Visualização normal

Antes de ontembellingcat
  • ✇bellingcat
  • Tracking a Sanctioned Russian Vessel’s West African Odyssey Bellingcat Investigation Team
    Sign up here to receive Bellingcat’s biggest investigations by email as soon as they are published. A sanctioned vessel that was previously reported to have transported weapons destined for Russian mercenaries has been traversing ports on the west coast of Africa since March, exhibiting what experts told Bellingcat  was an unusual set of movements and behaviours. Patria (IMO: 9159921) has been sanctioned by the US, Ukraine and Canada. Support Bellingcat Your donations directly co
     

Tracking a Sanctioned Russian Vessel’s West African Odyssey

25 de Agosto de 2026, 05:52

Sign up here to receive Bellingcat’s biggest investigations by email as soon as they are published.

A sanctioned vessel that was previously reported to have transported weapons destined for Russian mercenaries has been traversing ports on the west coast of Africa since March, exhibiting what experts told Bellingcat  was an unusual set of movements and behaviours.

Patria (IMO: 9159921) has been sanctioned by the US, Ukraine and Canada.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Radio France International (RFI) reported last year that it was one of two ships to deliver weapons to Conakry in Guinea that were intended for the Kremlin-controlled Africa Corps and their operations in Mali.

Satellite imagery and Automated Identification System (AIS) data from Lloyd’s List Intelligence shows Patria has shuttled between the Port of Douala in Cameroon and the Port of Owendo in Libreville, Gabon four times since March. 

It has also twice stopped in anchorage off the coast of Lagos, Nigeria: first in March and then again at the time of publication. Analysis shows the vessel also spent time in anchorage off the coast of Equatorial Guinea. 

The online news site, Modern Ghana, first reported Patria’s presence off the coast of Lagos in July after X-users @SONNAROW_OSINT and @RFNOSBlog picked up on Patria’s position.

It is not clear what Patria has delivered or picked up at these ports. Nor is it clear why it has spent so long going back and forth between them. But experts Bellingcat spoke to said the unusual patterns of behaviour raised numerous questions.

Charlie Brown, a former US Naval Officer and Senior Advisor at United Against Nuclear Iran said the combination of Patria’s repeated regional port calls, extended periods at anchor, and an apparent absence of a normal point-to-point trading cycle warranted scrutiny, especially as the ship is under sanction and is previously reported to have shipped arms. 

Tracking the Patria

Patria is a cargo vessel that has a distinct shape and features. Its bridge is located on the bow and it has a bright red deck that contrasts with its blue hull and two yellow cranes. 

At the end of the deck, the ship has a built-in ramp for vehicles (the Patria is a so-called roll on/roll off, or RoRo, vessel that is designed to transport wheeled vehicles). Its chimney is located next to the ramp.

Footage of the Patria, posted on Youtube on Jan 22, 2024. Credit: Hanro Shipping – Sakhalin Projects LLC / YouTube Channel @hanroship

This, in combination with the length of the ship (101 m), allowed Bellingcat to pick the vessel out in satellite imagery. AIS data helped us further track its long journey which began in the Sea of Japan, in Russia’s far-east, in January.

For the most part, we were able to match Patria’s AIS position with corresponding satellite imagery. We found no evidence of obvious spoofing incidents (where a ship intentionally broadcasts misleading AIS data) by the vessel during its months-long voyage, however, there were some instances where satellite images were not available and thus spoofing by the vessel cannot be completely ruled out.

MapLibre | Protomaps© OpenStreetMap contributors

Port of Olga, Russia

AIS data indicates that Patria loaded at the Port of Olga in the Sea of Japan between Jan. 21 and 23. Patria can also be seen on satellite imagery on these dates.

Credit: Planet Labs PBC.

Port of Douala, Cameroon

AIS data indicates that Patria unloaded some cargo in the Port of Douala between Mar. 11 and 12. Again, the ship can also be seen in satellite imagery on these dates.

Credit: Planet Labs PBC.

Lagos Anchorage, Nigeria

AIS data indicates Patria anchored off the coast of Lagos from Mar. 14 to 15.

A Sentinel-2 image from the 15th appears to show another ship next to Patria. AIS data indicates that this is JS Gratitude, a bunkering tanker. This close proximity suggests that Patria was refuelling.

Credit: Contains modified Copernicus Sentinel data 2026.

Bata Anchorage, Equatorial Guinea

AIS data and satellite imagery indicate Patria stayed off the coast of Equatorial Guinea for several days.

Credit: Planet Labs PBC.

Port of Owendo, Libreville, Gabon

AIS data and satellite imagery indicate Patria loaded at the Port of Owendo in Libreville after spending a few days off the coast.

Credit: Planet Labs PBC.

Port of Douala, Cameroon

AIS data and satellite imagery indicate Patria stayed at the Douala Anchorage from Apr. 6 to 14, before unloading at the Port of Douala between Apr. 14 and 18.

Credit: Planet Labs PBC.

Port of Owendo, Libreville, Gabon

AIS data suggests Patria loaded in Libreville again between Apr. 22 and 26.

Port of Douala, Cameroon

AIS data, supported by satellite imagery, indicates Patria stayed at the Douala Anchorage for nearly a month from Apr. 27 to May 21 before unloading in Douala from May 21 to 27.

Credit: Planet Labs PBC.

A third trip between the Port of Owendo, Libreville to Douala, Cameroon

AIS data indicates, after nearly a month’s wait in Douala anchorage, Patria again loaded at Owendo before returning to Douala to unload.

A fourth trip between the Port of Owendo, Libreville to Douala, Cameroon

AIS data indicates Patria again loaded at Owendo before returning to Douala to unload.

Lagos Anchorage, Nigeria

AIS data indicates, after a short visit to the Libreville anchorage, Patria anchored off the coast of Lagos where it remained at the time of publication.

Credit: Planet Labs PBC.

Examining the Patria’s Draught

We reviewed the draught of the ship at each port visit and found that the ship’s draught always dropped after a stay at the Port of Douala, suggesting it was unloading there.

A ship’s “draught” is the distance from the bottom of the hull (the keel) to the waterline. When loaded, a ship is heavier and sits lower in the water (e.g. a draught of six metres) than when it is unloaded (e.g. a draught of four metres).

Draught is the depth of a ship below the waterline. 

In the period from March to July, the Patria made five port calls to Douala and each time the draught decreased. Conversely, it called four times at the Port of Owendo in Libreville, each time the draught increased, meaning the ship became heavier, suggesting it was loading.

The draught is self-reported by ships but usually when it arrives at ports this kind of data is checked – reporting accurate draught is also a safety issue for ships arriving and departing at ports. 

Bellingcat asked the ship’s owners, managers and both ports if items were being transferred from Libreville to Douala but did not receive a response at time of publication.

Brown, the former US Naval Officer and now a Senior Advisor at United Against Nuclear Iran, said Patria’s movements were unusual.

“A sanctioned vessel linked to a prior military logistics shipment spending nearly six months operating between a small cluster of West African ports, Douala, and Owendo, without returning to a clear commercial trading pattern warrants scrutiny,” Brown told us.  


“While innocent explanations such as mechanical issues, commercial disputes, lack of cargo, chartering delays, or prolonged maintenance are possible, the combination of repeated regional port calls, extended periods at anchor, and an apparent absence of a normal point-to-point trading cycle is atypical for a merchant vessel.” 

He added that the current period of more than 30 days at the Lagos Anchorage, in particular, is noteworthy. 

David Soud, Head of Research and Analysis at I.R Consilium also told Bellingcat that Patria’s prolonged Lagos Anchorage could have innocent explanations such as its need for ongoing repairs, or that its operators were out of money, but added that there could also be more calculated reasons and it was laying low for a while.

Bellingcat analysed AIS data from Lagos Anchorage and found that while there has been high congestion, no other RoRo or container vessel waited longer than 10 days to enter the port in the period that Patria has been at Lagos Anchorage. At time of writing, Patria has been in anchorage for more than 30 days.

Regarding the Patria’s apparent deliveries of cargo between Libreville in Gabon, and Douala in Cameroon, Soud told Bellingcat:

“Given the vessel’s history of transporting military equipment to African seaports for overland delivery to Russian and allied forces in the Sahel, it’s not out of the question that some form of supplies for Russian or other forces could be picked up in Gabon, whose government has developed a closer relationship with Moscow, to be discharged in Douala, which is the main entry point for goods going to Central African Republic.”

Bellingcat asked the Nigerian Ports Authority why Patria had been in anchorage for so long, whether it had applied to dock and whether the port was aware of its sanctioned status but did not receive a response at time of publication.

The ports of Douala in Cameroon and Owendo in Libreville, Gabon did not respond to Bellingcat’s requests for comment about the Patria’s visits and the cargo it was carrying.

Bellingcat also contacted the two companies connected to the vessel – Hanro Shipping and Sakhalin Shipping Company which are listed as the vessel’s owner and manager respectively in sanctions documents. We also contacted the company connected to JS Gratitude. We did not receive a response at time of publication.


Youri van der Weide, Galen Reich, Yörük Işık contributed to this report.

Cover image: Planet Lab image shows the Patria at the Port of Douala, Cameroon, on April 17, 2026. Credit: Planet Labs PBC.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Tracking a Sanctioned Russian Vessel’s West African Odyssey appeared first on bellingcat.

  • ✇bellingcat
  • Welcome to Dubai: Kinahan Cartel’s Visas Revealed Financial Investigations Team
    This article is the result of a collaboration with The Sunday Times. You can find their corresponding piece here. The Kinahan cartel, led by Christy Kinahan (centre) and his sons Christopher Jr (left) and Daniel (right), controls one of the most powerful transnational crime groups in the world from the Emirates. Source: Supplied A key leader of the Kinahan cartel who is wanted by authorities around the world and has been living in hiding in Dubai for a decade has just had his Emirates resid
     

Welcome to Dubai: Kinahan Cartel’s Visas Revealed

1 de Agosto de 2026, 08:03

This article is the result of a collaboration with The Sunday Times. You can find their corresponding piece here.

The Kinahan cartel, led by Christy Kinahan (centre) and his sons Christopher Jr (left) and Daniel (right), controls one of the most powerful transnational crime groups in the world from the Emirates. Source: Supplied

A key leader of the Kinahan cartel who is wanted by authorities around the world and has been living in hiding in Dubai for a decade has just had his Emirates residence permit renewed.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

A Bellingcat and The Sunday Times review of public immigration records from the United Arab Emirates (UAE) has revealed that Christopher Kinahan Jr, the son of cartel founder Christy Kinahan, was issued with a new visa less than two weeks ago. 

This is despite his status as a sanctioned individual who is the subject of a $5 million reward from the US government for information leading to his arrest. 

Our analysis has also exposed the residence statuses of the crime gang’s other sanctioned leaders who remain at large in Dubai. The records include previously unknown companies where the cartel members are purportedly employed.

The US government has offered a $5 million reward for information leading to the arrest or conviction of Christopher Kinahan Jr for participating in transnational organised crime, namely narcotics trafficking and money laundering.

It comes after Christopher Jr’s older brother Daniel Kinahan lost his final appeal in Dubai last week to prevent being extradited back to Ireland. He is the second key figure of the crime group to be apprehended in the Emirates following his high-profile arrest in April.

The Kinahan Organised Crime Group is a $1.5 billion transnational network involved in drug trafficking, money laundering and arms smuggling. Investigators have connected it to Iran’s intelligence services and the Lebanon-based militant group Hezbollah.

The cartel’s senior leadership – Christy Kinahan, 69, and his sons Daniel, 49, and Christopher Jr, 45, their cousin Ian Dixon, 36, along with associates Sean McGovern, 40, Bernard Clancy, 48, and Johnny Morrissey, 66 – was sanctioned by the US government in 2022.

Christopher Kinahan Jr and his father Christy Kinahan, seen in the background of a photo posted to a Dubai restaurant’s social media in 2023.

The UAE reportedly banned the Kinahans from doing business in the wake of the sanctions and the Emiratis also claim to have frozen €200 million in Kinahan assets. However, our findings suggest the cartel is still doing business in the Emirates and its leadership has repeatedly engaged with immigration authorities in the years following the sanctions.

The visa records were accessed through publicly available UAE government websites. We entered data contained in the US government’s sanctions notice, including the gang members’ ID or passport number, birth date and nationality, to view their immigration files.

Action in Dubai

Six of the seven key cartel figures who were sanctioned by the US in 2022 lived in Dubai. Cartel lieutenant Sean McGovern was extradited to Ireland in 2025 and jailed in June.

Daniel Kinahan awaits extradition from Dubai.

Online Immigration Records

Our open source review of immigration records shows two members have active residence permits. The other two have expired permits.

Chris Kinahan Jr

Chris Kinahan Jr

Active Permit

Christopher Kinahan Jr’s residence permit was renewed on July 20 for a two-year period. His previous visa had expired in December 2024. The new residence card lists his employment as “sales officer” at a company named Island Star Tourism.

Bernard Clancy

Bernard Clancy

Active Permit

Bernard Clancy’s most recent two-year residence permit was renewed in January. Like Christopher Jr, Clancy’s stated profession is “sales officer”, but for a company named Al Matn Goods Wholesalers LLC.

Christy Kinahan

Christy Kinahan

Expired Permit
Ian Dixon

Ian Dixon

Expired Permit

Records for Christy Kinahan and Ian Dixon show the residence permits associated with their available passport numbers have expired.

Christy Kinahan

Christy Kinahan

Expired Permit

On his most recent visa, which expired on April 1, Christy Kinahan’s listed employer is OSA Management Consultancies DWC LLC. This firm is based at the same Dubai address as CV Aviation Consulting Services DWC LLC, another company reportedly linked to the cartel.

Ian Dixon

Ian Dixon

Expired Permit

Dixon’s employer listed on his most recent visa was Hoopoe Sports LLC, one of the firms sanctioned by the US for being “owned or controlled” by Dixon.

Christy Kinahan

Christy Kinahan

The UAE imposes a fine for each day a person stays in the country after their visa expires. A Dubai government portal shows Christy Kinahan owes the equivalent of more than USD $1,000 for an 81 day overstay.

Ian Dixon

Ian Dixon

Dixon, whose residency expired in 2024, owes more than USD $11,000 for an 852-day overstay.

Sanctioned
Christy Kinahan

Christy Kinahan

Dubai

Expired Permit
  • 81 days overstay
  • Fine: ~$1,000
Chris Kinahan Jr

Chris Kinahan Jr

Dubai

Active Permit
  • Renewed: Jul 2026
  • Island Star Tourism
Bernard Clancy

Bernard Clancy

Dubai

Active Permit
  • Renewed: Jan 2026
  • Al Matn Goods Wholesalers LLC
Ian Dixon

Ian Dixon

Dubai

Expired Permit
  • 852 days overstay
  • Fine: ~$11,000
Daniel Kinahan

Daniel Kinahan

Dubai

Sean McGovern

Sean McGovern

Dubai > IRE

Johnny Morrissey

Johnny Morrissey

Spain

Chris Kinahan Jr

Chris Kinahan Jr

Dubai

Active Permit
Residency Document
Residence permit for Christopher Kinahan Jr. Source: GDRFA Dubai
Bernard Clancy

Bernard Clancy

Dubai

Active Permit
Clancy Residency Document
Residence permit for Bernard Patrick Clancy under the name “Bernard Patrick”. Source: GDRFA Dubai
Christy Kinahan

Christy Kinahan

Dubai

Expired Permit
Father Residency Document
Ian Dixon

Ian Dixon

Dubai

Expired Permit
Dixon Residency Document
Expired residence permits for Christy Kinahan and Ian Dixon. Source: GDRFA Dubai
Christy Kinahan

Christy Kinahan

Dubai

Expired Permit
Father Residency Document
Expired residence permit for Christy Kinahan. Source: GDRFA Dubai
Ian Dixon

Ian Dixon

Dubai

Expired Permit
Dixon Residency Document
Expired residence permit for Ian Dixon. Source: GDRFA Dubai
Overstay Fines Document - Christy Kinahan
Screenshots of fine records for Christy Kinahan and Ian Dixon. Source: GDRFA Dubai
Overstay Fines Document - Ian Dixon
Screenshots of fine records for Christy Kinahan and Ian Dixon. Source: GDRFA Dubai

*Bellingcat searched the Dubai government’s identity and foreign affairs portal by inputting data about the cartel’s leadership that was contained in the US government’s sanctions notice. Searching the gang members’ ID or passport number, birth date and nationality returned a “Unified Number”, a unique identifier assigned to every UAE visa holder. This number, when entered with the other identity information on a UAE federal government portal, returned the visa holder’s current status, history and file number.

Roy McComb, a former deputy director of the UK’s National Crime Agency, told The Sunday Times it was preposterous to suggest that the UAE did not know the visa status of the cartel members in Dubai.

“How is Christy Kinahan in the UAE unlawfully and the authorities there are unwilling to take appropriate action? The Kinahans are not an unknown entity, they are at the very apex of organised crime,” he said. “For the UAE not to know their residency status beggars belief.”

David Haigh, a British solicitor who was imprisoned on fraud charges in Dubai and now assists victims of abuse in the region, said it was clear the cartel must be paying off officials. “If someone is living openly there for a long period of time with that level of heat, that to me shows there’s been corruption involved,” he said. “If they were using false passports to enter Dubai, that’s a serious federal offence.”

Daniel and Christy Kinahan – nicknamed “The Dapper Don” – at a Dubai sports arena last June. Source: WeCaptureYou, TrillerTV

The passport details publicly listed in the US sanctions provide an unprecedented glimpse into the timeline of the cartel leadership’s visa history, giving an overview of their initial entry and exit to the Emirates.

The records show that four of the six key gang members had entered the UAE long before the 2016 attempt on Daniel Kinahan’s life in Dublin and the ensuing deadly feud that led to the cartel’s full relocation to the UAE.

A passport number for Christopher Kinahan Jr is linked to short-term UAE visas issued as early as September 2013. A passport number listed for Daniel Kinahan, searched in combination with an alternative sanctions-listed date of birth that is not his real one, returned seven short-term UAE visas between 2013 and 2015. It is not known what name this passport was under, but Daniel Kinahan has reportedly held illegitimate passports in the past.

A short-term visa for details associated with Ian Dixon first appeared in 2015. Authorities allege that Dixon acted as a trusted lieutenant to Daniel Kinahan by helping move bulk cash across Europe, arranging payments and keeping tabs on money owed by a narco-trafficker. In June, we revealed that Dixon was the poster boy for a padel club in Dubai, where he has been captured playing the racquet sport on webcams. 

Left: Ian Dixon has been sanctioned by the US Treasury as part of its action against the Kinahan cartel. Right: Dixon at a racquet sports event post-sanctions. Source: US Treasury, sanddune_padel_dxb / Instagram

The earliest visas found for details associated with Sean McGovern and Bernard Clancy were from March and April 2016 respectively, the months after the 2016 attack in Dublin.

All key members of the group, with the exception of crime boss Christy Kinahan, gained residency in the UAE using Irish passports. The cartel founder’s British passport number is linked to his immigration file; both to his latest residence permit and four previous temporary visas. Records show the first visa associated with this passport was issued in February 2007 – the earliest known instance of Christy Kinahan entering the UAE. Another was issued in November 2009, and then two more in 2017. 

However, details for an Irish passport under one of Christy Kinahan’s aliases (“Christopher O’Brien”) return 31 separate records on the UAE’s visa inquiry portal between 2014 and 2017. Bellingcat confirmed this passport number was associated with the name Christopher O’Brien after discovering both in corporate documents for a now-defunct Hong Kong firm that was incorporated in February 2014. This suggests Kinahan may have been using a false passport to travel to and from the UAE in addition to traveling under his authentic document. A man was jailed in 2023 after admitting he supplied “fraudulently obtained genuine passports” to criminals, including Kinahan.

Details from sanctions against Christy Kinahan were found on publicly available corporate documents of a defunct Hong Kong firm (passport number blurred by Bellingcat). Source: US Treasury, Hong Kong Companies Registry

One short-term UAE visa issued for “Christopher O’Brien” ended on August 19, 2015. Posts on LinkedIn three days later showed Christy Kinahan – wearing black-framed glasses and named in the posts as “Christopher O’Brien” – surrounded by Iranian and Turkish businessmen in a high-rise company office in Ankara. These images, discovered by Bellingcat in posts under the name of the managing director of a now-defunct Turkish investment company, have since been deleted.

LinkedIn posts from August 2015 showing “Christopher O’Brien”, a.k.a Christy Kinahan, in an office in Turkey.

According to the Dubai government, employment-based residence visas are valid for two years and must be obtained by a company on its employee’s behalf. The employer is required to apply for a work permit through the UAE’s Ministry of Human Resources and Emiratization. The employee must pass a fitness test before their employer can apply for the residence permit.

The company names on Clancy and Kinahan Jr’s residence permits, Al Matn Goods Wholesalers and Island Star Tourism respectively, match existing firms in Dubai. However, Bellingcat was unable to confirm whether these entities are the same as the ones listed on the residence permits. It is also not known why Clancy’s residence permit only includes his first and middle names (“Bernard Patrick”) while the other cartel members’ visas used their full names. 

Wanted posters for Irish drugs smugglers Daniel, Christy and Christopher Kinahan Jr, released after the cartel leaders were sanctioned in 2022. Source: US Department of the Treasury

The firm named on Christy Kinahan’s permit, OSA Management Consultancies, is listed as an aviation consultancy on a Dubai government registry. In addition to sharing an address with cartel-linked firm CV Aviation Consulting Services, UAE company data accessed on Horizons, a platform created by Washington DC-based nonprofit C4ADS that aggregates public records, shows that both firms also have the same business licence number and date of incorporation, suggesting OSA may be a newer name for the same entity.

The managing director of Island Star Tourism told Bellingcat on the phone that Christopher Kinahan Jr was working as “commission-based staff, not in-office staff”. He confirmed he recognised Christopher Kinahan Jr’s name but said he had never met him. Asked how the company name appeared on his visa, he said “I don’t know”. He said if the UAE had any problem with Christopher Kinahan Jr, it would “not give permission”.

Al Matn Goods Wholesalers and OSA Management Consultancies did not respond to questions from Bellingcat.

The UAE foreign ministry has been approached for comment.


Connor Plunkett, Peter Barth, Beau Donelly and John Mooney contributed to this article. Scroll-driven interactive by Connor Plunkett and Miguel Ramalho. 

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Welcome to Dubai: Kinahan Cartel’s Visas Revealed appeared first on bellingcat.

  • ✇bellingcat
  • Poster Boy: Sanctioned Kinahan Cartel Lieutenant Found Playing Padel in Dubai Financial Investigations Team
    This article is the result of a collaboration with The Sunday Times. You can find their corresponding piece here. https://www.bellingcat.com/app/uploads/2026/06/1aa_Vid_Top_dixon062026.mp4 Every Friday evening, the brochure says, players can compete to win cash prizes in one of the world’s fastest-growing racquet sports. The padel club in Dubai’s west is the picture of modern wellness culture: climate-controlled courts, a private sauna and ice bath, and one-on-one coaching. The promo
     

Poster Boy: Sanctioned Kinahan Cartel Lieutenant Found Playing Padel in Dubai

27 de Junho de 2026, 15:02

This article is the result of a collaboration with The Sunday Times. You can find their corresponding piece here.

Every Friday evening, the brochure says, players can compete to win cash prizes in one of the world’s fastest-growing racquet sports. The padel club in Dubai’s west is the picture of modern wellness culture: climate-controlled courts, a private sauna and ice bath, and one-on-one coaching. The promotional image shows a bearded man in mid-swing, eyes locked on the ball. He wears matching activewear and a golden tan. The poster boy for padel is a talented player who once finished runner-up at an international tournament. He has also spent the past decade living in the shadows.

Left: Ian Dixon has been sanctioned by the US Treasury as part of its action against the Kinahan cartel. Right: Dixon, who appears to live a carefree lifestyle in Dubai, at a racquet sports event post-sanctions. Source: US Treasury, sanddune_padel_dxb / Instagram, asiapacificpadeltour / Instagram

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Ian Thomas Dixon is a key figure in the Kinahan cartel, the Irish organised crime group that authorities say has evolved into a US$1.5 billion transnational network involved in drug trafficking, money laundering and arms smuggling. Investigators have connected the cartel to Iran’s intelligence services and the Lebanon-based militant group Hezbollah. Its feuds with rival gangs have been linked to at least 18 murders across four countries.

Dixon, 36, along with the Kinahan Organised Crime Group’s senior leadership – Christy Kinahan, 69, and his sons Daniel, 49, and Christopher Jr, 45 – was sanctioned by the US government in 2022. Authorities allege the Irishman acted as a trusted lieutenant to Daniel Kinahan, who is said to manage the cartel’s vast drug trafficking operation by helping move bulk cash across Europe, arranging payments and keeping tabs on money owed by a narco-trafficker.

Wanted posters for Irish drugs smugglers Daniel, Christy and Christopher Kinahan Jr, released after the cartel leaders were sanctioned along with four key associates in 2022. Source: US Department of the Treasury

Bellingcat and The Sunday Times can today reveal how Dixon’s racquet sport hobby has left behind a digital trail that led to the most recent footage of him since those sanctions were imposed – the first time he has been pictured publicly in almost a decade. This investigation also uncovers the alias Dixon has used in Dubai and exposes the first open source links to an underworld associate who was recently extradited from the Gulf state and jailed in Scotland.

It comes as cartel leader Daniel Kinahan awaits extradition to Ireland after his arrest in Dubai on foot of a warrant issued by Irish authorities. The arrest, in April, followed an extensive policing and diplomatic effort from international law enforcement.

Bellingcat recently published images of ex-UFC fighter Mounir Lazzez with Daniel and Christy Kinahan at a 2025 MMA event in Dubai. Our investigation also linked Lazzez to multimillion-dollar transactions for crude oil tankers that were later sanctioned by the US. Source: WeCaptureYou, C4ADS Horizons

In March, investigations by Bellingcat and The Sunday Times exposed the first photographs of Daniel Kinahan and his father in years and also revealed that the cartel’s “friend”, former UFC fighter Mounir Lazzez, was connected to US sanctions against Iran.

The latest findings give an unprecedented glimpse into the recent activity of a key cartel associate who, until now, has largely flown under the radar.

Family Ties

When cartel founder Christy Kinahan moved to Spain after his release from an Irish prison in 2001, it wasn’t long before his new home became a hub for the gang. His sons, Daniel and Christopher Jr, soon followed him to the Costa del Sol – as did their younger cousin, Dublin native Ian Dixon.

From the late 2000s onward, Dixon worked for businesses linked to the crime family in the south of Spain. One of these was The Auld Dubliner, a pub in Estepona that reportedly served as a base of operations for the cartel. In 2010, the pub was raided and temporarily closed by authorities as part of Operation Shovel, a years-long multi-national police investigation into the cartel’s drugs and arms-trafficking activities.

Left: Dixon pictured in 2011 behind the bar at The Auld Dubliner in Estepona. Right: Exterior of the pub in 2012 (image highlighted by Bellingcat). Source: Facebook, Google Street View

Dixon would also work as a trainer at MGM Marbella, the boxing gym co-founded by Daniel Kinahan that would go on to represent some of the biggest pro boxers in the world. The company, which was renamed MTK Global, shut down after the US sanctions on the Kinahans were imposed in April 2022.

Top left: Ian Dixon at MGM Marbella in 2013. Top right: Dixon running a pads training session at the gym in January 2015. Bottom: Dixon pictured with Daniel Kinahan and others in Spain in 2013. Source: X, MGM Marbella / YouTube

In 2016, Dixon was arrested by Spanish police investigating the murder of Irish criminal Gary Hutch. The previous year, Hutch had been gunned down while out for a morning jog in a gated community on the Costa del Sol.

Dixon was released without charge, and another Kinahan cartel associate was later sentenced to 22 years for his role in the murder. The killing sparked a feud between the Kinahans and the rival Irish Hutch gang  that resulted in at least 18 deaths. 

Dixon and other key Kinahan members fled to Dubai in the wake of the deadly feud.

CCTV footage of Gary Hutch being pursued by a gunman in southern Spain, moments before Hutch was cornered and shot dead in September 2015. Source: BBC, The Irish Sun

Ian Dixon has no known convictions. But his alleged role in the Kinahan Organised Crime Group was laid bare when the US sanctioned him. Authorities said Dixon managed finances and moved bulk currency for Daniel Kinahan and also kept tabs on the debt owed by a narco-trafficker. 

The sanctions notice also said Dixon controlled Hoopoe Sports LLC, a Dubai firm that listed a number of pro boxers among its clients and reportedly received more than $4 million for bouts involving former heavyweight champion Tyson Fury. Boxing promoter Bob Arum told Yahoo Sports the money was for consulting fees owed to Daniel Kinahan.

Screenshot from a 2022 archive of US-sanctioned Hoopoe Sports’ website, showing pro boxers Jamie Conlan, Billy Joe Saunders, Hughie Fury and Michael Conlan among its clients list. Dixon’s company email address is visible on the footer. Source: arejaywoof / X, archive.org

Dixon lived in an exclusive gated community in Dubai, according to the 2022 sanctions notice. Online listings show that properties like his Spanish-inspired villa are worth up to $2.7 million.

Passion for Padel

Padel is an increasingly popular racquet sport from Mexico best described as a combination of tennis and squash. According to the sport’s governing body, it has more than 17.5 million weekly players across 150 countries and the UAE, where Dixon lives, has the second-highest number of padel courts in Asia. It was on these courts in late 2024 that Dixon played in the master final of the Asia Pacific Padel Tour (APPT).

A pre-match group photo was captured on the APPT male amateur final live stream. The photo, posted to Facebook, shows Dixon was part of the lineup. Source: APPT / YouTube, Facebook, US Treasury

APPT rankings show Dixon registered for the tournament under the name “Ian Thomas”. Like his cartel leader relative Christy Kinahan, who used his first and middle names as an alias on his Google review profile, Dixon had dropped his surname.

Finding a Fugitive – How we Located Dixon

Bellingcat found the padel club promotion showing Ian Dixon after running images of the cartel associate through a publicly available facial recognition search engine. Among the results was a link to a graphic designer’s online portfolio, which included the advertisement for the padel competition. The original photo had been posted on the sports club’s Instagram page in late 2023, with the caption: “Elevating fun, one swing at a time!” Dixon was not named.

Left: The padel tournament ad discovered via a PimEyes search for Ian Dixon. Right: The original picture and caption from the sports club’s Instagram page, posted in October 2023. Source: sanddune_padel_dxb / Instagram

We searched for additional open source evidence and located online profiles for a 36-year-old Irish padel player named “Ian Thomas” who had taken part in a number of matches in Dubai in recent years. One profile shows he played 16 ranked matches between September 2024 and April 2026 – the most recent being the week after Daniel Kinahan’s arrest. But the accounts did not include profile pictures.

Left: Screenshots from an online profile for 36-year-old Irishman “Ian Thomas” & Christy Kinahan’s Google review profile under the name “Christopher Vincent”. Right: Dixon pictured at a padel centre in an Instagram post from August 2024. Source: Rankedin.com, Google Maps, Instagram

Bellingcat searched for footage showing the padel events and venues listed on the profiles. It returned multiple social media posts and live-streams clearly showing Ian Dixon at the same events where “Ian Thomas” was registered as playing. Dixon can also be heard speaking with a Dublin accent and at one point is seen with a close relative of Daniel Kinahan.

Dixon and his doubles partner played four games over the December 13-15 weekend, eventually placing second after losing in the final. The Irish cartel associate is captured on film after the match receiving a silver medal and commemorative racquet.

Clip showing “Ian Thomas” in the final position in the APPT Dubai 2024 male amateur rankings, followed by Dixon on court during the match and receiving a racquet after his silver-medal placement. Source: asiapacificpadeltour.com, asiapacificpadeltour / Instagram

The Asia Pacific Padel Tour was held a month after senior Kinahan cartel figure Sean McGovern was arrested in Dubai on foot of an Interpol red notice. McGovern was extradited to Ireland last year and earlier this month jailed for 24 years for directing the activities of a criminal organisation in relation to murder and attempted murder. 

The tournament was live-streamed to YouTube via webcams set up on two courts. Dixon was captured throughout the three-day event, both playing on the court and mingling with others in the background. The hour-long male amateur final, which Dixon lost, is viewable in its entirety.

Clips from the tournament on December 15 showing Dixon before, during and after the amateur male final. Source: APPT / YouTube

Dixon also posed for photos during the tournament, but it appears he did have some reticence about appearing on social media. In two images from a different padel event hosted at the same venue a few months later, Dixon’s face had been covered. However, a third photo was not edited, confirming that it was Ian Dixon.

Top: Dixon posed for a photo before beginning the APPT amateur male final. Bottom: Dixon’s face was covered with a grey oval and an emoji in two social media posts from a different event. One of the pictures was not censored in another post. Source: APPT / Facebook, isdpadel / Instagram, ISD Dubai Sports City / LinkedIn

Kingpin in the Crowd

Among the people Dixon was seen with at padel events in Dubai was Stephen Jamieson, a Scottish criminal who was recently jailed for his role in a multimillion-dollar drug trafficking operation.

Dixon (left) and Jamieson (right) seen arriving and meeting on a live stream of a Dubai racquet sport event in December 2024. Jamieson was arrested by authorities in the Gulf state the following July. Source: Police Scotland, The Scottish Sun, asiapacificpadeltour / Instagram, APPT / YouTube

Dixon greeted Jamieson with a fist pump during the Dubai APPT tournament in December 2024 on the day the Irishman played in the amateur final.

Left: Jamieson watching padel games on days one and three of the APPT in 2024, when Dixon was also in attendance. Right: Police mugshot of Jamieson. Source: asiapacificpadeltour / Instagram, Police Scotland

Dixon was also pictured with Jamieson at a family day padel event just weeks before the Scottish criminal’s arrest. (Bellingcat is not publishing details of that event to protect the identity of family members.)

Clips from day three of the tournament showing Dixon meeting Jamieson. Both men arrived and left separately at different times. Source:  APPT / YouTube, BBC, The Scottish Sun

Jamieson, who has multiple convictions, was extradited from Dubai last year and is serving a six-year prison sentence in Scotland on organised crime and drug charges. The case against him was built around intercepted messages he had sent via the defunct encrypted communication network EncroChat – a network the Kinahans have also usedto direct drug shipments.

The Sunday Times reports today on the Kinahan cartel’s deeply entrenched links to organised crime in the UK, where it is known to control much of the illicit drug market. It said the footage showing that Dixon and Jamieson know each other could indicate an underworld connection, since cartel cadres do not associate with rival operations.

Dixon is among the remaining cartel figures at large in Dubai, along with Christy Kinahan, Christopher Jr and gang lieutenant Bernard Clancy. Source: US Treasury

Three of the seven alleged key Kinahan cartel figures have been arrested since the US sanctions were imposed. Johnny Morrissey, arrested in Spain in 2022, was later bailed and subject to a travel ban. Sean McGovern was jailed earlier this month and Daniel Kinahan awaits extradition to Ireland after his recent arrest in Dubai. Garda Commissioner Justin Kelly, of Ireland’s police force, recently said the investigation into the Kinahan cartel was ongoing and that authorities were continuing to focus on the other members of the gang.

Ian Dixon did not respond to questions from Bellingcat.


Connor Plunkett, Peter Barth, Beau Donelly and John Mooney contributed to this article. 

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

The post Poster Boy: Sanctioned Kinahan Cartel Lieutenant Found Playing Padel in Dubai appeared first on bellingcat.

  • ✇bellingcat
  • Heading Off: New Technique Helps Track Grain Smuggling Expansion to Libya Bellingcat Investigation Team
    On February 15, 2026, the bulk carrier, Grumant (IMO: 9385879) was pictured at the occupied Ukrainian Port of Feodosia on the Crimean peninsula. Satellite imagery suggests it had already been there for several days.  It appeared to stock up on grain before departing on a two-month-long journey eventually docking at the Port of Benghazi in Libya on April 18. While there have been previous reports of grain shipments from occupied Ukraine arriving in Libya, this is only the second time a Russian
     

Heading Off: New Technique Helps Track Grain Smuggling Expansion to Libya

12 de Junho de 2026, 05:51

On February 15, 2026, the bulk carrier, Grumant (IMO: 9385879) was pictured at the occupied Ukrainian Port of Feodosia on the Crimean peninsula. Satellite imagery suggests it had already been there for several days.  It appeared to stock up on grain before departing on a two-month-long journey eventually docking at the Port of Benghazi in Libya on April 18.

While there have been previous reports of grain shipments from occupied Ukraine arriving in Libya, this is only the second time a Russian ship has been observed delivering what the Ukrainian government describes as “stolen” grain to the country. The previous case involved the Damas Wave which travelled in January of last year to the port of Misrata which is under the control of the UN-recognised Government of National Unity (GNU). In addition to satellite imagery, Bellingcat deployed a new technique that analysed Grumant’s heading data which was contained in AIS information provided by Lloyd’s List Intelligence, to help confirm Grumant’s presence in Feodosia. 

Bellingcat has been tracking smuggled Ukrainian grain shipments as they find new markets, five of the ships we previously identified have since been sanctioned by the EU while another was sanctioned by the US Department of Treasury.

MapLibre | Protomaps© OpenStreetMap contributors

Bosphorus Strait

Grumant transits the Bosphorus Strait in the middle of the night.

Credit: Yörük Işık.

Black Sea

Grumant enters a region of the Black Sea known for GNSS interference, meaning that Grumant’s publicly reported Automated Identification System (AIS) position is unreliable.

Port of Feodosia

On February 15, a high resolution satellite image confirms the ship is docked at the port of Feodosia at berth No. 1 that is used for bulk and metal cargo. Matching features visible include Grumant’s grey decking, its seven hatches and bright yellow front mast. What appears to be leftover grain can be seen under the two port crates, immediately next to the ship.

Credit: Satellite image ©2026 Vantor.

Black Sea

Grumant exits the area of signal interference, meaning that its reported position on ship tracking services is now reliable again. Its AIS messages indicate it is travelling towards the Bosphorus.

Bosphorus Strait

Grumant transits the Bosphorus Strait towards the Sea of Marmara. Judging by the draft, with no visible red paint on its hull, the ship appears to be fully laden.

Credit: Yörük Işık.

Izmir Anchorage

Grumant arrives in Izmir, Turkey on February 23 and anchors off the coast until March 13.

Over the course of three weeks, Grumant never enters the Port of Izmir. It is not known if it was denied entry. Bellingcat asked the port operators but did not receive a response before publication.

Credit: Planet Labs PBC.

Aliağa

Grumant then loiters off the coast of Aliağa, about 50 km from Izmir. It stays here until March 16, never entering the port. It again is not known if it was denied entry. Bellingcat asked the port operators but did not receive a response before publication.

Near Benghazi

Grumant arrives in Libyan waters and stays off the coast of Benghazi until April 1.

Libyan Waters

Grumant briefly leaves the coast of Benghazi, but returns a few days later.

Benghazi

Grumant leaves the anchorage on April 18 and docks at the port of Benghazi where it unloads the grain. The ship was captured in a Vantor satellite image on April 20.

It leaves port on April 23, and heads back towards the Bosphorus.

Credit: Satellite image ©2026 Vantor.

Bosphorus Strait

After spending a few days off the coast of Tuzla, Grumant transits the Bosphorus towards the Black Sea.

Credit: Yörük Işık.

Lloyd’s List Intelligence has previously reported on the expansion of Russia’s grain smuggling operations, beyond the occupied port of Sevastopol to include Feodosia port

According to the Ukrainian activism, journalism and hacker group, Kiborg News, Grumant used deceptive shipping practices to deliver grain to Latakia, Syria in 2024. The report included several of Grumant’s shipping manifests, which showed it had repeatedly exported grain from Occupied Crimea to Syria. 

Heading Data Helps Locate Grumant

It is standard maritime practice that ships broadcast Automatic Identification System (AIS) messages which include a ship’s position, heading, and draught (among other information).

Because of longstanding Global Navigation Satellite System (GNSS) interference in parts of the Black Sea, the position data transmitted by an affected ship’s AIS system is often unreliable.

Between February 7 and February 19, 2026, data from Lloyd’s List Intelligence shows the Grumant transmitted 29 AIS messages, with unreliable positions in the vicinity of Feodosia. We know these positions are unreliable as they are erratic and some of them report the ship as being positioned on land.

Unreliable AIS positions – Grumant’s reported positions between February 7-19, 2026, via Lloyd’s List Seasearcher.

However, according to the IMO, the heading data transmitted by a ship’s AIS system must come from an onboard compass. A compass is unaffected by GNSS interference, meaning it is a more reliable source of information in these conditions.

Over the same dates, all 29 AIS messages reported the ship’s heading as 267 degrees or 268 degrees. The Port of Feodosia has a heading of 267.5 degrees. The close agreement between the ship’s heading and port heading strongly suggests that Grumant was moored at the port between February 7 and February 19, 2026.

We conducted an extra check of the heading data by reviewing satellite imagery available of berth 1 at Feodosia Port, which suggests that the same vessel was present on several days between February 6 and February 18. Imagery on Feb. 6 shows the port was empty in the morning and occupied in the afternoon. Grumant exited the area of GNSS interference on February 21, and berth 1 at the port was captured on satellite image on February 22 and appeared empty. The low resolution satellite imagery is only used as an additional check to see if a vessel is at the berth.

Timeline of open source observations related to Grumant’s presence (tick) or absence (cross) at Feodosia port. Empty entries indicate a lack of available data.
Sentinel-1 timelapse of Feodosia Port, Copernicus Sentinel data 2026. Annotations by Bellingcat.
PlanetScope timelapse of Feodosia Port, Planet Labs PBC. Annotations by Bellingcat.

Bellingcat checked all vessels transmitting AIS in the vicinity of Feodosia Port and found that Grumant was the only one that consistently transmitted a heading matching the Port of Feodosia over the period of interest.

We shared our research with Charlie Brown, a former US Naval Officer and Senior Advisor at United Against Nuclear Iran where he focuses on maritime sanctions enforcement and the tracking of illicit shipping. Brown told Bellingcat that while satellite imagery of vessels remained key for identification, when looking for reliable data in a spoofing environment it made sense to look at the various elements of AIS data to try and find some accurate information, despite GNSS spoofing.

“It’s quite standard for the independent gyro compass to be providing the heading […] I think the majority would not [be subject to spoofing] so it’s a good methodology to parse out the particular data and then make some inferences from that.”

“It’s neat to think of what can be derived from data that would otherwise be dirty or wrong. So there’s still some elements of use in there.”

He added that in theory there are probably some compasses that are subject to spoofing as well. 

He told Bellingcat that it was fair to say the heading data of the Grumant supported identification, but stressed the need to cross-reference with other data sources. 

While in this instance it has been possible to use AIS data to help verify the location of Grumant, it is relatively unusual to have access to this information. 

Ships that call to the occupied territories frequently disable their AIS transponders to do so.

This activity, known as “dark port calls”, is a common tactic for those engaging in illicit or sanctioned trades. 

Grumant does not transmit AIS messages from February 8 to 11, but this is the longest gap in data (see diagram above), with intermittent messages coming through after that point.

It is unclear why Grumant continued to transmit AIS during the period it was loading in Feodosia. 

A review of Lloyd’s List Intelligence data from January 2025 shows that on a previous voyage to the Black Sea the Grumant operated “dark” for 59 days.  

Visual Identification

On February 15, 2026, high resolution imagery showed Grumant docked in the Port of Feodosia. We compared it with other recent images of Grumant to confirm the match. 

The ship in the satellite image has a grey-coloured deck, which is uncommon enough for it to stand out. Many bulk carriers have cranes (including the ships we previously covered such as Krasnodar, Zafar and Zaid), Grumant does not have any. It also has seven hatches (openings for the grain) and a bright yellow front mast that matches the mast of Grumant (see the image of it transiting the Bosphorus). We can match the Grumant in the Feodosia image, not only to pictures of the Grumant shot from the ground, but also to the satellite image from Benghazi.

The length and breadth of the ship also matches that of the Grumant; 180 metres by 22.90 metres. 

Above: Image of the Grumant transiting the Bosphorus. (In yellow: the mast, red: the seven hatches, green: four vent masts, two on either side). Credit: Yörük Işık. Middle: Satellite image of the Grumant in Feodosia on February 15, 2026. (Matching elements are denoted in the same way as the image above). Bottom: Grumant captured at Benghazi port on April 20. Credit: Satellite image ©2026 Vantor. Annotations by Bellingcat.

Libya’s Relationship with Russia and Ukraine 

Libya has complicated internal dynamics with essentially two administrations in charge of different parts of the country – the Government of National Unity (GNU) in the west and the Libyan National Army (LNA) in the east.

In recent years, Russia has backed the LNA’s General Khalifa Haftar, based out of Benghazi, in the east of the country. But Jalel Harchaoui, a political scientist specialising in Libya with the Royal United Services Institute (RUSI), stressed that the two sides of this conflict, the LNA and the UN-recognised GNU, are not currently fighting. Instead they are in a flawed, multi-year truce.

Therefore, the east-west divide isn’t as clear-cut as during the civil war. While all shipments going to Benghazi and Tobruk are overseen by the LNA, not all shipments going to the city of Misrata (which is run by the GNU) are meant for the GNU-dominated part of the country. 

Harchaoui told Bellingcat: “the Tripoli government is in some regards pro-Ukraine, but if there’s business that can be done with Russia through the very opaque port of Misrata and all the right people get paid, the business is going to take place.”

That observation is potentially significant given at least one previously tracked vessel that went from occupied Ukraine to Libya docked in Misrata.

This was not the case of the Grumant, however, which arrived in an LNA-controlled part of the country. It is not known from open sources alone if the authorities in Libya or at the port in Benghazi knew the grain carried by Grumant had come from occupied Ukraine.

Bellingcat contacted the Benghazi-based LNA government and representatives of the Tripoli-based GNU government via the Libyan Embassy in The Netherlands. We also contacted the Port of Benghazi, Port of Imzir in Turkey as well as the Ukrainian and Russian authorities. Representatives of the LNA did not respond to requests for comment before publication, nor did the Port of Benghazi or Port of Izmir. The Libyan Embassy in The Netherlands replied to Bellingcat after publication, stating that Benghazi and eastern Libya are not under the authority or administrative control of the Government of National Unity and therefore they are not currently in a position to comment on Bellingcat’s findings.

Ukraine Continues to Pursue the “Shadow Grain Fleet”

“The port of Feodosia, located in the temporarily occupied Autonomous Republic of Crimea, is not under Ukrainian control, and any commercial activity conducted there is illegal,” the Ministry for Development of Communities and Territories of Ukraine and the Ministry of Foreign Affairs of Ukraine told Bellingcat in a joint response. 

They told us the loading of grain exported from the temporarily occupied territories is an illegal act and Russia was using ports as logistics centers to export stolen Ukrainian agricultural products.

“The expansion of such routes to third countries, in particular to North Africa, demonstrates Russia’s ongoing efforts to circumvent international sanctions and monetize resources stolen from the occupied Ukrainian territories.” 

The Ukrainian Ministry of Foreign Affairs sent information about Grumant’s (IMO: 9385879) “illegal activities” to the diplomatic missions in Great Britain, the Republic of Turkey and the Republic of Tunisia over the course of March to May this year, the ministries told Bellingcat. 

Ukraine is continuing to pursue legal action against Russia’s “shadow grain fleet” they told us. For instance, earlier this month a Swedish court approved the transfer of the Russian “shadow grain fleet” vessel CAFFA to Ukraine for investigation after it was arrested in Swedish waters. 

This case has set a new precedent, going beyond sanction and fines previously handed out to such vessels, and allowing for the detention and confiscation of a shadow fleet vessel in European jurisdictions, the ministries said.

According to Russian court documents Grumant’s previous owner Murmansk Shipping Company was dissolved and “Decision/Reshenie” LLC were listed as the International Safety Manager and operator of Grumant. Decision/Reshenie were also listed as the operator of Grumant in another court document, from an unrelated case. 

Bellingcat attempted to contact Decision/Reshenie to ask about Grumant’s grain shipment from Feodisia Port to Benghazi Port, but they had not responded at time of publication.


Youri van der Weide, Galen Reich, Yörük Işık and Bridget Diakun contributed to this report.

Cover image: Planet Lab image shows Grumant anchored off Izmir, Turkey on February 27. Credit: Planet Labs PBC.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.


The post Heading Off: New Technique Helps Track Grain Smuggling Expansion to Libya appeared first on bellingcat.

  • ✇bellingcat
  • Tracing Digital Links Between Viory and Ruptly Lucy Swinnen
    “In the age of misinformation, the line between fact and fiction is blurrier than ever.” “For those of us working in video news, verification isn’t a nice-to-have. It’s a necessity. It is how we protect the stories we help shape and how we earn and maintain trust in an increasingly chaotic information ecosystem,” Abu Dhabi-registered video news agency Viory posted on LinkedIn on April 9, 2026, offering training to help newsrooms and journalists sort fact from fiction.  The self-described “
     

Tracing Digital Links Between Viory and Ruptly

4 de Junho de 2026, 09:27

“In the age of misinformation, the line between fact and fiction is blurrier than ever.”

“For those of us working in video news, verification isn’t a nice-to-have. It’s a necessity. It is how we protect the stories we help shape and how we earn and maintain trust in an increasingly chaotic information ecosystem,” Abu Dhabi-registered video news agency Viory posted on LinkedIn on April 9, 2026, offering training to help newsrooms and journalists sort fact from fiction. 

The self-described “video news agency of the Global South” has delivered journalism training to multiple national press agencies across Africa, Asia and the Middle East.

However, when it comes to Viory itself, the line between fact and fiction is very blurry indeed. 

Bellingcat has found multiple links between the digital infrastructure of Viory and Ruptly news agency, a branch of sanctioned Russian propaganda outlet Russia Today, including shared IP addresses, a Viory-linked site using a digital security certificate registered to Ruptly, and Ruptly sending site performance data to Viory. While there have been previous reports on suspected links between the two outlets, our investigation adds new evidence about Viory’s ties to Ruptly media. 

When contacted for comment, both Viory and Ruptly denied any connection with each other.

Composite Image created by Bellingcat.

‘Video News Agency of the Global South’

Viory’s main offering is raw video footage of news events provided via subscription. According to Viory, its clients include “major international news outlets, local media organisations, and independent creatives in more than 170 countries”.

If its own figures are to be believed, Viory was strikingly well established at its launch in November 2023, by which time it claimed to have a “pre-assembled team of over 150 full-time staff, and an established network of over 3,000 video journalists across the world”.

The name “Viory” is a trade name. The company’s legal name is Darpo Vision FZ LLC, according to its website, which also states that it is registered in Abu Dhabi. In August 2024, Darpo Vision FZ LLC filed for a trademark in the US for the name Viory, which was approved in December of 2025

As of May 2026, Bellingcat found press releases and news reports referencing at least 30 agreements between Viory and partners in more than 22 countries, as well as cooperation agreements with government agencies, training agreements with universities and regional journalism bodies. 

This includes:

Viory also sponsored a glitzy event for its inaugural Global South Video News Awards in December 2025 at Abu Dhabi’s first-ever BRIDGE Summit.

Ruptly Revisited

Ruptly is a video news agency formerly based in Berlin and ultimately controlled by Russia Today (RT), which is owned by Russian state media company ANO TV-Novosti. ANO TV-Novosti has been on the EU sanctions list since December 2022 for spreading “pro-Kremlin propaganda and disinformation” and supporting Russia’s war against Ukraine. 

RT launched Ruptly, which operated in Berlin via a German-registered subsidiary in 2013, with the goal of “becom[ing] the go-to alternative resource in a highly concentrated market of professional news video footage, and to deliver coverage of stories that other agencies miss.”

Sanctions imposed on RT following Russia’s 2022 invasion of Ukraine choked off Ruptly’s source of funds in Germany, leading the German company to begin insolvency proceedings in October 2024. Ruptly continues to operate from Moscow as of 2026.

As with Viory, Ruptly’s main offering is providing raw news footage to subscribers around the world. It relies on a large network of international freelancers and stringers. In 2016 RT claimed that Ruptly had “surpassed” newswire services AFP and Reuters on YouTube, and was serving more than 600 media organisations in 45 countries.

Felix Huesmann of the German outlet RedaktionsNetzwerk Deutschland (RND), was the first to outline links between Ruptly and Viory while covering the insolvency proceedings of Ruptly. He found that Darpo Vision’s original details on the Abu Dhabi Creative Media Authority’s site included an email address d.toktosunova@gmail.com. It has not been confirmed who this email address belongs to; however, the username matches the first name initial and surname of Dinara Toktosunova, the managing director of Ruptly. When asked about this email address by Huesmann  in 2024, Ruptly “explained that Toktosunova is focused on securing the future of the Ruptly team [in Moscow] and is not working anywhere else as a managing director.”The activist group, OSINT For Ukraine, also outlined links between Ruptly and Viory, including the movement of multiple key staff between the two organisations and strong similarities between the two organisations’ platforms and content.

Darpo Vision’s Security Certificate

The legal entity behind Viory, Darpo Vision, was set up in one of Abu Dhabi’s free zones – special economic areas that have business-friendly incentives such as tax exemptions and that allow 100 percent foreign ownership. The free zones also offer what some describe as high levels of “corporate privacy,”  which others assert has created a haven for shell companies and opaque corporate structures.

Darpo Vision initially had its own web domain, darpo.vision. The site has since been removed. Whois records show that the domain was registered by Darpo Vision FZ LLC in December 2022 to a PO Box in Abu Dhabi, using a Russian domain name registrar and a Moscow phone number. 

Initially, Darpo.vision had its own Secure Sockets Layer (SSL) certificate – a digital certificate that authenticates a website’s identity, allowing it to secure and encrypt data. However, VirusTotal data shows that as of at least June 2024, darpo.vision was using a wildcard SSL certificate registered to ruptly.video. A Wildcard SSL certificate is a single certificate with a wildcard character (*) in the domain name field. This allows the certificate to secure a single domain and multiple subdomains. You can see historical SSL certificates for darpo.vision.


James Wilson, a software and networking engineer with 20 years of experience and currently Enterprise Technology editor at Risky Business Media, told Bellingcat that to prevent unauthorised use or forgery of SSL certificates, a private key is needed to create and use a wildcard certificate across multiple domains. 

“The fact that darpo.vision was using a wildcard SSL certificate for ruptly.video indicates that whoever was running darpo.vision also had access to the private key for ruptly.video’s SSL certificate. Normally, only the people operating Ruptly’s web hosting infrastructure would be likely to have access to that,” Wilson explained. 

When asked by Bellingcat about whether there were alternative possible explanations, Wilson suggested that it was theoretically possible that someone may have hacked Ruptly and stolen their private SSL key. 

“However, using that wildcard SSL certificate on a domain that didn’t match the wildcard in the certificate defies explanation as the browser would alert the user to the certificate error,” he added.

Shared IP Addresses

Bellingcat also identified multiple shared IP addresses which appeared to be concurrently in use by both Ruptly and Viory between May 2025 and May 2026. 

From 2025 onwards, the Russian IP address 158.160.132.25 has been used concurrently by viory.video, ruptly.video, ruptly.agency and ruptly.tv, according to VirusTotal. Similarly, since the beginning of 2026, IP address 84.252.135.88 has been used concurrently by viory.video, viory.team, ruptly.video, ruptly.agency and ruptly.tv, according to VirusTotal. 

VirusTotal data shows that from 2025 onwards, IP address 158.160.166.22 has been used by ruptly.video and viory.video while from 2026 onwards, IP address 158.160.226.68 has been used by viory.video and ruptly.tv. The VirusTotal data appears to show these IP addresses being used exclusively by Ruptly and Viory as of 2025 and 2026. However, VirusTotal does not necessarily capture all domains which resolve to an IP, and other domains may also have resolved to these IP addresses, which were not observed by VirusTotal’s passive DNS replication service. It is also important to note that in some cases, unrelated domains use the same IP addresses.

Ruptly Sends Site Performance Data to Viory

Viory’s and Ruptly’s site infrastructure was also linked through data sent via Sentry, an internal error tracking and performance monitoring platform. 

An API scan of Ruptly’s main client login page, ruptly.agency, on March 26, 2026, shows that the page was sending data to a subdomain of viory.team. This domain appears to be used by Viory primarily for backend purposes, based on subdomains which appear to refer to common developer and site management tools such as Traefik and ArgoCD, in addition to Sentry.io. Notably, two subdomains also appear to refer to Ruptly. 

The purpose of one domain sending data to another domain’s Sentry project is generally to consolidate all of the relevant performance and error data in one place for in-house developers to monitor. 

The ruptly.agency page’s request to viory.team also includes an authentication key for Viory’s Sentry project. Ruptly.agency is not the only Ruptly domain sending Sentry data to viory.team. As of May 9, 2026 the login page for ruptly.video’s own Sentry project, sentry.ops.ruptly.video, automatically redirects to sentry.ops.ruptly.video/auth/login/viory/. Ruptly Video’s Sentry login page also features “Viory” as the title.

The ruptly.video Sentry login page is also sending data to the viory.team Sentry project, the ruptly.agency homepage and using a favicon hosted on viory.team.

A third Ruptly domain, ruptly.tv, also sends performance data to viory.team’s Sentry project via cms.dev.ruptly.tv. 

James Wilson noted that in each case, the Ruptly domains sending data to Viory appeared to be using a different Sentry key.

“If you look at each of these snippets sending telemetry data [from the Ruptly domains], the specific Sentry keys for sentry.ops.viory.team are different for each. I presume that someone with access to Viory’s Sentry keys has generated and included fresh Sentry keys in each of these instances in order to differentiate between the telemetry from this site versus others using the same Sentry instance,” Wilson said. 

“This cuts against the idea that this is, for example, a case of someone just lazily copy-pasting code on Ruptly’s domains. It suggests that each of these snippets was likely to have been deliberately included. The alternative explanation of changing these API keys to some arbitrary value seems much less plausible given the lack of diligence in ensuring other aspects of the content didn’t cross-reference the domains.”

‘Ruptly’ Page Title on Viory Test Page

Finally, Bellingcat found a page at frontend.dev.viory.video/en that appears likely to be a developer test page for the front page of Viory’s main domain viory.video.

Notably, however, the page title reads “Stream trending news | Ruptly.” The page description included in the source code also refers to Ruptly:  

“Follow breaking world news in real-time and stream the latest developments in politics, sports, finance, science, tech, and more from one of the top online news sites. Download and share international news today with award-winning news agency Ruptl” [sic].

Screenshot of frontend.dev.viory.video/en page, captured May 10th 2026. Archived source.

Wilson said that the use of the Ruply page title and text on the Viory test page “looks like a case of lazy copy and pasting”.

“That could potentially be done by someone outside of Ruptly, although it would be strange.”

While this particular piece lies on the lower end of the spectrum of proof, Wilson said that together with the other stronger pieces of evidence, including multiple Ruptly domains appearing to send data to Viory using different API keys, and Ruptly’s wildcard SSL certificate on Darpo Vision’s site, the weight of evidence for a connection between Ruptly and Viory adds up.

“None of the pieces of evidence are watertight on their own, but when you add them together it’s difficult to think of other plausible explanations for all of them being true at the same time,” he added.

“None of the pieces of evidence are watertight on their own, but when you add them together it’s difficult to think of other plausible explanations for all of them being true at the same time,”

-James Wilson

Bellingcat also found that Ruptly appears to have connections to a company in Hong Kong. Company records from July 2022 indicate that this company was originally named Ruptly Limited, but in September of that year, the company’s name was changed to Lotus Production Limited. 

The Hong Kong company remains registered as active and filed annual reports in September 2025.

Russian Slant in the ‘Global South’ 

Anna Hiller, a Bangkok-based Consultant Research Analyst for the Institute for Strategic Dialogue told Bellingcat that the resources provided by Viory can be an attractive pool of source material for smaller media outlets, governments and academic institutions with small budgets.

She told Bellingcat that Viory’s editorial choices are clear when looking at the site’s videos.

“When accessing Viory, the prominence of pro-Russian and pro-China content is immediately noticeable, including numerous articles focused on Vladimir Putin, Russia-China cooperation, and broader China-related narratives.”  

Bellingcat contacted Viory, Darpo Vision and Lotus Production Limited to ask about the connections we found between the Viory website and Ruptly and between Lotus Production Limited and Ruptly. 

Viory said that it had no connection with Ruptly. “Viory has no connection with Ruptly; any suggestion otherwise based on ordinary use of similar digital platforms, tools or cloud providers is poorly founded and inaccurate; Viory is a UAE-based, privately held, self-funded and 100% privately owned organisation, and receives no funding, direction or instructions from any state media,” the company said in an email response. 

Ruptly also said it was not connected to Viory. It declined to respond to Bellingcat’s questions, including about specific findings such as Ruptly’s domains sending technical performance and error data to Viory, calling these questions “irrelevant”.


Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Tracing Digital Links Between Viory and Ruptly appeared first on bellingcat.

‘Snoopy’, ‘Adolf’ and ‘Password’: The Hungarian Government Passwords Exposed Online

9 de Abril de 2026, 09:25

Almost 800 Hungarian government email addresses and associated passwords are circulating online, revealing basic vulnerabilities in the security protocols of ministries involved in classified and sensitive work.

A Bellingcat analysis of breach data shows that 12 out of the government’s 13 ministries have been affected, which in some cases have exposed the confidential information of military personnel and civil servants posted abroad. 

Among those affected were a senior military officer responsible for information security, a counter terrorism coordinator in the foreign affairs department, and an employee whose role was to identify hybrid threats against the country.

The revelations come as Hungarians head to the polls this Sunday to decide if Viktor Orbán, leader of the right-wing populist party Fidesz and the country’s longest-serving prime minister, will be elected to a fifth consecutive term.

This is not the first time that deficiencies in the Hungarian government’s IT security have been revealed. In 2022, ahead of Hungary’s last election, Direkt36 reported that Russia’s intelligence services had gained access to the computer network of the Hungarian foreign ministry, including its internal communications channels.

It said Russian cyber attacks against the Hungarian government had been occurring for at least a decade and extended to the foreign ministry’s encrypted network for transmitting classified data and confidential diplomatic documents.

At the time, the foreign ministry denied it had been hacked. But in 2024, news outlet 444 published a letter that had been sent from Hungary’s National Security Service to the foreign ministry six months before the cyberattack was first reported. The letter linked the attacks to Russia and described more than 4,000 workstations and 930 servers as “unreliable”.

As part of this new analysis, Bellingcat identified a total of 795 unique email and password combinations among thousands of search results for Hungarian government domains in breach databases. Key departments that handle the country’s governance, defence, foreign affairs and finances were the worst affected.

The analysis does not include central government agencies that operate under the government’s official ministries and use separate domains, such as the tax and customs administration or the police – meaning breaches affecting government employees could be even more widespread.

The findings are not evidence of high-tech infiltration of Hungarian government systems. Instead, our analysis indicates that the breaches are more likely the result of poor digital hygiene. In many cases, staff used simple passwords along with their government email addresses for what appear to be non-work-related matters, such as signing up to dating, music, sport and food websites.

Some government workers used easy-to-guess passwords such as variations of the word “Password” or the number sequence “1234567”. One employee whose credentials were exposed in the 2012 LinkedIn hack used the password “linkedinlinkedin”. Another, in the defence ministry, used their surname. One leaked password from an employee in the foreign affairs ministry was “embassy13hungary”. 

Multiple breaches also contained phone numbers, addresses, dates of birth, usernames and IP addresses – data that, when exposed, could pose security risks.  

Additionally, a search of breach databases showed instances where computers have been infected with malware designed to steal login credentials. These records show that 97 machines across Hungarian government departments had been compromised, with stealer logs from as recently as last month found in the data.

Bellingcat contacted the Hungarian government’s spokesperson and the Prime Minister’s office, but did not receive a response.

The Weakest Link: Searching Breach Data

Breach databases are large collections of credentials harvested from previous cyber incidents. These databases can be searched by domain to identify email addresses belonging to a specific organisation, company or government. 

Darkside allows users to search a repository of breach data from the clear and dark web.

Bellingcat used Darkside, a paid service by District 4 Labs, to search the main email domains assigned to each of the Hungarian government’s 13 ministries. 

In total, 795 breaches containing government emails and associated passwords were identified. But most – 641 breaches – were linked to just four central institutions. 

In the examples detailed below, staff have been anonymised. However, Bellingcat has confirmed these accounts are genuine by cross-checking the employees named in the breaches against media reports and online profiles, such as LinkedIn.  

Ministry of Interior – this “super-ministry” oversees everything from health and education to the police, immigration, disaster management and local government 

Bellingcat identified 170 sets of emails and passwords linked to the domain used by the ministry in charge of domestic affairs. Passwords used by staff in this department included “Arsenal” and “Paprika”. Some used passwords that contained only three or four letters. We traced these accounts to professional profiles and government web pages listing both junior and senior staff.

One senior official in the prison service used the password “adolf”. After it appeared in breach databases the password was changed twice – first to a five-digit number and then to what appeared to be the name for a pet dog. The passwords were subsequently breached again. Bellingcat identified this employee through several instances of their name and email address being listed on public-facing documentation, including a press release celebrating an award for outstanding professional work.  

Ministry of Defence – responsible for national defence policy and directing the country’s defence forces

The credentials of staff working for the Ministry of Defence were found in 120 compromised records. This includes a 2023 breach of NATO’s eLearning services which resulted in 42 records containing emails, passwords and phone numbers becoming public.

The breaches peaked in 2021 but continued up to 2026. Included in the data were stealer logs, indicating that machines within the department may have been infected. 

Military personnel from junior ranks to command positions were identified. A Brigadier General used a common six letter nickname, based on his own, to sign up to a film festival. A Colonel specialising in “information security” took inspiration from an English football manager for his password: “FrankLampard”. A district director used the password “123456aA”, while a high-ranking member of Hungary’s delegation to NATO used a password that translates in English to “cute”. 

Ministry of Foreign Affairs and Trade – responsible for international relations, Hungarian embassies and consulates operate under the direction of the department

The credentials of current and former foreign affairs personnel have been exposed in dozens of data breaches from 2011 to February 2026. In total, there were 107 email and password combinations linked to this government ministry. 

Among the staff affected was a deputy head of mission, consuls, diplomats and communications personnel posted in Europe, the Americas and the Middle East. These include a counter terrorism coordinator, an EU spokesperson, and an individual whose role was to identify hybrid threats to Hungary.

Although the breaches peaked in 2020, with emails being found in 42 separate breaches indexed by Darkside, MFA emails have been circulated, often with passwords, in 36 separate breaches since the beginning of 2024. The most recent breaches were in 2026.  

Simple passwords appear to have left Hungary’s foreign affairs ministry vulnerable. In some cases, employees used a password that consisted of their own name and a two digit number. Others appeared to take inspiration from pop culture: “porsche911”, “frogger” and “Batman2013” are examples of real passwords used by staff.

Ministry of National Economy – oversees economic policy and financial strategy, including budget preparation and reducing national debt

Bellingcat’s analysis shows that staff in the Ministry for National Economy suffered 99 breaches. The Ministry of Finance, which was merged into this department in 2025, had suffered 145 breaches.

Among the breached data were the credentials of a deputy state secretary, who used the password “snoopy”. Other staff members used their date of birth or the word “Jelszo” – the Hungarian word for password.

A senior advisor who currently works in the ministry had their credentials breached four times using four different passwords, including “Kurvaanyad1” (roughly translated to “your mother is a wh**e”).

Cybersecurity Not Taken Seriously

Szabolcs Dull, a political analyst and the former editor-in-chief of the independent Hungarian news websites Index and Telex, said the government had failed to prioritise data security. 

“It’s clear from the data breaches that have come to light that government agencies did not take data security seriously,” he said. 

“This suspicion arose even when Russian hackers breached the foreign ministry’s IT system. That is why I believe Hungarian politicians and the public will interpret this new information as a continuation and confirmation of the Russian hacking story.”

Dull added that he was not aware of any investigation having been launched following the 2022 revelations of the Russian hack.

Kata Kincső Bárdos, a cybersecurity expert in Hungary, said it was difficult to understand why stricter controls would not be consistently enforced in government environments handling sensitive data.

She said governments should not only apply baseline rules for passwords – such as that staff use long, unique passwords and multi-factor authentication (MFA) – but also continuously monitor for compromised credentials and suspicious access patterns.

“Without MFA, systems become significantly more vulnerable to common attack methods such as phishing and credential stuffing,” she said. “A single compromised password can provide immediate access to internal systems.” 

Bárdos added that unauthorised access to government systems should automatically trigger incident response procedures, investigation and containment measures.

“It is also important to note that targeting lower-level employees is a well-documented and common tactic,” she said. “Attackers frequently gain initial access through phishing or weak credentials and then move laterally within systems.”


Bellingcat’s Ross Higgins and investigative journalist Eva Vajda contributed to this article.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post ‘Snoopy’, ‘Adolf’ and ‘Password’: The Hungarian Government Passwords Exposed Online appeared first on bellingcat.

  • ✇bellingcat
  • AI Used to Promote Non-Existent Evacuation Flights From the Middle East Foeke Postma
    The Netherlands’ largest newspaper, De Telegraaf, recently published an interview with a woman claiming to organise her own evacuation flights from Dubai, selling seats at €1,600 (US$ 1850) each. Four days later, her photo was removed from the article, though the interview remained. Bellingcat has found that the original image not only includes artefacts commonly associated with generative AI, but that the flights referenced in the article do not appear to exist. Subscribe to the Bellingc
     

AI Used to Promote Non-Existent Evacuation Flights From the Middle East

12 de Março de 2026, 07:46

The Netherlands’ largest newspaper, De Telegraaf, recently published an interview with a woman claiming to organise her own evacuation flights from Dubai, selling seats at €1,600 (US$ 1850) each. Four days later, her photo was removed from the article, though the interview remained.

Bellingcat has found that the original image not only includes artefacts commonly associated with generative AI, but that the flights referenced in the article do not appear to exist.

Subscribe to the Bellingcat newsletter

Subscribe to our newsletter for first access to our published content and events that our staff and contributors are involved with, including interviews and training workshops.

The story came at a time when thousands of Dutch people were reportedly seeking urgent ways to leave the region following Iranian missile and drone strikes across the Gulf in retaliation for US-Israeli strikes.

Published on De Telegraaf’s website on March 5, the headline reads: “Dutch people in the Middle East feel abandoned by the government: We just rented a plane ourselves.”

The Dutch minister of foreign affairs was confronted with this headline during a television interview, in which he described ongoing efforts by the Dutch government to repatriate citizens to the Netherlands.

The article features interviews with several Dutch people struggling to leave Dubai and Abu Dhabi, including Tamara Harema. Under the subheading “Dutch people hire their own plane”, Harema says she was “rebooked five times by Emirates” and that the official repatriation flights organised by the Dutch government were not ‘taking off’.

As part of a group, she says, they are organising buses and have hired an Airbus A321 to fly home. Harema is quoted as saying: “The first plane is already full, so we’re organising a second flight. Stranded travellers can contact us.”

However, several discrepancies in Harema’s photo, published in the original article, suggest it was AI-generated. No trace of a person matching Harema’s face or profile could be found, and flight-tracking data suggests no such plane took off.

The Photo

In the image below, the world’s tallest structure, Burj Khalifa, can be seen through the window overlooking the Dubai skyline. Each side of the tower is unique, with platforms that protrude at different heights and in different directions. It also contains several mechanical floors, which appear as dark bands in the photo.

Photo description as published by De Telegraaf reads: “Tamara Harema and a group organise their own flights to the Netherlands, for which they have rented an Airbus A321. “Otherwise, nothing would get off the ground.” © Own photo” Source: Published in De Telegraaf, March 5.

By cross-checking the height of the visible platforms together with the location of the mechanical floors, it’s possible to determine that Harema’s hotel room faces north-west, towards the Burj Khalifa’s south-east-facing facade.

Comparing Harema’s photo (bottom left) to all three sides of Burj Khalifa’s base suggests she is looking at the Southeast facade. Source: Harema’s image / Google Street View.

Several discrepancies are visible when comparing Harema’s photo with other images of the building, including an upper mechanical floor appearing higher than in other images and the absence of the water feature at the base of the building.

Harema’s image (left), compared to a screenshot of a video of the building from 2020 (right), suggests a discrepancy between the upper mechanical floors. The water feature is also absent. Source: Harema’s image / Youtube.

To establish whether Harema’s photo could have been taken several years earlier, Google Street View imagery was analysed from 2013 onwards. No match could be found when comparing the arrangement of buildings at the base of the Burj Khalifa.

In Harema’s photo, the arrangement of buildings at the base of the tower does not match historic Google Street View images. Source Harema’s image/ Google Street View.

Several other irregularities, as shown below, including the hotel room furniture and details of Harema’s clothing and jewellery, also suggest it may have been AI-generated.

(Left) a distorted lamp stand; (top right) blurring on the “V” of her T-shirt; (bottom right) an earring that appears to merge into her face – all discrepancies commonly associated with generative AI.


Fully Booked Airbus A321

Regarding whether the plane existed, Harema says in her interview that buses have already been arranged to collect passengers from two locations in Dubai on Saturday, March 7, after which a 232-seater Airbus A321 will depart from Muscat, Oman, for the Netherlands.

The article notes the cost is €1,600 (US$ 1850) per person, without detours. “Although we read that a Dutch repatriation flight costs €600, just try getting on such a flight,” says Harema.

According to Flightradar24, multiple A321s departed Muscat on March 7 and 8, but none bound for the Netherlands. The only aircraft that did arrive in Amsterdam from Muscat were either government-organised repatriation flights or scheduled Oman Air services, none of which were Airbus A321s.

Two Airbus A321s were recorded on the ground at Muscat Airport on March 7. One, belonging to Gulf Air, later departed for Rome via Riyadh March 8. The other, operated by SalamAir, had been flying routes between Oman and Bangladesh until March 3, but has since remained in Muscat.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

After contacting De Telegraaf, an explanation for the photo’s removal was added at the bottom of the article, stating that the photo did “likely not meet our journalistic guidelines.”

The newspaper’s deputy editor-in-chief, Joost de Haas, added:

“Regarding the quoted Tamara Harema, the editors contacted her after Mr. Chizki Loonstein—a long-standing source for one of our reporters—informed us about attempts to charter a plane. Mr Loonstein informed us that Ms Harema stayed in Dubai and could tell us more about it. This led to messages from which several quotes from Harema were extracted, as reproduced in the relevant passage of the article.”

A search for Loonstein led to a six-month-old report from another Dutch newspaper, NRC, which claimed that Loonstein, a lawyer, emigrated to Dubai after his legal company went bankrupt, leaving his clients, victims of fraud, worse off.

Contacted for comment, Loonstein confirmed that he knew Harema and had shared her contact details in “an app group” in relation to a flight from Muscat to Amsterdam. After this contact, Bellingcat sent him the photo of Harema to confirm her identity and asked him to share Harema’s contact details. In response, Loonstein refused to provide further comment. 


Merel Zoet and Claire Press contributed to this report.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post AI Used to Promote Non-Existent Evacuation Flights From the Middle East appeared first on bellingcat.

How Russia’s War Has Devastated Civilian Life in Ukraine

In the tiny town of Krasnopillia in rural Ukraine, the stillness of the night is shattered by the whine of a Russian drone. Seconds later, a community hospital bursts into flames. Sparks and debris rain down across the skeletons of trees as the fire sends plumes of smoke into the pitch-black sky.

Dozens of people are evacuated, according to local media reports – but as rescuers respond, in what appears to be a double-tap strike, Russian forces hit a shelter where more than 20 patients are huddled, including some with limited mobility. 

The strike in March 2025 comes just hours after a larger regional hospital in the northeastern Sumy governorate is targeted, decimating the primary health facilities serving the small town of Krasnopillia, whose prewar population was around 7,700. Healthcare services for the town “practically ceased” in the wake of the strikes, Olena Pryima, a local school director, told Bellingcat in a phone interview. 

“[The Russians] destroy the infrastructure so that people do not have the opportunity to live and exist normally. You cannot consult a doctor, nothing,” she said. “And now these people who remain, God forbid, the ambulance will not go there, just because the security situation does not allow it.”

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Her own school was among the many buildings destroyed in Russian strikes, and she says it has been impossible to rebuild amid the ongoing war. “We try to heat some accommodations, in spite of everything … especially since this winter is very difficult,” Pryima said. “But we are not talking about rebuilding at all now. We have hope; we are collecting some documents [such as testimonies and damage assessments], since this will end someday – and then we can rebuild something.”

For the past four years, Bellingcat has been documenting and verifying incidents such as these, chronicling the extensive damage to civilian life and infrastructure after the onset of Russia’s full invasion which began in February 2022.  

In over 2,500 cases of civilian harm that we have verified – the vast majority of which occurred on Ukrainian territory, although dozens also took place in Russia – more than 1,100 residential structures were hit. Hundreds of other civilian sites such as schools, playgrounds, fire stations, hospitals, churches, cultural centres, museums, businesses and farms have been impacted too. 

Our data – which includes cases that Bellingcat researchers were able to definitively geolocate using open source evidence, and does not reflect the full extent of civilian harm across Ukraine – pinpoints more than 300 attacks on schools or childcare facilities, 170 hits on healthcare or humanitarian sites, and four dozen incidents targeting food and related infrastructure. 

While many attacks were clustered around four main cities – Kharkiv, Donetsk, Kherson and Kyiv – we documented strikes across all areas of the country. Of the weapons that could be identified through available open source information, cluster munitions were used in more than 100 cases. 

Cluster munitions, which are banned in more than 100 countries (but not Russia or Ukraine), have killed more than 1,200 people since the war began, with Ukraine recording the highest number of annual casualties worldwide from these weapons in 2024 for the third consecutive year, according to the Landmine and Cluster Munition Monitor. 

Bellingcat and members of its volunteer community logged all verified incidents of civilian harm on an interactive TimeMap over a four-year period spanning February 2022 to December 2025. The map is no longer being updated, but it remains online as an archive (and can be seen below). 

An interactive map detailing incidents of civilian harm between February 2022 and December 2025.

Since Russia’s invasion four years ago, the civilian toll in Ukraine has been stark, with around 15,000 killed – including more than 750 children – and 40,600 injured, according to a January 2026 report by the Office of the United Nations High Commissioner for Human Rights. 

An analysis last year by Armed Conflict Location and Event Data (ACLED) found that Russia followed “a persistent pattern of targeting of populated areas … often indiscriminate, other times more deliberate”. 

Related videos from Bellingcat

New apartment complexes are listed for sale on Russian websites. Meanwhile, Ukrainians are struggling to reclaim their homes.

ACLED’s data for the period of February 2022 to late January 2026 highlights thousands of residential strikes across Ukraine, along with more than 750 attacks on healthcare facilities, 1,200 on educational sites, and 2,400 on energy infrastructure. A February 2025 World Bank report says it will take more than US$500bn to rebuild Ukraine. 

These numbers tell only part of the story. While much global media attention has focused on the politics of the Russia-Ukraine war, or highlighted strikes on large urban centres, civilians in remote rural villages have suffered outsized impacts from the destruction of schools, hospitals and cultural institutions – the key threads tying their communities together.

In Verkhna Syrovatka, a small village in Sumy of around 3,800 people, images from the scene of shelling in May 2025 revealed a massive hole in the community’s blue-roofed cultural house. Inside the facility, which once served as a place for rehearsals, children’s classes and folk ensembles, photographs and trophies could be seen amid piles of splintered wood and cracked concrete.

The village’s only school was also impacted, with many of its windows blown out, forcing classes to move online. This devastation reflects a countrywide trend, as UNICEF reports that Ukrainian children are falling behind in core subjects such as reading, maths and science.

Incidents of civilian harm recorder by Bellingcat in Verkhna Syrovatka. Readers can click or tap the dots to learn more about each incident.

Further south, the village of Opytne in the Donetsk region is gradually being erased, amid a series of Russian attacks dating back more than a decade to the 2014 occupation of the Crimean Peninsula. 

The village has changed hands repeatedly in recent years. In December 2022, drone footage revealed large-scale destruction of its residential area, including a medical office, music school and church. According to media reports, perhaps only half a dozen residents remain out of more than 1,000 who lived in the village a decade ago.

Image left shows the village of Opytne in 2021, before Russia’s full invasion (Credit: Airbus/Google Earth Pro). Image right shows the village of Opytne in 2024 (Credit: Maxar/Google Earth Pro).

A couple of months later, in February 2023 in Dvorichna, a rural settlement in the Kharkiv region, Russian forces launched another double-tap strike: as first responders searched for survivors from an earlier attack on the village council building, several emergency vehicles were hit. 

Located just south of the Russian border, Dvorichna has been occupied on and off since 2022. As a result, the village, whose population was roughly 3,500 four years ago, is estimated to house only 80 residents today.

Across Ukraine, the catalogue of horrors is endless. In Pravdyne, a small village in the Kherson region, the prewar population of more than 1,000 people was reported to have dwindled to fewer than 200 by late 2022. Corpses showing signs of torture have been exhumed from garden beds; in one case, residents reportedly buried the bodies of Ukrainian soldiers under slabs of slate to prevent dogs from reaching them. 

Incidents of civilian harm recorder by Bellingcat in Pravdyne. Readers can click or tap the dots to learn more about each incident.

In Sumy Oblast, Russian drone and missile attacks have forced residents to flee homes they inhabited for half a century. In the village of Hroza in northeastern Ukraine, one-fifth of the population died in a single attack while attending the funeral of a soldier, according to local officials.

What may never be calculated are the impacts this brutal conflict will have on future generations.

Incidents of civilian harm recorder by Bellingcat in Hroza. Readers can click or tap the dots to learn more about each incident.

Back in Krasnopillia, the local school director, Pryima says residents have tried hard to stay in what she calls “the zone of resilience”, but it has been a struggle.

“It’s very scary to fall asleep, because you don’t know if you’ll wake up in the morning,” she said, noting that residents live in constant fear of the drones that fly overhead, keenly aware that a bomb may drop at any moment. 

For Ukrainian children, the effects have been especially dire.

“Those children, before the full-scale invasion, were carefree, cheerful – what children should be,” Pryima said. “Those children are no longer there.” 


Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post How Russia’s War Has Devastated Civilian Life in Ukraine appeared first on bellingcat.

  • ✇bellingcat
  • How Russia’s Invasion is Impacting Ukraine’s Youth Bellingcat Investigation Team
    Last month, in the dead of a cold Autumn night, residents in the Ukrainian town of Balakliia were woken by the sound of two massive explosions. Social media footage showed apartments ablaze, balconies obliterated and a deep crater smouldering in a parking lot. Three people were killed and 13 injured in the November 17 attack, Ukraine’s State Emergency Services (SES) said. Four of those injured were children, the SES added. A kindergarten, situated just over a hundred metres from one of the
     

How Russia’s Invasion is Impacting Ukraine’s Youth

17 de Dezembro de 2025, 04:07

Last month, in the dead of a cold Autumn night, residents in the Ukrainian town of Balakliia were woken by the sound of two massive explosions.

Social media footage showed apartments ablaze, balconies obliterated and a deep crater smouldering in a parking lot.

Three people were killed and 13 injured in the November 17 attack, Ukraine’s State Emergency Services (SES) said. Four of those injured were children, the SES added. A kindergarten, situated just over a hundred metres from one of the impact sites, was also reported to have suffered damage.

Since the beginning of the full-scale invasion of Ukraine, schools, educational facilities and spaces used by children have repeatedly been damaged in strikes or closed because of them.  

According to the United Nation’s agency for children, UNICEF, many schools remain closed or continue to be disrupted by air raid alarms. Almost one million children have also been forced to study online, UNICEF states.

Balakliia lies in Kharkiv Oblast in the north east of Ukraine. Another Russian strike carried out there earlier in November caused damage near the town’s main square. Located just over 100 metres away was a high school and not far from that a local theatre school. While neither of those facilities appeared to be directly damaged, many other educational institutions have not been so lucky.

Educational Facilities in the Firing Line

A Ukrainian government website (saveschools.in.ua) has been tracking the number of kindergartens, high schools, colleges and universities that have been damaged and destroyed across the country.

At time of publication 3,676 educational facilities have been damaged nationwide and 394 destroyed, according to saveschools.in.ua.

These trends are reflected in social media data collected by Bellingcat.

Since the start of Russia’s full-scale invasion, Bellingcat has been gathering and verifying social media footage showing incidents of civilian harm. 

More than 2,500 incidents have been identified during this period, including attacks on hospitals, power stations, residential buildings and cultural sites. The full dataset is public and can be found here. But this is likely just a fraction of the damage caused across Ukraine as the data only captures incidents recorded and published on social media channels that have been verified.

Amongst this dataset are more than 200 cases of educational facilities that have been damaged or destroyed.

In September this year, for example, social media footage captured the moment a Russian drone hit an administrative building at Kharkiv’s National University of Pharmacy.

As far  back as July 2022, a school for the visually impaired in eastern Kharkiv was hit by Russian rockets, leaving windows smashed and classrooms burned out.

Just a few months before that, footage posted online appeared to show the remains of a missile that hit a school in the town of Merefa, situated around 30 kilometres to the southeast of Kharkiv.

Kharkiv’s Youth Bears Burden

More educational facilities have been damaged or destroyed in Kharkiv Oblast than in any other territory currently held by Ukraine, according to Bellingcat’s dataset and saveschools.in.ua statistics.

In Kharkiv city and its surrounding areas, Bellingcat found and archived footage of at least 26 schools, kindergartens, colleges or universities that have been damaged and destroyed since Russia’s full-scale invasion. A further 36 strikes that impacted areas around educational facilities in Kharkiv but did not directly hit them were also verified and archived by Bellingcat.

Bohdan Levchykov, a 15-year-old teenager, walks by a damaged habitation building in Balakliia, on October 13, 2025. OLEKSII FILIPPOV / AFP

Sustained attacks on educational facilities as well as widespread disruption to studies caused by the war are having a lasting impact on Ukraine’s young people, children’s rights groups say. 

A report from Save the Children earlier this year detailed how attacks on educational facilities had doubled in Ukraine over the course of 2024. The same report found that parents were scared to send their children to school and that many children were being forced to resort to online learning at home.

A 2024 report from UNICEF has found Ukrainian children are falling behind children in other countries across all/multiple subjects including  reading, maths and science.

In Balakliia, journalists from Agence France-Presse (AFP) bureaus in Paris and Kharkiv spoke to teenage student Bohdan Levchykov who said he studies at home and seldom leaves the house. Levchykov also spoke about the impact of losing his father in the early months of the war.

About an hour’s drive to the northwest, in the town of Khorocheve, a psychologist with the non-profit Voices of Children , Maryna Dudbyk, told AFP that the ongoing war means that everyone is living under stress. 

“This has a huge impact on children’s emotional state,” she said.

“We diagnose a lot of fear and anxiety among children. Adolescents suffer from self-harm, suicidal thoughts, and the loss of loved ones.”

Beyond Schools

Other facilities, beyond schools, regularly enjoyed by children have also been impacted by the war, compounding the challenges young people face.

Bellingcat’s dataset found 28 incidents where swimming pools, parks, football pitches, bowling alleys or museums had been impacted in and around Kharkiv. A further 16 incidents were recorded in areas surrounding such facilities. The below interactive shows (in red) incidents where educational or recreational facilities used by young people have been impacted by Russian strikes in and around Kharkiv. The other markers in the map (in purple) detail additional civilian harm incidents Bellingcat has been able to verify. A wider dataset of showing incidents that have impacted areas surrounding educational and recreational facilities can be found here.

Incidents of civilian harm directly affecting schools and childrens’ leisure facilities are highlighted in red.

One video from March this year showed young men playing football scrambling for cover as a drone can be heard overhead before an explosion can be seen.

Although Ukraine’s policymakers are facing many challenges as Russia’s invasion of Ukraine approaches its fifth year,  the mental health of the country’s youth is on their minds.

Oksana Zbitnieva, head of the Interministerial Coordination Center for Mental Health told AFP that “130,000 frontline health professionals—nurses, pediatricians, family doctors—have received certified training as part of a WHO mental health program.” 

Meanwhile, more than 300 “resilience centres” welcome children and parents across the country, with three hundred more expected to be built next year, according to Ukrainian Social Affairs Minister Denys Uliutine. 

New concepts are also being tested and tried.

Children leave an underground school in Kharkiv, on October 16, 2025. OLEKSII FILIPPOV / AFP

In Kharkiv, underground schools – located beneath the streets of the city – are being set up to help bring children back into the classroom.

City authorities told AFP there would be 10 underground schools operational by the end of 2025.

At a school visited by AFP, a rotating system allows it to continue offering children in-person education, even if only for a limited time, each week. The school enables every  child to attend  half a day of their class in-person each week. When the  child returns home they continue their education via remote classes, while another student comes into school for their half day spot. This allows the school to accommodate 1,400 children, including on weekends. 

Yet recent events in Kharkiv highlight that normal life is far from returning, despite recent peace efforts.

At the end of October, a kindergarten in the west of the city was struck by a Russian drone.

Footage from the scene showed panicked parents and disoriented children being carried from away by emergency workers as smoke billowed from the kindergarten.

Despite the scale of the destruction visible in social media footage, only one person (an adult male) was reported to have died during this strike.

For many youngsters in Ukraine, there may be no reclaiming the childhood that war has taken from them.

But Bohdan Levchykov in Balakliia believes there are still things to look forward to.

He told AFP about  the friends he had made online   – including one named Lana who lives more than 400km away in the city of Dnipro- and his  hopes of  meeting them in real life one day.

“I’ve talked about it with my mother,” he told AFP. 

“Maybe our parents can arrange something for us to meet,” he said hopefully.


Eoghan Macguire, Youri van der Weide and Logan Williams contributed to this report for Bellingcat as did Stéphanie Ladel and Olivia Gresham from Bellingcat’s Volunteer Community.

Boris Bachorz reported and conducted interviews for AFP with the help of Natalia Yermak.

A version of this story can be found on the website of the Central European Digital Media Observatory (CEDMO) website.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Twitter here and Mastodon here.

The post How Russia’s Invasion is Impacting Ukraine’s Youth appeared first on bellingcat.

  • ✇bellingcat
  • Profiting From Exploitation: How We Found the Man Behind Two Deepfake Porn Sites Kolina Koltai
    Content warning: This article contains descriptions of non-consensual sexual imagery. Depending on which of his social media profiles you were looking at, Mark Resan was either a marketing lead at Google or working for a dental implant company, a human resources company and a business software firm – all at the same time.            Facebook photos showed Resan vacationing in Bali (left) and relaxing at luxury hotels in Dubai (right). Blurring by Bellingcat But a Bellingcat investigation
     

Profiting From Exploitation: How We Found the Man Behind Two Deepfake Porn Sites

15 de Dezembro de 2025, 12:00

Content warning: This article contains descriptions of non-consensual sexual imagery.

Depending on which of his social media profiles you were looking at, Mark Resan was either a marketing lead at Google or working for a dental implant company, a human resources company and a business software firm – all at the same time.           

Facebook photos showed Resan vacationing in Bali (left) and relaxing at luxury hotels in Dubai (right). Blurring by Bellingcat

But a Bellingcat investigation has found that the Hungarian national is the key figure behind, and the likely owner of, at least two deepfake porn websites – RefacePorn and DeepfakePorn – that until recently were selling paid subscriptions. 

There is no question about the nature of these websites. RefacePorn’s landing page shows an explicit video of a woman performing a sexual act. As the video plays, her face is replaced with a variety of other women’s faces. The text above declares: “Face swap deepfake porn. Upload your face!” 

Deepfake porn sites such as these, which use artificial intelligence to create sexually explicit images and videos – usually without the consent of those whose faces or bodies are featured – have proliferated at an alarming rate in recent years. The impact on victims has been described as “life-shattering”, with the mental health effects similar to those reported by victims of sexual assault

While the technology to make these synthetic images is not new, the rise of mainstream AI image generator tools and “Nudify” apps has made it more widely available to people without deep technical expertise. Earlier this year, New Zealand MP Laura McClure held up an AI-generated nude of herself in parliament, describing how it took her less than five minutes to create after a quick Google search. 

A 2024 study by the My Image My Choice campaign found that there was a 1,780 percent increase in sexually explicit deepfakes last year compared to 2019. Almost all (99 percent) of victims were women, according to a 2023 study by Security Hero. 

Illustration for Bellingcat by Ann Kiernan

The creation of such images and videos is now illegal in a few countries, including the US and the UK, but legislation has not caught up in many others, and the owners of platforms that enable this content often face no repercussions. In May 2024, the EU passed a directive which mandates that member states – including Hungary, where Resan resides – criminalise the creation and distribution of non-consensual sexual deepfakes by June 2027. 

Alexios Mantzarlis, co-founder of Indicator, a news site that focuses on digital deception, said his publication estimates that deepfake porn sites likely make millions of dollars a year. 

“The incentive system will continue to exist until the tools become too toxic to handle for domain hosts and content delivery networks,” added Mantzarlis, who is also the director of the Security, Trust and Safety Initiative at Cornell Tech.

All Roads Lead to Resan

Bellingcat’s investigation into RefacePorn and DeepfakePorn – which spanned corporate registries, domain name registrations, payment redirect sites, website code and leaked data – led us back to Resan. 

By simulating the purchase of subscriptions on these websites, Bellingcat was led through a series of redirects to a payments dashboard by Peerwallet, a payment processor that recorded more than US$331,000 in sales from July 2024 to August 2025 by Dorocron LLP. Dorocron is a Canadian-registered company whose main – if not sole – source of income appeared to be from paid subscriptions to these sites. The real amount is likely higher, as this was just one of several payment processors the websites have used.

Subscribe to the Bellingcat newsletter

Subscribe to our newsletter for first access to our published content and events that our staff and contributors are involved with, including interviews and training workshops.

Dorocron LLP did not respond to multiple requests for comment via email, and calls to the number listed on sites that had the company’s details in their legal information sections went unanswered.

Resan is the only person who appears to have been publicly associated with Dorocron LLP, and he is also the sole director of a UK-registered company, Facitic Ltd, that registered the domain of RefacePorn. Resan did not respond to multiple requests for comment sent via email over the past two weeks. Multiple emails and phone calls to Facitic Ltd also went unanswered.

However, days after we first reached out to Resan, his LinkedIn and X profiles were deleted, and his previously public Facebook profile was either deleted or made private. Both RefacePorn and DeepfakePorn also became inaccessible, displaying an error message that said “this site can’t be reached”. 

Archives of RefacePorn and DeepfakePorn, which were previously available on the Internet Archive’s Wayback Machine, have also now been excluded from the archive. The Internet Archive told Bellingcat it processed exclusion requests submitted by someone with rights to both sites on Dec. 5. 

Following the Money

Like other websites Bellingcat has investigated, RefacePorn’s ownership was hidden behind a network of website domains, fake websites used to redirect payments, and international business registries. 

Using the tool DNSlytics, we examined the Google tag history on RefacePorn and found a tag that was also used on DeepfakePorn, as well as a website called facitic.com. 

Google Analytics tags are small pieces of unique code that developers can place in the backend of a website to track its analytics. Each code is unique to a specific user, who can use the same tag across multiple websites. 

Both RefacePorn and DeepfakePorn offer tiered subscription packages with similar names and prices based on the number of deepfakes that could be generated and the level of support. 

When simulating a purchase of one of these packages – without actually completing payment – on DeepfakePorn, we received a link to make a payment hosted through the domain “remakerai.me”. Similarly, a mock purchase on RefacePorn pointed us to a payment link on “airemaker.me”. Bellingcat has observed the use of redirects, which can be used to obscure payments, by other deepfake porn sites. Many payment processors, including Paypal and Stripe, have restrictions on buying or selling sexually oriented online content.

SiteAdminPaymentProcessorRedirectSiteAnotherRedirect SiteDeepfakeSiteSiteUser

Payment processors often block payments that come from websites making deepfake pornography.

Using a redirect site hides the original site from the payment processor, making it harder to block.

Despite this, payment processors sometimes manage to block the redirect site.

But If one redirect site is blocked, the site owner can quickly switch to another redirect site that isn’t blocked.

Graphic: Galen Reich

The redirected payment links hosted on airemaker.me and remakerai.me offered several payment options including Paypal, credit cards and cryptocurrencies. Bellingcat selected the credit card option, and in both cases was emailed a link to complete the purchase on a payment platform called Peerwallet. This email included a link to the seller’s profile, Dorocron LLP. 

This profile showed the funds received by the seller, which totalled more than $331,000 as of August 2025. This income was related to 16,264 sales. According to this dashboard, Dorocron LLP had been a member of Peerwallet since July 22, 2024, meaning these sales all occurred over the past year.

Screengrab of Peerwallet profile for Dorocron LLP, showing about US$331,000 in funds received for sales 

RefacePorn has been active since at least May 2022, according to promotional posts by an Instagram account with the username “Dorocron2323” and the account name “Hassler Mark”. Social media accounts for RefacePorn were also created on X and Facebook in May 2022.

Screengrab of an Instagram post from May 2022 promoting RefacePorn’s website, which is now down. Blurring by Bellingcat

While the transactions on Peerwallet were not broken down by domain, two were the payment redirect sites for the deepfake porn sites we investigated. Bellingcat’s review of the 21 “approved domains” listed on this profile found no evidence that payments were ever accepted through the other sites. 

Short-lived, “disposable” domains are known to be used by bad actors to evade detection, presenting a moving target for payment processors and authorities. As of publication, both airemaker.me and remakerai.me are no longer accessible. But in the course of the investigation, we observed RefacePorn and DeepfakePorn’s payment links redirecting to other third-party sites, before the sites went offline.

The Peerwallet profile showed transactions by users, as well as 21 approved domains including those redirecting payments for RefacePorn (refaceporn.com) and DeepfakePorn (deepfakeporn.app)

Of the 21 domains on Dorocron LLP’s Peerwallet profile, only two were still accessible as of the end of November, with the rest either down due to expired domains or server issues, displaying generic domain parking pages, or requiring a login to view. Though almost all of the sites had their registration information redacted, Resan was listed as the most recent registrant for one of the expired domains.

The two sites still accessible listed a variety of products, including eBooks and digital products. Both had almost identical products and templates, and listed Dorocron LLP under their company information in their footers. 

Bellingcat tried to check out items on each of the sites, and in both cases was prompted to log in. It was, however, impossible to register an account, and when we tried with an active email address we were redirected to a login page saying that the email address was “unknown”. 

Archived screengrabs of some of the sites that now have expired domains or require a login to view showed that many of them followed the same format, selling eBooks and video courses with “resell rights”.

Peerwallet told Bellingcat in September that Dorocron LLP was “not approved” to sell deepfake porn, and that it was looking into the issue. However, when Bellingcat asked for an update in November, Peerwallet appeared to have closed down. Emails to the payment processor’s founder have also gone unanswered. 

The Man Behind the Screen

Dorocron LLP was registered in British Columbia, Canada in March 2022. We were unable to verify if Resan’s name was on the corporate records as information on company owners or directors in British Columbia is restricted to law enforcement and other officials. 

However, Resan’s name has been used to register at least 13 sites alongside an email bearing  Dorocron’s name from as far back as 2013, nine years before Dorocron was registered in Canada. The earliest domain registration, from 2013, included the name of a now-dissolved UK-registered company called “Webnaser LTD”, whose registration documents also cite Resan as the sole director

WHOIS history information for a site that Resan first registered in 2013. Source: Whoxy

A leak found on data breach site Intelx.io shows that an almost identical password (with different capitalisation of some letters) was used to log into this “dorocron” Gmail account and a Netflix account associated with Resan’s personal email address. This password was also used to log into web domain registry GoDaddy using RefacePorn’s support email address. 

Leaked passwords on Intelx.io revealed another link between Resan and DeepfakePorn: an email with the username “resanmark” was used to log into DeepfakePorn’s website, with a password containing his birth year. In all, we found four unique passwords that were reused between Resan’s personal emails, the Dorocron emails, and a support email for RefacePorn. These four passwords include either Resan’s name or the date or year of his birth. 

Resan also posted two job listings from his now-deleted LinkedIn account about a year ago, for a full-stack web developer and a WordPress developer at Dorocron LLP. In the web developer listing, he described the company as “developing and applying revolutionary AI technologies” and said the job would have “high wages”. We could not find any other individual with a public association to Dorocron LLP on LinkedIn or elsewhere.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Aside from his links to Dorocron LLP, Resan is also the sole director and person with significant control of Facitic Ltd, a UK-registered company which was listed as the registrant for RefacePorn. 

Using DomainTools, we were able to see the historical registrant information in a WHOIS lookup of the site’s domain registration. When we checked this in August 2025, we were able to see that, as of June 2025, Facitic Ltd was the registered owner of RefacePorn. This information was later redacted – as it is for other sites linked to Resan such as DeepfakePorn. 

ICANN, which regulates websites, requires domain name providers to verify the accuracy of their customers’ details, including the registrant's name and contact details. Such details are publicly visible by default, but can be anonymised using paid privacy services

The UK registration for Facitic Ltd lists Resan’s country of residence as Dubai, while the registration for another UK company he registered – which was also listed as the owner of some of the now-expired approved domains on Dorocron LLP’s Peerwallet profile – states that he resides in Cyprus. Meanwhile, Resan’s social media accounts stated that he lives in Hungary. On Peerwallet’s dashboard, the primary user of Dorocron is listed as being based in Hungary. 

It is unclear if Resan actually holds positions in any of the six companies he listed himself as working at on his Facebook and LinkedIn profiles. Bellingcat has reached out to these companies to check, but has not received any replies as of publication. 

Some of the connections Bellingcat found between RefacePorn and Mark Resan:

Graphic: Galen Reich

On Nov. 10, 2025, a few weeks before we contacted him, Resan applied for Facitic Ltd to be struck off the UK companies register. Based on Resan’s filings, Facitic Ltd was incorporated with an initial capital of £100 in January 2024, and there has been no recorded change in its accounts since. 

This comes as UK regulator Ofcom cracks down on websites associated with UK businesses offering AI-powered nudify services. On Oct. 23, Ofcom imposed a £50,000 fine on UK-registered company Itai Tech Ltd, which has been linked to some of the biggest deepfake pornography sites in the world, for failing to prevent children from accessing pornographic content. 

It is unclear what triggered Resan to file to dissolve the company, and he did not respond to Bellingcat’s query about this. 

Small Sites, Big Harm

The websites linked to Resan are not among the largest in the deepfake porn industry. A similar but much larger site that Bellingcat has investigated, MrDeepFakes, received millions of visits each month. Bellingcat and its partners Tjekdet, Politiken and CBC exposed the site’s key administrator David Do in May, with MrDeepFakes going offline after we reached out to Do for comment. 

In comparison, RefacePorn and DeepfakePorn received about 91,000 and 154,000 visits in October, according to digital marketing platform SemRush. But their smaller size does not mean they can’t cause significant harm. 

Mantzarlis, of the news site Indicator, said there were “smaller players” taking bigger risks around regulation, such as “Crush AI”, a group of Chinese-owned apps that bypassed Meta’s moderation rules to run 25,000 ads on Facebook and Instagram before the social media giant sued them. 

“These smaller players are often the ones that are more actively trying to stand out on social media to catch up with the bigger ones,” Mantzarlis said.

In the course of our investigation, we ran tests using the free features on RefacePorn to determine if there were any restrictions on images that could be uploaded on the website. 

Without actually generating the content, we uploaded AI-generated images of adult women and underage girls. Unlike on other websites we have tested, which have added the bare minimum of checks to prevent uploading images depicting children, there was no restriction or evidence of age-related safeguards on RefacePorn. 

While there aren’t laws in Hungary explicitly prohibiting deepfake porn, the possession, creation and distribution of sexually explicit images of minors is illegal

“As the more established websites come under sustained regulatory pressure and others get litigated into oblivion, the minnows are ready to try and capture market share,” Mantzarlis said. 

And while some sites such as RefacePorn and DeepfakePorn may fold in the face of public scrutiny, others continue to operate, unchecked and easily accessible, online. 

“These websites are eminently replaceable and there's no reason to believe that there is any form of ‘brand loyalty’,” Mantzarlis said. “Perpetrators are going to search for ‘nudify’ or click on an ad and go to whatever tool does the job.”


Melissa Zhu contributed to this report.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here and Mastodon here.

The post Profiting From Exploitation: How We Found the Man Behind Two Deepfake Porn Sites appeared first on bellingcat.

  • ✇bellingcat
  • Russia’s Smuggled Grain Finds New Market in Saudi Arabia Bellingcat Investigation Team
    A joint investigation by Bellingcat and Lloyd’s List has identified Saudi Arabia as the newest country to import grain directly from a Western-sanctioned port in occupied Crimea, as Russia attempts to secure recognition of the Ukrainian territory via a US-led peace plan. Satellite imagery and Automated Identification System (AIS) data from Lloyd’s List Intelligence shows the bulk carrier Krasnodar (IMO: 9296781) sailed from Avlita Grain Terminal in Sevastopol to Saudi Arabia on two occasions
     

Russia’s Smuggled Grain Finds New Market in Saudi Arabia

12 de Dezembro de 2025, 09:38

A joint investigation by Bellingcat and Lloyd’s List has identified Saudi Arabia as the newest country to import grain directly from a Western-sanctioned port in occupied Crimea, as Russia attempts to secure recognition of the Ukrainian territory via a US-led peace plan.

Satellite imagery and Automated Identification System (AIS) data from Lloyd’s List Intelligence shows the bulk carrier Krasnodar (IMO: 9296781) sailed from Avlita Grain Terminal in Sevastopol to Saudi Arabia on two occasions between September and November 2025. Bellingcat confirmed Krasnodar’s journeys ended at Saudi Arabia’s King Abdullah Port in September and the Port of Jazan in November.

These journeys show that Saudi Arabia has joined buyers in Iran, Syria, Egypt, Turkey, Venezuela and Houthi-controlled territories in Yemen who are willing to accept what the Ukrainian government describes as “stolen” grain. 

MapLibre | Protomaps© OpenStreetMap contributors

Black Sea

Krasnodar goes dark – an AIS gap lasting more than two weeks begins on August 22.

Occupied Crimea: Port of Sevastopol

Imagery shows Krasnodar docked at Berth 21 of the Avlita grain terminal at the Port of Sevastopol on August 27.

Credit: Planet Labs PBC

Black Sea

Krasnodar turns its AIS back on in the Black Sea, as required to transit the Bosphorus on September 6.

Bosphorus Strait

Krasnodar transits the Bosphorus. Judging by the draft, with no visible red paint on its hull, the ship appears to be fully laden.

Credit: Yörük Işık

Saudi Arabia: King Abdullah Port

Imagery (as well as AIS data) shows Krasnodar docked at the King Abdullah Port. A pile of what appears to be grain is visible to the right of the image on September 18.

Credit: Planet Labs PBC

Bosphorus Strait

Returning via the Suez Canal, Krasnodar transits through the Bosphorus on September 28 with its red paint fully visible, indicating it is not heavily laden.

Credit: Yörük Işık

Black Sea

Krasnodar goes dark – an AIS gap lasting more than one week begins on October 6.

Occupied Crimea: Port of Sevastopol

Satellite imagery shows Krasnodar docked, with its hatches open, at Berth 21 of the Avlita grain terminal on October 8.

Satellite image ©2025 Vantor

Black Sea

Krasnodar turns its AIS back on in the Kerch strait. After a few days loitering in the Kerch strait, it transits through the Bosphorus.

Bosphorus Strait

With no red paint visible and the Plimsoll line near maximum draft, the vessel appears to be fully laden when it transits the Bosphorus on October 26.

Credit: Yörük Işık

Saudi Arabia: Jazan City

AIS data shows Krasnodar docked at Jazan City for Primary and Downstream Industries for seven days. Planet imagery captured it on November 6.

Credit: Planet Labs PBC

After leaving Jazan, Krasnodar returned to the Black Sea via the Bosphorus on November 23.

It stopped transmitting AIS for a third time on November 24 for nine days and has been intermittently transmitting data since.

Krasnodar was again captured in satellite imagery docked at the Avlita terminal in Sevastopol on November 26. 

Krasnodar captured in satellite imagery docked at the Avlita terminal in Sevastopol on November 26. Credit: Planet Labs PBC

Petrokhleb-Kuban Denies Visiting Avlita Terminal

Documents accessed on Russia’s federal registry indicate the vessel is leased by Russian firm Petrokhleb-Kuban, a major player in Russian and international grain markets. 

Petrokhleb Kuban told Bellingcat it “categorically denies any allegations of involvement in the theft of grain from Ukrainian regions”.

It added that Petrokhleb-Kuban does not export grain from the Avlita terminal to any country.

“Petrokhleb-Kuban does not operate at the port of Avlita and does not ship grain from there. All grain shipped by Petrokhleb-Kuban is produced by Russian farmers,” a spokesperson said. 

“The vessel Krasnodar follows all widely accepted safety protocols and does not disable its AIS while on passage. The AIS signal in the Black Sea is being jammed by the military due to the ongoing conflict between Russia and Ukraine.”

The spokesperson also said the vessel Krasnodar was loading barley at the port of Kavkaz, “as confirmed by bills of lading and port clearance.”

AIS interference is rampant in the Black Sea, however, instances of jamming typically do not last more than a couple of days. Further, third-party disruptions impact all vessels in one area indiscriminately. 

Bellingcat reviewed the AIS traces of vessels sailing near Krasnodar. In both voyages, Krasnodar was the only vessel in that area that stopped transmitting AIS data for that period of time.  

Bellingcat also checked available Planet Labs PBC and Sentinel-2 satellite imagery covering the grain terminal in Port Kavkaz during the two periods of August and October where Krasnodar has absent or unreliable AIS coverage and found no vessels matching the length of the Krasnodar.

Bellingcat identified Krasnodar in Avlita terminal on three occasions, by cross referencing satellite images of Krasnodar and recent images and video of the ship. Krasnodar was last detected at Avlita terminal in satellite imagery on November 26, again with its AIS switched off.  Krasnodar’s chimney is navy blue in colour, except for a white band on the left, right, and front side of the chimney. The ship’s other features – five grey hatches, four grey cranes, a red deck, a green floor on the bridge, all visually match known images of the ship.

Finally, the ship’s measurements (a total length of 183 metre according to Russia’s shipping registry) matches what we see in satellite images.

Visual Comparison: Images of Krasnodar at Avlita Terminal and other recent images of Krasnodar

The Krasnodar has a dark blue (midnight navy blue) chimney with a white band that runs around the sides and the front of the chimney, leaving the back completely blue.

A close up of the Krasnodar photographed in the Bosphorus on October 26, 2025. Credit: Yörük Işık.

The life boats are immediately to the left and right of the bridge. The boats can also be seen in satellite imagery from Saudi Arabia. The image below shows Krasnodar in Jazan.

Krasnodar seen in Satellite Image at the Port of Jazan, Saudi Arabia on November 6, 2025. Credit: Planet Labs PBC.

Satellite imagery also clearly shows the colour of deck (dull red), the floor colour of the bridge (green), the colour of the hatches and the cranes (grey). All of that, as well as the chimney (navy blue with white) can be matched with satellite imagery from Sevastopol that show Krasnodar docked at the Avlita grain terminal.

Left: Krasnodar seen in Satellite Image at the Port of Jazan, Saudi Arabia on November 6, 2025. Right: Krasnodar seen in Satellite Image docked at Avlita grain terminal in the Port of Sevastopol on October 8, 2025. Credits: Planet Labs PBC and 2025 Vantor.

Five grey hatches and a red deck. The image on the left is from Jazan (November 6). The image on the right is from Sevastopol (October 8).

A close up of the above images. Credits: Planet Labs PBC and 2025 Vantor.

If we zoom in on the bridge, we can also see that the shape and the colour (grey) of the top of the bridge are also a visual match. 

The chimney is not very clearly visible in the image from Jazan but it is clear that the chimney is dark in colour. The image from Sevastopol shows a dark blue chimney with a white band, which was also visible in images and video of Krasnodar.

Left: Krasnodar seen in Satellite Image docked at Avlita grain terminal in the Port of Sevastopol on October 8, 2025. Right: A close up of the Krasnodar taken in the Bosphorus on October 26, 2025. Credits: 2025 Vantor and Yörük Işık. Annotations by Bellingcat.

We see red on the hull, below the water line, in the Sevastopol satellite image. You can also see it in the image from when the ship transited the Bosphorus. The rest of the hull is dark.

Left: Krasnodar seen in Satellite Image docked at Avlita grain terminal in the Port of Sevastopol on October 8, 2025. Right: Krasnodar photographed in the Bosphorus on October 26, 2025. Credits: 2025 Vantor and Yörük Işık.

There are no live or historic sanctions on Krasnodar, according to Lloyd’s List Intelligence data.

Saudi Arabia Joins List of Importers of Russia’s Smuggled Grain


Krasnodar’s voyages from Sevastopol to Saudi Arabia demonstrate that Russia is continuing to expand its grain exports from occupied Crimea to new markets as it negotiates to end the war in Ukraine.

Crimea’s occupied ports have become important assets for Moscow, having evolved into key logistics hubs for dark grain exports over the course of the war.

Prior to the full-scale invasion of Ukraine in 2022, the ports in occupied Crimea were used for the small-scale export of grain and scrap metal, mostly to Syria and Turkey.

The occupation of additional territory in Donetsk and Zaporizhia enabled Russia to establish a new supply route, resulting in more grain being shipped south to Crimea for export to international markets.

The Port of Sevastopol and the Avlita grain terminal remain under European, UK and US sanctions. While no UN sanctions specifically target the port, a majority of UN member states have passed resolutions condemning Russia’s invasion of Ukraine and its occupation of Crimea since 2024. 

Ukraine has repeatedly tried to dissuade countries from purchasing shipments loaded with what it describes as “stolen” grain from occupied regions.

In 2023, Iran received its first grain shipments from Sevastopol. In 2024, it was joined by Venezuela, Libya, Egypt and the Houthis, which control territory in Yemen. Last month, Bellingcat revealed that the bulk carrier Irtysh (IMO: 9664976) delivered grain from the Crimean port of Sevastopol to the Houthi-controlled port of Saleef in Yemen despite Western Sanctions. 

Bellingcat and other news outlets have identified a total of eight countries that have imported grain directly from occupied Crimea.

While Saudi Arabia is the latest direct importer from Sevastopol, it is unclear if authorities are aware of the origin of the cargo. 

The grain shipments follow a similar pattern to Russia’s shadow fleet, which moves sanctioned oil barrels. In both cases steps are taken to disguise the origin of the cargo and port of loading.

Most ships calling to Crimea disable their AIS transponders, which is considered a deceptive shipping practice, and fraudulent documents are issued. 

Alona Shkrum, First Deputy Minister for Development of Communities and Territories of Ukraine, told Bellingcat that Ukraine was closely monitoring Russian exports from occupied territories. She said Ukraine had discussed the issue with Saudi Arabia on the sidelines of recent talks at the International Maritime Organisation Assembly.

She told Bellingcat that Ukraine had “received assurances that Saudi authorities are actively counteracting the risks posed by shadow fleet operations and other violations of international maritime law.” 

She added that Ukraine would continue to work with partners to identify and sanction vessels involved in the illegal export of grain from occupied territories. 

Bellingcat contacted both the Saudi Arabian Ministry of Foreign Affairs and the Russian Ministry of Foreign Affairs; neither responded to requests for comment. 

US-Russia Peace Plan and Ownership of Ukraine’s Ports


The US-Russia 28-point peace proposal includes the recognition of Crimea, Luhansk and Donetsk as “de facto” Russian. Ownership of Crimea and the occupied territories bordering the Sea of Azov is critical for securing shipping routes to and from Russia, and these ports play a vital role in supporting economic growth in the region. 

However, the impact of ceding control of this region and the port of Sevastopol to Russia is not mentioned in either the original US draft plan or subsequent amended versions.

Ian Ralby, chief executive of the maritime and resource security consultancy I.R. Consilium said while it was a high priority for Ukraine to ensure access to the grain market through the Black Sea is preserved, Russia is continuing to try to expand its global access to ports. 

“We see that there is a resurgence in Russia’s efforts on port access.”

“As the prospect of potential peace begins to loom, even though it seems to be much farther off than many would want, there is likely to be a renewed focus on the key strategic assets that matter for the future, and the ports have to be foremost among them.” 


Bridget Diakun, Yörük Işık, Youri van der Weide, Peter Barth and Galen Reich contributed to this report.

Cover image: Planet Lab image shows Krasnodar docked at Jazan City, Saudi Arabia on November 6. Credit: Planet Labs PBC.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Twitter here and Mastodon here.

The post Russia’s Smuggled Grain Finds New Market in Saudi Arabia appeared first on bellingcat.

From School to Battlefield to Grave: How Russian Cossacks drive young people to war

5 de Dezembro de 2025, 08:08

From School to Battlefield to Grave

How Russian Cossacks drive young people to war

This video was posted in April 2024 by Беркут, a student association within a Russian Federal University.

Students, about to leave for an Airsoft competition, stand in military formation outside a campus building.

This is Олег Монин who took Berkut’s oath four months earlier. Through this veiled Cossack Youth Organisation, he trained in combat tactics with returned fighters and transitioned from pretend to real weapons.

Within a year, Oleg abandoned his studies and enlisted in БАРС-15, a Cossack Volunteer Battalion fighting in Ukraine.

By Feb. 10, 2025 Oleg was dead. He died aged 19, less than four months after deployment in Ukraine.

As of February 2025 there were more than 18,500 Cossacks on the front lines in Ukraine and approximately 50,000 in the army reserve.

Cossack societies, organisations, and even military units provide an identity that is indigenous to Russia, Visiting Assistant Professor at Miami University, Dr Marcello Fantoni told Bellingcat.

This identity is “rooted in ‘traditional’ values, martial prowess, military readiness, orthodox religiosity and a culture not influenced by the ‘corrupting’ West,” Fantoni added via email. This is why “education is central to the overall enterprise”.

Oleg’s story demonstrates how the Cossacks drive young people from a school club to a war zone and enable a state-sponsored alternative mobilisation force.

WHO ARE THE RUSSIAN COSSACKS?

The Cossacks played an important role in the formation of the Russian Empire. They lived in communities called hosts on the edges of the empire. They operate under a military hierarchy ruled by a chief, the Ataman. Due to their loyalty to the Tsar, the Cossacks were repressed by the Bolsheviks after 1917.
Credit: Journal “Chronicle of War”, 1915; Nicholas II among officers

When the Soviet Union collapsed in 1991, the Cossacks’ descendants called for a “rebirth”. In 2005, a bill submitted by President Vladimir Putin allowed registered Cossack organisations members to serve in military units and police forces.
Credit: tamvesti.ru

New hosts were created in traditionally non-Cossack lands with a variety of institutions to direct them. In 2018, the government united them in the “All-Russian Cossack Society”. Putin tries to marginalise the traditional Cossack groups, analyst Paul Goble told Bellingcat while the ones “he has created for his own purposes” play a “major role in military and patriotic education”.
Credit: Kremlin

There are 13 registered Cossack Hosts across all of Russia.

Only 8 of Russia’s 83 recognized Federal Subjects do not have a registered Cossack Host.

In 2018, the Black Sea Cossack Host of Crimea entered the register. The peninsula has been under Russian occupation since 2014. The Cossack legacy is also vitally important to Ukrainian identity.

There are new hosts in the occupied Ukrainian territories of Kherson, Zaporizhzhia, Donetsk, and Luhansk.

Russian Cossack organisations have been “very active within the occupied Ukrainian regions,” Dr Fantoni told Bellingcat. They “recruit local residents and then deploy them for cultural and military purposes,” allowing Russia “to contest and even co-opt a central tenet of Ukrainian national identity – Cossackdom,” he said.

The national “All-Russian Cossack Society” VSKO was created in 2018, and in 2019, the State Duma gave Russian President Vladimir Putin exclusive authority to appoint its national Ataman.

Credit: Portal 'Russian Cossacks'; Vitaly Kuznetsov

At the top of the VSKO is Ataman Vitaly Kuznetsov, a Cossack General.

Credit: All-Russian Cossack Society; Vitaly Kuznetsov and Nikolai Doluda

Kuznetsov was appointed in November 2023, succeeding the first-ever national Ataman – Nikolai Doluda, then 70 years old and a sanctioned individual.

Kuznetsov has also become a leading Cossack interacting with the Russian state.

Credit: Kremlin; Dmitry Mironov and Vitaly Kuznetsov

Including with Dmitry Mironov, assistant to President Putin and Chair of the Council for Cossack Affairs.

Credit: All-Russian Cossack Society; Vitaly Kuznetsov and Dmitry Chernyshenko

And Deputy Prime Minister of Russia Dmitry Chernyshenko.

Credit: All-Russian Cossack Society; Vitaly Kuznetsov and Leonid Pasechnik

As well as Leonid Pasechnik, head of the Luhansk People’s Republic. Kuznetsov thanked Pasechnik in June for helping create three Cossack Cadet Corps in the occupied region.

Credit: Portal 'Russian Cossacks'; Vitaly Kuznetsov with Cossack students of the K.G. Razumovsky Moscow State University of Technology

According to Kuznetsov, the VSKO priorities are “development of military Cossack societies in all directions: education, culture, history, and most importantly, youth. Everything through youth.”

EVERYTHING THROUGH YOUTH

Cossack education can be divided into primary, secondary, and tertiary levels, all with the goal of promoting a unified system.

Credit: sestroretsk.com; Cossack kindergarten pupils

At the primary level are the Cossack kindergartens, which compete nationally to be named the best.

Credit: MOU 'Secondary School No. 43 named after V.F. Margelov'; Cossack students

There are Cossack schools and regular schools with a Cossack affiliation. Data from 2022 claim there were just under 2000 such institutions with around 210,000 students, but recent claims point to over 300,000 students.

Credit: shakhty-media.ru; Cossack Cadets

The most intense level of Cossack education is the Cossack Cadets Corps, of which there are 31 across the country, with the newest corps created in Russia’s Far East. They also compete nationally.

Credit: Moscow State University of Technology and Management named after K.G. Razumovsky (PKU); Cossack University graduation ceremony

Finally, the Association of Cossack Universities has 26 members, with many concentrated in Rostov and Krasnodar. There is also a Union of Cossack Youth, which in 2022 had more than 163,000 members. More than 5,500 Cossack youth took part in military exercises on training grounds in 2023.

Oleg’s story demonstrates how young people outside formal Cossack education can still get pulled in. It also shows that the Cossacks are but one of several interlaced strategies for “military-patriotic” education.

Oleg grew up in Saratov.

Image of youth practicing putting on a gas mask, posted on VKontakte by Lyceum N.3.
Credit: Image of youth practicing putting on a gas mask, posted on VKontakte by Lyceum N.3.

He studied in Lyceum N.3, a state-funded educational institution in Saratov. Often, the school promotes events like the national Zarnitsa competition. It includes activities like “putting on gas masks” or “sniper games” for third graders.

Credit: Military student club 'Fakel'; Students in military fatigues at an Avangard 24h training.

The school’s military club “Fakel” acts as an intermediary for these events and other nationwide military education initiatives such as the 24-hour-long Avangard training for tenth graders.

Credit: MAOU 'Lyceum No. 3 named after A.S. Pushkin'; School director receives an award for contribution to patriotic education.

In 2024, Natalia Saprykina, the director of Lyceum N.3, was awarded a Letter of Gratitude for her “contribution to the patriotic education of the younger generation” by a Deputy of the Regional Duma.

Oleg graduated from high school in 2023 at the age of 17.

In the same year he enrolled in InPIT, a higher education institution of the Saratov State Technical University.

By November Oleg had turned 18 and was wearing military fatigues and practising survival skills alongside other candidates of a “military-patriotic” student association named Berkut, at another local university, the Saratov State Law Academy (SSLA).

Credit Telegram @infberkut; Photo from Berkut's survival skills training.

Though Berkut is not explicitly a Cossack organisation, we established several connections between the head of Berkut, Alexander Andreevich, and Cossack organisations. As we’ll see, Andreevich was present at multiple military style training camps that Oleg took part in.

Neither Berkut’s VKontakte nor Telegram channel descriptions mention the Cossacks.

Credit: VKontakte @svpo_berkut; Translated screenshot of Berkut's VKontakte description.

Neither does its page in the University website.

Credit: SSLA; Screen grab of Berkut's page in the SSLA website.

The association’s official objectives are “forming a positive image of military service” and “popularisation of service in the Russian army and law enforcement agencies”. It is headed by Alexander Andreevich.

Credit VKVideo @svpo_berkut: Still from one of Berkut's VK videos.

However, some of Berkut’s videos include the banner of a Молодёжная казачья организация.

Credit: Telegram @atamanfetisov; Translated Telegram post by Andrey Fetisov.

A Telegram post by Andrey Fetisov, the Saratov District Ataman, refers to Berkut as a “Cossack Youth Movement”.

Even though Berkut (left) shares a name and eagle iconography with a notorious Ukrainian special police force (right), part of which defected to Russia during the occupation of Crimea in 2014, Bellingcat found no link between the two organisations.

Credit: VKVideo @svpo_berkut; Berkut Logo
Credit: Wikipedia; Emblem of the Berkut special police force of Ukraine.
FROM WAR GAMES TO REAL WEAPONS

By December 2023, nearing the end of the first semester, Oleg and the other candidates took the Berkut oath, making them official members. Oath-taking ceremonies are “invented traditions” among Cossack forces.

Credit: VKontakte @svpo_berkut; Berkut Oath Ceremony

Atop the dais stand senior members of Berkut, including the head of the organisation – Alexander Andreevich.

Credit: VKontakte @svpo_berkut; Berkut Oath Ceremony

Andreevich is an active Cossack who has been working under the guidance of District Ataman Andrey Fetisov since at least April 2023.

Credit: Instagram @fetisov_; Alexander Andreevich and Andrey Fetisov

More recently, in January 2025, they were both delivering a lesson to Cossack children for Yunarmiya, exemplifying the overlapping network of youth militarisation initiatives.

In July 2025, they both attended Saratov’s Council of Atamans that was hosted at the Ministry of Internal Policy and Public Relations of Saratov. Local organisations often meet there.

Credit: VKontakte Sergey Frolov; Alexander Andreevich and Andrey Fetisov at a Saratov council meeting.

In August 2024, Andreevich attended the iVolga Cossack Youth Festival, where he met Kuznetsov. The only two people featured speaking in an official video.

Credit: VKontakte @svpo_berkut; Alexander Andreevich and Vitaly Kuznetsov at a Cossack Youth Festival

Andreevich also led Oleg to two military-inspired events in April 2024.

The first, on April 13, was the annual Airsoft competition.

Credit: VKontakte War Games: Operation Satellite; Berkut members stand in formation at the Airsoft event
Credit: VKontakte @svpo_berkut; Oleg and other Berkut members inside a training helicopter

Five days later they went to a training that included trench tactics and simulated helicopter jumps.

Credit: VKontakte Alexander Andreevich; Oleg, Andreevich and other Berkut members at Rosgvardia training ground

Since 2023, Oleg often wore a distinctive yellow and red “Скорпион” call sign patch on his chest when wearing military fatigues, which distinguishes him from other youth at the events. That and other distinctive features identify him even with a mask or goggles.

Credit: Vkontakte Oleg Monin; Profile picture from Oleg's VK and Telegram posted on 2023-09-10
Credit: Vkontakte Oleg Monin; Profile picture from Oleg's VK posted on 2023-04-13

Bellingcat was able to geolocate this place to be a Rosgvardia training ground on the outskirts of Saratov.

Credit: VKontakte @svpo_berkut; Graphics for the geolocation of training in Rosgvardia training grounds

Notably, the trenches are not visible on Google Earth but are on Yandex Maps, which has more recent imagery for the region.

Credit: VKontakte @svpo_berkut; Trenches photo from Rosgvardia training grounds
Credit: VKontakte @svpo_berkut; Berkut at Rosgvardia training

This group photo tells its own story. The flags visible are, from left to right, for the Volga Cossack Host, the Immortal Regiment, the Kuban Cossack Host, and Veteran News.

Oleg is at the far right wearing his “Scorpion” and Berkut patches.

This time, ex-fighters were there too.

Sergey Frolkov is an ex-fighter in the war on Ukraine. He regularly posts photos with an Akhmat special forces patch, associated with Kadryovites . He is also a member of the local Combat Brotherhood association.

Credit: VKontakte Sergey Frolkov; Cropped photo of Sergey Frolkov

As is Oleg Mysov, another returned fighter who also engages in “patriotic education of youth” events.

Credit: VKontakte Oleg Mysov;Cropped photo of Oleg Misov

Both have attended Cossack events. Even though in this photo they are holding the Volga Cossack Host flag, Bellingcat could not clearly identify them as Cossacks.

A third man, Andrey Berdnikov is indeed a Cossack and a former fighter of BARS-15, the Battalion Oleg joined, though he was reportedly expelled by his Commander. On the left, Alexander Andreevich.

Credit: VKontakte PATRIOT; Cropped photo of Andrey Berdnikov

Bellingcat contacted Sergey Frolkov, Oleg Mysov and Andrey Berdnikov before publication to ask about their roles, but did not receive a response.

Five months later, in September 2024, Oleg went on a two-day training. Andrey Fetisov got a special thanks for the opportunity.

Credit: VKontakte Andrey Fetisov; Photo from the Sep 2024 training featuring Oleg

Bellingcat geolocated it to a military training ground in Samara, the same location where other Cossack recruits trained before deploying to BARS-15. Fetisov himself shared photos of this training ground two weeks after stepping down as Ataman to join BARS-15. Andreevich left and Oleg right in this photo.

Credit: VKontakte Andrey Fetisov; Geolocation graphics with Oleg and Andreevich

They used real weapons this time. A video montage shows participants firing live rounds.

Credit: VKontakte Andrey Fetisov

This is a photo that includes Oleg, Fetisov, and Andreevich. The first media we found for this event is from early September which is consistent with the sun position in this photo and the grass patches seen in satellite imagery from early September 2024.

Credit: VKontakte Andrey Fetisov; Geolocation graphics of photo with Oleg, Andreevich, and Fetisov

Bellingcat contacted Kuznetsov, Fetisov and Andreevich to ask about their roles in the Cossack community, but they haven’t responded.

This is the last time Bellingcat was able to trace Oleg’s whereabouts with open sources before he joined BARS-15.

VOLUNTARY RECRUITMENT

Many countries have a volunteer reserve system for getting more soldiers in times of war. In Russia, the system is known as BARS, created in 2015 and intensified in 2021. All BARS fighters sign a contract with the Ministry of Defense and get paid.

Mapping the geolocated positions of these units in the UAControlMaps Project dataset reveal widespread areas of operations. BARS Battalions are often reorganised. Estimates put the total number so far at over 30 BARS Battalions and 10 of them have overt Cossack affiliation.

Cossacks also operate as detachments in other military structures. By their own reckoning, in February there were more than 18,500 Cossacks on the front lines in Ukraine. In May the first-ever national Ataman, Nikolai Doluda, gave a higher figure of 46,000 Cossacks.

As of 2024, British Professor Rod Thornton estimated that BARS constitute some 10-30,000 troops in Ukraine, 15% of the total invasion force.

The Mediazona project tracks individual Russian losses in Ukraine and publishes bi-weekly reports. As of Nov. 21, 2025, they identified 149,241 publicly named casualties, Oleg among them.

The project also tracks volunteer casualties.

Deaths of volunteer fighters constituted 12.8% of losses in 2022 and 21.9% 2023. In 2024 they more than doubled to 45.7%. As of Nov. 21, verified deaths of volunteer fighters for 2025 were at 42.8%.

BARS-15

BARS-15 is a Cossack battalion created on May 15, 2022, and named Ермак after a historical Ataman. Originally composed of Cossacks from multiple hosts, mainly Volga and Oremburg, it now draws its members from the Volga Host only.
Credit: All-Russian Cossack Society

These are some of BARS-15 specific patches.

Credit: Telegram @bars15ermak; BARS-15 patch
Credit: OK Alexander Cherepanov; BARS-15 patch
Credit: VKontakte Kolya Karbon; BARS-15 patch
Credit: Telegram @izvestia64; BARS-15 patch
Credit: VKontakte @atamanovko; BARS-15 patch
Credit: VKontakte @atamanovko; BARS-15 patch
Credit: Rutube SAMARA | 450media; BARS-15 patch
Credit: Telegram @vskoru; BARS-15 patch
Credit: Telegram @vvko_russia; BARS-15 patch

While in BARS-15 Oleg was reportedly assigned to the 15th Separate Guards Motor Rifle Brigade. Several sources place BARS-15 as subordinate to the 15th Separate Guards Motor Rifle Brigade also known as the Black Hussars, headquartered at the Samara Oblast. Bellingcat geolocated this video from September 2024 to their training grounds.

Credit: VKontakte Oleg Monin; Profile picture from Oleg's VK posted on 2023-04-13

The panel reads Black Hussars. Oleg is on his knee in front of Andreevich, wearing his distinctive “Scorpion” patch.
Credit: VKontakte @svpo_berkut

The number of active Cossack fighters in BARS-15 is reportedly 400, a number echoed by a former Commander, with other sources saying over 900 volunteers have passed through as of September 2024. They reportedly took part in the invasion of Avdiivka among other combat activities in Ukrainian cities both in Donetsk and Luhansk.
Credit: VKontakte @vvko_russia

Bellingcat geolocated this warehouse to the west of Selydove, Donetsk, using satellite imagery and reference images from when the warehouse was a concrete products factory.

Credit: LLC 'Sembiz-1' Selidovsky Reinforced Concrete Plant; Geolocation graphics over crop from facebook image of warehouse
Russia captured Selydove in October 2024. BARS-15 posted from there in January 2025 and June 2025.

One of its former members is Andrey Fetisov, who temporarily stepped down as Saratov District Ataman and joined BARS-15 between approximately November 2023 and June 2024.
Credit: Telegram @izvestia64

The identification of Fetisov’s call sign – СЛЕНГ – suggests he took on military roles such as “Deputy Commander for Educational Work” and “Political Officer”.

In April 2024, Fetisov received a Medal for Bravery from Vitaly Kuznetsov, the national Ataman. Within six months, Fetisov would be taking Oleg to the BARS-15 training camp.
Credit: Telegram @izvestia64

There are many reasons why people are motivated to join Cossack groups, Dr Fantoni told Bellingcat, adding that these motivated individuals “are the driving force” behind militarisation. “Some do it out of patriotic motivations, others for political, economic or individual status gain, some even because this can protect oneself from future mobilisation to an actual fighting unit,” he said.

In the end

Oleg’s connection to the Cossacks was not typical. He did not attend a Cossack school or university and still found himself in their midst via the military youth groups he joined. As his story demonstrates, Cossacks are embedded into the education system. Their involvement includes Berkut showcasing Kalashnikovs to kids in a mall, a teacher and returned BARS-15 fighter weaving camouflage nets with children, a former BARS-15 commander giving inspirational lessons to young students, and Cossack cadets drawing “heartfelt mementoes” to send to BARS-15.

The Russian government announced that funding for the Cossacks will double in the next two years and it continues to implement its Strategy in relation to the Russian Cossacks 2021-2030.

The first-ever national Ataman and Kuznetsov’s predecessor, Nikolai Doluda, is working on a new national law on the Cossacks and the creation of a mobilisational reserve from the Cossacks.

This image first appeared on Oleg’s obituary posted by Fetisov. The vehicle, road, and equipment are consistent with those used by other fighters with the Black Hussars around February 2025.

According to recruitment posts BARS-15 training takes three weeks. A recent study found that to be the norm in Russia’s military while also labelling training as “low-quality and ineffective”.

Oleg’s obituary, published by his University states that “based on the results of training, he was appointed commander of a 120 mm mortar crew”.

Bellingcat reached out to Oleg’s parents.
His mother said she couldn’t speak about Oleg’s death,

it still hurts too much.

Additional research by Timothy B, Afton Briones, Sarah Grossman, Alexandra Malikova, Mitchell Polman, Olivia Gresham, Bonny Albo, Adam Arthur, Robert Chapman of the Bellingcat Volunteer Community.

Youri van der Weide and Aiganysh Aidarbekova contributed to this report.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here and Mastodon here. With the unpredictability of social media algorithms making it harder for news outlets to reach audiences consistently, we have also started a WhatsApp channel that you can join to stay updated on our stories.

Satellite images are courtesy of Yandex, Maxar, Airbus, MapBox and Google Earth.

Co-funded by the European Union. Views and opinions expressed are those of the author(s) only and do not necessarily reflect those of the European Union or the European Health and Digital Executive Agency (HADEA). Neither the European Union nor the granting authority can be held responsible for them.

The post From School to Battlefield to Grave<span id="hide-colon">:</span> <span class="subtitle">How Russian Cossacks drive young people to war</span> appeared first on bellingcat.

❌
❌