who said their client was in Fiji for a family member’s funeral. The lawyer requested that we wait until his return on June 23.
When The Press visited his residence – a two-storey family home in Christchurch’s affluent Aidanfield suburb – on June 25, Maharaj said he did not know who was behind LeakedBB or operated it and that he was not sure if the website was down.
He said he did not respond to the email queries and had not spoken to his lawyers about them because “all the evidence against me just sounded really weird” and it seemed like there was “some kind of targeted attack out on me” based on “manufactured evidence or something that’s pointing me to this garbage”. However, he refused to comment on the record about most of the specific evidence linking him to the site and referred these questions to his lawyer.
He also claimed that he had been contacted by people “trying to harass me to get me to send them money”, but declined to provide details on the record.
Jitendra Maharaj at the entrance of his residence on June 25, 2026. Source: Iain McGregor/The Press
Despite a further extension of the deadline until July 6 – more than a month after we first reached out – Maharaj and his lawyer had not provided any statement directly addressing the specific evidence linking him to the site as of publication.
PIN, the company Maharaj co-founded, did not respond to The Press’ requests for comment. However, there is no suggestion that PIN has any knowledge of or involvement in LeakedBB.
Profiting Off ‘Leaks’
LeakedBB was set up in 2019 and built a sizeable following over the next seven years, averaging an estimated two million visits a month from March to May this year. The board statistics shown on LeakedBB’s homepage in May displayed 2.2 million registered users and more than 2.6 million posts.
Screengrab of the board’s statistics as of May 26, 2026; personal information redacted by Bellingcat
Google’s Transparency Report shows it received more than 95,000 individual requests for over 350,000 pages on LeakedBB to be delisted from search results. This resulted in Google de-listing more than 169,000 pages from its search results, according to the report.
Shortly after the site went offline, a Reddit post noting the outage and asking for alternatives trended in the “hot” section of a piracy subreddit, accumulating almost 700 votes in a week. In response to a question by one commenter asking what the site was, another person replied: “Not only did it have ‘onlyfans’ content, also amateur, asian, arabic, celebrity and other hacked phone/icloud content from other sites.”
This comment accurately summarised some of the content on the site. In LeakedBB’s early days, it had sections for other types of “leaked” content such as computer programmes and eBooks. But within months, the forum’s discussions were almost exclusively about pornographic images and videos that members claimed had been leaked – implying that it was non-consensual, hacked or stolen content.
The most popular section on the forum contained content that claimed to be from sites such as OnlyFans and Fansly, which, if shared without the original creators’ consent, would be a violation of their intellectual property.
Reba Rocket, co-owner and chief operating officer of Takedown Piracy, a company that helps both adult performers and private individuals remove non-consensually shared explicit media, said sites like LeakedBB cause financial harm to legitimate content creators.
“People would not shove a DVD into their coat pocket and walk out of the store – that’s something tangible that they know they’re doing something wrong, whereas watching something on the internet for free doesn’t have that same connected moral,” she said.
Other sections on LeakedBB featured threads requesting or promoting content that often appeared to show women who did not have anything to do with the adult industry, which the posts claimed were leaked, hacked or even obtained through blackmail.
One post advertised images of girls from 29 US states: “There’s names and Facebook information if you want that,” the member, “Master Leaker”, posted. “There’s also two girls that got blackmailed into sending more nudes as well!”
LeakedBB user advertising a large file of “girls from 29 different states”; personal information redacted by Bellingcat
In the “Requests” section, users shared clothed images of women or social media handles of potential victims, and asked if others had leaked content of them. In one recent post looking for a “Florida Milf”, a user wrote: “She may go by the name [redacted]. Looks like the daughter graduated from [redacted]. Anyone have content of her? Sex tapes?”
Some users also posted nude or intimate images of women they had found elsewhere, asking for help finding out their real identities. “Who is she?” or “Can anyone ID?” were some common questions in the posts.
Non-consensual intimate image sharing (NCII), colloquially referred to as “revenge porn”, is far from new. It is a known problem on Reddit, where, in 2022, a BBC investigation found “thousands” of such images being shared despite the platform’s attempts to crack down on the issue.
LeakedBB, however, seemed to take the opposite approach: instead of trying to moderate or prevent users from posting what appeared to be NCII, it sought to profit from and reward it.
Except for preview images, most of the content users shared in the “leaks” section was behind a paywall and could only be accessed with memberships costing up to US$99.99 or by redeeming credits.
The site rewarded members with credits for posting “leaked” content, as well as when other members spent credits to “unlock” their content. These credits could be used to access links that users could otherwise only view with a paid upgrade, or redeemed for cryptocurrency at varying rates (the most frequent contributors had the option to cash out the equivalent of up to $0.15 for each thread they posted).
There was also an annual Christmas contest, with last year’s total prizes worth over $4,000 in cryptocurrency for users who posted or liked the most threads.
Screengrab of a forum announcement on LeakedBB posted on Dec. 7, 2025.
Rocket said LeakedBB had “damaged many people”, including clients of her company. “Those specific clients are not in the adult industry,” she said, “but LeakedBB seemed more than happy to share their non-consensual content”.
The “leaks” were often posted with women’s purported real names, locations and social media accounts, as well as preview images showing their uncovered faces. One poster said sharing a woman’s social media details “adds to the experience”.
“For me, it makes my jerk-off sesh feel more personal, as if she’s an actual person I know rather than a moviestar/pornstar,” the post said.
Screengrab of a post where a LeakedBB user shared content of a woman, including her socials; personal information redacted by Bellingcat
There were more than 80 responses to this thread, mostly thanking the original poster for sharing the content. One of them, however, claimed to be the woman shown in the images: “Please remove this link. These photos were illegally stolen from me. This constitutes revenge porn and violates US law. Police are already involved. Not only is it illegal but just gross.”
Allison Mahoney, the founder and managing attorney at ALM Law in New York and Colorado, told Bellingcat she received calls about cases involving NCII “all the time”.
“It kind of amazes me, given the amount of media attention this has gotten over the years, that people are still engaging in this type of abuse so cavalierly,” said Mahoney, whose firm specialises in providing legal services for abuse survivors and children harmed in welfare systems.
Mahoney and Rocket agreed that sites sharing NCII often had real-world implications for victims, especially when images were posted alongside personal information, including names, contact information and professions.
“We have clients who … their children were kicked out of Catholic school, or they lost their mainstream job, or relationships ended, or families cut them off simply because content was posted online without their consent and viewed by others,” Rocket said.
Mahoney said online abuse can turn into offline abuse when victims have their personal information, like their name, profession and contact information, posted with their images. She has seen clients who had strangers show up at their homes or places of work, threatening their physical safety – a situation she said was “really terrifying”.
In July last year, LeakedBB closed a marketplace it had hosted for more than five years, which allowed users to sell leaks and services to each other. Lucifer NightStar, the administrator account on the site, said there were allegations of people selling “UA [underage] material”, which was “not something we want on [LeakedBB]”.
Screengrab of a post where Lucifer NightStar explained why the marketplace section had been shut down.
On one section of the forum, which was specifically for sharing content from other sites that hosted leaked pornographic content, LeakedBB had a disclaimer: “Please note that posting any content on any one below the legal age of 18 is against the law. We have a zero tolerance policy on such things and your account will immediately be banned / reported.”
But this warning did not appear on other sections of the forum, including those featuring threads of “amateur nudes” described as having been leaked. Some threads on the forum, which remained accessible shortly before the entire site was taken down, also described images of “young teens”.
While it is not known if those descriptions are accurate, in a recent post on Reddit a person asked for help taking down non-consensual photos they said were taken when they were a minor, hacked from Snapchat, and posted on LeakedBB, among other sites.
“I am in school to become a teacher and searched my name on google. If you go down a bit these websites come up,” they wrote. “I am so devastated and can’t believe this has happened to me.”
While speaking to The Press outside his residence on June 25, Maharaj said that when it came to publishing non-consensual pornography and child sexual abuse imagery, “It should be obvious anyone’s against that.”
Who Is Lucifer NightStar?
Lucifer NightStar was the username for the only account with the title of “Administrator” on the LeakedBB forum. This user posted FAQs for the site and almost every forum announcement throughout its history.
The URL of this account’s profile page shows the user ID (UID) of “1”. According to documentation for MyBB, a free and open source forum software that LeakedBB has credited for powering the site, the first user of the forum is assigned the UID “1” and has super administrator privileges – meaning their account cannot be deleted, banned or otherwise altered by regular administrators.
While the profile did not state the user’s location, it did show a local timestamp based on the user’s timezone settings, which matched GMT+12 – a timezone used in several countries in Oceania, including New Zealand and Fiji.
Lucifer NightStar’s recent posts generally avoid mentioning non-consensual intimate imagery, focusing on administrative updates and issues, troubleshooting and the annual Christmas contest. However, in the first few months of the forum’s existence, the user posted a thread with a “LeakedBB Exclusive” of “leaked Kiwi girls”.
One of Lucifer NightStar’s first posts on LeakedBB, sharing content described as “leaked Kiwi girls”.
In another discussion thread from 2020, Lucifer NightStar vouched for a user’s ability to “influence” another member’s ex-girlfriend to share nudes.
(Top) LeakedBB user offering their services to obtain nudes from another user’s ex-partner; (Below) A response from Lucifer NightStar vouching for this user being a “premium collector”. Personal information redacted by Bellingcat
Maharaj did not respond to The Press and Bellingcat’s question about whether he was Lucifer NightStar. However, one of the administrator’s posts led us to a clue pointing to Maharaj’s possible connection with LeakedBB.
Logica Ltd and MyBBplugins
In one post in May 2021, responding to a user reporting problems paying with Apple Pay, Lucifer NightStar shared a screenshot of what the payment screen should look like. A company name was visible in this image: “Logica LTD”.
Screenshot of a forum post by Lucifer NightStar on how to pay for a premium upgrade for LeakedBB using Apple Pay, showing the company name “Logica LTD”.
New Zealand company records show that Logica Limited was registered by Maharaj in February 2021, just months before this post. The company address is also in Christchurch, where Maharaj lives.
(Note: This is a different company from Logica Partners Limited, based in Auckland, which has no apparent connection with Maharaj or LeakedBB and is unrelated to this investigation.)
The records from the New Zealand Companies Office show that Maharaj has been the sole director of Logica Limited since its incorporation. He stated on his LinkedIn profile that he was self-employed as the CEO of Logica NZ from May 2020 to August 2021.
(Maharaj’s LinkedIn profile appears to have been deleted between June 13 and June 15, after The Press and Bellingcat’s initial enquiries and during the period his lawyer said he was in Fiji attending a family member’s funeral.)
Left: Screengrab of Jitendra’s work history from LinkedIn; right: Company registration information for Logica Limited (redaction by Bellingcat). Sources: LinkedIn, New Zealand Companies Office
But that was not the only connection to Logica Limited. On May 4, 2022, a YouTube user with the display name “LeakedBB” uploaded a video on how to pay for memberships on the site. This video was also embedded on LeakedBB’s homepage.
The video showed how users could pay by credit card. When they clicked to purchase a membership, LeakedBB would redirect them to another website to buy a digital avatar pack with a price corresponding to their selected membership tier.
After purchasing this “referral product”, users were encouraged to leave a comment and a positive rating to receive an “extra bonus month”. Archived versions of the website show view counts in the tens of thousands for some of these avatar packs.
The thumbnails of the “digital avatars” as well as their price and description, as shown in the video, were identical to those shown on the archived version of a site, logica.nz, which is recorded as Logica Limited’s website on OpenCorporates. This site also lists “Logica LTD” in its copyright information at the bottom of its landing page.
(Bellingcat last accessed a live version of the video on June 15. By July 1, we noticed that the video had been removed by the uploader.)
Left: YouTube video on how to purchase upgrades on LeakedBB. Right: Archived purchase screen of the same avatar pack on Logica.nz
In a forum thread on LeakedBB dedicated to explaining alternative ways to pay for membership, hundreds of users posted that they had just purchased the “Mystic Avatar Pack” or the “Pixel Avatar Pack” to gain access to the site. One user included screenshots of their purchase, showing the site URL to be “logica.nz”. Other users also stated that they had made the purchase on this website and were waiting to receive their upgrades.
Shared screenshot from a LeakedBB user who purchased a “Pixel Avatar” pack in exchange for membership, showing that they left a comment, like other users, on the purchase page on logica.nz. Personal information redacted by Bellingcat
This website’s landing page now displays only a note stating that it is under maintenance. However, according to archives captured by the Internet Archive, it was still selling “digital avatar packs” in March 2025.
This type of payment structure not only conceals the nature of the transaction from the payment processor (as non-consensual content violates most platforms’ terms of service), but it also hides the transactions for the user, as payments are not described as being made to “LeakedBB” on bank statements.
When asked about the links between LeakedBB and Logica Limited, Maharaj only told The Press at the doorstep interview on June 25 that “Logica was my company. I cannot say what happened there right now”.
According to the New Zealand Companies Register, Logica Limited is in good standing, with its most recent annual filing submitted by Maharaj in March 2026.
The Domain Name System (DNS) records of LeakedBB revealed another connection that seems to point back to Maharaj. Using online investigations tool DNSlytics, we viewed DNS records for the website and found that in 2020, the MX (mail exchange) record for LeakedBB.com was set to LeakedBB.net. An MX record is the mail server set up to accept emails for that domain. For LeakedBB.com, this was later changed to ProtonMail.
While the WHOIS ownership of LeakedBB.net is obscured, we found it on a list of sites that had DNS certificates issued by another site, mybbplugins.com. A DNS certificate is used to prove ownership of a domain and requires an administrator to validate that certificate.
According to WHOIS records from cyberthreat intelligence platform DomainTools, mybbplugins.com was publicly registered to Maharaj from December 2011 to February 2019, after which the registrant information was redacted.
The same site also issued a DNS certificate for a domain bearing Maharaj’s name (jitendramaharaj.com) as well as two domains that include part of his first name, jit-pay.cc and thejitshow.com. DNS certificates for these domains were issued between 2016 and 2021, according to free Certificate Transparency monitoring site crt.sh. Both “leakedbb” and the domain names linked to Maharaj’s name (i.e. “jitendramaharaj”, “jit-pay” and “thejitshow”) were also used as subdomains for mybbplugins.com, records from DomainTools show.
Another link appeared when we inspected the code of the oldest saved archive of the payment screen on LeakedBB, from November 2019, which showed a ProtonMail address associated with the PayPal form at the time with a string of seven digits as the username.
This string of seven digits is an exact match for what appears to be part of a Fiji-based phone number listed on WHOIS records for websites registered to Maharaj’s name including mybbplugins.com, from 2008 to 2011. It is unclear whether Maharaj was using this phone number in 2019, by the time LeakedBB was set up, and a different Fiji-based phone number was used with his name when the registration for mybbplugins.com was renewed in 2016.
Top: The archived HTML code for LeakedBB’s payment page, with a ProtonMail email linked to its PayPal account. Bottom: The WHOIS domain registry for mybbplugins.com, registered to Maharaj in 2011, with a phone number matching the digits to the ProtonMail email. Graphic: Galen Reich
Explore some of the links between Maharaj and LeakedBB:
Graphic: Galen Reich
From MyBB to LeakedBB
Bellingcat also found several other apparent connections between Maharaj and other applications hosting adult content.
An account with the username “Jitendra M.” has been posting on the MyBB community forum since 2008, with the account ID originally using the username “Darkmew”. An archived capture of this account’s profile information showed a date of birth and a location in Fiji.
This date of birth matches the one listed on a Facebook profile Bellingcat found under Maharaj’s name. His LinkedIn profile also shows that prior to moving to Christchurch, he worked in Nadi, Fiji, and he has listed addresses in the city for some of the domains registered to his name, as well as an email with a Fijian domain. This user also mentions that they are a pilot.
Jitendra M.’s profile bears a “former staff” label, indicating that he used to work for MyBB. A previous commit (save) of a file containing details of MyBB team members shows that the full name associated with this account’s user ID and username was “Jitendra Maharaj”, and his website was listed as jitendra-maharaj.com.
Archived versions of this site show photos and details that match those from Maharaj’s public social media profiles and interviews. For example, a 2011 capture shows that he mentioned being a pilot at a company called Pacific Sun. Pacific Sun was later rebranded as Fiji Link, and Maharaj’s LinkedIn profile, before it was deleted, stated that he worked for Fiji Link from 2009 to 2015. A blog post on the site also refers to mybbplugins.com as the author’s “newest endeavour”.
Left: Archived profile of “Darkmew”’s profile on MyBB; Right: Screengrab of information from a Facebook profile under Maharaj’s name, which has either been made private or deleted as of publication.
Very shortly after joining the MyBB community forum in Feb 2008, Jitendra M. asked about using MyBB for “warez” (an internet slang term for pirated digital content) and/or adult content. He stated that he was “interested in using it for a [sic] adult forum”.
During this time, he also posted asking about streaming videos from a server and how to use a PayPal account without a credit card for “people putting money into my account for services I provide”. In late 2008, Jitendra M. purchased a web domain, reaperscrypt.info, which Wayback Machine archives show hosted pornographic content while it was online in 2009. This domain was publicly registered to Maharaj from November 2008 to January 2010.
In 2013, he posted about selling the mybbplugins.com domain. However, as previously mentioned, Maharaj’s name was still publicly registered as the owner of the domain until February 2019, when registration data was redacted.
Top: Post by Jitendra M. about using MyBB for warez and adult sites using MyBB; Bottom: Post about selling mybbplugins.com
Bellingcat was able to view Facebook and Instagram accounts under Maharaj’s name and showing his profile picture in early May. These accounts painted a picture of a family man, with his public photos mainly showing his wife and children. His Facebook account had been either deleted or made private by May, and his Instagram account, while still active, has not been updated since 2013.
Archives of an X account using the same username as Maharaj’s Facebook and Instagram accounts also show several posts from November 2019 promoting LeakedBB.
Archived tweets from an account, using the same username as what appeared to be Maharaj’s former Facebook and Instagram accounts, which posted links to LeakedBB in November 2019. Personal information redacted by Bellingcat
The “Darkmew” username that Jitendra M. originally used was also used for a GitHub account which hosts a repository described as the “official repository for Pay it Now – PIN Token”. This account, which now redirects to an account with the username “JitMaharaj”, has also forked (or copied) two apps created by other people: one to create a subscription platform “like onlyfans.com” that uses cryptocurrency for payments; the other designed to scrape and report illicit content from LeakedBB.
Screengrabs from the “JitMaharaj” GitHub account, which forked repositories for an application designed to create a platform “like ‘onlyfans.com’, and another to report illicit content from LeakedBB.
These forked repositories were among 38 visible on JitMaharaj’s account on June 17, but by July 1 – after a June 22 query from The Press asking Maharaj whether he owned this account – there were only 25 repositories listed on this account. The two repositories mentioned above were among those removed.
Maharaj did not respond to questions about whether he owned any of the accounts or domains mentioned in this section.
‘Hiding Behind Screens’
Mahoney said that successfully removing clients’ images from platforms like LeakedBB was a time-consuming task. “Some sites, usually the sites hosted overseas, will just ignore the request and won’t take them down,” she said.
In the US, which accounted for almost half (40 percent) of LeakedBB’s web traffic in May, the Take it Down Act recently came into effect. The new federal law requires platforms to quickly remove non-consensually shared intimate imagery when it is reported.
However, there has been little discussion of the law on LeakedBB. One user asked in the “Help” forum how this act would affect the site and its members back in October 2025, but Lucifer NightStar never responded to this post.
LeakedBB user asking about the Take It Down Act
Rocket said having content removed for her US-based clients could be difficult when the platforms were based overseas: “A lot of it depends on where the platform is hosted, who runs their ad network and who is monetising – who their payment processors are,” she said.
LeakedBB accepted cryptocurrency payments through NOWPayments, a cryptocurrency payments gateway based in the Netherlands and Estonia. The purchase page for its subscription plans, which allowed users to gain unrestricted access to the site, redirected to a NOWPayments purchase screen to transfer cryptocurrency to LeakedBB.
In response to questions from Bellingcat, NOWPayments confirmed that LeakedBB’s activities violated its terms of service. The payments provider said it had deactivated LeakedBB’s account and blacklisted the platform immediately, as of June 4.
LeakedBB did have a form for people to request that their content be taken down under the Digital Millennium Copyright Act (DMCA), a US copyright law. However, this required victims to submit personal information such as a physical address and a business email address, and stated that it would reject requests that used email addresses from free services like Google and ProtonMail. Such details appear to go beyond those required for DMCA takedown requests on other sites: for example, Google only requires a first and last name, and an email address from any domain.
In one Reddit thread discussing the difficulty of removing content from LeakedBB under the DMCA, someone commented: “Some of this seems fairly standard, some of it seems like it’s designed to make people not request a takedown for fear of doxing [sic] themselves.”
On the page to submit DMCA takedown requests, LeakedBB also stated that successful requests would lead to them removing content hosted on their servers, but not links to third-party hosting providers – which is how a large portion of the content was made available to the website’s users.
In New Zealand, where Maharaj is based, posting intimate imagery without consent is illegal under the Harmful Digital Communications Act. People face up to two years imprisonment or a fine up to NZ$50,000 (US$29,200), while for a company, the fine can be as high as NZ$200,000.
Netsafe is the only approved body in the country that handles complaints under this act. The agency’s chief online safety officer Sean Lyons told The Press that the law was quite novel and other jurisdictions were “envious” when it was enacted – it was able to respond to generative AI technology that didn’t exist when it was written, and gave New Zealand courts powers to issue takedown orders, even in other countries.
Still, Lyons said the law had its limitations: it was mostly intended for use where one individual was harming another, and if the responsible party was overseas, the law’s efficacy largely relied on responsible platforms doing the right thing.
“There are times when within our process, we will have contacted platforms or hosts and they will have said, ‘Who the heck are you?’…[Or] ‘We know what we’re doing, we are quite comfortable with what we are doing, and we don’t give a stuff about what it is that you are telling us, or about New Zealand law, or about the harm.’”
Mahoney and Rocket agreed that current laws were limited in their effectiveness against sites like LeakedBB.
“The fact of the matter is there are places where … until there is an enforceable international law, that content is going to be available forever, which means there is a risk of it being shared forever,” Rocket said.
Mahoney said image-based abusers have also become more sophisticated over time: “Technology is advancing, and the law is always playing catch-up,” she said.
But she suggested that identifying those responsible for the abuse could have a deterrent effect: “The anonymity that people have hiding behind screens really contributes to this and emboldens people to act in ways that are very abusive to people.
“If people understand that there’s a risk that their identity and their bad behaviour will be revealed, the hope is that it will curtail some of this and dissuade people from engaging in this type of conduct, which is so, so harmful to the victims.”
If you are a victim or know anyone who is affected by image-based abuse, resources and support are available through StopNCII.org.
Galen Reich and Melissa Zhu from Bellingcat and Michael Wright from The Press contributed to this article.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
Bellingcat has geolocated footage circulating on social media that appears to show coffins placed in newly dug trenches following the recent deadly earthquakes in Venezuela. The site identified extends over two hectares beside an existing cemetery in La Esperanza, a town near La Guaira on the country’s northern coast. It was visited by a representative of […]
Bellingcat has geolocated footage circulating on social media that appears to show coffins placed in newly dug trenches following the recent deadly earthquakes in Venezuela.
The site identified extends over two hectares beside an existing cemetery in La Esperanza, a town near La Guaira on the country’s northern coast.
It was visited by a representative of our Latin American reporting partners who captured pictures of work ongoing at the site. They also report speaking to a resident who said that refrigerated trucks with several bodies had been coming and going.
Stills from a video published by Colombian outlet TV and showing a group of coffins in a dug trench. Source: RTV Facebook
The location matches a site identified in July 6 reports by AFP and Deutsche Welle (DW), which detailed that 150 unidentified bodies had been buried in a long row of individual graves.
AFP and DW published pictures of individual crosses and stones, quoting a resident of the town who stated that the burials were “numbered by plots and also by the code” so they could be identified at a later date.
It is not known if the coffins visible in the social media footage relate to the 150 unidentified bodies later referred to by AFP and DW, or if they are separate burials at the same general location.
Reuters also published pictures of the site on July 6 and showed video of coffins arriving on the back of flat bed trucks.
Top: A map highlighting the location of the site southwest of Catia La Mar. Bottom: Stitched frames of TikTok video showing a panoramic view of the burial site. The satellite image (inset) captured on 30 June 2026 shows a matching sector of land approximately the size of two football pitches. The land began to be cleared on 27 June 2026 next to the Municipal cemetery La Esperanza in La Guaira State. Credit: Mapcreator, TikTok. Satellite: Copernicus Sentinel data (2026), processed by ESA
More than 3,500 people are confirmed to have died as a result of the earthquakes so far. But that figure is expected to rise significantly, with the UN reporting that the death toll could reach 10,000.
Oran Finegan, Director of Forensic Action International and former Head of Forensics for the International Committee of the Red Cross (ICRC), told Bellingcat that, while it is best practice for the burial of deceased persons to take place in individual graves, it is not uncommon to see long trenches like those seen in the social media footage when there are high numbers of unidentified deceased and it is not practical to immediately provide individual graves.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
He pointed to documentation from the ICRC that details best practices in such circumstances. He also made the important distinction between common graves, where bodies are temporarily kept until identification can take place, and mass graves, where bodies are dumped clandestinely without any care or process. What is seen in the footage appears to be the former, he said. There has been no evidence of the latter.
Finegan emphasised that it was vital that burials were mapped and recorded properly during any burial process so that identification could take place at a later date. Documenting where bodies were coming from, laying each body with enough distance from each other and ensuring each coffin or body bag had a unique number was key, he said.
While it has not been possible to ascertain the exact processes being followed at or preceding burials at the La Esperanza site, media reports in nearby La Guaira have recorded complications with identification and burial processes.
According to the BBC the scale of the disaster has overwhelmed local services, forcing institutions to improvise. Some bodies were being placed outside, exposed to the sun, at a port facility in La Guaira, the BBC reported.
A further complication is that many of the bodies recovered have reportedly been unrecognisable.
One woman told the independent Venezuelan publication RunRun.es that she was sent a tag and number for a body bag that did not match the bodies of her relatives. She was then told that her relatives’ bodies had been misidentified and sent for burial at a site in the town of Los Teques.
The New York Times reported last week that overwhelmed morgues were filling with unidentified bodies, forcing authorities to consider mass burials.
The Venezuelan Attorney General’s Office, the Judicial Police and National Service of Forensic Medicine Sciences did not respond to requests for comment for this article. However, President Delcy Rodriguez has previously stated that all bodies are being processed through a forensic identification system which includes fingerprints records, photographic documentation and forensic odontology.
Rodríguez has also said that “no one will go to a mass grave”.
The President of the Venezuelan Professional Funeral Sector Association (Asoproinfu), Davenio Velásquez, stated that there is a protocol for unidentified bodies to be buried temporarily in “five hundred individual burial niches” in Caracas. He added that they will be exhumed and cremated after six months if not identified.
Finegan added that exhuming and cremating bodies prevents identification and it is not a best practice. However, he said it is important to understand local cultural and religious customs. He also added that the six-month deadline for reclaiming remains is likely unrealistically short for such a major disaster.
Identifying the Burial Site
Terrain features in the social media videos Bellingcat found are consistent with those seen beside a graveyard on the outskirts of La Esperanza, a town situated on Venezuela’s northwest coast near the La Guaira region that was significantly impacted by the earthquakes.
These features allowed us to geolocate the site seen in the footage.
Firstly, a video published on Facebook on July 1 by Colombian digital outlet RTV appears to show a large grave with approximately half a dozen coffins situated within it. The video (which we will refer to as Video 1) further shows a group of people in civilian clothes beside a truck with more coffins on the back. It was not possible to verify the contents of the coffins.
Stills from a video published by Colombian outlet TV and showing a group of coffins in a dug trench. Source: RTV Facebook
Another video (which we will refer to as Video 2) posted to Instagram by an independent creator who said it was shared by a source on the ground also shows a series of large holes on a plot of land that appears similar to the first video.
Stills from a video published by an independent creator showing trenches at a site similar to video 1. Source: eylyngenv Instagram.
Bellingcat sought to identify where these videos were taken by first searching for any other potential reference images and footage we could compare them to.
We found one video posted by a former army Colonel and now Mayor of Vargas Municipality, José Manuel Suárez Maldonado, posing beside heavy machinery as it prepared a plot of land that was due to be given to the local community as a new cemetery plot. The video was first published in June 2024.
Video 3 Major of Vargas promoting future free plots at la Esperanza town municipal cemetery back in June 2023. Credit: Instagram
By comparing the footage in the mayor’s video with the RTV and independent creator video – as well as matching landmarks visible in the mountaineering app Peakvisor – we were able to verify that all were filmed on the same plot of land.
For example, a distinctive tree formation is visible in Video 1 and Video 2, suggesting they were filmed at the same site.
Matching trees in the background of Video 1 (left) and Video 2 (right) suggests they were filmed at the same site.
Mountain features and hillsides seen in the background of Video 2 match those seen in Video 3.
Stills from Video 2 (left) and Video 3 (right) the terrain in the background in both videos appear to be the same and are consistent with a mountain ridge seen from cemetery La Esperanza. Credit: Instagram
The rocky facade of one hillside visible in Video 2 also matches what can be seen in Video 3.
Stills from Video 2 (right) and Video 3 (left) the rocky formation of the hill in the background appears to be the same.
Combined, the visual comparisons allow us to ascertain that the three videos were filmed in the same place.
We then compared the hills and mountains visible in Video 2 to what can be seen in the mountaineering app, PeakVisor. This allowed us to confirm the location just outside La Esperanza.
Comparison between the Video 2 (bottom) with a 3D landscape modeled in PeakVisor for the respective location.
Satellite imagery of this site taken on June 25 shows a patch of land that appears green, filled with vegetation. By June 27, a newly scraped area of approximately 1.5 acres – roughly the size of a football pitch – appeared in exactly the same place.
A GIF shows satellite imagery captured over the La Esperanza site on June 25, June 27 and June 29. Credit: Copernicus.
It is important to note that the recently cleared area appears to have been excavated or altered before.
Satellite imagery from 2022 and 2023 shows work being carried out in the same spot before it once again became overgrown.
However, Bellingcat identified a white marquee visible in Video 2, providing a temporal reference to show that at least one of the videos was filmed in 2026.
Thismarquee was visible in satellite imagery captured on June 27, 2026, at the exact spot visible in Video 2.
Top: GoogleEarth 3D view of the surrounding terrain. Center: Stills from video 2 stitched to build a panorama view of the site used to determine the point of view of the camera filming. A white marquee is visible in the footage. Bottom: This white marquee appears to be visible on land only on satellite Imagery from Planet captured in June 2026. Sources: GE Pro/LandSat/Copernicus/Airbus, Instagram, Planet Labs PBC.
In footage posted to TikTok on July 2 (which we are labelling Video 4) the same tent appears to be visible.
The cleared sector of land matches the shape of the work visible in more recent satellite imagery of the site.
Satellite imagery from previous years also shows that the cleared area looks slightly different when viewed from above. This allows us to be confident that the social media footage aligns with the more recent satellite imagery rather than previous years when the area was also cleared.
Stitched stills from a TikTok Video 4 posted on 2 July showing dug graves at la Esperanza Cemetery. The cleared area seen in social media footage aligns with the more recent satellite imagery rather than previous years when the area was also cleared.Credit: TikTok. Satellite (inset): Copernicus Sentinel data (2026), processed by ESA.
Bellingcat’s reporting partners contacted the Venezuelan Attorney General’s Office, the Judicial Police and National Service of Forensic Medicine Sciences, the President of the Association of Funeral Industry Professionals (Asoproinfu) but did not receive a response before publication.
Finegan, the forensics expert, said that the current death toll was likely an underestimation and authorities are expecting it to rise.
But he said that even when families are unable to immediately identify their loved ones, it was vital to ensure that the deceased are buried respectfully and in a way that preserves the possibility of future identification. This he added can bring families a degree of comfort in the most difficult circumstances.
This investigation was the result of a collaborative effort with our Venezuelan and Latin American partners: Efecto Cocuyo, Alianza Rebelde Investiga (ARI)—comprising El Pitazo, Runrunes and TalCual—and the Latin American Center for Investigative Journalism (CLIP).
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
If you’ve seen reports of a wildfire in your region and you’re looking for open source data, NASA’s fire-tracking tool is often the first place to start. It provides a heat signature and an approximate location. But detection is only the first step in understanding what’s happened. In this guide, we explore ways to analyse […]
If you’ve seen reports of a wildfire in your region and you’re looking for open source data, NASA’s fire-tracking tool is often the first place to start. It provides a heat signature and an approximate location. But detection is only the first step in understanding what’s happened. In this guide, we explore ways to analyse and report on the scale and severity of wildfires, including those in protected areas where ecosystems are often most fragile. We also examine how often fires recur in the same region over multiple seasons, helping to identify patterns in fire activity as climate change reshapes fire risk around the world.
Satellite imagery from Copernicus Browser will be used to visualise the spread of the fire, and vegetation health indices to assess burn severity. The datasets will then be combined in QGIS for more in-depth analysis. At each stage, suggestions will be offered for turning the data into clear, reportable findings.
Throughout this guide, a single case study will be used: Sicily’s Zingaro Nature Reserve. In 2025, wildfires swept across the region, destroying forests, grasslands and croplands. Located on the Capo San Vito peninsula, the reserve was so severely affected that sections remain closed today.
Visualising Scorched Earth
When investigating a wildfire, it’s important to narrow down whenit occurred and whereit spread. The Landsat and Sentinel-2 missions are well-suited to this task, providing regular free imagery of most of the Earth’s landmass.
Below are two sets of Sentinel-2 imagery showing conditions shortly before and after a fire on July 25, 2025,near Capo San Vito, Sicily. The top two images are true-colour, similar to what would be seen from an aeroplane window. The image on the top right shows an area of scorched earth on the eastern side of the peninsula, but the exact extent of the fire is difficult to determine because the colour of the ground has changed only slightly.
Satellite images of Capo San Vito, Sicily, showing before (left) and after (right) a fire on July 25, 2025. Top row: true-colour imagery. Bottom row: false-colour imagery highlighting fire damage in red. Source: Contains modified Copernicus Sentinel data 2025, processed with Copernicus Browser.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
The bottom two images are false-colour and highlight the difference between healthy vegetation and burned areas. Such imagery is possible because Sentinel-2 captures bands of light outside the visible range, a technique known as multispectral imaging. In these images, the near-infrared (NIR) band is coloured green, and the shortwave infrared (SWIR) band is coloured red. Healthy vegetation mainly reflects NIR light, so it appears green, while burned areas mainly reflect SWIR light, so they appear red.
These images were created with Copernicus Browser, a free browser-based tool from the European Space Agency for accessing and working with Sentinel imagery. It allows users to browse the Sentinel-2 catalogue by date and visualise different band combinations. You don’t need an account to use the browser, but signing in enables additional features.
If you’d like to try Copernicus Browser without further explanation, you can go straight to the false-colour post-fire image here.
To follow along step by step, first open Copernicus Browser. Then to visualise Sentinel-2 imagery:
Zoom to the desired area on the map or use the search bar (San Vito Lo Capo, north-west Sicily)
Select the date of interest (‘2025-07-27’ selected below).
Select the layer of interest (‘True color’ by default; SWIR selected below).
Screenshot of Copernicus Browser. Annotations by Bellingcat.
By identifying the last available image before the fire and the earliest image after it in which the full burn area is visible, it’s possible to establish the location and timeline of the fire.
This allows us to report the following finding: “Satellite imagery reveals the extent of the damage caused by wildfires across the Capo San Vito peninsula on Sicily’s northern coast between July 20 and July 27, 2025.”
Extra exercise: Look up a recent fire (e.g., wildfires near Penco, Chile in January 2026), navigate to the affected location and try to visualise the burned area using Copernicus Browser.
The visibly scorched area can be measured using the Area of Interest tool (highlighted below), which allows users to draw a polygon on the map and calculate the total area in square kilometres. (Once drawn, keep the polygon in the editor, as it will be used again later.)
Estimated burn area of 53.97 km2 using the Area of Interest tool. Screenshot of Copernicus Browser. Annotations by Bellingcat.
Reportable finding: “The wildfire that swept across Sicily’s Capo San Vito peninsula in 2025 burned more than 50 km2 of the peninsula, according to Sentinel-2 data.”
Repeatedly measuring the burned area over time allows you to follow the progression of a fire. This method was used by Bellingcat when covering the Etosha National Park wildfire in late September 2025.
Extra exercise: Replicate the analysis of the Etosha National Park fire from this Bellingcat article.
Assessing Burn Severity
Some fires only affect surface vegetation, while others scorch the ground and cause long-lasting damage. Burn severity can be measured using an index called the Normalised Burn Ratio (NBR).
How Does the Normalised Burn Ratio (NBR) Detect Burned Areas?
The spectral response of a material describes how reflective it is to different types of light. The graph below shows the difference between healthy vegetation and bare soil in terms of the amount and types of light they reflect.
Reflectance data reproduced from the ECOSTRESS Spectral Library using Conifer for Healthy Vegetation and Black Loam for bare soil. Graphic by Bellingcat.
By focusing on the NIR and SWIR bands, where reflectivity differs significantly between healthy vegetation and bare soil left after a burn, an index can be calculated:
NBR = (NIR – SWIR) / (NIR + SWIR)
A high NBR indicates healthy vegetation, while a low NBR indicates burned areas.
Copernicus Browser doesn’t include a default NBR layer, but it can be added via a custom script, as shown in the screenshot below:
Load the script by clicking the green circular arrows to the right of the URL.
Click ‘Apply’ (you may need to scroll down).
Alternatively, you can skip these steps and go straight to the custom NBR post-fire image here.
Screenshot of Copernicus Browser. Annotations by Bellingcat.
The NBR layer displays positive values in green (healthy vegetation) and negative values in purple (burned areas), making the boundary of the scorched area much clearer than before.
To calculate the change in NBR in Copernicus Browser, use the Statistical Information tool (a free account is required to access this feature).
Within the date selector, choose a date a few weeks or months after the fire.
Using the Area of Interest polygon, select the ‘Statistical Info chart’ icon.
Set the maximum cloud cover to around 30% using the slider in the top right.
Select a date range that captures the available data surrounding the fire (July 20-27 shown below).
Identify when the fire occurred on the graph (this will be marked by a sharp drop in the NBR, as shown below).
Hover over the points on the graph immediately before and after the fire to display the mean value.
Composite of screenshots from within Copernicus Browser.
In this example, the pre-fire image had an average NBR of 0.11 and the post-fire image had an average NBR of -0.18. The NBR decreased by 0.29, which represents a moderate burn.
Severity Level
Change in NBR
Unburned
Less than 0.100
Low
0.100 – 0.269
Moderate
0.270 – 0.659
High
0.660 or greater
Burn severity table from the US Forest Service (page 38), simplified by Bellingcat.
Reportable finding: In late July, the fire, which scorched more than 50km2 of Sicily’s Capo San Vito peninsula, was deemed moderately severe according to the US Forest Service guidelines.
Extra exercise: Find a custom visualisation script of interest from this repository and explore what it does.
Wildfires in Conservation Areas
By focusing on protected sites such as nature reserves and national parks, we can begin to assess how wildfires affect areas of high conservation value. Controlled burns are widely used in agriculture and land management, but unchecked fires in protected areas risk eroding fragile ecosystems.
The proportion of the Zingaro Nature Reserve that was damaged by the fire can be estimated by combining the NBR image created in Copernicus Browser with a dataset from Protected Planet, a global map of protected areas that includes nature reserves.
QGIS, a program for working with geographic data, is well-suited for this type of analysis. Download and install QGIS on your computer. For help with this step, refer to the QGIS installation guide.
To download the NBR image from Copernicus Browser:
With the NBR visualisation selected, click the ‘Download’ icon.
Switch tabs at the top from ‘Basic’ to ‘Analytical’.
Change the image format to ‘TIFF (32-bit float)’.
Change the image resolution to ‘HIGH’.
Change the coordinate system to ‘Popular Web Mercator (EPSG:3857)’.
Toggle the ‘Clip extra bands’ switch to the off position (see image below).
Select the ‘Custom’ layer check box (and deselect any others).
Click ‘Download’.
Wait. It could take several minutes for the image to be generated and downloaded.
Screenshot of Copernicus Browser. Annotations by Bellingcat.
Once the image has downloaded, rename it to NBR.tiff to make it easier to work with.
Next, open QGIS and click ‘New Project’ in the upper left.
Load the image from Copernicus Browser by dragging and dropping the downloaded file into QGIS.
Useful QGIS Terminology
CRS – The Coordinate Reference System describes how the world should be measured and projected. Two of the most common are:
EPSG:4326 – WGS 84, which uses latitude and longitude as the unit of measurement.
EPSG:3857 – WGS 84 / Pseudo-Mercator, which uses metres as the unit of measurement.
Raster – a type of data that uses pixels to represent information (such as satellite imagery)
Vector – a type of data that uses points, lines, and polygons to represent information (such as a burn area polygon).
Processing the NBR Image
Next, we categorise each pixel in the NBR image as burned or unburned.
Previous analysis in Copernicus Browser showed that the Zingaro Nature Reserve’s NBR value dropped below zero only after the fire (before image: mean NBR value on July 20, 0.11; after image: mean NBR value on July 27, -0.18).
We can use this analysis to set a threshold; anything below zero will be categorised as burned.
The QGIS Raster Calculator lets us apply our threshold to the NBR image and create a new layer.
Open the Raster Calculator by selecting ‘Raster > Raster Calculator…’ from the menu bar at the top.
Screenshot of the QGIS Raster Calculator. Annotations by Bellingcat
The Raster Calculator lists the raster bands available in the project. In this example, there are five. These bands are set by the custom script we used in Copernicus Browser and are numbered as follows:
Red
Green
Blue
Pixel validity (not used in this example)
NBR index
To create a new raster layer that applies our threshold on the NBR index band:
Double-click the fifth band (ending ‘@5’) to add it to the expression box at the bottom.
Add < 0 using your keyboard (shown above).
Select the ‘Create on-the-fly raster instead of writing layer to disk’ checkbox.
Click ‘OK’.
The expression NBR@5 < 0 tells QGIS to categorise NBR index values as burned if they are less than zero.
The new layer shows burned areas as white (a value of 1), and unburned areas as black (a value of 0).
Screenshot of QGIS.
Extra exercise: Download an NBR image captured before the fire. Use the Raster Calculator to create a new layer that shows burn severity.
As before, drag and drop the downloaded file into QGIS. This time, the download is a zip file and contains many PDF files as well as the geodatabase file of interest. Scroll down to the bottom of the list and select the ‘gdbtable’ file with a polygon icon on the left side (see the blue highlighted row below), then press ‘Add Layers’.
Screenshot of QGIS. Annotations by Bellingcat.
This adds the nature reserve polygon as a layer in QGIS (and gives it an arbitrary colour). The nature reserve is almost completely contained within the white burned area, indicating it was heavily affected by the wildfire.
Screenshot of QGIS.
Quantifying the Burned Area in the Nature Reserve
To measure the proportion of the nature reserve that was burned by the wildfire, we will use the Zonal Histogram tool from the QGIS Processing Toolbox to count the number of unburned and burned pixels within the reserve polygon.
Open the toolbox with ‘Processing > Toolbox’, and a pane should open to the right. In the Processing Toolbox search field, look up ‘Zonal Histogram’ and double-click the result to open the tool.
To create a new layer:
Set the ‘Raster layer’ to the threshold burn area layer (NBR@5 < 0)
Set the ‘Vector layer containing zones’ to the nature reserve polygon layer (should start with ‘WDPA_’).
Click ‘Run’
Click ‘Close’
Screenshot of QGIS. Annotations by Bellingcat.
This will create a new layer called ‘Output zones’, which is a copy of the nature reserve polygon with pixel counts added.
Select the output layer in the lower left and click ‘Attribute Table’ in the upper right. (The attribute table is a spreadsheet-like view of the data contained in a layer.)
For the output layer, there is just one row because there is only one polygon. If the layer contained many polygons, there would be many rows.
The newly calculated counts are added to the end of the table, so scroll all the way to the right. Look for fields starting with ‘HISTO_’. Here, HISTO_0 is the count of unburned pixels (value of 0), and HISTO_1 is the count of burned pixels (value of 1).
Screenshot of QGIS. Annotations by Bellingcat.
To calculate the proportion of burned area, the number of burned pixels is divided by the total number of pixels.
Proportion = 57413 / (57413 + 2195) = 0.96318…
A value of 0.96318 means that just over 96.3% of the nature reserve burned.
Reportable finding: In late July, more than 95% of the Zingaro Nature Reserve burned in a wildfire, according to Sentinel-2 satellite imagery and Protected Planet data.
Tracking Past Wildfires
To assess the significance of an ongoing wildfire, it is important to place it in historical context. How does it compare with previous fires in the same area? Is it part of a seasonal pattern, or does it represent an unusually severe event?
With coverage dating back to 2008, the European Forest Fire Information System (EFFIS) automatically maps wildfires across Europe, North Africa, and parts of the Middle East.
Fire data can be requested directly from EFFIS using web form, with results delivered by email. For ease, you can also download Bellingcat’s archived copy of EFFIS wildfire data for Italy covering 2015–2025.
For this section, it is best to open a new QGIS project.
To view and analyse historic wildfires in the Zingaro Nature Reserve using EFFIS data:
(Optional) Add the OpenStreetMap layer from the XYZ Tiles category by double-clicking it.
Load the EFFIS data into QGIS. If prompted to select a coordinate transformation, click ‘OK’ to accept the default option.
Load the Protected Planet Zingaro Nature Reserve polygon as described earlier.
Open the Vector Intersection tool by selecting ‘Vector > Geoprocessing Tools > Intersection…’ from the menu bar at the top.
Screenshot of QGIS Annotations by Bellingcat.
The Intersection tool creates a new layer containing only the fires that affected the Zingaro Nature Reserve. To create the new layer:
Set the ‘Input layer’ to the EFFIS fires layer.
Set the ‘Overlay layer’ to the Zingaro Nature Reserve polygon layer.
Click ‘Run’.
Screenshot of QGIS Annotations by Bellingcat.
QGIS functionality can be extended through plugins, including Data Plotly, which adds data visualisation tools. To install Data Plotly, open the Plugin Manager by selecting ‘Plugins > Manage and Install Plugins…’ from the menu bar, then:
Search for ‘Data Plotly’ in the available list.
Select the plugin from the search results.
Click ‘Install Plugin’ to download and install it.
Screenshot of QGIS Annotations by Bellingcat.
Once installed, open the Data Plotly panel with ‘View > Panels > DataPlotly’. The panel should appear on the right-hand side of the QGIS window.
To plot a graph of historic wildfire activity within the nature reserve, configure Data Plotly as follows:
For ‘Plot type’, choose ‘Bar Plot’.
Set the ‘Layer’ to the newly created ‘Intersection’ layer.
In ‘X field’, type “year(initialdat)”. This expression extracts the year from the fire’s approximate start date, allowing events from the same year to be grouped together.
In ‘Y field’ enter “$area/1000000”. This expression calculates the burned area within the nature reserve in square kilometres.
Note: EFFIS data provide initial and final dates for each fire, which are approximate because they depend on the availability of satellite imagery. These dates should be treated as bounds for when a fire occurred, rather than as the dates when it started and ended.
Next, switch to the Layout tab in Data Plotly:
Untick ‘Show Legend’. Only do this for simple plots where a legend is not required.
Add a title and labels for the X and Y axes.
Finally, click ‘Create Plot’ and wait a few seconds for the chart to be generated.
Screenshot of QGIS Annotations by Bellingcat.
The chart shows that the Zingaro Nature Reserve has experienced several significant wildfires over time. However, in 2025, the data show that the fire burned a larger area within the reserve than the major fires recorded in 2020 and 2017.
Bar chart showing the burned area of the Zingaro Nature Reserve between 2015 and 2025.
Reportable finding: The Zingaro Nature Reserve has experienced three major wildfires since 2015. Of these, the 2025 fire burned a larger area within the reserve than those recorded in 2020 and 2017.
The tools and methods in this guide can be applied to wildfires in many other regions. By combining satellite imagery with environmental and historical datasets, it’s possible to move beyond detection and begin to quantify a fire’s impact. In doing so, you can also place individual incidents in context, revealing whether they are part of a recurring pattern or an unusually severe event.
Merel Zoet and Claire Press contributed to this report.
This guide contains modified Copernicus Sentinel data (2025), processed with Copernicus Browser, as well as data from the European Forest Fire Information System (EFFIS) of the European Commission Joint Research Centre.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
At least 1,719 people are reported to have died after two devastating earthquakes struck northwestern Venezuela last week. The final casualty count is expected to rise significantly. Some media outlets report resident’s growing frustration with the Venezuelan government and its recovery efforts. Sky News on June 29 reported that the United Nations Coordinator for Humanitarian […]
At least 1,719 people are reported to have died after two devastating earthquakes struck northwestern Venezuela last week.
The final casualty count is expected to rise significantly.
Some media outlets report resident’s growing frustration with the Venezuelan government and its recovery efforts.
Sky News on June 29 reported that the United Nations Coordinator for Humanitarian Affairs in Venezuela was preparing for as many as 10,000 deaths.
Social media posts, news reports and drone footage have been shared in recent days, proving vital sources for many Venezuelans (both in the country and living abroad) who are searching for information about loved ones who remain missing.
Social media pages have been set up listing many of those who are yet to be accounted for. Others have contacted Bellingcat asking if apartment blocks relatives were staying in are still standing.
Bellingcat has received satellite imagery from Planet Labs PBC that shows one the worst affected areas in the country, including collapsed buildings and apartment blocks in La Guaira.
Readers can move laterally and vertically to observe the full image in the interactive below as well as zoom in on specific areas to assess the damage. A share button on the top right will copy a shareable link to the zoomed in area.
Scroll and zoom to see damage throughout the affected Venezuelan coast. Toggle between English and Spanish. Share a link to a specific location by clicking the button on the top right. The before imagery is from Jul 30, 2025 and Dec 12, 2023. After imagery is from Jun 27, 2026. SkySat imagery via Planet Labs PBC.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.
The high resolution image covers a 14-mile stretch of Venezuela’s northern coast from the towns of Catia La Mar to Caraballeda, which have been among the worst impacted.
Other areas to be significantly impacted but not included in the imagery above include Caracas, Maracay, Valencia, Barquisimeto and Yaracuy.
We have compared the satellite imagery we obtained with previous images captured before the earthquake to identify which parts of this 14-mile stretch of coastline to show changes since the quakes.
Readers can toggle between the imagery captured on June 27 (five days after the Jun. 24 quakes) and a composite of reference images taken on Jul. 30, 2025 and Dec. 11, 2023 (before the quakes).
Zooming in on specific areas reveals the scale of the damage.
For example, several buildings seem to have been flattened in the below before and after images showing the Playa Grande area.
Before imagery (left) of Playa Grande is from Feb 27, 2026. Imagery from after the earthquake (right) is from Jun 26, 2026. SkySat imagery via Planet Labs PBC.
The Planet Labs imagery also confirms significant destruction in the town of Carabelleda.
Before imagery (left) of Carabelleda is from Jun. 19, 2026. Imagery from after the earthquake (right) is from Jun 27, 2026. SkySat imagery via Planet Labs PBC.
Another area, Macuto, has been significantly impacted as well.
Before imagery (left) of Macuto is from Mar 20, 2026. Imagery from after the earthquake (right) is from Jun 27, 2026. SkySat imagery via Planet Labs PBC.
Footage taken on the ground and posted to social media also displays the devastation.
A minute-long video filmed on a 500-meter section of José María España Avenue in Carabelleda shows as many as a dozen collapsed buildings, most of them high-rises. This drone footage gives an aerial look of the destruction of at least six apartment blocks in the same area.
Other open source information about the damage in cities such as Caracas, Valencia and beyond can be found on this site where individuals are uploading images and videos detailing damage.
While international rescuers continue to arrive in Venezuela, the threat of aftershocks remains.
Reuters also reports that engineers fear many buildings that remain standing could be vulnerable and are requesting an audit of state housing.
Carlos Gonzales, Jake Godin and Miguel Ramalho contributed to this report.
Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.
Support Bellingcat
Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.