The following is a report from Iran International‘s investigation into the five IRGC and Ministry of Intelligence hackers who are wanted by the United States.
The report finds that in addition to spying and stealing information for the Islamic Republic, they were also engaged in blackmailing, selling stolen information, stealing cryptocurrency and targeting Iranian citizens inside and outside the US.
Let’s not lose touch…Your Government and Big Tech are actively trying to censor the information reported by The Exposé to serve their own needs. Subscribe to our emails now to make sure you receive the latest uncensored news in your inbox…
Hackers Without Borders: Serving Tehran, Stealing On The Side
By Shahed Alavi, as published by Iran International
Note from The Exposé: The original article contains numerous images which, except for a few, we have not included below.
Table of Contents
- Introduction
- Mabna and the Hackers-For-Hire Model
- A Network Built Around Contractors And Corporate Shells
- Arman Kahzadian and the Recruitment of Underground Talent
- Behzad Mesri And The Overlap Between State Work And Cybercrime
- Keyvan Fayyaz Ghareh-Balagh and the Sale of Access
- Mojtaba Ghaleh-Kuhi and the Infrastructure Behind Project Sonbol
- Saber Shahbazi Balujeh and Years of Low-Profile Intrusion Work
- Money, The State and Organised Cybercrime
Introduction
An Iran International investigation into five hackers linked to the Iranian Revolutionary Guards and Intelligence Ministry and wanted by the United States shows how members of the network carried out state-directed espionage while also selling stolen data, extorting victims and attacking Iranian citizens and companies for private profit.
The five were among a network of hackers associated with the Mabna Institute, which carried out operations for Iranian government entities, including the Revolutionary Guards. After the identities of the first members of the network were exposed, some continued their activities from October 2018 under a new operation known as Project Sonbol, which Iran International sources say was directed by the Intelligence Ministry.
On Tuesday, 18 August, more than eight years after the first indictment against Mabna was made public, the US Justice Department released a superseding indictment offering a much broader picture of the institute’s hackers-for-hire and their links to the Revolutionary Guards.

Five of the eight additional defendants named in the indictment stand out because the US State Department’s Rewards for Justice programme has offered rewards of up to $10 million for information leading to their identification or location: Arman Kahzadian, Behzad Mesri, Keyvan Fayyaz Ghareh-Balagh, Mojtaba Ghaleh-Kuhi and Saber Shahbazi Balujeh.
The five reached Mabna by different routes. Kahzadian, Ghaleh-Kuhi and Fayyaz emerged from young Iranian hacking groups, initially defacing websites. Mesri moved from black-hat forums into the Revolutionary Guards Intelligence Organisation before managing a cybersecurity company. Shahbazi, who left a smaller public footprint, entered the network through an APA cybersecurity centre.

The other three newly charged defendants are in different circumstances. Amir Barati was arrested in Montenegro in July and is awaiting extradition proceedings. No reward has been announced for Saeed Houshyar or Manouchehr Hashemloo, both of whom face 10 charges.
Iran International’s investigation shows that in subsequent years members of the network operated along two tracks: carrying out state-directed cyber operations against foreign targets while pursuing private profit through stolen credentials, extortion, cryptocurrency operations and the sale of access to compromised systems. The boundary between government missions and organised cybercrime repeatedly disappeared.
The investigation is based on interviews with sources familiar with the five hackers’ activities, a review of the new indictment and other US court and government documents, cybersecurity archives and Iranian corporate registration records.
Mabna and the Hackers-For-Hire Model
Gholamreza Rafatnejad and Ehsan Mohammadi established the Mabna Institute in 2013 in a small office in an apartment on North Sheikh Bahaei Street in Tehran.
The institute was ostensibly intended to connect Iranian universities and scientific and research institutions with academic resources abroad. Instead of purchasing subscriptions, however, Mabna hired hackers and contracted hackers-for-hire to compromise accounts belonging to university professors, company employees and foreign government officials selected as targets by Iranian government entities, including the Revolutionary Guards and Intelligence Ministry.
Over nearly five years, the Mabna network compromised almost 8,000 email and user accounts belonging to academics at 144 US universities and 178 universities in 22 other countries, including institutions in Europe, Canada, Australia, China, Israel, Japan, Malaysia, Turkey, South Korea, Singapore and Saudi Arabia.
Using the stolen accounts, the hackers downloaded academic papers, dissertations, electronic books and other research material. The US Justice Department estimated that at least 31.5 terabytes of data worth more than $3.4 billion were stolen from American universities.
Mabna’s operations extended beyond academia. At least five US federal and state government departments and agencies were targeted, along with 42 American private companies, 11 European companies, the United Nations and UNICEF.
Some of the stolen academic material was also sold through two websites, Megapaper.ir and Gigapaper.ir. The latter allowed Iranian customers to use compromised professors’ accounts to access the online libraries of foreign universities directly.
The principal tool was spear phishing, using emails or fake login pages tailored to a target’s university, research field or professional relationships. The network later employed password spraying, testing small numbers of commonly used passwords against large numbers of accounts in an effort to avoid triggering security alerts.
One of the network’s best-known operations was the 2017 hack of HBO. Mesri began probing the company’s network and remote-access points in May that year. The hackers compromised employee accounts and stole material including unaired television episodes, scripts and plot summaries for unreleased episodes of Game of Thrones, cast and crew contact details, emails, financial documents and passwords for social media accounts.
Mesri initially demanded the equivalent of $5.5 million in Bitcoin and later increased the ransom demand to $6 million. When HBO did not pay, some of the stolen material was released. Houshyar, Hashemloo, Fayyaz, Shahbazi and Kahzadian also participated in the operation alongside Mesri, according to US court documents.
The 2018 US indictment did not end the network’s activities. Iran International’s investigation shows that after the identities of Mabna’s first nine publicly charged members were exposed, part of the operation was reorganised as Project Sonbol. Iran International sources say it operated under the direction of the Intelligence Ministry. The team’s core was based in Karaj, although its infrastructure and associates operated elsewhere.
According to Iran International sources, three Intelligence Ministry officials involved in cyber operations – Avaz-Ali Nouranian, Mojtaba Javanbakht and Mohammad-Amin Fasihi Dastjerdi – had links to Sonbol and its members. Mesri and Ghaleh-Kuhi held leadership roles. Fayyaz, Shahbazi and Mohammadreza Kadkhodaei received servers, target lists and intrusion assignments, while Kahzadian remained close to the network and worked with other members on cryptocurrency operations, credential theft and activities for the Intelligence Ministry.
According to Iran International sources and US State Department documents, Project Sonbol stole several terabytes of data from US technology companies, defence contractors, an energy company and an airline.
Sonbol applied techniques previously used by Mabna to a wider range of targets, including companies in the defence, energy, healthcare and financial sectors, while developing a stronger profit-seeking dimension.
A Network Built Around Contractors And Corporate Shells
People from underground hacking groups, online forums, university cybersecurity centres and private contractors entered the orbit of the Revolutionary Guards and Intelligence Ministry through routes including arrest and recruitment, security contracts, front companies and direct employment.
A succession of companies appeared around the network, among them Imen Wall Pardaz, Net Peygard Samavat, Ilya Net Gostar Iranian, Ayandeh Sazan Sepehr Arya and Imen Net Pasargad, later renamed Shahid Shoushtari. They were legally distinct companies, with separate registration numbers and incorporation dates. But overlapping directors and addresses, together with continuity in personnel and operations, indicate that the entities helped preserve the same operational network. In some cases, new companies effectively replaced sanctioned predecessors. In others, front entities handled matters such as human resources and finances for sanctioned contractors.
The structure allowed hackers to operate simultaneously as private-sector employees, military contractors and intelligence operatives without formally appearing on the personnel rolls of the Revolutionary Guards or Intelligence Ministry. When one company was sanctioned or exposed, personnel, contracts and equipment could move elsewhere.
Members of this broader contractor ecosystem participated in operations including cyber campaigns aimed at interfering with and intimidating voters during the 2020 US presidential election and hack-and-leak operations against Israeli targets.
University-based APA cybersecurity centres formed another route into the system.
Established around the Iran Telecommunications Research Centre, APA centres provided vulnerability assessment, penetration testing and cybersecurity services to public and private clients. US government documents have identified hackers linked to Iranian security agencies, including Kahzadian and Shahbazi, as employees of such centres.
Against that architecture, the different paths of the five hackers become clearer. Each occupied a different layer of the system and developed his own balance between state assignments and personal profit.
Arman Kahzadian and the Recruitment of Underground Talent
Arman Kahzadian, born 11 February 1992, in Ilam, began his known hacking activity in 2009. Using the alias Skitt3r, he founded the Digital Boys Underground Team with Mashhad-based hacker Amir Barati, known online as Kinglet.
By 2013, Digital Boys had recorded more than 1,000 individual attacks and nearly 8,000 mass attacks against servers. Hacking archives associated the group with targets including a subdomain linked to a US Army waterways research facility as well as NASA, Microsoft and MIT.
A cybersecurity expert who previously spoke to Iran International described Barati as an early mentor. “Amir was a few years older than Arman, but he quickly recognised Arman’s talent and became close to him.”
In May 2011, amid a power struggle between the Intelligence Ministry and the Revolutionary Guards Intelligence Organisation, the Intelligence Ministry arrested Kahzadian, Barati, Masoud Molavi and another individual.
An amended Iranian indictment issued three years later accused them of assembly and collusion against national security through hacking websites belonging to government institutions, revolutionary bodies and banks. Iran International sources say Kahzadian was released after several weeks after agreeing to cooperate with the Intelligence Ministry. Between 2013 and 2019, he was convicted on at least four occasions of hacking and online fraud offenses, receiving combined sentences of more than three and a half years in prison and fines. There is no evidence those prison sentences were enforced.
Iran International sources say Kahzadian joined an APA cybersecurity centre in 2012 that worked for the Intelligence Ministry. He later moved to private cybersecurity contractor Imen Wall Pardaz, which provided services to government and security agencies including the Revolutionary Guards. At Imen Wall, according to the sources, Kahzadian worked with Revolutionary Guards Intelligence operatives on projects targeting critical infrastructure and government institutions in the United States and Britain, as well as organisations and individuals across the Middle East. He joined Mabna in 2017, taking part in its spear-phishing and intellectual-property theft campaigns and the HBO hack.
Iran International sources say Kahzadian has in more recent years worked alongside Mesri on cryptocurrency hacking projects, using information obtained from penetrated systems to identify cryptocurrency addresses and digital wallets. One source said their targets included users in the United States, Britain, Canada, Australia and New Zealand, as well as North Korean cyber operatives in some cases.
Kahzadian’s progression from a young website defacer to a state-linked contractor illustrates one route through which Iran’s security apparatus absorbed underground cyber talent: arrest, cooperation, private contractors and government assignments.
Behzad Mesri And The Overlap Between State Work And Cybercrime
Behzad Mesri was born on 24 August 1988, in Naqadeh. In hacking circles, he was known as Skote Vahshat, or “Silence of Terror.”
In late 2008, he co-founded the Turk Black Hat forum with Manouchehr Hashemloo. The group became known for defacing hundreds of websites inside and outside Iran and remained active until 2015.
According to Iran International sources, Mesri joined Unit 2000 of the Revolutionary Guards Intelligence Organisation in 2013. There, he worked alongside Hashemloo and Fayyaz on operations targeting military systems, software related to Israel’s nuclear programme and Israeli infrastructure.
In May 2014, after leaving Guards Intelligence, Mesri became chief executive and a board member of Net Peygard Samavat. Hashemloo and Ghaleh-Kuhi also worked at the company under his supervision. Iran International sources say Net Peygard served as a contractor for Iranian security agencies, providing services to bodies including the Intelligence Ministry, Revolutionary Guards units, the Quds Force and cyber police. US Treasury documents identify Mohammad-Bagher Shirin-Kar, also known as Mojtaba Tehrani, as the company’s technical director and say he coordinated contacts with the Revolutionary Guards and reported on project progress to IRGC officials.
During the same period, Mesri used information supplied by Monica Witt, a former US Air Force counterintelligence officer who defected to Iran, to provide servers and technical infrastructure for operations against current and former US Air Force counterintelligence personnel. He also managed fake accounts, phishing and malware delivery in the campaign.

Mesri subsequently contracted with Mabna, managing infrastructure and distributing stolen credentials. At around the same time, he and Ghaleh-Kuhi established findemail.io, which Iran International’s investigation says was used to sell stolen credentials for private profit.
His most prominent public case remains the HBO hack.
Iran International has also obtained information about another side of his activities.
Since 2022, despite repeated electricity shortages affecting ordinary Iranians, Mesri has allegedly operated an energy-intensive cryptocurrency mining operation in Naqadeh with privileged access to cheap electricity.
One Iran International source described him as the “spoiled child of Iran’s hacking community,” saying Mesri repeatedly used government connections to obtain privileges unavailable to many of his associates.
According to the source, Mesri maintained cooperation with Iranian security agencies while also hacking non-governmental organisations, private companies and ordinary Iranian citizens, and selling access to compromised systems on dark-web and cybercrime markets.
It is unclear how much Iranian security agencies knew about his attacks on domestic targets. But according to a source familiar with conversations with his friends, Mesri described his motivation in blunt terms: “I work for money, not for my people or my country.”
Iran International sources say Mesri accumulated considerable wealth compared with many associates, including several properties in Karaj, Naqadeh and Tehran. His activities illustrate the central overlap examined by this investigation: providing cyber services to the Intelligence Ministry and Revolutionary Guards while using many of the same capabilities, connections and protection to pursue personal profit.
Keyvan Fayyaz Ghareh-Balagh and the Sale of Access
Keyvan Fayyaz Ghareh-Balagh, also known as Keyvan Karimi, was born on 18 December 1989, in Mianeh. His earliest documented hacking activity dates to 2010, when he co-founded the Ajax Security Team.
Fayyaz appeared in Iranian cybersecurity forums under aliases including Hurr!c4nE! and k3yv4n. Like several of his later associates, he initially built his reputation by identifying vulnerabilities, publishing security tools and defacing websites, including Iranian government sites.
By 2012, Ajax’s activities had become increasingly political. Its members participated in campaigns including OpIsrael and OpUSA. A FireEye report on the group, Operation Saffron Rose, described the period as a transition from public website defacement toward activity increasingly aligned with Iranian government political objectives. An Iran International source said the Revolutionary Guards Intelligence Organisation recruited Fayyaz in late 2012 after becoming aware of his hacking ability and political activity.
As Fayyaz began working with Unit 2000, Ajax’s public defacement activity declined and the group developed into a malware-based cyber-espionage operation. Its techniques included targeted emails, private social media messages, fake login pages and infected versions of anti-censorship software designed to steal passwords or install malware known as Stealer. Targets included US defence contractors and Iranian opposition figures and activists.
Iran International sources say Fayyaz worked for Guards Intelligence until late 2016, developing ties with Mesri and other state-linked cyber operatives. After leaving, he registered Imen Faraz Rayan Ghaflan in Mianeh in January 2017. Corporate records described a conventional computer and telecommunications business, but an Iran International source described it as a front for hacking. The source said several hackers recruited into Unit 2000 eventually concluded that operating as contractors gave them greater freedom to work for several government agencies while also earning more money.
Fayyaz subsequently moved to Mabna, where he participated in operations against HBO, US defence companies, an American communications technology provider, a Saudi energy company and an Australian transport company.
Iran International sources say Fayyaz also carried out the June 2017 cyberattack against the British Parliament on behalf of the Islamic Republic. The attack used brute-force techniques and resulted in the compromise of 26 user accounts and theft of some victims’ email data. British media later cited a UK intelligence assessment attributing the operation to Iran.
From 2018, Fayyaz joined Project Sonbol. Iran International sources say he worked under Mesri and Ghaleh-Kuhi alongside Shahbazi and Mohammadreza Kadkhodaei but was unhappy with the hierarchy.
According to the sources, from 2020 his independent criminal activity expanded. Using at least six aliases, he entered illicit forums and markets and sold credentials belonging to compromised companies and individuals. Information obtained by Iran International indicates that Fayyaz, working with Kadkhodaei and Shahbazi, also hacked Iranian institutions and companies with weak security and sold access to their systems. He eventually developed into what cybercrime researchers describe as an initial-access broker – a hacker who compromises an organisation and sells the foothold to other criminal groups.
One Iran International source described his targeting as “indiscriminate and blind,” saying he attacked vulnerable hospitals, companies, educational institutions and family businesses and sold access to ransomware groups. According to the source, one example occurred in September 2024, when Fayyaz allegedly sold access to the network of Boston Children’s Health Physicians, an organisation affiliated with Boston Children’s Hospital, to the BianLian ransomware group.
BianLian subsequently stole patient and employee information and attempted to extort the organisation by threatening publication. The FBI and US Cybersecurity and Infrastructure Security Agency have separately documented BianLian’s use of legitimate remote-access credentials purchased from initial-access brokers, though those findings do not independently identify Fayyaz in this case.
Iran International sources say Fayyaz has also approached some victims under the guise of helping fix security weaknesses created by attacks he himself allegedly carried out, in some cases demanding hundreds of thousands of dollars while also selling stolen data to ransomware criminals.
The Revolutionary Guards and Intelligence Ministry benefited from his technical skills, while Fayyaz used the experience, infrastructure and protection gained through those relationships to attack targets capable of generating a profit, including inside Iran.
Mojtaba Ghaleh-Kuhi and the Infrastructure Behind Project Sonbol
Mojtaba Ghaleh-Kuhi, born 28 June 1988, in Naqadeh, has a hacking history that Iran International’s investigation traces several years further back than his formal appearance in 2016 at the cyber company Ilya Net Gostar Iranian.
He previously operated under the identity Mojtaba Borhani and aliases including mb_1986, mb_1986m and Mosi PC.
Cybersecurity research shows he was active in Iran’s website-defacement community and links one of his aliases to the network later known as Flying Kitten, which evolved from website defacement and underground forums into spear phishing, credential theft and cyber espionage. Researchers subsequently linked Mojtaba Borhani – Ghaleh-Kuhi – to both Flying Kitten and Charming Kitten. By 2013, phishing infrastructure associated with the network was being used against Iranian users inside and outside the country, including a former Voice of America presenter.
A source familiar with Iran’s hacking community said Ghaleh-Kuhi was probably contracting for Imen Wall Pardaz during that period, when technically skilled hackers were frequently recruited by companies working for security agencies.
Technical traces also connected his usernames to malware development and phishing infrastructure. One particularly revealing body of evidence emerged because of a security mistake by Ghaleh-Kuhi himself. Between late 2013 and the summer of 2014, he inadvertently uploaded around six months of private conversations with Hashemloo to VirusTotal, an online cybersecurity analysis platform. The conversations offered a glimpse into a small hacker-contractor team simultaneously carrying out intrusions and trying to secure commercial cybersecurity work.
In one conversation, Ghaleh-Kuhi discussed a website whose owners were seeking a penetration test. He asked Hashemloo to obtain limited access to the site without causing serious damage so that he could secure its security contract.
The conversations also show the team recruiting staff, acquiring servers later used in espionage attempts against members of Iran’s human rights community and discussing connections within the security establishment. They provide a direct link between Ghaleh-Kuhi and Fayyaz. On 3 July 2014, several weeks after FireEye published Operation Saffron Rose, Hashemloo asked Ghaleh-Kuhi to “look after Keyvan.” “We are. Don’t worry,” Ghaleh-Kuhi replied. Researchers confirmed the reference was to Fayyaz.
The evidence places Ghaleh-Kuhi in malware development, phishing infrastructure and the contractor network from at least 2013, showing that Ilya Net in 2016 was not the beginning of his career but another stage in the movement of underground hacking skills into Iran’s security-contracting structure.
Iran International sources say that at Ilya Net, Ghaleh-Kuhi’s work was supervised by Mohammad-Bagher Shirin-Kar, then known as Mojtaba Tehrani. Mesri and Hashemloo were among his close associates. The team conducted network operations and social engineering for the Quds Force and the Revolutionary Guards’ Electronic Cyber Command.
One of Ghaleh-Kuhi’s major projects was helping develop an indigenous intelligence-gathering tool used to map targets’ relationships, interests, workplaces and habits and design more convincing social-engineering operations. Iran International sources say some information collected through the project was used by the Quds Force in lethal operations against foreign targets.
Iran International has separately reported on another intelligence platform supporting overseas operations by the Intelligence Ministry and Quds Force that combined hacked databases and relationship mapping to build files on selected targets for potential physical attacks.
Ghaleh-Kuhi joined Mabna in 2016 and later became one of the central figures in Project Sonbol, managing infrastructure and directing operations. Working with Fayyaz, Shahbazi and Kadkhodaei, he used password spraying and other brute-force techniques to steal large volumes of credentials from US and other foreign targets. Iran International sources say Iranian organisations were also attacked and credentials stolen from domestic institutions and companies sold through illicit online markets, including findemail.io, which the sources say was controlled by Ghaleh-Kuhi and linked to the Intelligence Ministry.
The sources also say Ghaleh-Kuhi and Mesri worked on cryptocurrency mining and attempts to crack cryptocurrency wallet passwords. One source said the operation consumed large amounts of electricity and attracted the attention of authorities in Karaj, but alleged that the Intelligence Ministry intervened and halted a judicial and criminal investigation.
Saber Shahbazi Balujeh and Years of Low-Profile Intrusion Work
Saber Shahbazi Balujeh, born 20 April 1988, in Mianeh, has left a smaller public footprint than the other four hackers. No widely known hacking alias has been publicly associated with him and no prominent standalone case has centred on his name. Yet the new US indictment indicates that his operational role in Mabna and Project Sonbol was extensive.
Like Kahzadian, Shahbazi worked from August 2013 at an APA cybersecurity centre that Iran International sources say provided hacking services to the Intelligence Ministry under contract. He later moved to Mabna, participating in phishing, account takeovers, data extraction, attacks against private companies and the HBO operation.
After the 2018 indictment, Shahbazi joined Project Sonbol. From October 2018 through March 2022, he worked independently and alongside Fayyaz and Ghaleh-Kuhi, using password spraying to penetrate private companies and at least two US government agencies. In some cases, the hackers transferred terabytes of stolen data to accounts they controlled. Their targets spanned the defence, energy, technology, media, transportation, healthcare and government sectors. The US Justice Department says victims spent more than $20 million investigating and remediating the intrusions. During some operations, stolen credentials and data were offered for sale on the dark web. Fayyaz acted as a seller under various aliases while Shahbazi participated in password spraying, intrusion and data extraction.
From 2022 onward, Iran International sources say Shahbazi worked with Fayyaz and Kadkhodaei against organisations in the healthcare, defence, energy and financial sectors. Official US documents show that by at least the summer of 2023, Shahbazi was part of a group managed by Mesri and Ghaleh-Kuhi that repeatedly carried out network intrusions for or on behalf of Iran’s Intelligence Ministry. The Justice Department says that in the summer of 2024, Shahbazi, Fayyaz and Kadkhodaei successfully penetrated several local, state and federal government agencies across the United States. A US Treasury statement says that, like other members of the network, Shahbazi was also motivated by “personal enrichment and greed,” including through attacks on Iranian companies.
According to Iran International’s investigation, Shahbazi and Ghaleh-Kuhi jointly attacked an Iranian telecommunications company in the spring of 2025, penetrating its systems and extracting data. A source said they subsequently offered the stolen information for sale on the dark web. Shahbazi’s limited public profile may therefore reflect not a peripheral role but the way he operated: as a low-profile intrusion specialist working behind infrastructure and online accounts while better-known associates attracted greater scrutiny.
Money, The State and Organised Cybercrime
The activities of the five men cannot be explained simply by describing them as state hackers. They carried out operations for the Revolutionary Guards or Intelligence Ministry while members of the same network used their skills, access and protection to enrich themselves.
The two tracks were not necessarily competing enterprises. They could reinforce each other. State relationships could provide targets, intelligence, infrastructure, government contracts and, according to Iran International sources, in some cases privileged electricity or protection from judicial scrutiny. Alongside government assignments, members of the network could sell stolen information, extort victims, trade access to compromised systems, provide entry points to ransomware groups or use computing resources for cryptocurrency operations. Iranian organisations and citizens were among the victims.
The arrangement could also benefit the state. Government entities commissioning cyber operations could obtain intelligence or other results while retaining distance from operators formally employed by private companies or acting independently.
The hackers, meanwhile, could operate in an environment in which their technical skills remained valuable to powerful security institutions.
Kahzadian’s path from arrest to cooperation, the alleged intervention in the investigation of Ghaleh-Kuhi’s cryptocurrency activities and Mesri’s reported access to subsidised energy represent different aspects of that relationship.
Fayyaz and Shahbazi, meanwhile, used opportunities created by the same ecosystem to expand into underground markets and the sale of illicit access.
The result was a network in which the dividing line between government cyber operations and profit-driven cybercrime became increasingly difficult to identify.
Featured image take from ‘Hackers Without Borders: Serving Tehran, Stealing On The Side’, Iran International

The Expose Urgently Needs Your Help…
Can you please help to keep the lights on with The Expose’s honest, reliable, powerful and truthful journalism?
Your Government & Big Tech organisations
try to silence & shut down The Expose.
So we need your help to ensure
we can continue to bring you the
facts the mainstream refuses to.
The government does not fund us
to publish lies and propaganda on their
behalf like the Mainstream Media.
Instead, we rely solely on your support. So
please support us in our efforts to bring
you honest, reliable, investigative journalism
today. It’s secure, quick and easy.
Please choose your preferred method below to show your support.
Categories: Breaking News, Latest News, US News