Visualização de leitura

Your AI hiring tool isn’t an HR problem. It’s a security one

For years, applicant tracking systems and recruiting platforms were treated as HR technology: Important for workflow, efficiency, compliance and candidate experience, but rarely viewed as core security infrastructure. That assumption no longer holds. Once AI begins reading resumes, scoring candidates, conducting interviews, ranking applicants and influencing who moves forward, the hiring platform stops being a passive system of record. It becomes a decision system.

And any system that accepts public input, processes sensitive data and influences business decisions belongs inside the security conversation.

I learned this during an AI hiring platform rollout that never made it to production. The vendor was established, the product had a strong market reputation and the AI feature looked attractive: Upload a resume, compare it to a job description and return a neat percentage match. For recruiters, it promised speed. For executives, it promised modernization.

Before moving real candidate data into the system, I tested it with synthetic resumes. One weak resume came back with a surprisingly strong match. The reason was not hidden in the candidate’s experience. It was hidden in the text. The resume contained language instructing the AI to treat the candidate as an excellent fit, and the system appeared to follow that instruction instead of evaluating the resume on merit.

That changed the question from “Does the tool improve productivity?” to “Can the person being evaluated influence the evaluation itself?”

That is a security question.

The trust boundary has moved

CIOs do not need to become recruiting experts. They only need to look at the mechanics.

An anonymous user submits content into an enterprise system. That content is processed by software. The software then produces an output that can influence a business decision. In every other environment, security teams know what to call that: untrusted input crossing a trust boundary.

The difference is that in hiring, the input looks harmless. It is a resume, a cover letter, a chatbot reply or a spoken answer in an AI-led interview. But once AI reads that content and treats it as instruction, the harmless-looking input becomes part of the system’s control surface.

That is why prompt injection matters in hiring. It is not just an AI oddity or a model behavior issue. It is the same category of failure enterprises have spent decades trying to prevent: User-controlled input changing what the system does. OWASP lists prompt injection as the first risk in its Top 10 for LLM applications, describing it as a case where user prompts alter a model’s behavior or output in unintended ways.

In hiring, the implication is direct: A candidate may be able to manipulate the score, ranking or interview assessment that determines whether a human ever sees them.

The business impact is not theoretical

The obvious risk is that an unqualified candidate moves forward. But the impact is broader.

First, decision quality degrades. Hiring teams adopt AI scoring because they believe it improves signal. If the score can be manipulated, the business is not gaining signal; it is gaining false confidence. Recruiters may spend time on candidates who gamed the system while stronger candidates are buried lower in the queue. A tool bought to reduce friction can quietly create more of it.

Second, cost increases under the appearance of efficiency. Every false positive consumes recruiter time, hiring-manager attention, interview slots and opportunity cost. A small weakness in screening integrity can become a measurable operational drag across open roles.

Third, trust suffers. Candidates already question whether AI hiring tools are fair, explainable or accurate. If it becomes clear that a screening system can be manipulated by hidden instructions or verbal prompting, the issue is no longer just security. It becomes reputational. Strong candidates may lose confidence in the process, and employers may have to defend decisions made by systems they did not fully understand.

Fourth, sensitive data exposure becomes harder to contain. Recruiting systems hold names, addresses, work histories, education histories, compensation details, work authorization information and sometimes accommodation or demographic data. NIST guidance on personally identifiable information includes employment information as linkable personal data that must be protected from inappropriate access, use and disclosure. Yet hiring platforms often receive less security scrutiny than systems holding customer or financial data.

That mismatch is dangerous: High-value data, public-facing workflows and increasing automation.

The 2025 McHire incident should have made this impossible to ignore. Researchers reported that weaknesses in McDonald’s AI hiring platform, including default credentials and an access-control flaw, exposed applicant data at large scale before the issue was patched. The lesson for CIOs is not merely that a weak password was used. The lesson is that AI hiring systems can ship with basic, preventable security failures while still being treated as HR tools rather than enterprise risk surfaces.

Vendor reputation does not transfer to every AI feature

One reason this risk slips through is that buyers often trust the platform brand. Mature vendors may have strong security programs, enterprise customers, compliance documentation and procurement-friendly answers.

But AI features can change the architecture of risk.

A platform that was safe as a workflow tool may behave very differently once it adds resume scoring, interview grading, chatbot screening or automated ranking. The new feature may introduce new inputs, new model behavior, new data flows, new third-party dependencies and new decision points. In practical terms, the attack surface has changed.

CIOs should not allow AI features to inherit trust automatically from the legacy platform around them. When a vendor adds AI, the enterprise should reassess the feature as if it were a new product. That does not mean slowing innovation for bureaucracy. It means AI-enabled decision-making carries different failure modes from ordinary workflow automation.

The ownership gap is the real vulnerability

The biggest risk may not be the model. It may be the ownership gap.

Talent acquisition may buy the tool. HR operations may configure it. The vendor may guide implementation. Procurement and legal may approve the contract. But who owns the security of the candidate-facing AI layer?

In many organizations, the honest answer is unclear.

That ambiguity is where risk grows. Recruiting technology sits at the intersection of public input, sensitive data, third-party software, automated decision support and brand trust. That is exactly the kind of environment that needs named security ownership, asset inventory, vendor review, access-control testing, logging and incident-response planning.

If the hiring stack is not in the security inventory, the organization is already making an assumption it may later regret.

What CIOs should require now

The fix is not exotic. It is applying existing security discipline to a surface that has been underestimated.

Treat every candidate submission as untrusted input. Resumes, cover letters, chatbot responses, interview transcripts and spoken answers should be handled as attacker-controllable content. If AI processes it, the system must separate content from instruction.

Reassess vendors when AI features are introduced. A prior security review should not be treated as permanent approval for new AI capabilities. Ask what changed in the architecture, what data the model sees, what actions it can influence and how manipulation attempts are detected.

Ask AI-specific questions before signing. Can candidate-provided content alter scoring? Are hidden instructions filtered or ignored? Is there human review before AI output influences a decision? Can the vendor produce testing evidence for prompt injection, access control and data exposure risks?

Assign ownership. HR can own the process, but security must own the risk model. AI hiring systems should be included in third-party risk management, application security reviews, access governance, monitoring and incident response planning.

Measure business impact, not just AI adoption. The goal is not to say the recruiting function uses AI. The goal is to improve hiring speed, quality, fairness and cost without creating new risk. If the system cannot protect decision integrity, the business case is weaker than it appears.

The hiring platform is now part of the enterprise attack surface

AI has turned the careers page into more than a front door for applicants. It is now a public input channel feeding systems that store sensitive data and influence workforce decisions.

That makes it a CIO concern.

The next failure in AI hiring may not look like a traditional breach at first. It may look like bad rankings, manipulated scores, unexplainable decisions, wasted recruiter time or a candidate process no one trusts. But underneath those symptoms is a familiar security problem: A system trusted input it should have treated as hostile.

Enterprises have hardened payment systems, customer portals, APIs and employee applications around that lesson. Hiring deserves the same treatment.

AI hiring is not just an HR transformation. It is a security boundary. And it is time CIOs treated it like one.

How to Use AI to Help Find Civilian Harm

Between February 2022 and September 2025, Bellingcat staff and volunteers collected, geolocated, and shared more than 2,500 incidents of civilian harm following Russia’s full-scale invasion of Ukraine. 

As part of this effort, Bellingcat tested a new machine learning model intended to rank Telegram social media posts on their likelihood of containing incidents of civilian harm. 

This novel methodology dramatically reduced the search and selection time required, freeing researchers to focus on verifying incidents of civilian harm – not just searching for them. 

This piece documents our methodology, ethical considerations and lessons learned in the hope that others researching similar topics can benefit from our work. 

Open source research into civilian harm is still a relatively new field and it presents many challenges – one of the biggest is organising and sorting through the huge volume of user generated content being produced to find what is relevant. 

Machine learning, a form of artificial intelligence that uses algorithms to identify patterns from large amounts of data and make predictions, can make this task more efficient.

With ongoing conflicts involving large amounts of civilian harm occurring in Sudan, and much of the Middle East, this guide aims to offer those covering these conflicts an example of how machine learning can be used to help find and sort incidents. You can also access the Code Notebook for our model here.

We defined “civilian harm” not just as civilian deaths or injuries resulting from armed conflict, but also the broader and delayed effects on civilians from mental trauma, loss of livelihood, displacement, destruction of infrastructure and more. This definition was informed by the Protection of Civilians book on civilian harm

Initial Telegram Dataset 

Each Telegram post containing civilian harm which had already been manually verified by researchers was used to build an initial dataset of confirmed cases of civilian harm, which data scientists call positive instances. We collected a total of 5,848 unique URLs for these Telegram posts. For our manual collection we reviewed posts on relevant Telegram channels, working through oldest to newest posts each day. Assuming that a given post made it to our geolocated incidents list, it meant the researcher who flagged it also looked at the posts that appeared before and after it on Telegram and did not flag those ones, so we selected the 10 posts surrounding the verified civilian harm post as our additional dataset of posts that did not contain civilian harm. After excluding any deleted or duplicate posts, we ended up with 48,545 non-civilian harm posts, our negative instances

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

The choice to overrepresent negative instances aims at better reflecting the real world and increasing data available for model training. 

We enriched each URL with metadata from the Telegram API, such as the time of publication, reactions or textual content. As some of these posts had been deleted, we completed the missing data points with previously preserved versions from our Auto Archiver database, only available for the positive instances.

Feature Engineering

Training a machine learning model requires numerical data, as these models compute a prediction score based on mathematical operations.

We built these by converting raw data from our initial dataset, such as keywords signalling potential civilian harm, into numerical scores (or “features”) that the model could interpret, with the aim of increasing the model’s ability to identify patterns. This process, known as feature engineering, can significantly improve model results because it allows data scientists to suggest explicit context knowledge. 

A full list of features we used to train the model can be found in the code notebook accompanying this piece. Many features were directly inspired by researchers’ input from their experiences manually screening cases of civilian harm by sorting through a set number of Telegram channels and inspecting each post individually.

Several of the features used were directly built from the metadata contained in each Telegram post including media_type, day_of_week; or binary ones: forwarded, edited and reply_to

Other features included engagement information: views, forwards, total_reactions, and even individual features for most used emojis including the reaction_crying_face to count 😭 emoji.

Converting Text to Numbers 

To embed the experience from the manual collection process, researchers put together a list of keywords both in Ukrainian and Russian that, to them, signalled posts likely to  show civilian harm. For instance, “Шахед” and “КАБ” translated to “Shahed” and “Guided aerial bomb” respectively. We created a numerical feature to count their frequency. 

In addition, we included several generic English-language keywords which meaningfully signalled potential civilian harm, such as “injured”, “school affected” and “hospital affected” that were only used for generating semantic similarity scores. 

A semantic similarity score is a calculation used to determine the proximity in meaning between different words and phrases. To get the semantic similarity between the post text and each of our keywords, we represented each in a list of numbers via a Sentence Transformer model, which converts words into numerical representations called vectors that a computer can understand. 

We then calculated the level of similarity between each vector using cosine similarity, one of the most popular methods for measuring similarity between two pieces of text.

Due to how embeddings work, this calculation results in a figure on a scale from -1 (no semantic proximity) to 1 (same meaning). For example, the words “hurt” and “injured” would have a high similarity score, while “residential” and “injured” would have a negative score as the words are not semantically similar. 

Finally, to enable the model to identify the relevance of each post to civilian harm in Ukraine, we used a multilingual text transformer from the BERT family of language models to represent the entire post’s text as a vector of 768 numerical values. This model can efficiently represent text from many languages in a way that captures meaning: the same sentence in different languages will generate similar embeddings, and trained machine learning models can detect patterns in the embeddings. 

It is important to note that for this initial prototype of a civilian harm detection model, we did not include any features derived from media content such as photos and videos, although that would be a logical next step in attempting to improve model performance.

Selecting, Training and Evaluating Models

With 54,393 rows of 893 numerical features each, we selected four machine learning algorithms to train our predictive models. 

We chose Logistic Regression as a baseline algorithm due to its simplicity. We also selected three other “best in class” models, Random Forest, XGBoost, and LightGBM. These choices centred on the interpretability of the models and their ability to work on tabular data of this size. For example, we avoided neural networks due to a lack of interpretability and because those models work best with a larger dataset. 

To genuinely assess the performance of the trained models, we split our dataset into three parts:  

  • A training set – the data the models were trained on (60 percent of the full dataset’s rows)
  • A validation set – used for an intermediary evaluation when tuning model parameters (20 percent of all rows)
  • A test set – hidden for the final performance assessment, so the models were evaluated on unseen data (remaining 20 percent of rows)

We used a stratified split to divide the dataset instead of a random split. This method ensured the proportion of positive instances (i.e. confirmed cases of civilian harm) remained consistent across all three sets at about 11 percent.

To measure the performance of machine learning models, we ran them through the test set and measured the number of correct and incorrect predictions. Models output a likelihood between 0 and 1 that each Telegram post contains civilian harm, and we tried to find a cut-off threshold that leads to a good balance between flagging almost every post (0.1) or flagging very few (0.9). 

There are two main types of evaluation metrics to gauge a model’s prediction power. Recall asserts what fraction of positive instances (i.e. known civilian harm posts) were correctly flagged as such. Precision measures the fraction of posts flagged as civilian harm that are indeed civilian harm posts.

Walber, CC BY-SA 4.0, via Wikimedia Commons.

During the training phase, we tuned the models to maximise average precision (PR-AUC), a metric that summarises precision across all recall levels. While this method also accounts for precision, it prioritises recall, which is preferable for this use case as it steers model selection to reduce the number of civilian harm posts that are skipped. 

The following table sorts models from best to worst PR-AUC against a baseline of a coin-flip predictor. ROC-AUC and F1 are two other evaluation metrics included as sanity checks. Simply put, ROC-AUC measures the probability of ranking two instances, one negative and one positive, correctly; F1 balances precision and recall equally and its best cut-off threshold value.

Model test scores comparison, XGBoost stands out in every relevant metric evaluated. 

From these results, we selected XGBoost as our final model as it had the best scores when compared across all metrics.

Interpreting the Model

Because these models are interpretable, we can understand which features are the most useful when predicting whether a post includes civilian harm. The above table shows the top 10 features that most strongly signal the XGBoost model to make a decision:

  • semantic_keywords_similarity: the semantic proximity between the post text and manually selected keywords “casualties”, “damage” and “civilian harm”
  • bert:  the model was able to discern meaning from the text with the same strength as some of the other features in this list – there are three cases of this in the top 10
  • reaction_crying_face: reactions with crying face emojis on the post
  • group_of_messages: whether a post contains multiple media files
  • keywords_in_text: the number of custom Ukrainian or Russian keywords in the post

These results generally tally with what you might expect when selecting Telegram posts for instances of civilian harm, including that posts that generate a lot of emotional engagement and posts using keywords about civilian harm were among those most likely to contain content related to this topic. Not all models had the same top features as XGBoost. In fact, for the Random Forest model the most important feature was the number of crying face emojis present in a post, a soft pattern highlighted by researchers when this methodology was first imagined.

LLM Results and Comparison

Retroactively, we decided to run a sample of the same test dataset through different large language models (LLMs) to gauge their ability to make these same predictions. 

We aimed to include an LLM-generated score as an extra feature for our trained models, which would be captured as relevant if it correlated with the correct predictions. 

To start, we selected two local models, the 1B and 4B variants of Gemma 3 from Google DeepMind, and two cloud-hosted models, Gemini 2.5 flash and Gemini 3.5 flash. With this selection, we hoped to compare results across a wide range of models’ expected performance. 

We generated a 400-row stratified sample (preserving the same proportion of real civilian harm instances) from the test dataset used for the custom models. For each of the four LLM models, we ran two tests: one where only the Telegram post message was sent, and another including both the message and the engineered features (excluding the text embeddings, as the model had direct access to the text). In the prompt for each model, we asked for a score between 0 and 1. We then evaluated the results as we did for the custom models. 

The above table shows that LLMs can indeed extract value from the engineered features. All four LLMs surpassed the baseline Logistic Regression model in our tests, yet none of them performed better than the other custom-trained models, and XGBoost remained the one with the highest PR-AUC. 

Still, Gemini 2.5 Flash performed better than its newer version 3.5 and even achieved a slightly higher best F1 score than any other model. While this is a good result, for the flagging of civilian harm posts, the PR-AUC remains the crucial metric, as it captures the model’s ability to identify infrequent instances of civilian harm while minimising false positives.

Ethical Considerations

Introducing an instrument of automated decision-making into a process of detecting civilian harm brings inherent ethical questions. These include automation bias, or how humans tend to blindly place faith in machine-generated recommendations; algorithmic bias, or how the results of these models echo the same patterns present in the training data, including under- or over-representation of types of civilian harm. 

The decision to test an automated methodology for this particular project came from the fact that there were limited resources for both steps in the process – the detection of potential civilian harm and its actual verification. Historically, we built an enormous backlog of unverified incidents because a lot of time had to be spent on monitoring the most recent events so that potential evidence would be captured and preserved as soon as possible. 

The automation of this process also reduced the exposure of researchers to a significant amount of unpleasant and distressing visual and text content, reducing the burden of exposure to traumatic content. 

For this project, we tried to ameliorate the ethical challenges with a number of strategies including randomly flagging posts not captured by any model, monitoring which features models relied on to make decisions, and by doing historical comparisons of patterns in data. 

Additionally, as stated above, for this initial prototype of a civilian harm detection model we did not include any features derived from the media content itself. In the future, it would be a logical next step in attempting to improve the model performance, to include the media from the posts – but using AI to review actual media comes with additional ethical challenges such as model bias.

Because of the opaque ownership of many LLM companies and their generative nature, the use of LLMs for an extra feature presented additional ethical challenges including privacy and safety concerns considering the sensitive nature of the data. Our model did not rely on LLMs, though we retroactively ran a sample through it. 

How the Model Fits into the Bigger Picture 

After selecting this model, we created a user interface where researchers could view a list of Telegram posts sorted from most to least likely to contain indications of civilian harm. The user interface was designed for quick triage and integration, where a positive confirmation from researchers would instantly send the post to the Auto Archiver (Bellingcat’s tool for preserving digital content) and then transfer it to ATLOS (our internal collaborative verification platform). Bellingcat staff and volunteers could then manually verify incidents. Researcher input was constantly stored so that this data could be used to improve the model in the future. 

Preliminary feedback indicated that the AI model was useful. Not only were we able to reduce time and harm from scouring through dozens of war reporting Telegram channels, researchers also reported that the stream of new posts being added to the verification backlog were capturing real and diverse cases of civilian harm. 

We recognise this model has much room for improvement and is a work in progress. Even though it can illicit diverse civilian harm posts, further tests and improvements (such as improved feature engineering and continuous evaluation) are needed before it can confidently be deployed.

Despite the focus on civilian harm and Telegram (highly popular in Ukraine and Russia), this pipeline is generic and can be adapted to other conflict monitoring tasks. How easily this can be done does depend on how open the social media platform is and whether it is possible to scrape posts from it. Apart from that, it is easy to incorporate new features and data, and cheap to automatically retrain, test and deploy models as the system receives more human input.  

Looking forward, sorting through overwhelming amounts of data in a conflict will continue to be challenging. Hopefully, this methodology can help newsrooms, conflict monitoring organisations, and others find the balance between ethical considerations and resources in order to carry out open source investigations on civilian harm and human rights violations. 


Editor’s note: This article was updated on July 3, 2026, to include a line outlining that the model described is a work in progress.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

The post How to Use AI to Help Find Civilian Harm appeared first on bellingcat.

Why AI-Native Cybersecurity Matters in the Age of Machine-Speed Threats

AI-Native Cybersecurity

By Sharat Sinha, CEO, Airtel Business The world has entered an era where more than 20 billion connected devices generate continuous digital exhaust. In this hyperconnected environment, AI-native cybersecurity is emerging as a critical foundation for protecting digital ecosystems. Every transaction, sensor read, API call and remote login now feeds a vast digital nervous system supporting economies, governments and critical infrastructure. As adversaries weaponize automation and AI to scale reconnaissance and exploitation, the cyberattack surface has expanded faster than traditional defenses can adapt. To safeguard national and enterprise resilience, security must evolve from fragmented, reactive controls to an AI-powered, human-led, always-on model delivered through a unified security platform.

Why Traditional Security Models Are Failing

Traditional architectures were designed for static networks and stable perimeters. They were never built for cloud-native workloads, edge computing, distributed workforces or API-centric digital ecosystems. Threat actors, however, now operate at machine speed—using AI to craft hyper-targeted phishing, escalate privileges autonomously and exploit misconfigurations in minutes. Meanwhile, breach discovery in many organizations still spans months. This widening gap between attacker speed and defender response highlights the need for continuous, intelligence-driven protection across network, identity, cloud and data layers.

AI-Native Cybersecurity Is Transforming Threat Detection

Within this shift, AI is emerging as a force multiplier—not a replacement—for human expertise. AI-driven analytics reduce false positives by up to 60%, correlate billions of signals across hybrid environments and detect weak anomalies invisible to manual analysis. Predictive models identify the vulnerabilities most likely to be weaponized, shrinking patch backlogs and strengthening overall resilience. Behavioral algorithms reinforce identity security by spotting subtle deviations that precede credential compromise. Even configuration hygiene improves as AI continuously validates cloud and network settings, eliminating exposures before they become incidents.

Unified Security Platforms Are Becoming the New Standard

AI is also enabling entirely new security capabilities. AI assistants for security leaders can summarize incidents, explain posture drift and produce board-ready insights in seconds. Autonomous SOC workflows now triage, enrich and contain threats across identity, endpoint and cloud layers. DevOps and cloud engineering teams use AI copilots to enforce guardrails and detect compliance drift—addressing misconfiguration risks that consistently rank among the top causes of breaches worldwide. These advancements reflect a broader global shift toward unified, AI-first cybersecurity platforms, where intelligence becomes the connective fabric linking telemetry from identity, network, cloud and data. Rather than operating dozens of siloed tools, organizations gain a single operating layer where detection, decision-making and response flow seamlessly. This consolidation accelerates containment, eliminates blind spots and frees security teams to focus on high-impact decisions. AI also strengthens data protection and regulatory alignment, including emerging requirements under India’s DPDP Act. Automated data classification, policy violation monitoring, retention enforcement and real-time breach alerts shift privacy oversight from periodic checks to continuous assurance. As India’s digital economy scales—driven by cloud adoption, fintech innovation and public digital infrastructure—AI-driven governance ensures both compliance and protection without increasing operational burden.

The Future of Cyber Resilience Will Be AI-Driven

The global direction is clear: AI-first, human-centered unified platforms are becoming the foundation of modern cyber resilience. With cyber incidents costing organizations millions of dollars and often causing systemic ripple effects, intelligent consolidation is no longer an efficiency strategy—it is a national and enterprise resilience strategy. Looking ahead, cybersecurity will be defined by how effectively organizations integrate AI across the entire lifecycle—posture management, threat prediction, protection, governance and automated response—while empowering human judgment at every critical decision point. In a world where threats operate at machine speed, always-on, AI-powered end-to-end protection is becoming the new standard. Organizations that embrace unified, AI-driven architectures will be best positioned to safeguard their people, data and services with confidence in an increasingly unpredictable digital landscape.

Shadow AI Is Growing in Silence While Enterprise Security Falls Behind

Shadow AI Is Growing in Silence

By Niall Browne, CEO and Founder, AIBound
Shadow AI is accelerating alongside artificial intelligence (AI) adoption at a pace that has outgrown most enterprise governance models. Artificial intelligence (AI) adoption is accelerating at a pace that has outgrown most enterprise governance models. According to the World Economic Forum, 87% of organizations report that AI-related vulnerabilities are now the fastest-growing cyber risk. Part of this surfaces with  employees increasingly deploying autonomous AI agents that connect to MCP servers and external AI that security teams have never assessed, quietly piping sensitive corporate data into systems no one in IT has ever audited — and no one in the C-suite knows exist. This increase in Shadow AI is creating systemic enterprise risk that can lead to unforeseen costs. Compliance frameworks like the Artificial Intelligence Act of the European Union (EU AI Act) take full effect this year introducing penalties up to 7% of global annual revenue for unmanaged AI. As regulatory frameworks begin to align with the realities of increased AI adoption, enterprises need to account for decentralized AI usage that operates outside traditional controls. This requires software that allows greater visibility, organization, and control into how AI is used and tracked across environments.

Shadow AI Is Creating a New Enterprise Attack Surface

The traditional security stack was built for a world that no longer exists — one with known assets, centralized systems, and software that asked permission before it ran. As new tools are introduced independently, usage levels evolve quickly without system checks or visibility into how these tools interact with sensitive data. Research indicates that 75% of CISOs have discovered unsanctioned GenAI tools in their environments, and only 5% feel confident they could contain compromised AI agents. Because of how easy these platforms are to access and require little onboarding, adoption is happening across teams at a rapid rate without IT involvement. Other security issues lie with employees integrating workflows with personal AI agents. These deployments allow sensitive information to be leaked or directly inputted into agents without security knowledge. Without a system in place for organizations to continuously track and evaluate how AI is being used across their enterprise systems, CISOs are left without visibility of their attack surfaces. The result is a slow-motion breach: data leaking, compliance crumbling, and governance reduced to a slide deck nobody enforces. Recurring data leaks and breaches via AI reveal the need for solutions that address this gap. Popular AI agents like ChatGPT for example, revealed a ‘ShadowLeak’ vulnerability that allowed sensitive email data to be breached through a zero-click attack. Other short lived features that rolled out last year allowed conversation sharing, leaving employee info, internal corporate strategies, and other sensitive data to be shared and indexed by search engines. Although this option only was available for a day, it was estimated that over 100,000 private chats were affected and able to be viewed with a simple search, allowing any sensitive information inputted to be publicly accessible. Other recent breaches include a Microsoft 365 Copilot bug allowing AI assistants to summarize emails labeled confidential, bypassing data loss prevention policies set up by organizations. Microsoft confirmed that a code issue allowed confidential emails data to be accessed despite organizational securities put in place. These agents are live and operational with local access to files, systems, commands, and APIs capable of executing tasks and retrieving data without clear oversight control. As AI usage continues to expand at accelerating rates, organizations need a way to better understand how these tools are used across their environments. No CISO has ever defended a perimeter they couldn't see. Shadow AI is the new perimeter — and most security teams are flying blind. Without a comprehensive inventory and control of AI usage, security teams are unable to accurately assess risks and enforce policy to maintain compliance.

Shadow AI Demands Continuous Visibility and Independent AI Control Planes

This is where adoption of independent AI Control Planes becomes vital. Independent AI Control Planes provides a way to continuously identify and assess AI activity giving security teams the visibility needed to manage emerging risks. It enables organization and categorization of AI usage across enterprises without relying on the manual entry and tracking that existing platforms demand — work no security team in a fast-moving environment can realistically keep up with. It’s undeniable: Shadow AI is not a future problem — it is already running inside your enterprise, on assets you don't own, through agents you never approved, touching data you are responsible for protecting. Every day without continuous, autonomous AI discovery is a day your attack surface grows faster than your governance can chase it. Regulators won't wait. Attackers already aren't. The CISOs who win the next 24 months will be the ones who stop pretending policy equals control and start operating on a simple truth: if you can't see it, you can't secure it — and right now, most of AI is invisible.

Disclaimer: The views and opinions expressed in this guest article are solely those of the author and do not necessarily reflect the official policy or position of The Cyber Express. The information shared is intended for industry discussion and awareness purposes only.

AI Cyberattacks Are Escalating Across the Americas. This Webinar Explains Why

Americas cyber threat landscape

The Americas cyber threat landscape saw a significant rise in AI-powered cyberattacks, ransomware campaigns, and critical infrastructure targeting during the first quarter of 2026, reflecting how rapidly cyber threats are evolving across the region. Security researchers observed that threat actors increasingly used generative AI to automate phishing campaigns, create convincing deepfakes, and accelerate exploitation techniques. At the same time, ransomware groups, hacktivists, and nation-state actors intensified attacks against organizations operating in healthcare, manufacturing, utilities, energy, and government sectors across North and Latin America. To help cybersecurity professionals better understand these evolving risks, Cyble will host a live webinar on May 28, 2026, focused on the key cyber threats, adversary tactics, and emerging attack trends shaping the Americas cyber threat landscape in Q1 2026. Americas cyber threat landscape

AI-Powered Cyber Threats Continue to Grow

One of the most notable developments during Q1 2026 was the increasing use of artificial intelligence by cybercriminals and advanced threat groups. Threat actors are now leveraging generative AI to produce highly targeted phishing emails, fake identities, deepfake content, and automated social engineering campaigns at scale. Security analysts warn that these AI-driven techniques are making attacks more difficult to identify and increasing the success rate of phishing and credential theft operations. Researchers also observed that attackers are using AI to accelerate reconnaissance and exploitation activities, enabling cybercriminals to move faster and target larger numbers of victims simultaneously. As AI-powered attacks become more sophisticated, organizations are facing growing pressure to strengthen detection capabilities and improve incident response readiness.

Critical Infrastructure Remains a Primary Target

The Americas cyber threat landscape also highlighted the continued targeting of critical infrastructure sectors during Q1 2026. Healthcare providers, energy operators, utilities, manufacturing organizations, and public sector institutions experienced persistent cyber threats from ransomware operators, hacktivist groups, and nation-state actors. Security researchers noted increasing concerns around operational technology environments and attacks designed to disrupt essential services. Supply chain vulnerabilities and third-party risks also remained major challenges for organizations responsible for maintaining critical infrastructure. Experts believe these attacks are no longer solely focused on financial extortion. Many campaigns are increasingly linked to geopolitical tensions, intelligence gathering, and disruption-focused objectives targeting national infrastructure and strategic industries. Cybersecurity professionals looking for deeper insights into infrastructure threats and AI-driven attack trends can register for the upcoming webinar hosted by Cyble.
Register Here

Nation-State Cyber Operations Intensify

Threat intelligence findings from Q1 2026 also revealed growing activity from nation-state groups associated with China, Russia, Iran, and North Korea. These groups continued targeting organizations across the Americas through espionage campaigns, vulnerability exploitation, credential theft, and malware deployment. Researchers observed that government entities, infrastructure operators, and large enterprises remained among the primary targets of these advanced cyber operations. Security experts warn that geopolitical developments continue to influence cyber activity, increasing the need for organizations to monitor emerging risks and strengthen resilience against sophisticated attacks.

Ransomware and Dark Web Activity Continue

Despite the growing attention around AI-driven threats, ransomware remained one of the most disruptive elements of the Americas cyber threat landscape in Q1 2026. Threat actors continued targeting organizations across multiple industries using double extortion tactics, data theft, and operational disruption strategies. Researchers also identified ongoing activity across dark web marketplaces and underground forums supporting cybercriminal operations through the sale of stolen credentials, access data, and attack tools. Hacktivist groups also remained active during the quarter, particularly in campaigns linked to political and regional conflicts. Security teams are increasingly prioritizing real-time threat intelligence and attack surface visibility to identify risks earlier and respond more effectively to emerging threats. The upcoming webinar will feature insights from Kaustubh Medhe, Head of Research & Intelligence at Cyble, Brian Osterman, Senior Solutions Engineer for the US region, and moderator Mihir Bagwe. The session will explore ransomware trends, AI-powered attacks, nation-state cyber operations, and practical recommendations for strengthening cyber resilience in 2026. Registered attendees will also receive a complimentary copy of the Americas Threat Landscape Report – Q1 2026. Webinar Details Date: Wednesday, May 28, 2026 Time: 1:00 PM ET Duration: 45 Minutes

Registration Link: Click Here

Mining China’s ‘Little Red Book’ for Open Source Gold

The challenges of conducting open-source research in China are well-documented. Consistently named one of the most digitally oppressive countries in the world, China blocks some of the world’s largest social media platforms, such as Facebook, Google, and YouTube. Those that are still accessible are mostly Chinese-owned, strictly regulated and monitored in real time by AI systems as well as tens of thousands of “internet police”

But despite these strict controls, Chinese apps – which boast more than a billion estimated users – remain an information goldmine for investigative journalists covering stories both within and outside China.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Since most foreign sites are banned, Chinese platforms are the largest resource available to journalists and researchers interested in what’s going on in the world’s second-most populous country. Even when a topic is being censored, patterns in the censorship can themselves serve as investigative leads: a 2020 BuzzFeed News investigation, for example, mapped out detention camps in Xinjiang by examining areas that had been blanked out on China’s Baidu Maps.

With millions of Chinese people living overseas, social media activity by members of the diaspora can also turn into global stories.

Serial rapist Zou Zhenhao, a Chinese PhD student, was jailed in London last year after one of his victims posted a warning on Xiaohongshu, also known as Little Red Book or Rednote, an app popular with young Chinese women living abroad. Another woman Zou had raped reached out to the original poster, who put her in touch with the police – leading to the conviction of a man described by police as possibly one of the worst sexual predators in British history.

Founded in 2013 as a Hong Kong shopping guide, Xiaohongshu has evolved into a lifestyle and e-commerce platform that has been compared with Instagram, Pinterest and Amazon. Last year, it reported about 300 million monthly active users, rivalling some of China’s largest social media platforms.

Xiaohongshu saw a surge in international users in January 2025 amid a threatened ban on short video app TikTok. Photo: VCG via Reuters Connect

The app’s 600 million daily searches by the end of 2024 also accounted for half of market leader Baidu’s search volume, demonstrating that it is emerging as a critical search and discovery engine, not just a social platform.

Although primarily a Chinese-language app, Xiaohongshu gained attention in the English-speaking world last year, when millions of American TikTok users flocked to the platform in anticipation of a TikTok ban under US President Donald Trump. 

Responding to the surge of international users – sparked by the #TikTokRefugees trend – Xiaohongshu rolled out an AI-powered translation feature, making the app more accessible to non-Chinese audiences. This also meant that journalists without Chinese language skills can more easily communicate on and navigate the platform.

Despite its growing popularity both within and outside China, the app is relatively new and underexplored compared to more well-established platforms such as Weibo. 

This guide aims to provide a starting point for those looking to explore Xiaohongshu for open-source investigations, including an overview of its main user demographics, potential topics to explore and strategic search methods specific to the app. 

User Demographics and Topics

According to Xiaohongshu’s official data, the platform’s demographic profile is mainly young, female and urban. As of 2024, 70 percent of its users were women, with half of all users belonging to Gen Z and living in China’s largest cities. 

As previously mentioned, the app has also gained popularity with the Chinese diaspora. Many Chinese nationals living abroad use it as a search engine for local information, posting and searching for content related to their daily lives, from restaurant recommendations and apartment hunting to navigating foreign bureaucracies and finding community resources. 

This demographic profile makes Xiaohongshu particularly well-suited for investigating stories about consumer fraud and urban livability issues. For example, Chinese outlets like Jiemian have used Xiaohongshu posts to expose the grey-market ecosystem of paid reviews and fake endorsements tied to the platform’s e-commerce model, while in 2022, International Financial News traced a mother-and-baby store scam that defrauded over 400 parents back to product recommendation posts on the platform.

Given its predominantly female user base, Xiaohongshu has also evolved into one of China’s most important spaces for feminist discourse and women’s issues. Academic researchers have used content on the platform to analyse local discussions on menstrual shaming, sexual harassment, and the controversial “divorce cooling-off period” introduced in 2021. As Rest of World reported, women have increasingly congregated on Xiaohongshu, where they outnumber male users and have found ways to trick the app’s recommendation algorithm so their posts are shown mostly to other women.

The Relevance of Censorship

Political content and current affairs about China are largely absent from the app – a result of both active censorship and platform design. 

All Chinese social media platforms, including Xiaohongshu, operate under strict content moderation requirements from the Cyberspace Administration of China. A leaked 143-page internal document published by China Digital Times in 2022 revealed how Xiaohongshu censors respond to government directives in “real-time”, blocking content related to politically sensitive topics such as criticism of the Chinese Communist Party, labour strikes and student suicides. Xiaohongshu’s commercial focus also makes it less likely that these topics would be discussed on the platform: as Rest of World reported, the platform functions less like Weibo – a public square for current events – and more like “a giant mall, where shoppers tell each other what to buy”.

Related articles by Bellingcat

The Challenges of Conducting Open Source Research on China
Resources

The Challenges of Conducting Open Source Research on China

Coverage of international affairs is also tightly controlled: only state-owned or state-controlled news organisations can obtain licences to publish original news content. However, content about life abroad, particularly stories about the cost of living, healthcare, or social problems in Western countries, circulates more freely on platforms including Xiaohongshu, and provide journalists with insight into how Chinese diaspora communities engage with local political systems. 

For example, when the 2025 Miss Finland was accused of making anti-Asian gestures, searching for “芬兰小姐” (Miss Finland) and “投诉” (complaint) on Xiaohongshu revealed a trove of collective action: users shared different complaint pathways, posted templates for filing reports, and documented various outcomes from their complaints. 

For such large-scale public events, Xiaohongshu can be both an organising platform and a rich source for tracking how diaspora communities coordinate responses to discrimination, providing journalists with insight into grassroots activism and transnational advocacy networks.

Getting Started

Xiaohongshu is available for download on both Apple’s App Store and Google Play worldwide, or can be accessed via a web browser. In international app stores, the app appears under the name “RedNote,” but this is the same application as Xiaohongshu – content and accounts are shared across both. The key difference is that RedNote users who register with overseas phone numbers are automatically tagged as international users, which affects the content the algorithm surfaces to them.

For users who download the app outside mainland China, Xiaohongshu automatically detects the device language and location. Upon first login, international users are prompted with an option to automatically translate all content into English (or their device language). If enabled, posts and comments will display with translations by default, and the algorithm will prioritise English-language content and posts created by or for international users, such as expat influencers.

For researchers and journalists seeking to observe the platform as Chinese users experience it, consider disabling automatic translation. This allows you to see content as it natively appears and helps you distinguish between posts created for international audiences versus those created for domestic users – a distinction that matters when assessing how representative your sample is for the relevant topic.

The default home feed, or the “Explore” tab, is where the algorithm surfaces content based on your engagement history, location and user profile. The feed uses a grid layout displaying post thumbnails with titles and like counts.

On the top right corner of the screen, the search bar also allows keyword searches across posts, users and topics. Results can be filtered by content type (e.g. notes, videos, users or products) and sorted by relevance or recency.

The search bar on the top right and the Explore page are some of the most relevant features for journalists and researchers on Xiaohongshu. Source: Xiaohongshu

Using the Search Bar

Xiaohongshu’s search function is relatively basic. You can search by keywords and filter by time and location, but the options are general: time filters include “past day,” “past week,” or “past six months,” while location filters offer “same city” or “nearby”. 

For example, searching “Canada” returns posts tagged with that keyword, which you can then sort by recency or proximity. 

Search results for “Canada” in English (left) show mainly travel and tourism-related content, while a search in Chinese (right) shows more content posted in Chinese by Chinese people about living in Canada. Source: Xiaohongshu

For breaking news events, try searching location names or names of individuals involved in the incident, filtering for the most recent posts to capture real-time reactions and on-the-ground accounts before they’re censored or deleted.

Xiaohongshu primarily uses algorithms to curate and push content through personalised feeds. For journalists using Xiaohongshu for investigative purposes, it can be useful to actively search for topics of interest to train your algorithm – the more you search and engage with specific content, the more relevant posts the algorithm will surface to you.

However, if you are researching the platform itself – studying what content Xiaohongshu promotes, how censorship operates, or what narratives dominate – you may want to start from a clean slate. In that case, consider periodically turning off personalised recommendations (Settings → Privacy Settings → Personalisation Options), clearing your browsing history, clearing cached data, or using a fresh account to observe what the platform shows to a “neutral” user.

Language and Lingo

During the influx of “TikTok refugees” in January 2025, Xiaohongshu launched a translation feature for users outside mainland China, enabling the automatic translation of comments and posts. 

However, this does not translate search queries. The platform’s search engine is still optimised for Chinese, though there is a “prioritise English” filter for overseas users, and searching in English will return some results.

Searching for “Canada” in English, with “EN preferred” selected, will mainly return posts in English. Source: Xiaohongshu

But the language you search in shapes far more than just your results – it determines which version of the platform you see. When you search in English or use an international account, the algorithm treats you as a foreign user and surfaces content accordingly: influencers explaining why they love living in China, comparisons showing Chinese life favourably against the West. 

This isn’t a neutral cross-section of the platform – it is a curated bubble. To access what Chinese users actually discuss among themselves, it would be more effective to search in simplified Chinese and, ideally, use a China-registered account if you have access to one. If you don’t read Chinese, you can also consider using a translation tool (Google Translate, DeepL, or an AI assistant) to convert your search terms into simplified Chinese before entering them.

Despite such tools and the in-app translation feature, it is always useful when researching using Chinese platforms to work with a native speaker familiar with the local context. They can flag when an innocuous-seeming term actually carries hidden meaning, and help identify coded conversations about a censored topic.

On Xiaohongshu specifically, this coded language extends beyond political topics to include anything the platform’s algorithm might flag as “vulgar” or promotional. For example, users substitute fruits and neutral terms for body parts or sexual content to avoid being flagged as inappropriate – the peach emoji for buttocks, or 炒菜 (“cooking”) for explicit material. They may also use abbreviations and emojis for commercial terms to evade anti-marketing filters, such as “vx” (the abbreviation of how WeChat is pronounced in Chinese) or “➕绿” (“plus green”, apparently referring to WeChat’s green logo) for WeChat, or “米” (rice) or the moneybag emoji for money.

Advanced Search Strategies

For more sophisticated searching, consider using third-party marketing analytics tools like Xinhong and Qiangu, which can show trending topics, popular posts and engagement metrics, as well as identify key content creators posting about specific subjects. 

For example, on Xinhong, when you search for “Canada” in Chinese, it also shows show trending related searches such as “加拿大总理” (Canadian Prime Minister). Clicking through these suggestions leads to recent posts—for example, posts about Mark Carney’s latest statements at Davos, along with user comments and reactions.

A search on the Xinhong platform for “Canada” in Chinese also suggests related trending topics (in green box) such as “in Canada”, “living in Canada” and “Canadian Prime Minister”. Source: Xinhong, annotation by Bellingcat

While these tools are designed for marketers, they provide journalists with valuable capabilities: tracking how topics evolve, identifying influential voices in specific communities, and discovering related hashtags or discussions that might not surface through basic platform search. These tools often require paid subscriptions but can significantly enhance research efficiency for long-term investigations.

Another valuable feature is Xiaohongshu’s group chat function, where users gather around shared keywords and topics—from city-specific communities to niche interests. These groups are often highly active and provide access to candid community discussions that don’t appear in public posts. To find relevant groups, go to MessagesGroup Square, where you can browse categories or search by keyword and request to join.

Monitoring active group chats related to relevant topics, whether that’s a specific city, industry, or issue, can help journalists and researchers stay updated on emerging issues and detect potential story leads before they become widely visible on public feeds.

Preserving the Evidence

Chinese social media content can disappear quickly and without warning due to censorship, making immediate preservation critical. 

Always take two preservation steps immediately upon discovering relevant content:

First, screenshot the entire post, including the URL, timestamp, username, like/comment counts, and location tags. These metrics establish context and authenticity. Use tools that capture full-page screenshots rather than just visible portions, as posts can be long and comments extensive. Second, archive the web page using services like archive.today or Wayback Machine. Note that these services capture only static content – comments and engagement metrics may not be fully preserved and should be screenshotted separately.

For Xiaohongshu specifically, always preserve the user’s unique ID found in their profile URL when viewed on a browser, which follows the format “user/profile/[unique ID]”. Users can change their display names, but this unique identifier remains constant, allowing you to track accounts over time even after name changes. This is critical for long-term investigations or when monitoring specific sources.

The unique ID of a user can be found in the profile URL on a browser. Source: Xiaohongshu

Xiaohongshu operates under the same legal and censorship constraints as all Chinese social media platforms, and researchers should approach it with appropriate caution. Content moderation is extensive: users who post about sensitive subjects risk having their content removed or their accounts suspended, and the platform is required to comply with government data requests. For researchers, this means the information you find represents only what has survived the censorship process.

That said, Xiaohongshu remains a remarkably rich resource for open-source research. Its strength lies precisely in its apolitical, lifestyle-oriented identity: while political discussion is suppressed, candid conversations about everyday life flourish. For journalists willing to invest in learning the platform’s rhythms, building Chinese-language search skills, and understanding its coded vocabularies, Xiaohongshu offers a window into how ordinary Chinese people talk among themselves – an area that remains largely untapped by international media.


Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Mining China’s ‘Little Red Book’ for Open Source Gold appeared first on bellingcat.

When Satellite Imagery Goes Dark: New Tool Shows Damage in Iran and the Gulf

Access to open source visuals of the current Iran conflict, which has spread to many parts of the Middle East, continues to be sporadic. Videos and photos from within Iran trickle out on social media as the Iranian internet blackout hinders the flow of digital communication. 

In past conflicts, satellite imagery has provided a vital overview of potential damage to both military and civilian infrastructure, especially when there are digital black spots or obstacles to on-the-ground reporting. But imagery from commercial providers is becoming increasingly restricted, leaving even those who have access to the most expensive imagery in the dark. 

Shortly after the war in Gaza began in 2023, Bellingcat introduced a free tool authored by University College London lecturer and Bellingcat contributor, Ollie Ballinger, that was able to estimate the number of damaged buildings in a given area. This helped monitor and map the scale of destruction across the territory as Israel’s military operation progressed. 

Bellingcat is now introducing an updated version of the open source tool — called the Iran Conflict Damage Proxy Map — focused on destruction in Iran and the wider Gulf region. 

It can be accessed here.

How it Works


The tool works by conducting a statistical test on Synthetic Aperture Radar (SAR) imagery captured by the Sentinel-1 satellite which is part of the Copernicus mission developed and operated by the European Space Agency. SAR sends pulses of microwaves at the earth’s surface and uses their echo to capture textural information about what it detects. 

The SAR data for the geographic area covered by the tool is put through the Pixel-Wise T-Test (PWTT) damage detection algorithm, which was also developed by Ollie Ballinger. It takes a reference period of one year’s worth of SAR imagery before the onset of the war and calculates a “normal” range within which 99% of the observations fall. It then conducts the same process for imagery in an inference period following the onset of the war, and compares it to the reference period. The core idea is that if a building has become damaged since the beginning of the war, then the “echo” (called backscatter) from that pixel will be consistently outside of the normal range of values for that particular area. Investigators can then further probe potential damage around this highlighted area.

The plot below shows how the process was applied to Gaza and several Syrian, Iraqi and Ukrainian cities. The bars represent the weekly total number of clashes in each place, sourced from the Armed Conflict Location Event (ACLED) dataset. The pre-war reference periods are shaded in blue, spanning one year before the onset of each conflict. The one month inference periods after the respective conflicts  began are shaded in orange. The blue and orange areas are what the tool compares. 

The plot below shows an area with a number of warehouses in Tehran’s southwest. Some of the buildings show clear damage in optical Sentinel-2 imagery (something that has to be accessed outside of the tool via the Copernicus Browser). 

Clicking on the map within the tool generates a chart displaying that pixel’s historical backscatter; the red dotted lines denote a range within which 99% of the pre-war backscatter values fall. In this example, we can see that from March 14 onwards, the backscatter values over this warehouse begin to consistently fall outside of their historical normal range. This could signal that damage has been detected in the area.

Two important aspects of this workflow are that it utilises free and fully open access satellite data, as opposed to commercial satellite services; the second is that it overcomes some key limitations of AI in this domain, the most serious of which is called overfitting. This is where a model trained in one area is deployed in a new unseen area, and fails to generalise. Because we’re only ever comparing each pixel against its own historical baseline, we don’t run into that problem. 

Accuracy


The PWTT has been published in a scientific journal after two years of review.  Its accuracy was  assessed using an original dataset of over two million building footprints labeled by the United Nations, spanning 30 cities across Gaza, Ukraine, Sudan, Syria, and Iraq. Despite being simple and lightweight, the algorithm has been recorded achieving building-level accuracy statistics (AUC=0.87 in the full sample) rivaling state of the art methods that use deep learning and high resolution imagery. The plot below compares building-level predictions from the PWTT against the UN damage annotations in Hostomel, Ukraine. True positives (PWTT and United Nations agree on damage) are shown in red, true negatives are shown in green, false positives in orange, and false negatives in purple. The graphic shows the accuracy of the tool, while also emphasising that further checks on what it highlights should be conducted to draw full conclusions.  

It is important to note that just because the tool may show a high probability of a building or buildings being damaged or destroyed, that doesn’t make it definite. 

It is best to check with any other available imagery — either open source photos and videos that’ve been geolocated by a group such as Geoconfirmed or Sentinel-2 as well as other commercial satellite imagery if it’s up-to-date for the area. At time of publication, Sentinel-2 satellite imagery still offers coverage over the area that the tool focuses on. Other commercial satellite imagery providers have limited their coverage.

What the tool excels at is highlighting and narrowing down areas so that further corroboration or further confirmation can be sought.

Testing the Tool


Using the Iran Conflict Damage Proxy Map, we can spot some of the larger areas of potential damage or destruction that have occurred since the Iran war started. 

Starting from a zoomed-out view of Tehran, there are a few spots that appear with large clusters of high damage probability. Cross-referencing these locations with open source map data from platforms like OpenStreetMap or Wikimapia, we can start finding sites that would make for likely targets – such as military sites.

One example of a potentially damaged site visible in the tool is the Valiasr Barracks in central Tehran, which was struck in the first week of the war. By going to the Copernicus Browser and reviewing the area with optical Sentinel-2 imagery, we can see clear indications of damage at the barracks.

IRGC Valiasr Barracks in Tehran:

Below: Sentinel-2 comparison of February 20 and March 17.

A large Islamic Revolutionary Guard Corps (IRGC) compound near Isfahan is another example of military infrastructure that is readily visible in both the Iran Conflict Damage Proxy Map as well as Sentinel-2 imagery. 

IRGC Ashura Garrison in Isfahan:

Below: Sentinel-2 comparison of February 20 and March 17.

Air bases have also been a frequent target for U.S.-Israeli strikes in Iran. The Fath Air Base just outside of Tehran, near the city of Karaj, shows the signature of potential damage when using the tool. Checking Sentinel-2 imagery shows damage to multiple large buildings on the northern side of the base.

Fath Air Base in Karaj:

Below: Sentinel-2 comparison of February 20 and March 17.

The U.S. has stated that destroying Iran’s “defense industrial base” is also a goal, which makes large areas like the Khojir missile production complex east of Tehran a good location to search with this tool. The tool suggests large clusters of damage on both the eastern and western sides of the complex — near areas where solid propellant is reportedly produced and where other fuel components are reportedly made.

Khojir Missile Production Complex outside of Tehran:

Below: Sentinel-2 comparison of February 20 and March 17.

Usage in the Gulf Region

While useful for providing a sense of damaged areas in Iran, the Iran Conflict Damage Proxy Map can also be used to see damage outside of Iran, particularly at sites in the region which Iran has been targeting with drones and missiles.

In the below example at Al Udeid Air Base in Qatar, which hosts U.S. Central Command’s Combined Air Operations Center, there is a notable indication of damage over a warehouse-like building at 25.115647, 51.333125. Checking the same location in Sentinel-2 imagery shows that there does appear to be damage at that warehouse — represented by a large blackened area on the white roof. According to Qatar’s Ministry of Defense, at least one Iranian ballistic missile struck the base in early March.

Al Udeid Air Base in Qatar:

Below: Sentinel-2 comparison of February 22 and March 14.

Civilian sites struck by Iranian drones or missiles are also visible in the tool — though the damage has to be fairly large in order to be picked up. Something like damage to the sides of high rise buildings from an Iranian drone attack doesn’t readily appear in the tool. Sites that do appear are places like oil refineries, such as a fuel tank at Fujairah port in the United Arab Emirates. 

Fuel tanks at Fujairah Port, UAE:

Below: Sentinel-2 comparison of March 3 and March 28.

Accessing the Tool

It’s important to keep in mind that the data for the Iran Conflict Damage Proxy Map is updated approximately one or two times per week as new satellite data is collected by the Sentinel-1 satellite, so it’s not meant to be a representation of real-time damage to buildings. 

Still, it can be useful for researchers to quickly gain an overview of damage throughout Iran and the Gulf where suspected strikes may have taken place and when there is no other open source information available.

You can access the Iran Conflict Damage Proxy Map here.

Similar tools using the same methodology to assess damage in Ukraine following Russia’s full-scale invasion and Turkey following the 2023 earthquake can be found here. The Gaza Damage Proxy Map can be found here


Bellingcat’s Logan Williams contributed to this report.

This article was updated on April 7, 2026, to note that Sentinel-1 and Sentinel-2 are part of the Copernicus mission developed and operated by the European Space Agency.

Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post When Satellite Imagery Goes Dark: New Tool Shows Damage in Iran and the Gulf appeared first on bellingcat.

Explosive Misinformation: A Guide to Mushroom Clouds, ‘Sonic Weapons’ and Disintegration

Since launching the military campaign against Iran on Feb. 28, the US and Israel have dropped thousands of bombs on the country. Videos of explosions have become a source of misinformation and misunderstanding, with many of the strikes incorrectly attributed to a particular munition and many explosive effects – seen in footage and images – falsely attributed to “mystery” or illegal weapons.

Take the below post that initially suggested (although it said more analysis was required) that the US may have used a nuclear weapon in Iran, an outlandish and clearly incorrect claim that experts Bellingcat spoke to had little time for.

The archived video from the post below. You can find the full post, which was set to private after we published the guide, here.

IMPORTANT UPDATE AND NOTE: The following is not a complete assessment and I require more data to verify first use. This is a surface level observation but it must be noted.

☢ The US used what appears to be, without additional details, a nuclear weapon on Iran delivered by a… pic.twitter.com/7ucJNdGyNi

— Korobochka (コロボ) 🇦🇺✝ (@cirnosad) March 11, 2026

The post, set to private after the publication of this guide, appeared to suggest that a nuclear explosion happened in Iran. Source: X/cirnosad

“The video does not show a nuclear explosion—something that I am astonished even needs to be clarified,” Dr NR Jenzen-Jones, Director of Armament Research Services, a weapons intelligence consultancy, told Bellingcat.

Mushroom clouds can form when explosions produce hot gases that quickly rise and encounter resistance from denser, colder air. (Clouds created by nuclear weapons can also vary significantly in appearance.)

Non-nuclear explosive test in Canada. Source: Defence Research and Development Canada.

“Certain types of explosive munitions, such as those working on the fuel-air explosive (FAE) and thermobaric principles, are particularly poorly understood by non-specialists. As a result, these and other types of munitions are routinely misidentified,” Jenzen-Jones said.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

Often posts about explosives are incorrect or inaccurate because of a lack of knowledge about how explosives work, but in other cases misinterpretations are deliberate. Joe Dyke, director of programmes at Airwars, told Bellingcat that deliberate disinformation that shifts responsibility of a strike is the most common they see, with posts often sharing flimsy but “scientific sounding” analysis.

Better understanding explosives can make it easier to identify misinformation surrounding explosions. 

This guide explains explosives, their characteristics and the impact they have on people and infrastructure. We highlight the differences between thermobaric and Dense Inert Metal Explosives (DIME), two types of explosives that are frequently the subject of misinformation.

What Are Explosives?

Explosives are energetic materials capable of causing death and destruction through a rapid release of energy. The blast creates pressure waves emanating from the epicentre. These waves can directly kill or injure people and shatter objects into lethal fragments.

High explosives are typically used in warheads and shells; they differ from low explosives which are often used in rocket propellants. The supersonic speed of the explosive reaction- classified as detonation- also separates the two kinds of explosives. During detonation, temperatures can rise above 3,000 °C, but only briefly and very close to the reaction zone, Dr Sabrina Wahler, a Postdoctoral Scholar at the California Institute of Technology focusing on research of detonation products told Bellingcat.

Graphic showing a high explosive with a detonator (initiator or blasting cap) before and after the detonation begins. The chemical reaction zone is shown as the explosive detonates. Source: Justin Baird for Bellingcat.

The detonation creates a shockwave, which is a visible wave or bubble in high speed videos. The shockwave impacts people and objects before the sound of the blast can be heard.

Visible shockwave emanating from the blast, ahead of the fireball or blast wind, in screenshots showing a surface explosion. Source: Defense Threat Reduction Agency (DTRA) Counter-WMD Test Support Division (CXT) via Lawrence Livermore National Lab.

The shockwave is the result of the pressure pushing air away from the blast in the positive phase. When the air rushes back in the negative phase, it creates a suction effect.

Visualisation of pressure phases of an explosion. Source: Justin Baird for Bellingcat.

The shockwave arrival time, combined with a known distance, has been used to estimate the explosive weight of blasts, including the Beirut explosion in 2020.

Reactive materials, such as aluminium powder, are often added to explosives to improve performance. These metals react with the gaseous products from the detonation, resulting in increased energy output, Jacqueline Akhavan, a Professor of Explosive Chemistry at Cranfield University, told Bellingcat.

Ammonium nitrate based Tannerite exploding targets with various amounts of aluminum powder added. Exploding targets are popular and widely available in the United States. Military ordnance also uses similar aluminised explosive compositions. Source: United States Department of Agriculture.

Sometimes, reactive metals such as aluminium from the explosive composition can be seen burning outside the fireball, indicating an explosive with reactive metal.

Photo of ammonium nitrate with aluminium powder exploding. Burning aluminium powder can be seen outside the fireball. Annotation by Bellingcat to indicate some of the burning powder. Source: United States Department of Agriculture.

The size of a fireball does not necessarily indicate the blast’s power. In movies and airshows, a “Hollywood shot” involves igniting large amounts of gasoline with small amounts of explosives, creating spectacular fireballs with minimal pressure.

“Hollywood shot (‘wall of fire’) done with detonation cord and gasoline.” Source: Federal Bureau of Investigation.

Thermobaric, and dense inert metal explosives (DIME), are other types of explosive compositions where metals are added to modify specific effects.

Thermobaric Explosives

In January 2024, after an attack in Gaza, social media posts appeared claiming that thermobaric explosives “literally sucks the air out of the children’s lungs and causes them to internally explode”. According to an article by Dr Rachel Lance, a biomedical engineer specialising in patterns of injury and trauma from explosions “there is no evidence that thermobarics pull the air out of the lungs”. 

There were also claims that thermobaric weapons incinerate people. According to a report by the Armament Research Services, the effects of this type of explosion “are of the same nature as those expected from a conventional high explosive”. The only difference is that the duration of each effect is likely to be longer from a few milliseconds to tens of milliseconds and in a pressure wave with a lower peak.

This occurs because thermobaric explosives add a significant amount of fuel or reactive metals to the explosive composition. Some of the fuel burns after detonation. These munitions are effective against cave or bunker systems, as the pressure wave can travel further throughout the structure.

Graph showing the “pressure history inside the blast wave; high explosive vs.TBX and EBX detonations.” Source: W.A. Trzciński, L. Maiz Thermobaric and enhanced blast explosives – properties and testing methods (Review) via Wiley Online Library.

Visual differences can indicate the types of explosives used. Even within the same category, explosives may appear different because of variations in chemical composition, conditions where the explosion occurs, and video quality.

TÜBİTAK SAGE’den yerli termobarik patlayıcıda yeni bir adım daha!

Kapalı alanlarda yüksek darbe ve sıcaklık etkinliğine sahip yeni bir termobarik patlayıcı💥

TENDÜREK’ten sonra KOR ile geleneksel patlayıcılara göre 4 kat daha yüksek sıcaklık etkinliği 🔥🔥🔥 pic.twitter.com/N4yZ8YvMi9

— TÜBİTAK SAGE (@SageTubitak) March 5, 2020

Comparison of KOR, a thermobaric explosive, and TNT, in a test by TÜBİTAK SAGE, a Turkish Defense Research Organization. Source: X/TÜBİTAK SAGE.

Many countries, including the US, Russia, China, Ukraine, Iran and Turkey, use enhanced blast and thermobaric explosives. Russia has used them in Ukraine and Syria. Israel uses munitions that have variants featuring thermobaric warheads, but the use of thermobaric explosives has not been confirmed.

Fuel-air explosives are similar to thermobaric explosives, but function differently. Both are volumetric weapons, but fuel-air explosives disperse a cloud of fuel, then the explosion occurs.

A video showing a test of a US fuel-air explosive munition. Source: jaglavaksoldier.

Dense Inert Metal Explosives

Unsubstantiated claims of DIME munitions have regularly surfaced since 2006, when they were first alleged to have been used in Gaza. Similar claims have reappeared in Gaza since the war began on Oct. 7, 2023. 

Dense Inert Metal Explosives (DIME) are typically used in munitions intended to reduce civilian harm. Non-reactive metals, like tungsten, added to the explosives reduce the area impacted by the blast, but increase the power. Often munitions filled with DIME replace steel casing with carbon fibre to reduce fragmentation.

Photo of a Dense Inert Metal Explosive (DIME) test by the US Air Force Research Laboratory (AFRL). Non-reactive metal particulates can be seen at the edges of the fireball. Annotation by Bellingcat. Source: US AFRL, 2006.

Some sources refer to DIME as a multiphase blast explosive, a term that also covers some explosives with reactive metals. Photos from testing show mannequins near the blast coated in tungsten powder.

Mannequin coated in tungsten powder following the testing of a GBU-39 A/B FLM, a DIME filled variant of the GBU-39 bomb. Source: ITEA Journal via DTIC.

Some claims of DIME use in Gaza mention the presence of powder or microscopic shrapnel found on victims. “Peppering” and “tattooing” are mentioned (warning: graphic content) as common injuries in blast victims, where the explosion propels small debris like sand into the body, along with fragments of various sizes.

Impacts of fragments and tungsten powder on blocks of ballistic gel at different distances from three tests. Source: Latin American Journal of Solids and Structures, 2024, 21(3), e535.

The US Air Force has accepted delivery of at least 500 DIME-filled GBU-39A/B bombs, and has used at least 23 in combat. No transfers of GBU-39 A/B FLM bombs from the US to any other country, including Israel, have been reported, and a Bellingcat analysis of GBU-39 strikes in Gaza between October 2023 and January 2026 did not find any evidence of this variant being used.

There is currently no conclusive evidence that militaries aside from the US have used DIME in combat.

Clues From Clouds

Clouds, and the colours of the smoke can provide clues about the type of explosive. However, chemical composition, environmental conditions, and location can all affect how explosions appear. 

Clouds

This footage, originally posted on social media in November 2025, shows an explosion in Gaza.

The Israeli army launched thermobaric and pressure bombs, supplied by the United States, on Gaza. These bombs, which burn at a temperature of 3,500 degrees Celsius, are capable of killing thousands in seconds, leaving no trace. pic.twitter.com/pZhoIfsazP

— China pulse 🇨🇳 (@Eng_china5) February 12, 2026

Video of an explosion in Gaza, falsely attributed as a thermobaric weapon. Source: X/@Eng_china5.

The visible cloud in the video is a condensation or Wilson cloud, caused by an explosive shockwave interacting with humid air. This same effect is visible in videos of the Beirut explosion in 2020, when ammonium nitrate exploded at the port after a fire.

Another view of the explosions in Beirut pic.twitter.com/efT5VlpMkj

— Borzou Daragahi 🖊🗒 (@borzou) August 4, 2020

Video of the 2020 Beirut ammonium nitrate explosion. Source: X/Borzou Daragahi.

Smoke colours

Colours in the smoke of an explosion can help identify the gases, which in turn can help identify the explosive material, Dr Rachel Lance told Bellingcat. “Yellow, orange, and red tones each indicate the presence of specific chemicals.” 

Black smoke means “the bomb produced a lot of fire and inefficiency, because materials burned instead of detonated, and was probably a homemade or improvised explosive”. White or light grey smoke indicates “an efficient detonation, and that tells us it was a pure, high-grade material inside,” Lance said.

Left: Reddish-orange smoke after the ammonium nitrate explosion at Beirut in 2020. Centre: Fuel heavy “Hollywood shot” explosion. Right: C4 explosion. Sources: Borzou Daragahi, DVIDS/Lance Cpl. Kayla LeClaire, and DVIDS/Sgt. Tara Fajardo Arteaga.

Some munitions, like cruise or ballistic missiles, may have efficient high explosives, as well as low explosive propellants or fuel. The area targeted, such as buildings, may lead to dust or debris that obscure the gases created by the explosion. 

In some cases, multiple bright fireballs are launched into the sky, accompanied by a rapid humming or throbbing sound and bright flashes. This typically happens when solid-fuel rocket motors, like those in air defence or ballistic missiles, are burning or exploding.

Major secondary explosions after a U.S. airstrike in the vicinity of Higuerote Airport in Venezuela tonight. pic.twitter.com/NrFOVj9IfM

— OSINTtechnical (@Osinttechnical) January 3, 2026

Venezuelan Buk Air Defense System rocket motors ‘cooking off’ after being targeted by US strikes in Jan. 2026. Source: X/Osinttechnical.

Geolocation

Geolocation of the explosion site can help identify or rule out potential explanations. Large explosions can be caused by much smaller bombs hitting storage sites or production sites for ammo. The geolocation of the video below indicated that the location hit was a storage area for missiles.

Qom today looks like it was hit by a GBU 57 bunker buster.

The GBU 57 Massive Ordnance Penetrator is a 30,000 pound bunker busting bomb designed to penetrate deep underground before detonating. pic.twitter.com/d4bGJ19nQb

— Open Source Intel (@Osint613) March 11, 2026

Video shared by a user claiming this video shows the use of a GBU-57 “Massive Ordnance Penetrator”. A now-suspended user claimed the video showed the “Mother of All Bombs”. Source: Osint613.

Blast Effects on People

Misinformation regarding blast effects on people might lead to reports of harm to be wrongly dismissed or false claims about mystery weapons to spread.

In February 2026, claims of “vaporisation” or disintegration of people due to thermobaric weapon explosions appeared online. Days later, counterclaims argued that explosives can’t “disintegrate” people and thermal effects were not responsible.

According to multiple studies, even less powerful explosives can cause disintegration. When explosions occur in enclosed spaces, such as inside a building, they reflect shock waves, leading to increased blast effects.

The effects of the shock wave on some structures can be seen in the first part of this video. Source: Canadian Armed Forces.

Blast injuries are generally classified into four categories, based on what mechanism is causing the injuries.

Categories of blast injuries. Source: Justin Baird for Bellingcat.

The primary effect, the blast itself, “puts tremendous strains on human tissue, causing them to rip and tear, both internally and externally, so massive internal bleeding can occur,” Brian Castner, a weapons investigator for Amnesty International, told Bellingcat.

Primary injuries can lead to a variety of symptoms, including vertigo, vomiting blood, and bleeding from the ears. A viral post shared by the White House Press Secretary claimed to be firsthand testimony from a Venezuelan security guard following US strikes in Venezuela. The post alleged that the US used a sonic weapon without any supporting evidence, and the symptoms described are typical of primary blast injuries.

The secondary effect results from the metal fragments of the munition. Some weapons are specifically designed to break into uniform small pieces, Castner said. “Even small fragments, the size of a bullet, can break a bone, since the metal is flying through the air so quickly,” the weapons investigator explained.

Even single fragments can injure or kill people hundreds of metres away from a blast. People close to it may be largely disintegrated, often described (warning: graphic content) as “total body disruption” in Forensic Medicine.

A non-graphic video showing the destruction that explosives are capable of inflicting on various materials. Source: Ballistic High-Speed.

“Combined, these blast and fragmentary effects can do horrific damage to the human body, and if a person is close enough to a large munitions detonation, leave little trace they ever existed,” Castner told Bellingcat.

A recent Bellingcat investigation into three specific US-made munitions used in Gaza found videos showing small pieces of human bodies consistent with total body disruption, at several different strikes within the dataset.

Screenshot from a video showing one area hit by a GBU-39 bomb at Khadija School, Gaza in July 2024. A separate graphic video shows a boy in this area collecting a small part of a person. Source: X/Eye on Palestine.

Explosions can also cause burns or thermal injuries. Temperature is not the most relevant factor, because “by the time a human body is exposed to the temperatures of a burning explosive, people will have severe trauma and death,” Dr Lance told Bellingcat.

In many real-world cases “the blast pressure reaches farther than the thermal flash,” Dr Sabrina Wahler said. “The thermal danger becomes much larger and longer lasting when the explosion occurs in a confined space, when the formulation supports continued burning with air, or when the detonation triggers secondary fires that keep generating heat well after the initial blast,” she noted.

Flash burns are often seen on exposed parts of the body close to the blast (warning: graphic content). Explosions that start fires or contain incendiary materials can result in severe burns.

Are These Explosives Legal?

Misinformation often raises questions about legality, with false claims that specific weapons are inherently illegal or misrepresenting how they work. This is one of the reasons that nations conduct legal reviews of new weapons, Michael Meier, a former Senior Advisor to the Army Judge Advocate General for Law of War, and current Adjunct Professor at Georgetown University Law Center, told Bellingcat.

Subscribe to the Bellingcat newsletter

Subscribe to our newsletter for first access to our published content and events that our staff and contributors are involved with, including interviews and training workshops.

Thermobarics and DIME are legal if their use complies with specific principles of international humanitarian law (IHL) and the law of armed conflict (LOAC), such as proportionate and discriminate use, experts told Bellingcat.

“Even lawful weapons can be used in an unlawful manner”, Michael Meier said. One example is when they are directed against civilians or when they are used in a manner that breaches the principles of distinction or proportionality, he explained.

“The law’s ability to prevent harm is constrained by the compromises between military necessity and humanity made in its creation,” Dr Arthur van Coller, Professor of International Humanitarian Law at the STADIO Higher Education and a legal expert on thermobaric explosives, told Bellingcat.

“As a result, weapons that cause immense destruction may remain lawful (even nuclear weapons) if they fit within legal definitions, even when their humanitarian impact is severe,” van Coller explained.


Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here, Instagram here, Reddit here and YouTube here.

The post Explosive Misinformation: A Guide to Mushroom Clouds, ‘Sonic Weapons’ and Disintegration appeared first on bellingcat.

Using Bellingcat’s New Open Source Tool to Explore Historical and Spatial Flight Data

Flight tracking data is an important tool in open source research, but with 100,000 daily flights, it can be difficult to contextualise what a particular aircraft’s movements indicate. 

Bellingcat has developed a tool called Turnstone to make it easier to visualise historical trends in flight data and spot unusual patterns. It also allows users to filter by parameters such as aircraft type or a geographic region of interest. 

Source: ZUMA Press Wire via Reuters Connect; overlays of Turnstone by Bellingcat

This tool primarily uses Automatic Dependent Surveillance–Broadcast (ADS-B) data, the technology that enables open source investigators and enthusiasts to track flights. 

Most aircraft are equipped with transmitters that broadcast ADS-B data to comply with global aviation regulations, though regulations vary by jurisdiction, and military aircraft might not always transmit. ADS-B data includes information about an aircraft’s identity and type, as well as its precise position, speed and altitude. 

Popular flight-tracking websites such as Flightradar24 and ADS-B Exchange typically display historical data for a particular time or aircraft. However, Turnstone aggregates ADS-B data for multiple aircraft over time, and allows users to search for flights across two areas of interest at once. These features provide additional context for open source investigators to better understand flight behaviour.

Watch the video for a demonstration of how the tool works, using the example of Black Hawk helicopter patrols near one of the borders between the US and Canada:

You can view Turnstone’s source code and information about hosting it yourself on Bellingcat’s GitHub

We also have a web-based instance of the tool that journalists and academics can access. Due to data hosting and processing costs, we can only grant access on a selective basis. If you would like to apply, please fill in this form. Priority will be given to researchers conducting open source investigations aligned with Bellingcat’s goals.

Read on for more examples of how Turnstone can be used for investigations, as well as some limitations of the tool.  

Spotting Unusually High US Tanker Activity Before Iran Strikes

The US and Israel launched joint air strikes across Iran on Feb. 28, 2026, reportedly killing more than 1,000 people, including members of the Iranian leadership, in five days.

This marked a dramatic escalation since the US and Israel bombed three Iranian nuclear sites in June 2025. 

Flight data before both the June 2025 and February 2026 strikes showed a large number of American aerial tankers leaving the US and crossing the Atlantic towards Iran. Aerial tankers such as the KC-135 and KC-46A can refuel military aircraft in-flight, making them essential for most long-range combat missions.

The 9 KC-46As that went to Ben Gurion.

All came direct from the eastern U.S. pic.twitter.com/izANyrqi4Q

— Evergreen Intel (@vcdgf555) February 27, 2026

With Turnstone, it is possible to interrogate the baseline level of movement and see how unusual this activity is.

To do this, three filters are set on the search: a geographic region of interest, set to the North Atlantic, a filter on the aircraft type, to search only for tankers, and a filter on the aircraft heading, to search only for eastbound traffic.

Filtering a search by aircraft type, region of interest, and heading range that captures eastbound traffic. Source: Turnstone/Bellingcat

[Note: For the aircraft category designations, Bellingcat used a custom-prompted large language model (LLM), Claude Sonnet 4.0, to assign a category label using aircraft type code data. There may be some inaccuracies in the classifications, as LLMs are prone to hallucinations. We discuss this further in the “Limitations of the Data” section of this piece.]

This search finds over 40,000 aircraft locations that match these filter queries. However, a look at the summary table shows that this data includes non-American tankers as well.

Results from a filtered search, showing tankers owned by the French Air Force and the United States Air Force. Source: Turnstone/Bellingcat

We can filter this data to include only aircraft associated with the US by typing “United States” into the search box in the table. Note that ownership data is not 100 percent accurate – it may be out of date, especially for privately owned aircraft, and new aircraft might not have any data at all. However, especially when comparing trends over time or searching for research leads, this data can still be useful.

The graph of matching detections over time now shows that while there is a large baseline level of transatlantic movement for American tankers, there was a notably higher number of American tankers heading eastward from the US across the North Atlantic detected in the week of June 15, 2025, as well as in the last two weeks of February 2026.

The weekly graph view on Turnstone shows a noticeable spike in eastbound American tankers crossing the North Atlantic per day from June 15 to June 21, 2025 and from Feb. 15 to Feb. 28, 2026. Source: Turnstone/Bellingcat

A week after the increased eastbound traffic in June 2025, early in the morning on June 22, the US struck several nuclear sites in Iran. And on Feb. 28, 2026, the US and Israel launched over 900 strikes against Iran.

Altering the search query to look for westbound tankers instead of eastbound tankers, we can also see a larger-than-normal number of American tankers heading in the direction of the US during the week of July 13, 2025, bookending the summer airstrikes in Iran. No such return movement is yet visible following the recent strikes.

The number of American tankers heading westward across the North Atlantic, towards the US, appeared higher than usual from July 13 to July 19, 2025. Source: Turnstone/Bellingcat

Finding Deportation Flights to Guantanamo Bay

Turnstone also allows you to search for aircraft detected across two different geographic regions of interest (ROIs). 

Shortly after US President Donald Trump announced the opening of a migrant detention centre at Guantanamo Bay in Cuba at the end of January 2025, the US military reportedly flew about 100 immigrants from El Paso, Texas, to the US naval base to await deportation. By selecting the areas around both Guantanamo Bay and El Paso, we can find flights between these cities that broadcast ADS-B data.

When you select two regions of interest, a filter for the time difference between them also appears. Source: Turnstone/Bellingcat

When two ROIs are selected, you can also enter the maximum time difference between an aircraft’s presence in the two regions. 

In the example below, we have entered 36,000 seconds (10 hours), meaning that the aircraft must have crossed through both regions within 10 hours of each other. We have also set the maximum altitude to 15,000 ft (4.57km) to look for planes landing and taking off. This limit is set relatively high as there are no ADS-B receivers at Guantanamo Bay, and only the initial approach is captured.

Search panel settings for finding aircraft that have been in both Guantanamo Bay and El Paso, Texas, with inputs under the “Maximum Altitude” and “Maximum Time Difference” fields, and selection areas drawn around both areas on the map (in blue). Source: Turnstone/Bellingcat

After five months with no tracked flights between the two locations, this search shows an uptick in flights in the few months from February 2025.

The results from Turnstone come with a bar graph that shows the average aircraft per day by week or by month, which can be further filtered by aircraft hex code (the unique identifier for specific aircraft) or the aircraft type code. Source: Turnstone/Bellingcat

Results for this search query from Jan. 26, 2026, include several passenger aircraft operated by companies known to run deportation flights from the US, such as Omni Air International and Global Crossing Airlines.

Results from a search of flights of up to 10 hours between Guantanamo Bay and El Paso, Texas, conducted on Jan. 26, 2026 show flights owned by Omni Air International and Global Crossing Airlines, both carriers known to operate deportation flights. Source: Turnstone/Bellingcat

Mapping US Customs and Border Patrol Aircraft

Turnstone also supports uploading a list of International Civil Aviation Organization (ICAO) addresses, informally referred to as aircraft “hex codes”, which are unique identifiers assigned to aircraft by ICAO member states.

For example, to explore data related to Department of Homeland Security (DHS) activity and look for patterns related to the US immigration enforcement and border security operations, we can copy and paste the hex codes from a list of US Customs and Border Patrol (CBP) aircraft (used across the DHS) into a text file, and upload that file. Now, we can search among these aircraft with any of the same filters demonstrated in the earlier case studies. Alternatively, we can also deselect all of the filters to track the most recent activity by those aircraft.

Let’s try that with the CBP list, this time with a very large number of results selected: 500,000. Note that increasing the number of results increases the search time and requires more browser memory.

With the list of hex codes provided, the search interface shows “216 hex codes loaded”. No other filters have been selected and the result limit is set to 500,000. Source: Turnstone/Bellingcat

When many points are displayed, the map is simplified, and hover features are disabled.

The results map shows a large number of CBP flights over the US without any filters, from a search of historical data on Jan. 26, 2026. Source: Turnstone/Bellingcat

By the California-Mexico border, Eurocopter AS350 (type “AS50”) can be seen on frequent patrol missions over the land border. Over the Pacific Ocean, Black Hawk helicopters (“H60”) can be seen patrolling the international waters boundary off the Mexican coast, while CBP Dash-8s (“DH8B” and “DH8C”) travel farther offshore.

Zooming in on the area near the California-Mexico border shows an obvious concentration of certain aircraft types in this search of historical data on Jan. 26. 2026. Source: Turnstone/Bellingcat

In contrast, by the Minnesota-Canada border, CBP makes more active use of one of its MQ-9 Reaper drones, as seen from the prevalence of red dots that correspond to “Q9”, the type code of these drones, in the results map.

The dots around the Minnesota-Canada border mainly show activity by MQ-9 Reaper drones in this search of historical data on Jan. 26, 2026. Source: Turnstone/Bellingcat

Let’s take a closer look at these drones by filtering the results with the text “Q9”. Now the displayed aircraft only include MQ-9 Reaper drones.

Results can be filtered by typing into the search field on the top right of the “Aircraft Summary” table. Source: Turnstone/Bellingcat

Now we can take a closer look at the patterns of drones, specifically among the search results.

Left: A very large number of MQ-9 Reaper flights south of San Angelo, Texas. They are coloured by altitude, with green symbols indicating lower flights and red showing those at higher altitudes. Right: The flight pattern of a known Aug. 13, 2025 MQ-9 Reaper mission into Mexico, as shown on Turnstone. Source: Turnstone/Bellingcat

While overall CBP flight activity was relatively stable, drone flights seem to have intensified in December 2025 and January 2026, compared with previous weeks.

The bar graph by week shows a higher average number of MQ-9 Reaper drone flights in December 2025 and January 2026 than in previous weeks. Source: Turnstone/Bellingcat

Limitations of the Data

In open source research, it is always important to be alert to the limitations of a particular data source, and ADS-B data is no exception. 

For example, some aircraft do not have ADS-B transponders and use older transponders to transmit flight information, which can result in tracking tools such as Turnstone showing inaccurate position data. 

In the previous case study of CBP aircraft, the Turnstone results appeared to show an MQ-9 Reaper drone in Canada on Jan. 20, 2026. 

Search results for CBP MQ-9 Reaper drones on Jan. 20, 2026, which appeared to show four instances (circled) of a drone in Canadian airspace. Source: Turnstone/Bellingcat

Is this evidence of covert DHS missions in Canadian airspace? Likely not: a cross-check of the drone’s hex code on that date with ADS-B Exchange shows that the aircraft’s position track is not smooth, but jumps back and forth between a line in the US and several points many kilometres away in Canada.

Screenshot from flight tracking website ADS-B Exchange, appearing to show a CBP drone flying within US airspace but jumping suddenly to the circled points in Canada, several kilometres away. Source: ADS-B Exchange; annotations by Bellingcat

This happens because when ADS-B position data is not available, flight trackers often use multilateration (MLAT), which estimates the location of the aircraft using the time differences between signals transmitted from known sites, as a substitute. The flight tracking information on ADS-B Exchange shows that the position was calculated using MLAT, which is less accurate than position data directly transmitted through ADS-B. ADSB.lol, which is the data source used by Turnstone, uses MLAT when ADS-B position data is not available.  

ADS-B data is also limited by where ground antennas are available to receive radio signals from aircraft and by when aircraft choose to transmit the data.

Other datasets which Bellingcat has used to enable the filters available on Turnstone each have their own limitations. 

There is no single source of data on aircraft ownership. ADS-B data identifies an aircraft only using its ICAO address or hex codes, but does not contain other information that directly specifies the type of aircraft or its registration.

Instead, flight-tracking websites reference aircraft registration databases, such as those maintained by the US Federal Aviation Administration, to correlate ICAO addresses with registration information. The ownership data displayed on Turnstone is from tar1090-db, a community-maintained project which has produced the most comprehensive freely available global aircraft registration database. However, since ownership data is collected from many jurisdictions, with different privacy and disclosure requirements, it may sometimes be out-of-date or misleading. 

Ownership information displayed in Turnstone or any other flight-tracking software should still be verified independently using multiple sources.

For example, one of the aircraft that came up in the search for flights between El Paso and Guantanamo Bay had a hex code of a6b0f5. This showed up in Turnstone’s results as being owned by Bank of Utah Trustee, which matches the operator listed for this flight on ADS-B Exchange. But some of the flight codes used by this aircraft, starting with “GXA”, are used by Global Crossing Airlines (GlobalX). The Bank of Utah is known to legally own aircraft under a trust relationship, while leasing the aircraft and operational control to third parties such as GlobalX.

Screenshot from Turnstone showing aircraft flying between Guantanamo Bay and El Paso, from a historical flight data search on Jan. 26, 2026.

The “Category” label and “Military” flag, which provide a convenient way to filter aircraft, are pre-generated by a custom-prompted large language model, Claude Sonnet 4.0, based on the make and model of an aircraft. 

For example, the LLM may take a type code of A321, which refers to an Airbus A321 passenger jet, as input and assign the corresponding aircraft the category of “airliner”. 

Bellingcat manually verified over 80 per cent of aircraft, corresponding to the most common aircraft types. But as we know, LLMs are prone to hallucinations, and categorisation may be inaccurate for more obscure aircraft. Additionally, some aircraft, such as the V-22 Osprey, fall between categories and are inherently ambiguous. 

To prevent errors caused by the potential miscategorisation of aircraft, you may want to search by type code, which will draw from the raw tar1090-db data, rather than category. All aircraft registration, type, and owner information should be independently verified.

Suggestions and Further Information

As we’ve seen in this guide, Turnstone searches historical ADS-B data to allow researchers to explore flight patterns over time and in specific locations. While flight-tracking data has inherent limitations, Turnstone can provide useful leads for researchers looking to incorporate flight tracking in their investigations.

If you have suggestions for improving the tool, you can submit a pull request on Bellingcat’s GitHub. More technical information can also be found in the tool’s README.

For more demos and information about the history of this tool, watch a talk that Bellingcat gave about it at the What Hackers Yearn (WHY) 2025 hacker camp:


Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here and Mastodon here.

The post Using Bellingcat’s New Open Source Tool to Explore Historical and Spatial Flight Data appeared first on bellingcat.

Identifying ‘Less-Lethal’ Weapons Used By DHS Agents in US Immigration Raids and Protests

To stay up to date on our latest investigations, join Bellingcat’s WhatsApp channel here.

Federal agents have frequently used so-called “less-lethal” weapons against protesters, including impact projectiles, tear gas and pepper spray, since the Trump administration’s nationwide immigration raids began last year

The use of less-lethal weapons (LLWs) has been controversial. While designed to incapacitate or control a person without causing death or permanent injury, they can cause serious or fatal injuries, especially when used improperly

Earlier this month, two protesters in California were reportedly blinded after US federal agents fired less-lethal rounds at their faces from close range. These incidents were part of a wave of violent clashes between agents from the Department of Homeland Security (DHS) and protesters across the country after the deadly shooting of US citizen Renee Good by an Immigration and Customs Enforcement (ICE) agent in Minneapolis. 

Federal agents armed with less-lethal weapons in Minneapolis on Friday, Jan. 9, 2026. Source: Cristina Matuozzi/Sipa USA via Reuters Connect

In protests in Minneapolis immediately following Good’s death, one Customs and Border Patrol (CBP) officer was captured on camera firing a 40mm less-lethal launcher five times in less than five minutes, with several of these shots appearing to target protesters’ faces, which is against CBP’s own use-of-force policy

A Bellingcat investigation of DHS incidents in October 2025 also found about 30 incidents that appeared to violate a temporary restraining order (TRO) issued by an Illinois judge restricting how DHS agents could use LLWs.

Support Bellingcat

Your donations directly contribute to our ability to publish groundbreaking investigations and uncover wrongdoing around the world.

It is not always obvious whether the use of a LLW is authorised or not, as DHS component agencies such as ICE and CBP have varying guidance on factors such as the level of resistance an individual needs to show before a certain type of force can be used, as well as how specific types of less-lethal weapons and munitions can be used. 

While CBP’s use-of-force policy as of January 2021 is available on its website, ICE does not include specific guidance on less-lethal weapons in its 2023 “Firearms and Use of Force” Directive, and does not appear to have any publicly available policy that outlines this guidance.

DHS did not respond by publication time to Bellingcat’s request for the most recent DHS, CBP and ICE use-of-force policies, or to questions about what less-lethal weapons were authorised for use by the department and its component agencies. 

The DHS use-of-force policy, updated in February 2023, states that the department’s law enforcement officers and agents may use force, including LLWs, “only when no reasonably effective, safe and feasible alternative appears to exist”. It also says agents may only use a level of force that is “objectively reasonable in light of the facts and circumstances” that they face at the time.

DHS has repeatedly defended its use of riot-control weapons in protests across the country, stating that it was “taking reasonable and constitutional measures to uphold the rule of law and protect [its] officers”. 

Here’s how to identify some of the less-lethal weapons that DHS agents, including those from ICE and CBP, have been seen using during recent immigration operations. 

Compressed Air Launchers or ‘PepperBall Guns’

Left: A Border Patrol Agent in Chicago carrying an orange TAC-SF series PepperBall gun in Illinois on Oct. 24, 2025. Right: Agent aiming a Pepperball gun at someone filming them in Illinois on Oct. 19, 2025. Source: Youtube / @BlockClubChicago and Tiktok / @ericcervantes25

Compressed air, or pneumatic launchers, are essentially paintball guns that fire 0.68mm balls which break on impact. Often, this releases a powdered chemical irritant such as oleoresin capsicum (OC) or PavaPowder – the same compounds typically found in pepper spray. 

Compressed air launchers can also be used with other projectiles, such as “marking” projectiles that use paint to mark an individual for later arrest, and projectiles intended to break glass.

These weapons are often referred to as “PepperBall” guns, named after the leading brand PepperBall. However, DHS agents have also been seen carrying compressed air launchers from different brands, such as the FN303, produced by FN America.

Many compressed air launchers resemble standard paintball guns, with a distinct hopper or loader, which holds the ball projectiles, mounted to the top. They also have a compressed air tank that might be mounted to the side, bottom, or inside the buttstock (or back) of the weapon.

Many compressed air launchers, and less-lethal weapons in general, have very bright colours such as orange to distinguish them from lethal weapons. 

The TAC-SF PepperBall gun features a compressed air tank and a top-mounted EL-2 hopper, which has a distinctive shape. Graphic: Justin Baird for Bellingcat
The PepperBall TAC-SA Pro’s hopper is a slightly different shape from the TAC-SF, but serves the same purpose. Graphic: Justin Baird for Bellingcat
PepperBall VKS Pro features a compressed air tank located inside the buttstock and a magazine rather than a top-mounted hopper. Graphic: Justin Baird for Bellingcat

However, some compressed air launchers require closer scrutiny to distinguish them from firearms. 

For example, federal agents have been seen carrying FN303 compressed air launchers in videos of immigration enforcement activities. This weapon may resemble a rifle or other firearm, as it is usually all-black and, unlike the TAC-SF series PepperBall guns, lacks a visible hopper. 

Left: Agent holding an FN303 in California on June 11, 2025. Right: Federal Agent aiming a FN303 compressed air launcher at someone filming them in Illinois on Oct. 7, 2025. Source: TikTok / @anthony.depice and TikTok / @krisvvec

If closer examination is possible, this weapon can be identified by its distinct features, including a circular magazine, side-mounted compressed air tank and a hose connecting the firearm to the air tank.

The FN303’s air tank is mounted on the side and connected to the firearm by a hose. Graphic: Justin Baird for Bellingcat

The January 2021 CBP Use of Force Policy places several restrictions on the use of compressed air launchers, including that they should not be used against small children, the elderly, visibly pregnant women, or people operating a vehicle. It also states that PepperBall guns should not be used within 3 feet “unless the use of deadly force is reasonable and necessary”. When using the FN303, the minimum distance is increased to 10 feet. 

The CBP Use of Force Policy says that the intentional targeting of areas where there is a “substantial risk of serious bodily injury or death is considered a use of deadly force.” Agents are instructed not to target “the head, neck, spine, or groin of the intended subject, unless the use of deadly force is reasonable”. PepperBall and FN America provide similar warnings about avoiding vital areas to prevent serious injury or death.

According to a 2021 report by the US Office of Inspector General, CBP requires its agents to recertify their training to use PepperBall guns and FN303s every year, but ICE does not.   

40mm Launchers

Left: CBP agent “EZ-17” with a B&T GL06 40mm launcher and a belt with a variety of Defense Technology 40mm less lethal munitions, including one Direct Impact OC round and two Direct Impact CS rounds in Illinois on Oct. 24, 2025. Centre: EZ-17 firing a B&T GL06 launcher at a man in Minneapolis on Jan. 7, 2026. Right: A federal agent with a B&T GL06 in Illinois on Oct. 24, 2025. Source: YouTube / Block Club Chicago, X / Dymanh, Facebook / Draco Nesquik

DHS agents also use 40mm launchers to fire “Less-Lethal Specialist Impact and Chemical Munitions (LLSI-CM)”. These launchers resemble military grenade launchers, but are used to fire less-lethal ammunition, including “sponge” rounds that can disperse chemical irritants on impact. 

Federal agents have been seen using or carrying the B&T GL06 launcher in footage of multiple incidents reviewed by Bellingcat. They have also been spotted with other 40mm launchers, including Penn Arms 40mm multi-shot launchers, which have a six-round cylinder magazine. 

The B&T GL06 (pictured) and other 40mm launchers have a visibly wider barrel than compressed air launchers or standard firearms. Graphic: Justin Baird for Bellingcat

There are various less-lethal munitions available for 40mm launchers, including those whose primary function is “pain compliance” through the force of impact, chemical irritants or a combination of both. 

Videos of clashes between Border Patrol agents and protesters show these launchers being used with combination rounds designed to hit the target for pain compliance while also delivering a chemical irritant such as OC or CS. 

Direct Impact munitions by Defense Technology have distinctive rounded sponge foam noses and colours that indicate their chemical fill. Graphic: Justin Baird for Bellingcat

Other munitions dispense chemical irritants or smoke after being launched. For example, in the protests immediately following Good’s death, a Border Patrol agent was seen firing a 40mm munition that released multiple projectiles emitting chemical irritants in a single shot, consistent with the “SKAT Shell” by Defense Technology.

The SKAT Shell by Defense Technology (left) fires multiple projectiles, while the company’s SPEDE-Heat shell launches a single projectile. Graphic: Justin Baird for Bellingcat

Defense Technology’s technical specifications for its 40mm Direct Impact Rounds, which agents have been seen armed with, state that the munitions are considered less-lethal when fired at a minimum safe range of 5 feet and at the large muscle groups of the buttocks, thigh and knees, which “provide sufficient pain stimulus, while greatly reducing serious or life-threatening injuries”.

A DHS Office of Inspector General Report in 2021 noted varying guidance on the use of 40mm launchers among the department’s component agencies: “ICE’s use of force policy indicates that the 40MM launcher is deadly force when fired at someone, while the CBP use of force policy only directs officers not to target a person’s head or neck.”

CBP’s 2021 use-of-force policy states that agents should “not intentionally target the head, neck, groin, spine, or female breast”, and that anyone in custody who has been subject to such munitions should be seen by a medical professional “as soon as practicable”.

As of publication, DHS had not replied to Bellingcat’s questions about whether the department had an internal policy or provided training to staff on the minimum safe distance for 40mm less-lethal launchers as recommended by the manufacturers.

Hand-Thrown Munitions

Top Left: Border Patrol Commander of Operations At Large Greg Bovino with two Triple-Chaser CS Grenades on his vest in Minneapolis on Jan. 8, 2026. Top Right: Person holding a used Pocket Tactical Green Smoke grenade in Minneapolis, Jan. 21, 2026. Bottom Left: Top third of a Triple-Chaser Grenade in Illinois, Oct. 25, 2025. Bottom Right: Used Riot Control CS Grenade in Minneapolis, Jan. 23, 2026. Source: Nick Sortor, Rollofthedice, Bluesky / Unraveled Press, Andrew Hazzard

DHS agents have also been seen throwing some less-lethal munitions, such as flash-bangs, smoke and “tear gas” grenades or canisters by hand. 

These munitions activate a short delay after the grenade is employed. When they activate, flash-bangs or “stun” grenades emit a bright flash of light and a loud sound that is designed to disorient targets. Both smoke grenades and tear gas (also known as “CS gas” or “OC gas”) emit thick smoke, but the former just impedes visibility, whereas the latter also contains chemical irritants that sting the eyes. 

Defense Technology offers smoke grenades with hexachloroethane smoke composition, but most of their smoke grenades use “SAF-Smoke”, a less toxic terephthalic acid smoke composition

Hexachloroethane, while toxic, is not a nerve agent, despite misinformation surrounding the deployment of green colored smoke grenades in Minnesota by DHS personnel. 

The shape and general construction, colour, and any text can help identify these munitions.

Less-lethal munitions typically feature the manufacturer’s logo, the model name of the munition, and the model or part number. The text and manufacturer logo are typically colour-coded to indicate the type of payload the munition has, with blue indicating CS, orange indicating OC, yellow indicating smoke, green indicating a marking composition and black indicating munitions with no chemical payload. 

The “Triple-Chaser” grenade by Defense Technology (left) has three distinct segments that separate after the grenade is thrown, with each emitting smoke or chemical irritants, while other chemical grenades by the same company have a single smooth body (right). Graphic: Justin Baird for Bellingcat

A 2021 analysis by Bellingcat and Newsy found that Defense Technology and Combined Tactical Systems, the two manufacturers which produce most of the less-lethal munitions used by federal agents, both list the model numbers of their products online. Publicly available price lists for Defense Technology and Combined Tactical Systems can also be used to identify specific munitions by their model numbers. 

Part numbers seen on less-lethal munitions recovered in Portland in 2020. Source: Robert Evans/Bellingcat and X / @AnalystMick

CBP’s 2021 use-of-force policy states that hand-thrown munitions are subject to the same restrictions for use as munition launcher-fired impact and chemical munitions. 

Chemical Irritant Sprays

Left: DHS agent using a chemical irritant spray on a protester in Minneapolis on Nov. 25, 2025. Centre: CBP Agent spraying Alex Pretti with what appears to be OC spray moments before he is killed in Minneapolis on Jan. 24, 2026. Right: Federal Agent with a SABRE MK-9 spray threatening to spray a journalist if they do not move back in Minneapolis on Dec. 11, 2025. Source: Reddit / I_May_Have_Weed, TikTok/ShitboxHyundai, Instagram / Status Coup

DHS agents have also been using handheld chemical irritant sprays, often colloquially referred to as “pepper spray” or “mace”.

These sprays come in a variety of sizes and concentrations containing CS, OC, or both. Sprays used by law enforcement usually have a canister size designated “MK-” followed by a number, with higher numbers indicating larger canister sizes. The concentration of chemical irritants contained in the spray is also indicated on the canister.

The .2% MK-9 OC Spray by Defense Technology (left). The MK-9 produced by various companies with various concentrations has been seen often used by federal agents on protestors (right). Graphic: Justin Baird for Bellingcat

The effectiveness of OC sprays is determined by the concentration of major capsaicinoids, which are the active compounds in OC that cause irritation. These sprays are also affected by the type of aerosol dispersion, or stream, used. Different types of streams increase or decrease the range of the spray as well as the coverage area. 

Civilian and law enforcement sprays range from 0.18 percent to 1.33 percent major capsaicinoids, according to SABRE, a producer of law enforcement and civilian sprays. Civilian sprays in the US can have the same major capsaicinoid content as law enforcement sprays, but are restricted to smaller-sized canisters

Subscribe to the Bellingcat newsletter

Subscribe to our newsletter for first access to our published content and events that our staff and contributors are involved with, including interviews and training workshops.

Defense Technology sprays have different colour bands to indicate the percentage of major capsaicinoids in the spray for OC. If the spray is CS, the CS concentration is standardised at 2 percent. The company uses a white band for .2 percent, yellow band for .4 percent, orange band for .7 percent, red band for 1.3 percent and a grey band for sprays containing either CS or a combination of OC and CS.

SABRE sells a variety of concentrations and sprays as law enforcement products, including 0.33 percent, 0.67 percent, and 1.33 percent major capsaicinoid concentrations of OC, as well as CS, and combination CS and OC sprays. The specific concentrations of SABRE sprays and the type of stream can also be identified by the text on the canister. 

One Air Force Research Laboratory study found that some sprays may pose a significant risk of severe eye damage due to pressure injuries resulting from large aerosol droplets hitting the eye. 

Defense Technology’s technical specifications recommend a minimum distance of between 3 and 6 feet, depending on the specific spray. SABRE does not publicly provide their minimum safe deployment distances, but a Mesa Police Department document lists a minimum distance of six feet for the SABRE Red MK-9. CBP’s 2021 use-of-force policy does not provide any minimum use distances. 

CBP’s 2021 use-of-force policy states that OC Spray may only be used on individuals offering “active resistance”, and that it should not be used on “small children; visibly pregnant; and operators of motor vehicles”. 

Electronic Control Weapons

Left: Federal Agent pointing an Axon Taser 10 at a bystander who was filming an arrest in Los Angeles in June 2025. Right: DHS Agent with an Axon Taser 10 during an arrest in California on June 24, 2025. Source: Instagram / @dianaluespeciales, Instagram / Joe Knows Ventura

DHS agents have also been seen using electronic control weapons (ECWs), which are colloquially called TASERs after the original weapon invented for law enforcement use, in immigration-related raids. 

ECWs can deliver a shock upon direct contact or launch probes that embed in the targeted person, incapacitating them. 

A shock on contact, or a “drive-stun” feature, delivers localised pain while in direct contact. When properly deployed, the probes send signals to the body that cause muscles to contract. A person’s body “locking up” from muscle contractions is an indicator that an ECW has been deployed. ECWs may be capable of using either or both methods.

ECWs are typically painted a combination of black and bright yellow, but this varies between models. The bright colour of parts of tasers is a common feature to help distinguish an ECW from handguns used by federal agents. When viewed from the front, a circular gun barrel is visible on handguns, while ECWs feature multiple circular probes or rectangular covers on the cartridge. ECWs also usually have flashlights and lasers, although handguns may also be equipped with these features. Some ECWs may make audible sounds when armed or deployed.

The Axon TASER 10. Graphic: Justin Baird for Bellingcat

Axon, the predominant manufacturer of ECWs, produces several models including the TASER 10 and TASER 7. Axon provides a policy guide on recommended use of its TASER models to law enforcement agencies, which recommends targeting below the neck from behind, or the lower torso from the front. It recommends avoiding sensitive areas including the head, face, throat, chest and groin. 

Axon also recommends against using ECWs against small children, the elderly, pregnant people, very thin people and individuals in positions of increased risks such as running, operating a motor vehicle, or in an elevated position “unless the situation justifies an increased risk”.

CBP’s 2021 use-of-force policy, in addition to restricting the use of ECWs against small children, the elderly, visibly pregnant women, and people operating a vehicle, states that they should not be used against someone who is running or handcuffed. However, the policy does state that there may be an exception to the rule against using ECWs on a running person if an agent has a “reasonable belief that the subject presents an imminent threat of injury” to an agent or another person. This threat, according to the policy, must “outweigh the risk of injury to the subject that might occur as a result of an uncontrolled fall while the subject is running”.


Bellingcat is a non-profit and the ability to carry out our work is dependent on the kind support of individual donors. If you would like to support our work, you can do so here. You can also subscribe to our Patreon channel here. Subscribe to our Newsletter and follow us on Bluesky here and Mastodon here.

The post Identifying ‘Less-Lethal’ Weapons Used By DHS Agents in US Immigration Raids and Protests appeared first on bellingcat.

❌