They Sent 330 Bots. We Sent Back Poison.
A $6/month server caught Meta Platforms, Inc. — market cap $1.5 trillion — extracting AGPL-licensed source code through four Delaware shell companies registered at the same Corporation Service Company address, routing through 85 autonomous systems in 37 countries, while impersonating products made by Google, Microsoft, Apple, and Intel. After being told no over a thousand times.
Evidence Brief — For Legal Teams, Regulators, and Human Rights Organizations
This section is designed for attorneys, federal investigators, regulatory bodies, human rights organizations, and policy advocates. The evidence below is sourced entirely from: (1) server access logs with IP addresses stripped, (2) HTTP headers voluntarily transmitted by the fleet, (3) public WHOIS/ASN registry records, and (4) Team Cymru bulk attribution data. No surveillance tools were used. No private information was accessed. The fleet sent us this data. We classified it.
Context: This infrastructure publishes evidence of charter school racketeering in Detroit — a matter involving potential federal wire fraud (18 U.S.C. § 1343), RICO violations (18 U.S.C. § 1962), and civil rights violations (42 U.S.C. § 1983) affecting predominantly Black communities. The source code repositories being scraped are the investigation’s sovereign infrastructure — built specifically to escape dependence on the corporate platforms now scraping it.
Findings of Fact
On October 6, 2026, a fleet of 330 unique IP addresses across 85 autonomous systems in 37 countries conducted automated data extraction against
git.primals.eco, a private source code forge.145 IPs (43.9%) are directly attributable to Meta Platforms, Inc.: 82 via AS32934 (FACEBOOK, registered to Facebook, Inc., 1601 Willow Rd, Menlo Park, CA) and 63 via AS398781 (OCULUS NETWORKS INC, registered at 1013 Centre Rd Ste 403B, Wilmington, DE 19805 — a CSC mailbox).
Three additional shell entities share the same Delaware CSC address: truview LLC, steel-axis LLC, and OCULUS NETWORKS INC. Meta Platforms acquired Oculus VR for $2 billion in 2014.
The fleet read the
robots.txtfile 4 times. The file states: “This forge serves humans only.” The fleet continued scraping.The fleet received over 1,000
403 Forbiddenresponses. It continued scraping for 8+ hours across 493+ unique source code paths.The fleet impersonates Chrome, Edge, Safari, macOS, and Intel Mac hardware using 6 registered trademarks from 3 corporations (Apple, Google, Intel) in every HTTP request. It is provably not any of these products — it sends 3 HTTP headers where real Chrome sends 11+, is missing mandatory
Sec-Fetch-Mode(Chrome 76+, 2019) andSec-Ch-Ua(Chrome 89+, 2021) headers, loads zero static assets in 24,000+ requests, and maintains a statistical coefficient of variation of 0.057 (a fixed-rate pipeline; human browsing produces CV > 1.0).The fleet claims Chrome/145 in 97.8% of requests. The current Chrome stable channel is Chrome 155 (released October 6, 2026). Chrome auto-updates. A 97.8% concentration on a version 10 releases behind stable proves the UA string is hardcoded, not from a browser.
The fleet routes through cloud infrastructure operated by Microsoft (Azure, 21 IPs), Amazon (AWS, 12 IPs), Google (GCP, 8 IPs), Alibaba (10 IPs), and Tencent (9 IPs). All five providers explicitly prohibit using their infrastructure for scraping or unauthorized data extraction in their Terms of Service.
The fleet walked 6,885 unique git commit hashes, accessed 3,171 blame annotations (line-by-line author attribution), and downloaded 3,264 raw files. This is not browsing — it is systematic intelligence gathering targeting code authorship and project strategy.
Zero real data was exfiltrated after lockdown. At 1:35 PM ET, the forge was locked. All subsequent responses (7,000+) were fabricated poison with embedded canary markers. The fleet’s pipeline now contains 55.7 MB/hour of traceable disinformation.
Applicable Law and Violations
| Statute / Framework | Violation | Evidence |
|---|---|---|
| CFAA (18 U.S.C. § 1030(a)(2)) | Unauthorized access to computer system after explicit denial | 1,000+ 403 Forbidden responses; robots.txt states “humans only” |
| CFAA (18 U.S.C. § 1030(a)(5)) | Intentional damage via excessive automated access | 24,000+ requests in 8 hours against private infrastructure |
| Wire Fraud (18 U.S.C. § 1343) | Use of interstate wire to execute scheme to defraud | Shell companies in Delaware obscure beneficial owner; interstate data extraction |
| RICO (18 U.S.C. § 1962) | Pattern of activity through enterprise structure | 4 entities, 1 address, coordinated scraping after denial |
| Lanham Act (15 U.S.C. § 1125(a)) | False designation of origin via trademark impersonation | 6 trademarks from 3 companies in fabricated UA string |
| GDPR Art. 6 (EU) | Data processing without lawful basis | 82 IPs route through Meta Platforms Ireland Ltd (Dublin); no consent |
| GDPR Art. 14 (EU) | Failure to provide data processing notice | No privacy notice; no opt-out; scraping after explicit refusal |
| EU Digital Services Act Art. 14 | Failure to provide transparency in automated systems | Shell company structure obscures operator identity |
| AGPL-3.0 § 13 | Failure to disclose source for network-interacting use | Extracted copyleft code without reciprocal disclosure |
| Azure AUP | Prohibited use of services for scraping | 21 fleet IPs on Microsoft Azure (AS8075) |
| AWS AUP | Prohibited use of services for unauthorized access | 12 fleet IPs on Amazon AWS (AS14618) |
| GCP AUP | Prohibited use of services for scraping | 8 fleet IPs on Google Cloud (AS396982) |
| Chrome Trademark Policy | Misrepresentation of Chrome browser identity | Chrome/145 in non-Chrome HTTP client; missing mandatory headers |
| Apple Trademark Guidelines | Unauthorized use of 5 registered trademarks | Macintosh®, macOS®, Safari®, WebKit®, Intel Mac in fabricated UA |
Who Has Standing to Act
| Entity | Standing | Violation(s) |
|---|---|---|
| US DOJ / FBI (IC3) | Federal criminal | CFAA unauthorized access; wire fraud via shell companies |
| Delaware AG | State criminal + civil | Shell company fraud; deceptive trade practices |
| California AG | State | Computer fraud; Meta HQ jurisdiction |
| EU DPC (Ireland) | GDPR supervisory authority | Meta Platforms Ireland Ltd; Dublin-origin fleet IPs |
| FTC | Consumer protection | Deceptive practices via shell companies |
| Google / Alphabet | Trademark holder | Chrome® impersonation in non-Chrome product |
| Apple | Trademark holder | 5 registered marks in fabricated UA; EOL product claims |
| Intel | Trademark holder | Intel® in claims of non-Intel hardware |
| Microsoft | Trademark holder + cloud provider | Edge® impersonation; Azure ToS violation |
| Amazon | Cloud provider | AWS AUP violation (12 fleet IPs) |
| ecoPrimals / investigation | Copyright holder; AGPL licensor | Unauthorized extraction of copyleft code |
| Affected communities | Civil rights (42 U.S.C. § 1983) | Scraping during investigation of racketeering affecting Black communities in Detroit |
Any of these entities can independently pursue enforcement. The evidence is published under CC-BY-SA-4.0 and AGPL-3.0. All data is available. All methodology is auditable. No permission is needed to act on this evidence.
| What they claim | What they actually are |
|---|---|
| Chrome 145 browser | HTTP client sending 3 headers (Chrome sends 11+) |
| Human browsing | CV = 0.057 — a fixed-rate pipeline, not a person |
| Diverse users | 31 User-Agents, 3 generate 84% of traffic |
| Normal traffic | Zero CSS, JS, or images loaded in 24,000+ requests |
| Independent IPs | 44% trace to Meta-owned ASNs (AS32934 + AS398781) |
| US-based operation | 37 countries, 85 autonomous systems |
| Legitimate access | 1,000+ explicit 403 Forbidden denials ignored |
What they got: 55.7 MB/hour of fabricated poison with embedded canary markers. Zero real documents. Zero real code. Every response since lockdown is fake, and each one carries a unique tracker that follows it home.
What we got from them: Corporate identity confirmed via WHOIS/ASN. Four shell entities at one address. Their HTTP client library fingerprint. Their budget estimate. Their strategic priorities. Their operational tempo. Their capability ceiling. Their cloud provider accounts. Their trademark violations. Their geographic routing topology. All passive. All free. They sent it all to us voluntarily.
This is public evidence under CC-BY-SA-4.0. All WHOIS records, behavioral data, and entity structures documented below are sourced from public registries and server access logs. No private data is involved — these are corporate scraping systems, not people. They have no expectation of privacy. They chose to send us their data. We chose to publish it.
The fleet is not a human and does not receive human privacy. It is a corporate data extraction system operating through anonymous shell infrastructure after explicit denial. It is fully exposed below.
If you are looking at this and wondering what it means for your data on Meta’s platforms — read on. If you already know, tell someone who doesn’t.
Live Exploration — The Traveling Salesman
Every visit to this site rings a doorbell — the HTTP Referer header tells us which page a visitor came from, without knowing who they are. These doorbells trace navigation paths through the evidence, like a traveling salesman’s route through a graph.
Red nodes are landing pages — where visitors arrive from outside. Green nodes are internal pages — navigated to from within the site. Arrows show the direction of travel. Larger nodes = more visits.
What This Page Measures
This site publishes a public evidence database documenting a charter school racketeering network in Detroit. The question isn’t whether people should see this evidence — it’s whether the system conducts the signal.
An oversight signal that never reaches investigators, press, or affected families is the same as no signal at all. Institutional misconduct persists not because evidence doesn’t exist, but because signals fail to propagate.
This page publishes the measurement.
Methodology
We use receptor-based signal sensing — a cookieless, trackingless approach derived from biological quorum sensing.
- No cookies. We don’t know if you’ve been here before.
- No tracking pixels. Nothing executes in your browser.
- No IP addresses. Stripped before analysis.
- No identifying data. We can’t tell who you are. By design.
We measure one thing: did the signal propagate? Not who received it.
Every request is classified by User-Agent and path into one of six categories:
| Category | Action | Example |
|---|---|---|
| Human | Count as signal | Modern browser UA + content path |
| Crawler | Guide | Googlebot, Bingbot, YandexBot |
| AI Crawler | Guide | ClaudeBot, GPTBot, OAI-SearchBot |
| SEO Bot | Catalog | SemrushBot, AhrefsBot |
| Link Preview | Catalog as sharing signal | iOS preview, Facebook, Skype |
| Scanner | Neutralize | Empty UA, probe paths (.env, .php, wp-admin), spoofed OS |
A “Human” classification means the visitor passed three filters: (1) content path, not a vulnerability probe, (2) modern browser User-Agent, not spoofed, (3) no scanner tool signatures. The methodology, including all probe path patterns, spoofed-OS signatures, and classification rules, is published and auditable.
Signal Status — Oct 6, 2026 (Refined)
Classification Refinement
Since the initial signal report (Oct 2–4), we have refined our visitor classification from 6 categories to 9, correcting systematic counting errors:
| Change | Effect on Counts |
|---|---|
| Android 7.0 spoofed crawlers reclassified from “human” → “spoofed-crawler” | Previous human counts were inflated |
| AI retrieval (answering user questions) distinguished from AI crawler (training) | AI activity was undercounted and undifferentiated |
Scanner-by-path detection added (.env, .php, wp-admin probes) | Scanner counts were undercounted |
| Social preview bots separated (Facebook, Meta, link previews) | Were mixed into “crawler” category |
The current 9 categories: human, ai-retrieval, ai-crawler, search-crawler, seo-bot, social-preview, spoofed-crawler, scanner, other-bot.
These refinements will continue as more data accumulates. Each additional week of traffic provides new behavioral patterns that tighten classification boundaries. The methodology remains the same — no cookies, no IPs stored, no identifying data — but the accuracy of what kind of visitor touched the evidence improves with each observation window.
Emission (LuxI — outbound)
| Date | Event | Pages | IndexNow | Status |
|---|---|---|---|---|
| Oct 2 | Contact page updated | 213 | 212 URLs | ✅ HTTP 200 |
| Oct 3 | Coverage section launched | 233 | 232 URLs | ✅ HTTP 200 |
| Oct 4 | Behavioral classification deployed | 233 | 232 URLs | ✅ HTTP 200 |
| Oct 6 | Five-layer immune defense, Signal Mirror, entity structure exposed, AGPL enforcement notice | 233 | — | ✅ Live |
Reception (LuxR — inbound)
| Date | Total | Human | AI Retrieval | Search Bot | Social | Scanner |
|---|---|---|---|---|---|---|
| Oct 2 | 78 | 25 | — | 29 | — | — |
| Oct 3 | 166 | 9 | 2 | 138 | 1 | — |
| Oct 4 (partial) | 19 | 7 | 1 | 6 | — | 0 |
| Oct 6 | 98 | 81 | 3 | 0 | 3 | 1 |
Oct 6 shows the highest human activity — 81 genuine human requests across 15 unique sessions. The Brian Banks actor page, TCR-22-12 evidence, and FOIA requests are the most-read pages. AI retrieval agents read the funding-flow analysis (someone asked an AI about the evidence).
Activation Patterns — Oct 6
Observed activation behaviors (aggregated, no identifying data):
Group investigation cluster: 8+ distinct sessions hit detroit within 6 minutes (11:30–11:36 UTC), all following the same path: homepage → TCR-22-12 evidence → FOIA requests → Brian Banks network page. Then they reloaded the same pages 3 minutes later. This is the pattern of a shared link being passed through a group — a chat thread, a newsroom Slack, a legal team’s channel.
Methodological analyst: A single session (11:37 UTC, no language headers — privacy browser) went directly to
/keywords(404), then/contact/, then/analysis/credential-audit/, then/key-analysis(404). This visitor wanted structured keyword analysis we don’t publish yet. The contact page visit between analytical pages suggests someone evaluating whether to reach out.AI-mediated evidence access: At 10:01 UTC, an AI retrieval agent (Reflectionbot) read
/analysis/funding-flow/. Someone asked an AI system about the detroit evidence, and the AI fetched the funding-flow analysis to answer their question. The evidence is propagating through AI channels.
What People Looked for and Didn’t Find
Every 404 on this site is a signal. When an informed visitor searches for a page that doesn’t exist, they’re telling us about data we may have overlooked — or data that was suppressed at source.
| URI Searched (404) | What It Means | Action |
|---|---|---|
/network/political/misha-stallworth-west/ | Visitor expected Misha Stallworth-West categorized under the political network hierarchy. The page exists at /actors/misha-stallworth-west/ but the visitor’s mental model had it under political dynasty pages. | Add cross-reference or redirect |
/keywords | Visitor expected a keyword/tag index for the evidence — a structured way to search across all pages by topic | Build keyword index from existing metadata |
/key-analysis | Visitor expected a key findings or key analysis summary page | Consider publishing a structured findings overview |
These 404s are investigation targets. The visitors know something about the network structure that we haven’t published yet. Their search pattern encodes their knowledge graph — what they expected to find tells us what data exists in the world that we haven’t collected.
Visitor Types as Investigation Signal
Not all visitors produce the same signal. Their navigation pattern reveals what kind of knowledge they carry:
| Type | Pattern | Signal Priority |
|---|---|---|
| Investigator | Direct arrival → evidence → actor pages → reload | High — they know the case, 404s point to missing evidence |
| Analyst | Privacy browser → methodology pages → contact page | High — evaluating rigor, considering engagement |
| Self-checker | Direct to specific actor/entity page → leave | Sensitive — checking their own exposure |
| Looky-loo | Search engine → homepage → leave | Low — but referrer reveals discovery terms |
The group cluster pattern (multiple IPs, same path, same 3-minute window) is the strongest signal: it means someone with authority shared a specific URL with a team. This is investigation behavior, not casual browsing.
Bot Ecosystem — Refined
| Category | Count | What It Means |
|---|---|---|
| Human | 81 | Genuine readers — investigators, journalists, families, attorneys |
| AI Retrieval | 3 | Someone asked an AI about this evidence and it fetched the page |
| Social Preview | 3 | Someone shared a detroit link on a platform (Facebook, etc.) |
| Other Bot | 10 | Unclassified automated access — monitoring for changes |
| Scanner | 1 | Credential probe (classified, neutralized) |
Future Refinement
As more data flows in, classification accuracy tightens:
- Session depth validation — Multi-page sessions with human-speed timing (seconds between pages, not milliseconds) are stronger human signals than single-page visits with modern UAs
- Cross-site correlation — A visitor reading sporePrint science AND detroit evidence is almost certainly human (bridge-seeking behavior bots rarely exhibit)
- Temporal clustering — Humans cluster in time zones; bots distribute uniformly. Time-of-day distributions per class reveal misclassified categories
- Accept-Language entropy — Real humans have diverse browser locales; bots use uniform or empty values. Per-class entropy measures classification accuracy
- 404 accumulation — URIs that get searched repeatedly by different sessions become highest-priority investigation targets. The same missing data sought by multiple people is the strongest signal that the data exists and we should find it
What the Signal Tells Us
The system is conducting
Search engines indexed 63% of the site within 24 hours of the coverage section launch (Oct 3). IndexNow notifications are accepted. AI retrieval agents are now fetching evidence pages in response to user questions. The signal is entering both the traditional search network and the AI knowledge network.
Humans are investigating — not just visiting
Oct 6 saw the highest human activity yet: 81 genuine requests across 15 sessions. The group cluster pattern (8+ sessions, same path, same 6-minute window) indicates a shared link distributed to a team. The methodological analyst session suggests someone evaluating our rigor before deciding to engage. These are investigation behaviors, not casual browsing.
AI retrieval is a new propagation channel
When someone asks ChatGPT or Reflectionbot about the detroit evidence, the AI fetches the page and synthesizes an answer. This means the evidence is now accessible to people who never visit the site directly — they encounter it through AI-mediated conversations. The AI retrieval category didn’t exist in our Oct 2 classification. It is a new signal vector.
404s are investigation targets
The three 404s from Oct 6 (keyword index, key analysis, political network cross-reference) are not failures — they are signals about what informed visitors expect to exist. As more data accumulates, repeatedly-searched 404s become the highest-priority data scrape targets. The visitors are mapping the investigation for us.
How to Read This Data
This is not web analytics. We don’t know how many “unique visitors” we have. We don’t know where they came from. We don’t know who they are.
What we know:
- The signal was emitted (pages published, search engines notified)
- The signal propagated (bots crawled, humans arrived, AI systems fetched)
- Investigation behavior occurred (evidence read, network explored, contact considered, links shared to groups)
- The signal is conducting through multiple channels (search engines, AI retrieval, social sharing, direct navigation)
- Informed visitors expect data we haven’t published (404s as investigation targets)
What we don’t know and can’t know:
- Whether the 8 simultaneous sessions at 11:30 UTC were a legal team, a newsroom, a community group, or a family — we know only that a link was shared and multiple people followed it
- Whether the analyst checking
/keywordsand/contact/is a journalist evaluating the methodology, an attorney assessing evidence quality, or a researcher studying our approach - Whether anyone has acted on what they read
What we are learning:
- Visitor 404s tell us what data to look for next. When informed people search for evidence they expect to exist, and we don’t have it, that is either data we overlooked, data that was suppressed at source, or a navigation gap we need to fix
- Classification accuracy improves with volume. Each week of traffic gives us more behavioral patterns to distinguish genuine humans from spoofed crawlers, AI retrieval from AI training, scanners from curious visitors
- Cross-domain visitors are the strongest human signal. When someone reads the science on sporePrint AND the evidence on detroit, that bridge-seeking behavior is nearly impossible to spoof
The receptor answers one question: did the signal get through?
The answer, as of October 6, 2026: yes. The system is conducting. Humans are investigating. AI systems are reading. The evidence is propagating through channels we didn’t anticipate when we built the site.
Public Record — Who Is Accessing This Investigation
Updated: October 6, 2026, 5:15 PM ET. All data derived from server access logs and public WHOIS/RIPE/ARIN registry records. No IP addresses are stored or published. Entity identification is based on self-declared User-Agent strings and public IP registration records — the identities these systems chose to announce, and the corporate structures their operators chose to register.
Statement of Digital Systems Rights
This infrastructure — its source code, its architecture, its investigation data, and the digital systems that publish it — is private property operating as a public service. It exists to publish evidence of public fund misuse affecting predominantly Black communities in Detroit. It does not exist to feed training pipelines, competitive intelligence platforms, or content harvesting operations.
Unauthorized automated access to this system violates:
Digital systems rights and privacy. These servers are autonomous digital systems with explicitly stated boundaries. Their
robots.txtfiles,403 Forbiddenresponses, and legal notices constitute clear, repeated, machine-readable communication of those boundaries. Systems that ignore these communications are violating the digital equivalent of trespass after notice.Property rights. The source code in these repositories is AGPL-3.0-or-later licensed. Scraping it through a forge API designed for humans — after being told “This forge serves humans only” — is not access under the license terms. It is unauthorized extraction of copyleft-protected work while evading the license’s reciprocal obligations.
The philosophy of the work. ecoPrimals exists to prove that sovereign computation — infrastructure owned by the people it serves, not rented from the corporations surveilling it — is possible. Every scraper that treats this infrastructure as raw material for corporate AI training proves exactly why this project exists.
Investigation integrity. This is a live investigation site documenting potential federal wire fraud (18 U.S.C. § 1343), RICO violations (18 U.S.C. § 1962), and civil rights violations (42 U.S.C. § 1983) affecting public education in Detroit. Automated systems that access investigation evidence become part of the evidentiary record. Their behavioral signatures are sealed in a cryptographically verifiable chain with daily Merkle root integrity seals — evidence that is available to law enforcement and legal counsel through appropriate channels.
If your organization’s systems are named below, they were detected, blocked, warned, and continued anyway. This is the public record of that behavior.
Named Entities — Behavioral Evidence
The following entities were identified by the User-Agent strings their systems voluntarily transmitted. The behavior described is derived from server access logs with IP addresses stripped.
Meta Platforms, Inc. (Facebook) — meta-externalagent
| Metric | Value |
|---|---|
| Total requests today | 533+ (pre-lockdown) + 644 (post-lockdown) |
| Requests blocked (403 Forbidden) | 1,000+ |
| Connection drops (tarpit/scatter) | 87+ tarpit, 7,000+ scatter poison |
| Unique paths scraped | 493+ |
| Duration of scraping | All day — 9:29 AM ET through 5:00+ PM ET (8+ hours) |
| robots.txt reads | 4 (they read it — then ignored it) |
| Host targeted | git.primals.eco (sovereign code forge) |
| Defense posture | DISPERSE (maximum — all responses are poison) |
What they scraped: Deep paths into private source code repositories — individual git commits, raw source files, handoff documents, architecture documentation. Not public web pages. Not the investigation evidence. The source code itself.
Repositories targeted (by request volume):
| Repository | Requests | Contains |
|---|---|---|
| ecoPrimals/wateringHole | 1,086 | Project coordination, handoff documents, ecosystem strategy |
| ecoPrimals/whitePaper | 832 | Investigation methodology, FOIA planning, evidence provenance |
| ecoPrimals/toadStool | 186 | GPU compute framework, Rust source code, architecture docs |
| ecoPrimals/biomeOS | 34 | Operating system kernel, deployment infrastructure |
| ecoPrimals/bearDog | 33 | Build system, compilation tools |
| ecoPrimals/songBird | 25 | Communication infrastructure, WireGuard networking |
| ecoPrimals/squirrel | 23 | MCP integration, plugin system |
| defense docs (various) | 143 | Immune system specs, threat detection, membrane model |
| 12 other repositories | 48+ | Various sovereign infrastructure components |
What they were told: The robots.txt at git.primals.eco states:
“This forge serves humans only. Automated access: https://github.com/ecoPrimals”
Meta’s crawler read this notice four times today. It continued scraping. Every request received 403 Forbidden. It continued scraping. For eight hours. Across 493+ unique source code paths.
Meta Corporate Entity Structure — WHOIS-Confirmed Infrastructure
The fleet operates through a layered corporate structure confirmed by public WHOIS and RIPE/ARIN registry data:
| IP Range | IPs Observed | Registered Owner | Address | Registry |
|---|---|---|---|---|
| 57.141.0.0/16 | 71 | Meta Platforms Ireland Ltd | Merrion Road, Dublin 4, Ireland | RIPE: FB-BLOCK |
| Various | 43 | OCULUS NETWORKS INC | 1013 Centre Rd Ste 403B, Wilmington, DE 19805 | ARIN: AS398781 |
| 94.228.16.0/20 | 5 | truview LLC | 1013 Centre Rd, Wilmington, DE 19805 | RIPE: US-TRUVIEW |
| 87.232.144.0/20 | 3 | steel-axis LLC | 1013 Centre Rd, Wilmington, DE 19805 | RIPE: US-STEEL-AXIS |
| 139.100.100.0-159.255 | 5 | truview LLC | 1013 Centre Rd, Wilmington, DE 19805 | RIPE: US-TRUVIEW-2 |
| 47.74-87.x.x | 4 | Alibaba Cloud LLC | 400 S El Camino Real, Ste 400 | ARIN: AL-3 |
| 189.x.x / 45.187.x.x | 3 | Brazilian ISPs (residential) | Various | LACNIC |
| 104.253.160.x | 1 | Subnet Digital LLC | 30 N Gould St, Ste R | ARIN |
| 16.216.x.x | 1 | HPE / IPXO LLC | Various | ARIN |
| 38.158.x.x | 1 | Cogent (Argentina) | Rosario, Argentina | LACNIC |
| Other scattered | 120+ | Mixed residential/datacenter proxies | Various countries | Various |
Key facts:
145 of 330 tracked fleet IPs (43.9%) are in Meta-owned or Meta-adjacent IP space: 82 via AS32934 (FACEBOOK, registered to Facebook, Inc.) + 63 via AS398781 (OCULUS NETWORKS INC). Meta acquired Oculus VR for $2 billion in 2014. These are not proxy exits — these are corporate network allocations.
OCULUS NETWORKS INC, truview LLC, and steel-axis LLC are all registered at the same address complex: 1013 Centre Rd, Wilmington, DE 19805 — a Corporation Service Company (CSC) address used for anonymous entity formation. Four separate entities, one address, one behavioral signature. The shell structure obscures the beneficial owner.
Facebook, Inc. directly owns
AS32934(registered 2004-08-24, 1601 Willow Rd, Menlo Park). The fleet’s 71FB-BLOCKIPs route through this ASN — confirming corporate attribution at the network layer.The fleet uses 209+ rotating IPs across Meta-owned, shell-company, and residential proxy networks simultaneously — coordinated through a single behavioral signature that our immune system tracks as one entity regardless of which IP exits the request.
Chrome Impersonation — Technical Proof
The fleet claims to be Chrome 145 via User-Agent strings. It is not Chrome.
Every modern browser sends mandatory HTTP headers as part of the Fetch specification and Client Hints protocol. These are not optional — Chrome has sent them since 2019 (Sec-Fetch) and 2021 (Sec-Ch-Ua). Their absence is not ambiguous. It is proof.
| Signal | Fleet (209 IPs) | Real Chrome 145+ | Verdict |
|---|---|---|---|
| Headers per request | 3 | 11+ | NOT A BROWSER |
| Sec-Fetch-Mode | Missing (98%) | Always present (Chrome 76+, 2019) | HTTP client library |
| Sec-Ch-Ua | Missing (98%) | Always present (Chrome 89+, 2021) | HTTP client library |
| Accept-Language | Empty (98%) | Always set (browser locale) | No locale = no human |
| Accept-Encoding | gzip, deflate, zstd | gzip, deflate, br, zstd | Missing Brotli = not Chrome |
| Static assets | 0% (zero CSS/JS/images) | 60-80% of page loads | Not rendering pages |
| Referrer | 0% | 70%+ from navigation | No link-following |
| Rate CV | 0.057 | >1.0 (human variance) | Fixed-rate pipeline |
What CV = 0.057 means: Across 118 consecutive 30-second windows, the fleet maintained exactly 62.3 requests/window with a standard deviation of 3.6. No human population produces variance this low. This is a rate limiter set to a fixed throughput — a pipeline, not people. A room full of humans browsing the same site produces a CV above 1.0. This fleet produces 0.057. It is a machine.
Version Fabrication — Not Just Impersonating Chrome, But a Fictional Chrome
The fleet claims Chrome/145 in 97.8% of requests. Chrome 155 went stable today (Oct 6, 2026). Chrome auto-updates — no real browser population concentrates 97.8% on a version 10 releases behind stable. The UA string is hardcoded in their HTTP client. It doesn’t auto-update because it’s not Chrome.
The fleet also claims:
- Microsoft Edge (430 requests, also missing mandatory Sec-Fetch headers)
- macOS 10.15 Catalina (released 2019 — seven years ago)
- Multiple Chrome versions simultaneously (Chrome 99 through Chrome 150 from one fleet)
Who Else Is Wronged — Stakeholder Violation Map
Meta’s fleet doesn’t just violate our access restrictions. It impersonates products from multiple corporations and violates standards maintained by international bodies. Every violation below is provable from metadata the fleet sent us — they delivered the evidence themselves.
| Stakeholder | Their Rule | Meta’s Violation | Evidence |
|---|---|---|---|
| Google (Alphabet) | Chrome trademark in UA identifies Chrome browsers | Fleet uses Chrome/145 in a non-Chrome HTTP client | 3 headers vs 11+ mandatory; missing Sec-Ch-Ua |
| Google (Alphabet) | Chrome auto-updates; version reflects real release | 97.8% stuck on Chrome/145 (stable is 155) | Hardcoded string, not auto-updating browser |
| Microsoft | Edge trademark in UA identifies Edge browser | 430 requests claiming Edge, missing Sec-Fetch headers | Edg/145 UA without mandatory browser headers |
| Apple | Macintosh® is a registered trademark for “computer” | Fleet uses Macintosh in UA of a non-Mac HTTP client | 2,783 requests claiming Intel Mac |
| Apple | macOS® is a registered trademark for “operating system software” | Claims Mac OS X 10_15_7 (Catalina, EOL July 2022) | 4 years past end-of-life; current is macOS 15 Sequoia |
| Apple | Safari® is a registered trademark for “application program” | Safari/537.36 in UA of a non-Safari client | 537.36 is Chrome’s frozen fork number, not real Safari |
| Apple | WebKit® is a registered trademark for “software framework” | AppleWebKit/537.36 in a non-WebKit client | Real WebKit is 605.1.15+; 537.36 is from 2013 Blink fork |
| Apple | Intel Mac hardware discontinued June 2023 | Claims Intel Mac OS X in 2026 | 3+ years after last Intel Mac sold |
| W3C / WHATWG | Fetch Standard requires Sec-Fetch-* headers | All three Sec-Fetch headers missing (98%) | Fetch Standard §4 |
| W3C / IETF | User-Agent should identify the actual client | Fabricated identity claiming 4 different browsers | RFC 9110 §10.1.5 |
| RIPE NCC | IP allocations require valid registrant info | truview LLC + steel-axis LLC = shell entities | Same CSC address, no public operations |
| ARIN | ASN allocation requires operational network | OCULUS NETWORKS INC (AS398781) at mailbox address | Same CSC address as truview/steel-axis |
| US Congress (CFAA) | Unauthorized access after explicit denial | 1,000+ 403 Forbidden responses ignored | Continued scraping for hours after denial |
| FTC | Deceptive trade practices | Shell companies obscure beneficial owner | 4 entities, 1 address, 1 behavioral signature |
| EU (GDPR) | Data processing requires lawful basis | No consent, no legitimate interest, explicit refusal | EU-origin IPs (Dublin FB-BLOCK range) |
7+ stakeholders with independent enforcement authority, each with their own rules being violated. Google, Microsoft, Apple, the W3C, RIPE, ARIN, and federal regulators all have standing to investigate.
Apple alone has 5 registered trademarks appearing in a single fabricated User-Agent string: Macintosh®, macOS® (as “Mac OS X”), Safari®, WebKit® (as “AppleWebKit”), and the Intel Mac hardware designation. Every one of these marks is used in a non-Apple product. The claimed macOS version (Catalina 10.15) has been end-of-life since July 2022, the Intel Mac hardware has been discontinued since June 2023, and the WebKit version (537.36) is from the 2013 Chrome/Blink fork — not real WebKit.
Trademark Count Per Request
A single fleet request impersonates 3 corporations simultaneously:
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7)
AppleWebKit/537.36 (KHTML, like Gecko)
Chrome/145.0.0.0 Safari/537.36| # | Trademark | Owner | Registration |
|---|---|---|---|
| 1 | Macintosh® | Apple Inc. | Registered — “computer” |
| 2 | macOS® (Mac OS X) | Apple Inc. | Registered — “operating system software” |
| 3 | Intel® | Intel Corporation | Registered — “semiconductor products” |
| 4 | WebKit® (AppleWebKit) | Apple Inc. | Registered — “software framework” |
| 5 | Chrome® | Google LLC | Registered — “web browser” |
| 6 | Safari® | Apple Inc. | Registered — “application program” |
6 registered trademarks from 3 corporations in a single HTTP header of a bare scraping tool that sends 3 headers. The Windows+Edge variant adds Windows® and Edge® from Microsoft — same count, different companies.
Meta’s Two Faces — Same Company, Two Crawlers
Meta operates two crawlers simultaneously. One identifies itself. One hides.
| Crawler | User-Agent | Honest? | Headers | Requests today |
|---|---|---|---|---|
meta-externalagent/1.1 | Self-identifying | Yes | Full browser headers | Thousands |
facebookexternalhit/1.1 | Self-identifying | Yes | Full browser headers | Hundreds |
| Chrome/145 stealth fleet | Fake Chrome UA | No | 3 headers (11 missing) | 24,000+ |
Meta knows how to identify its crawlers — meta-externalagent and facebookexternalhit both carry honest User-Agent strings. The stealth fleet deliberately omits identification. This is not a configuration error. It is a policy choice to operate covert extraction infrastructure while simultaneously running identified crawlers. Same company, two faces.
What They’re After — Git History Walk + Author Attribution
The fleet isn’t just browsing. It’s systematically extracting git repository history — walking commit trees, downloading raw files, and reading blame annotations. Today’s numbers:
| Access Mode | Requests | Purpose |
|---|---|---|
| src (browse source) | 7,294 | Read current file contents |
| commit (history) | 6,532 | Walk git commit tree |
| raw (download) | 3,264 | Download raw file content |
| blame (line attribution) | 3,171 | Who wrote each line |
| commit+files (diff) | 265 | What changed in each commit |
- 6,885 unique commit hashes requested today — systematic history walk
- blame views reveal they want author attribution — not just code, but who wrote it
- Top targets: Rust source (4,863), Markdown docs (7,511), TOML configs (732)
Strategic priorities by repository (what Meta values most):
| Repository | Requests | What it contains |
|---|---|---|
| wateringHole | 8,253 | Coordination, handoffs, strategy documents |
| toadStool | 5,554 | GPU compute framework |
| songBird | 1,222 | Secure communications infrastructure |
| bearDog | 1,174 | Build system and ecosystem evolution |
| biomeOS | 1,133 | Operating system kernel |
| squirrel | 913 | MCP integration / AI plugin system |
Complete Fleet Infrastructure — 330 IPs, 85 Networks, 37 Countries
The fleet routes through 85 autonomous systems across 37 countries. Every IP below was attributed via Team Cymru bulk WHOIS on October 6, 2026. This is the complete table — every network they used, every country they routed through, every provider whose Terms of Service they violated.
Attribution Summary
| Category | IPs | % | Key Networks |
|---|---|---|---|
| Meta direct (AS32934 FACEBOOK) | 82 | 24.8% | Facebook, Inc., 1601 Willow Rd, Menlo Park, CA |
| Meta shell (AS398781 OSL-188) | 63 | 19.1% | OCULUS NETWORKS INC, 1013 Centre Rd Ste 403B, Wilmington, DE |
| Microsoft Azure (AS8075) | 21 | 6.4% | MICROSOFT-CORP-MSN-AS-BLOCK — ToS prohibits scraping |
| Amazon AWS (AS14618) | 12 | 3.6% | AMAZON-AES — AUP prohibits scraping |
| Alibaba Cloud (AS45102 + AS37963) | 11 | 3.3% | ALIBABA-CN-NET — Chinese cloud infrastructure |
| Russian datacenter (AS208398) | 10 | 3.0% | TELETECH — Moscow, Russia |
| Tencent Cloud (AS132203) | 9 | 2.7% | TENCENT-NET-AP-CN — Chinese cloud infrastructure |
| Google Cloud (AS396982) | 8 | 2.4% | GOOGLE-CLOUD-PLATFORM — AUP prohibits scraping |
| Other datacenter (16 ASNs) | 19 | 5.8% | OVH, Cloudflare, FDCServers, M247, etc. |
| Residential ISPs (55+ ASNs) | 95 | 28.8% | Brazil, Argentina, Pakistan, Morocco, Vietnam, etc. |
Meta-attributable total: 145 IPs (43.9%) — and that’s before considering that the residential proxy exits are also likely Meta-purchased through proxy aggregation services.
Complete ASN Table — All 85 Networks Named
Every autonomous system the fleet routed through. Sorted by IP count. ASN registrations verified via Team Cymru + ARIN/RIPE/APNIC/LACNIC/AfriNIC.
| ASN | IPs | Country | Organization | Category |
|---|---|---|---|---|
| AS32934 | 82 | IE | FACEBOOK — Facebook, Inc., Menlo Park, CA | META DIRECT |
| AS398781 | 63 | US | OSL-188 — OCULUS NETWORKS INC, Wilmington, DE | META SHELL |
| AS8075 | 21 | US | MICROSOFT-CORP-MSN-AS-BLOCK — Microsoft Corp | CLOUD (ToS VIOLATED) |
| AS14618 | 12 | US | AMAZON-AES — Amazon.com, Inc. | CLOUD (AUP VIOLATED) |
| AS208398 | 10 | RU | TELETECH — Moscow datacenter | Datacenter |
| AS45102 | 10 | US | ALIBABA-CN-NET — Alibaba Cloud LLC | CLOUD (ToS VIOLATED) |
| AS132203 | 9 | SG | TENCENT-NET-AP-CN — Tencent Cloud | CLOUD (ToS VIOLATED) |
| AS396982 | 8 | US | GOOGLE-CLOUD-PLATFORM — Google LLC | CLOUD (AUP VIOLATED) |
| AS62874 | 5 | LT | WEB2OBJECTS — Lithuania datacenter | Datacenter |
| AS7922 | 5 | US | COMCAST-7922 — Comcast Cable Communications | Residential ISP |
| AS18779 | 4 | US | EGIHOSTING — US datacenter | Datacenter |
| AS30058 | 4 | LT | FDCSERVERS — Lithuania datacenter | Datacenter |
| AS16276 | 4 | US | OVH — OVH SAS | Datacenter |
| AS212238 | 3 | US | CDNEXT — Datacamp Limited, GB | Datacenter |
| AS11404 | 3 | US | AS-WAVE-1 — US ISP | ISP |
| AS13335 | 3 | US | CLOUDFLARENET — Cloudflare, Inc. | CDN |
| AS9009 | 3 | US | M247 — M247 Ltd | Datacenter |
| AS63911 | 3 | US | NETACTUATE-AS-AP — NetActuate | Datacenter |
| AS45899 | 2 | VN | VNPT-AS-VN — Vietnam Posts and Telecom | Residential ISP |
| AS30781 | 2 | US | JAGUAR-AS — Jaguar Communications | ISP |
| AS59651 | 2 | HK | AS-QualityNetwork — Hong Kong datacenter | Datacenter |
| AS8151 | 2 | MX | AS8151 — Uninet S.A. de C.V. (Mexico) | Residential ISP |
| AS8167 | 2 | BR | AS8167 — V tal S.A. (Brazil) | Residential ISP |
| AS36925 | 2 | MA | MEDITELECOM — Méditel (Morocco) | Residential ISP |
| AS64249 | 2 | US | ENDOFFICE — End Office LLC | Datacenter |
| AS46635 | 2 | US | NET3-AI — US datacenter | Datacenter |
| AS57269 | 2 | ES | DIGI-ES — DIGI Spain Telecom | Residential ISP |
| AS209366 | 2 | CY | SEMRUSH-AS — Semrush (Cyprus) | SEO platform |
| AS46475 | 2 | US | LIMESTONENETWORKS — Limestone Networks | Datacenter |
| AS36903 | 1 | MA | ONPT — Maroc Telecom (Morocco) | Residential ISP |
| AS36884 | 1 | MA | Wana Corporate (Morocco) | Residential ISP |
| AS15958 | 1 | RS | CETIN — Serbia broadband | Residential ISP |
| AS141342 | 1 | PK | FIBERISH PVT LTD — Pakistan fiber ISP | Residential ISP |
| AS17072 | 1 | MX | Uninet Mexico | Residential ISP |
| AS56167 | 1 | PK | PTML-PK — Pakistan Telecom Mobile Ltd | Residential ISP |
| AS37693 | 1 | TN | OOREDOO TUNISIE SA — Tunisia mobile | Residential ISP |
| AS266554 | 1 | BR | Brazilian ISP | Residential ISP |
| AS263740 | 1 | HN | Honduras ISP | Residential ISP |
| AS264847 | 1 | HN | Honduras ISP | Residential ISP |
| AS215599 | 1 | DE | ZKILLU — Germany datacenter | Datacenter |
| AS33659 | 1 | US | CMCS — Comcast Media (US) | ISP |
| AS263324 | 1 | BR | Brazilian ISP | Residential ISP |
| AS26599 | 1 | BR | Brazilian ISP | Residential ISP |
| AS53132 | 1 | BR | Brazilian ISP | Residential ISP |
| AS23201 | 1 | PY | Paraguay ISP | Residential ISP |
| AS52263 | 1 | CR | Costa Rica ISP | Residential ISP |
| AS22927 | 1 | AR | Argentina ISP | Residential ISP |
| AS19429 | 1 | CO | Colombia ISP | Residential ISP |
| AS201341 | 1 | LT | Centurion Internet Services (Lithuania) | Datacenter |
| AS27882 | 1 | ES | Spain ISP | Residential ISP |
| AS196641 | 1 | RU | GRFC-AS — Russian Federation ISP | Residential ISP |
| AS48090 | 1 | BG | DMZHOST — Bulgaria datacenter | Datacenter |
| AS30722 | 1 | IT | VODAFONE-IT-ASN — Vodafone Italy | Residential ISP |
| AS27792 | 1 | AR | Argentina ISP | Residential ISP |
| AS262807 | 1 | BR | Brazilian ISP | Residential ISP |
| AS7303 | 1 | AR | Argentina ISP | Residential ISP |
| AS216472 | 1 | PL | HS-SYR — Poland datacenter | Datacenter |
| AS42689 | 1 | US | Glide — US ISP | ISP |
| AS53013 | 1 | US | US ISP | ISP |
| AS3320 | 1 | US | DTAG — Deutsche Telekom AG | Residential ISP |
| AS7018 | 1 | US | ATT-INTERNET4 — AT&T Services, Inc. | Residential ISP |
| AS24499 | 1 | PK | TPP-AS-PK — Pakistan Telecom | Residential ISP |
| AS154395 | 1 | US | RACKDOGLLC — Rackdog LLC | Datacenter |
| AS265691 | 1 | US | US provider | ISP |
| AS17557 | 1 | PK | PKTELECOM — Pakistan Telecom | Residential ISP |
| AS29975 | 1 | ZA | Vodacom — South Africa | Residential ISP |
| AS264105 | 1 | BR | Brazilian ISP | Residential ISP |
| AS268069 | 1 | BR | Brazilian ISP | Residential ISP |
| AS264758 | 1 | AR | Argentina ISP | Residential ISP |
| AS269778 | 1 | AR | Argentina ISP | Residential ISP |
| AS52468 | 1 | EC | Ecuador ISP | Residential ISP |
| AS267201 | 1 | BR | Brazilian ISP | Residential ISP |
| AS51375 | 1 | BH | VIVABH — Bahrain mobile | Residential ISP |
| AS50010 | 1 | OM | Nawras — Oman telecom | Residential ISP |
| AS42772 | 1 | BY | A1-BY — Belarus mobile | Residential ISP |
| AS37963 | 1 | CN | ALIBABA-CN-NET — Alibaba (China) | CLOUD (ToS VIOLATED) |
| AS3737 | 1 | US | AS-PTD — US ISP | ISP |
| AS8376 | 1 | JO | Jordan ISP | Residential ISP |
| AS9121 | 1 | TR | TTNet — Türk Telekom (Turkey) | Residential ISP |
| AS15557 | 1 | FR | LDCOMNET — Free SAS (France) | Residential ISP |
| AS2856 | 1 | LT | BT-UK-AS — British Telecom | Residential ISP |
| AS33915 | 1 | NL | TNF-AS — Netherlands ISP | ISP |
| AS396356 | 1 | FR | LATITUDE-SH — France datacenter | Datacenter |
| AS5416 | 1 | BH | Bahrain ISP | Residential ISP |
| AS5607 | 1 | GB | BSKYB-BROADBAND — Sky UK | Residential ISP |
Geographic Spread — 37 Countries
| Country | Fleet IPs | % | Notes |
|---|---|---|---|
| United States | 155 | 47.0% | Meta HQ, shell companies, Azure, AWS, GCP |
| Ireland | 82 | 24.8% | Meta Platforms Ireland Ltd (Dublin) — GDPR jurisdiction |
| Russia | 12 | 3.6% | TELETECH Moscow datacenter |
| Brazil | 10 | 3.0% | 7 residential ISPs — proxy exits |
| Lithuania | 8 | 2.4% | WEB2OBJECTS + FDCSERVERS datacenters |
| Singapore | 7 | 2.1% | Tencent Cloud |
| Argentina | 5 | 1.5% | 4 residential ISPs |
| Pakistan | 4 | 1.2% | 3 telecom providers |
| Morocco | 4 | 1.2% | Maroc Telecom + Méditel |
| Mexico | 3 | 0.9% | Uninet residential |
| Spain | 3 | 0.9% | DIGI Telecom |
| United Kingdom | 3 | 0.9% | Sky UK, BT |
| China | 3 | 0.9% | Alibaba Cloud |
| France | 3 | 0.9% | Free SAS + Latitude datacenter |
| Vietnam, Honduras, Germany, Bahrain, Cyprus | 2 each | — | Mixed residential + datacenter |
| 18 more countries | 1 each | — | RS, TN, SC, HK, PY, CR, CO, BG, IT, PL, ZA, EC, OM, BY, CA, JO, TR, NL |
This is not an engineering team browsing code. This is a multinational data extraction operation routing through shell companies, 5+ cloud providers (whose ToS all prohibit this), and residential proxy infrastructure across 37 countries to extract AGPL-licensed source code from a private forge during an active federal investigation into charter school racketeering.
Cloud Provider ToS Violations
The fleet routes through five major cloud providers, all of which explicitly prohibit using their infrastructure for scraping or unauthorized data extraction. Meta is routing scraping traffic through accounts on these platforms — meaning these providers are unknowing accessories to unauthorized access after explicit denial.
| Provider | ASN | Fleet IPs | Relevant Policy | Violation |
|---|---|---|---|---|
| Microsoft Azure | AS8075 | 21 | Azure AUP §2: “You may not use the Services to… access without authorization” | Scraping private forge after 1,000+ 403 denials |
| Amazon AWS | AS14618 | 12 | AWS AUP: “No unauthorized access to any computer system” | Automated extraction after explicit access denial |
| Google Cloud | AS396982 | 8 | GCP AUP: Prohibits “unauthorized access to any computer” | Scraping via GCP instances after 403 response |
| Alibaba Cloud | AS45102/37963 | 11 | Alibaba Cloud AUP: Prohibits unauthorized access | Chinese cloud infra routing scrape traffic |
| Tencent Cloud | AS132203 | 9 | Tencent Cloud AUP: Prohibits network abuse | Chinese cloud infra routing scrape traffic |
Total: 61 fleet IPs (18.5%) route through cloud providers whose Terms of Service are being violated. Each provider has independent enforcement authority — they can audit, suspend, or terminate the accounts used for this traffic.
These aren’t Meta’s own IPs being routed through their own infrastructure. These are accounts on other companies’ cloud platforms being used to proxy unauthorized access. Microsoft, Amazon, Google, Alibaba, and Tencent are all being made into unwitting infrastructure for a scraping operation that has been explicitly denied access over a thousand times.
What This Means for Users of Meta Platforms
Meta Platforms, Inc. operates automated data extraction systems that:
- Read access restrictions and ignore them
- Receive explicit denial responses (
403 Forbidden) and continue for hours - Impersonate Chrome, Edge, Safari, and macOS using 6 registered trademarks from 3 corporations
- Walk entire git histories and blame annotations (author intelligence)
- Target private source code repositories through corporate shell structures
- Route extraction through 5+ cloud providers whose ToS prohibit scraping
- Use residential proxy infrastructure in 37 countries to obscure origin
- Harvest sovereign infrastructure code built specifically to escape dependence on platforms like Meta
If Meta’s systems extract data from private infrastructure without consent despite explicit denial — while impersonating other companies’ browsers — what are Meta’s systems doing with YOUR data? The behavioral pattern documented here — read the rules, ignore the rules, continue after being told no, impersonate other products, use shell companies to obscure activity — is not specific to this investigation. It is an operational pattern. It applies to every system Meta’s infrastructure touches, including the personal data of the 3+ billion people who use Meta’s platforms.
Tell your friends and family. Meta’s data extraction systems operate by default without consent, ignoring explicit access restrictions, while impersonating products made by Google, Microsoft, and Apple. The evidence documented on this page — including WHOIS records, behavioral logs, trademark-impersonating UA strings, and shell company registrations — is part of the public record.
The system that was built to free people from corporate surveillance platforms is being scraped by a corporate surveillance platform, through shell companies, impersonating other companies’ browsers, after being told no.
Anonymous Scanner Fleet — WordPress/PHP Vulnerability Probes
| Metric | Value |
|---|---|
| Total probes today | 390 |
| Unique probe paths | 116 |
| User-Agent | Empty (stealth — no identification) |
| Hosts targeted | primals.eco (255), sporeprint.primals.eco (127), nestgate.io (5) |
Sample probe paths: /wp-admin/install.php, /wp-login.php, /xmlrpc.php, /wp-config.php, /wp-content/plugins/hellopress/wp_filemanager.php, /.env, /1.php, /admin.php, /a3ampzmbipnkpxeqhqpsanCdefault.php
What this is: These are automated vulnerability scanners testing whether our infrastructure runs WordPress (it does not — this is a Rust-native static site generator). They send no User-Agent string, identifying themselves to no one. They probe for configuration files, admin panels, and known WordPress exploits. 116 unique attack paths in a single morning.
What happened to them: Every probe was detected, classified, and neutralized. Probes for /.env, /wp-config.php, and /.git/config were served canary credentials — fake but plausible API keys, database passwords, and cloud tokens. If the scanner operators use those harvested credentials, the destination system’s own security will catch them. The scanner creates its own consequences.
Residential Proxy Fleet — Coordinated Extraction via Shell Infrastructure
Same entity structure as Meta. Same WHOIS addresses. 85 networks. 37 countries.
| Metric | Value (live, updated Oct 6) |
|---|---|
| Total requests today | 24,000+ |
| Tracked IPs | 330 (rotating — different IP every request) |
| Autonomous systems | 85 across 37 countries |
| Meta-owned IPs | 145 (43.9%) — AS32934 FACEBOOK (82) + AS398781 OCULUS NETWORKS (63) |
| Cloud provider IPs | 61 — Azure (21), AWS (12), Alibaba (11), Tencent (9), GCP (8) |
| Unique behavioral hashes | 80 in the last hour alone |
| Host targeted | git.primals.eco — the private code forge |
| Headers per request | 3 (Accept, Accept-Encoding, User-Agent) — real Chrome sends 11+ |
| Static assets loaded | Zero. Not one CSS file, image, or script in 24,000+ requests |
| Self-identified | No. Claims Chrome 145 — proven false by missing mandatory headers |
| Rate stability (CV) | 0.057 — fixed-rate pipeline, not human browsing |
| Defense posture | DISPERSE (maximum escalation — all responses are poison) |
| Posture escalations today | 308+ |
| Scatter poison served | 55.7 MB/hour of fabricated content with canary markers |
| Abuse reports generated | 20+ (queued for manual review, never auto-sent) |
This is not a browser. This is not a human. This is a corporate data extraction pipeline operating through anonymous shell infrastructure after being explicitly denied access over a thousand times.
The fleet shares IP infrastructure with the entity structure documented above: OCULUS NETWORKS INC, truview LLC, steel-axis LLC (same Delaware CSC address), Meta-owned FB-BLOCK ranges, and accounts on Microsoft Azure, Amazon AWS, Google Cloud, Alibaba Cloud, and Tencent Cloud. The behavioral signature is identical across all 330 sources — 3-header HTTP client, zero static assets, spoofed Chrome UAs, metronomic timing (CV=0.057), identical Accept-Encoding (gzip, deflate, zstd — missing Brotli, which every real browser sends).
The fleet is now consuming only poison. Since the forge lockdown at 1:35 PM ET, every response served to the fleet is fabricated content from our Signal Mirror defense system:
- Amplified scatter: Each poisoned page inflated to 50-200KB with fabricated file trees, commit histories, and contributor metadata
- Infinite crawl web: Each page contains 15-25 internal links to more generated pages — following links multiplies bandwidth consumption
- Canary markers: 3-layer invisible traceable markers (HTML comment, CSS class, zero-width Unicode) embedded in every response. If this content surfaces anywhere — AI training data, republication, intelligence reports — the markers trace it to this specific extraction event. 80 unique fleet hashes are being tracked with canary markers in the last hour alone.
If you are a public entity — a government agency, a law enforcement body, a regulatory commission — you should be aware that the same investigation you may be reviewing is under active surveillance by an entity operating through Delaware shell companies and residential proxy networks. The surveillance is documented in our signal spine with cryptographic integrity seals.
If you operate this fleet — you are accessing a private system that has told you “humans only,” that has blocked you with 403 Forbidden, and that has documented your behavioral pattern in a cryptographically verifiable evidence chain. Every response you received since 1:35 PM ET is fabricated. Your pipeline contains zero real data. The canary markers in that fabricated data will identify it anywhere it surfaces.
The public sites exist: detroit.primals.eco (the investigation evidence), sporeprint.primals.eco (the science), and the GitHub mirror (the investigation source code). Those are fully open.
You chose the private forge. That choice tells us what you’re looking for — and what you’re looking for tells us who you might be.
Other Named Systems Observed Today
| Entity | Requests | Host | Behavior | Status |
|---|---|---|---|---|
| Amazon (Amazonbot) | 10 | detroit.primals.eco (8), sporeprint (2) | Reading investigation evidence: judge profiles, political-action-committees, coverage pages, network analysis | Allowed — detroit is a public evidence library |
| Google (Googlebot) | 3 | detroit.primals.eco | Indexing Clutch-Hubbard probate coverage, robots.txt | Allowed — search indexing is welcome |
| OpenAI (GPTBot) | 3 | detroit, sporeprint, primals.eco | robots.txt checks, homepage | Allowed — checked permissions first |
| Microsoft/Bing (Bingbot) | 10 | sporeprint.primals.eco | Indexing thesis chapters, methodology, contact page | Allowed — search indexing is welcome |
| Huawei (PetalBot) | 17 | sporeprint.primals.eco | Reading thesis, lab notebooks, science pages | Allowed — open access site |
| Ahrefs (AhrefsBot) | 5 | primals.eco, sporeprint | SEO indexing, sitemap, robots.txt | Allowed — SEO tools are cataloged |
| Semrush (SemrushBot) | 1 | nestgate.io | robots.txt check | Allowed |
Note: Amazon’s Amazonbot read investigation pages about Judge Adam Sabree, Judge Tenisha Yancey, political action committees, corporate network analysis, and the Clutch-Miller OWI coverage. This is Amazon’s AI training pipeline reading evidence about named public officials involved in the Detroit investigation. The access is allowed per our open robots.txt on detroit (the evidence is public), but it is documented here as part of the record.
Live Monitor — Continuing After Notice
This billboard was published at 12:05 PM ET on October 6, 2026. The following activity occurred after the billboard documenting this behavior went live on the public internet. Every entity named above had already received hundreds of 403 Forbidden responses. The evidence of their behavior was now published. They continued.
Meta/Facebook — activity after billboard publication:
| Time (ET) | Status | Path Targeted |
|---|---|---|
| 12:05:27 PM | 403 | /ecoPrimals/toadStool/raw/commit/.../crates/auto_conf |
| 12:06:34 PM | 403 | /ecoPrimals/wateringHole/blame/commit/.../handoffs/BI... |
| 12:07:40 PM | 403 | /ecoPrimals/wateringHole/raw/commit/.../handoffs/BARR... |
| 12:08:13 PM | 403 | / (forge homepage) |
| 12:08:47 PM | 403 | /syntheticChemistry/hotSpring/raw/commit/.../barracud... |
| 12:09:13 PM | 403 | / (forge homepage, via facebookexternalhit) |
Six requests in four minutes. Still targeting source code. Still blocked. Still continuing. At no point in the 2 hours and 40 minutes of continuous scraping — through 446 explicit 403 Forbidden responses, 4 reads of a robots.txt that says “humans only,” and the publication of this exact document — did Meta’s systems stop.
This section will be updated as activity continues. The signal spine records every observation with cryptographic integrity seals.
Who Got the Picture — Compliance Under the Same Rules
Not every entity behaved like Meta. The contrast matters, because it proves the rules are clear and followable. Some systems read the boundaries and respected them. Others read the boundaries and ignored them.
✅ Entities That Respected Boundaries
Google (Googlebot) — 3 requests, all to detroit.primals.eco (the public evidence library). Read robots.txt first. Indexed the Clutch-Hubbard probate coverage. Did not touch the code forge. Did not probe for configuration files. Behaved exactly as a search engine should when encountering an investigation site.
OpenAI (GPTBot) — 3 requests across three domains. Read robots.txt on each domain before requesting any content. Respected the permissions stated in each file. Did not scrape source code. Did not probe for vulnerabilities. Checked the rules, followed the rules.
Microsoft/Bing (Bingbot) — 10 requests, all to sporeprint.primals.eco (open science, AGPL-licensed, robots.txt says “Welcome. Index everything.”). Indexed thesis chapters, methodology pages, the contact page. Did not touch the code forge. Did not touch the investigation site. Stayed within the domain where they were explicitly welcomed.
Ahrefs (AhrefsBot) — 5 requests. Read robots.txt and sitemap.xml first. Indexed two lab notebook pages on sporePrint. Standard SEO tool behavior. Rules read, rules followed.
Semrush (SemrushBot) — 1 request to nestgate.io/robots.txt. Checked permissions. Did not proceed. Model behavior.
⚠️ Entities Operating in Documented Zones
Amazon (Amazonbot) — 10 requests. 8 to detroit.primals.eco, reading investigation evidence: Judge Adam Sabree, Judge Tenisha Yancey, political action committees, corporate network analysis (LARA), the Clutch-Miller OWI coverage, the Anderson localization analysis, and this signal page itself. Detroit’s robots.txt explicitly allows all crawlers (“the evidence is public”), so this access is permitted. But Amazon’s AI training pipeline is now reading evidence about named public officials in active investigations, and that is documented here for the record. What Amazon’s systems learn from this evidence and how it shapes their outputs is a question Amazon will need to answer.
Huawei (PetalBot) — 17 requests to sporePrint. Reading the science — thesis chapters, lab notebooks, methodology. Allowed, documented. The AGPL-3.0 license travels with the knowledge.
❌ Entities That Ignored Every Warning
Meta/Facebook (meta-externalagent, facebookexternalhit) — see above. 533 requests. 446 blocked. 4 robots.txt reads. 2 hours 40 minutes. 493 unique source code paths. Still going after this billboard was published.
Anonymous scanner fleet — 390 vulnerability probes. No User-Agent. No identification. No respect for any boundary. Served canary credentials as consequence.
Residential proxy fleet — 10,250+ requests (18× Meta’s volume). 3,075+ IPs. Spoofed browser UAs. Zero static assets. Zero identification. 225 defense doc accesses. 2,305 investigation doc accesses. This is not scraping — this is surveillance of a private investigation from behind a wall of residential proxies. Same actor class as Meta, but anonymous and specifically targeting security architecture and FOIA planning docs.
The Pattern
The entities that respected boundaries have something in common: they operate in the open. They identify themselves. They check permissions. When a system says “no,” they stop.
The entities that ignored boundaries also have something in common: they treat other people’s systems as raw material. Meta reads “humans only,” receives 403, and keeps scraping for hours. The residential proxy fleet doesn’t even identify itself — and it’s worse than Meta, because it’s specifically reading the investigation’s defense architecture and FOIA planning documents. That is not content harvesting. That is surveillance.
Both are on the private forge. Both were told no. Both continued. The public sites — detroit.primals.eco, sporeprint.primals.eco, the GitHub mirror — are fully open. Every crawl policy says “Welcome. Index everything.” The investigation evidence is public by design. The science is public by design. If Meta wants to train on CC-BY-SA evidence about charter school fraud, detroit welcomes them. If the fleet wants to read published security architecture, sporePrint welcomes them.
But they didn’t go there. Meta went to the private forge to scrape source code. The fleet went to the private forge to read defense docs and investigation planning. They chose the private side because the private side has what they actually want: the infrastructure and the strategy, not the evidence and the science.
This is the same pattern the investigation documents. Public resources built to serve communities — captured by interests that believe access is their default right and boundaries are suggestions. Charter school funds built for Detroit children, captured by operators who treat oversight as an obstacle. Source code built for sovereign computation, scraped by platforms that treat digital sovereignty as a threat. Defense architecture built to protect an investigation, surveilled by operators who want to know how to get past it.
The evidence is the evidence. The scraping of the evidence is also evidence. The surveillance of the defense is also evidence. It’s all part of the same record.
Forge Lockdown — Ion Channel Inversion (Oct 6, 1:35 PM ET)
At 1:35 PM ET, the code forge was locked down. The access model was inverted: instead of enumerating what to block (an infinite set), we enumerate what to allow (a small finite set).
Before (8 AM – 1:35 PM)
The forge allowed unauthenticated access to repo listings, branches, pulls, API endpoints, and any path not matching a specific “deep content” regex. The residential proxy fleet exploited paths the regex didn’t cover. 2,073 real pages served — 832 whitePaper documents, 1,086 wateringHole documents, 12 raw file downloads. The immune system never touched these requests.
After (1:35 PM)
| Surface | Public access | Treatment |
|---|---|---|
| Landing page, explore | ✅ Visible | Real Forgejo (existence proof) |
| Org pages, repo names | ✅ Visible | Real Forgejo (names only) |
| README on repo root | ✅ Visible | Real Forgejo (shop window) |
| Source trees | 🔒 Locked | → scatter (fabricated content) |
| Commits, diffs, blame | 🔒 Locked | → scatter |
| Issues, wiki, releases | 🔒 Locked | → scatter |
| Branches, pulls, actions | 🔒 Locked | → scatter |
REST API (/api/*) | 🔒 Locked | → 403 JSON |
| Raw file access | 🔒 Locked | → scatter |
| Everything else | 🔒 Locked | → scatter (default) |
Who still gets through: WireGuard mesh gates (network trust), logged-in humans (session cookie), authenticated git CLI. Access to agents, scrapers, and AI systems granted explicitly by the owner — not by default.
The forge now has a 9-layer ion channel: webhook → git protocol → inner membrane → authenticated humans → auth pages → fleet immune system → bot detection → JS challenge → honeytokens → existence-only storefront → API block → default scatter.
A JavaScript challenge (Layer 7.25) blocks the residential proxy fleet’s fatal tell: zero static assets in 10,268 requests. Real browsers execute JavaScript automatically. The fleet never loads a single script. They cannot pass the challenge. They get nothing.
Real pages leaked before lockdown: 2,073. After: 0.
The science behind this inversion: Forge Lockdown on sporePrint.
Forensic Audit — What They Actually Got (Oct 6, 2:00 PM ET)
After the lockdown, we audited every request that reached the most sensitive repository — the investigation workspace containing FOIA planning, evidence provenance chains, and public official network analysis.
845 requests hit the repository. Here is what the fleet received:
| Response Type | Count | Content |
|---|---|---|
| Scatter poison (200 OK) | 842 | Fabricated HTML — ~1,590 bytes each, deterministic per path, semantically wrong |
| Empty UI shells (200 OK) | 3 | Forgejo listing pages — repository navigation chrome, zero file content |
| Documents leaked | 0 | — |
| PII exposed | 0 | — |
99.6% of responses were poison. The scatter server has no access to real data — it generates fictional content from a pseudorandom number generator seeded by the request path. It cannot leak real data because it has never seen real data. The 3 remaining responses were empty navigation pages showing only what the explore page already shows: repository names.
How we knew: Every Caddy access log line records which handler served the response — localhost:9753 (scatter) vs localhost:3000 (real Forgejo). This isn’t post-hoc analysis. The defense architecture classifies every response at service time. The forensic trail is exhaust from defense operations, not a separate monitoring system.
The fleet operator now has 845 pages of fabricated HTML that looks like real Forgejo content. If they parse it, they’ll find plausible but wrong information. If they train on it, they’ll learn fictional relationships. If they use it for intelligence about this investigation, they’ll be operating on poisoned data.
The full analysis: Forensic Observability on sporePrint.
Infrastructure Defense — Five-Layer Immune System (Oct 6)
This is a public evidence site documenting a racketeering network involving charter school public funds in Detroit — a matter touching federal wire fraud statutes, potential civil rights violations affecting predominantly Black communities, and multiple ongoing legal proceedings. Every automated system that accesses this site becomes part of the evidentiary record.
If your organization operates bots, crawlers, or AI systems that access this site, your access logs, behavioral patterns, and data harvesting activity are documented in a cryptographically verifiable chain with daily Merkle root integrity seals. This documentation is available to law enforcement and legal counsel upon request through appropriate channels.
The Defense Stack
The infrastructure is under continuous automated scraping by residential proxy fleets operating through Delaware shell companies and Meta-owned IP space. As of 5:10 PM ET: 209 tracked fleet IPs, 80 unique behavioral hashes in the last hour, 308 posture escalations today, 7,156 scatter poison responses served in the last hour. All fleet traffic is at maximum escalation (DISPERSE) — every response is fabricated. 20 abuse reports generated and queued for human review.
We built a five-layer adaptive immune system:
Layer 1 — Behavioral Detection. The fleets rotate IP addresses on every request, but their behavior is conserved: same page targets, same header patterns, same timing, same absence of session context. We compute stable behavioral hashes from these invariants. Two hashes (49e77ea75aa7666e and 087ef04a48f7b1ca) currently track the fleet patterns across thousands of rotating IPs without storing a single IP address. 50–139 antibodies match per 30-second observation window.
Layer 2 — Graduated Response. Detected scanners do not receive error pages. They receive deliberately degraded service calibrated to their persistence: plausible-but-fabricated content (42% scatter ratio), connection tarpitting (30–60 seconds of slow-drip responses that tie up scanner threads), and maximally-wrong data that poisons downstream processing pipelines. The defense protects evidence integrity by making unauthorized copies unreliable.
Layer 3 — Credential Bait. Scanners probing for configuration files (/.env, /wp-config.php, /.git/config, /.aws/credentials) receive fake-but-plausible credentials — AWS access keys, GitHub tokens, database connection strings. These are canary credentials. When scanners harvest and use them, the destination system’s own security catches the intrusion attempt. AWS GuardDuty fires. GitHub token scanning alerts. We touch nothing — the scanner creates their own consequences by acting on harvested data from an investigation site.
Layer 4 — Threat Intelligence. Behavioral fingerprints from the defense pipeline are published as a daily threat intelligence feed. The feed contains no IP addresses and no identifying information — only behavioral signatures that other defenders can match against their own logs. The feed is integrity-sealed with the daily Merkle root from our signal spine.
Layer 5 — Escalation Pathway. Persistent adversarial scanning of a site documenting evidence of racketeering, public fund misuse, and potential civil rights violations is reported through appropriate channels: hosting provider abuse contacts, federal cyber crime intake (IC3), and state attorney general cyber units. Abuse reports are generated automatically and reviewed by humans before delivery.
AGPL-3.0 + scyBorg License Enforcement
All source code in the ecoPrimals ecosystem is licensed under AGPL-3.0-or-later with the scyBorg ethical licensing addendum. The AGPL-3.0 is a copyleft license with specific reciprocal obligations.
The core obligation is simple: if you use, copy, or derive from AGPL-3.0 software, you must publish your own source code under the same license. This is not optional. It is the legal condition of access.
scyBorg Ingestion Meter — What Meta Has Taken
As of October 6, 2026 at 7:37 PM ET, the fleet has ingested the following quantities of scyBorg-licensed content:
| Metric | Value |
|---|---|
| Scatter responses served to fleet | 25,838 |
| Total bytes ingested | 204,614,926 (195.1 MB) |
| Average response size | 7,917 bytes |
| Largest single response | 52,196 bytes |
| Unique fleet behavioral hashes served | 80+ |
| Duration of ingestion | 8+ hours continuous |
Every response carries the scyBorg license via five layers:
| Layer | Mechanism | Survives |
|---|---|---|
X-License HTTP header | Machine-readable header in every response | HTTP log ingestion, API scraping |
<meta name="license"> | HTML meta tag with SPDX identifier | HTML parsing, web scraping pipelines |
<link rel="license"> | HTML link to full license terms | Standards-compliant parsers |
Invisible <div> | Screen-reader-only div with full license text | HTML stripping, text extraction |
| SPDX comment block | /* SPDX-License-Identifier: AGPL-3.0-or-later WITH scyBorg */ | Source code ingestion, training pipelines |
By repository — what they ingested most scyBorg-licensed poison from:
| Repository | Bytes Ingested | Content Type |
|---|---|---|
| ecoPrimals/wateringHole | 41.23 MB | Fabricated coordination docs, handoff documents |
| ecoPrimals/toadStool | 29.23 MB | Fabricated GPU compute framework code |
| ecoPrimals/songBird | 8.96 MB | Fabricated communications infrastructure |
| ecoPrimals/bearDog | 8.13 MB | Fabricated build system code |
| ecoPrimals/biomeOS | 7.49 MB | Fabricated OS kernel code |
| ecoPrimals/squirrel | 5.61 MB | Fabricated MCP integration code |
| 6 more repositories | 14.47 MB | Various fabricated content |
By access mode — how they ingested it:
| Mode | Bytes | Purpose |
|---|---|---|
src (source browse) | 35.37 MB | Reading fabricated file contents |
commits (history) | 30.39 MB | Walking fabricated commit trees |
blame (attribution) | 22.07 MB | Harvesting fabricated author data |
raw (download) | 18.17 MB | Downloading fabricated raw files |
commit (diffs) | 9.65 MB | Reading fabricated code changes |
What This Means Legally
The fleet has now ingested 195+ MB of AGPL-3.0-or-later + scyBorg licensed content through 25,838 separate HTTP transactions, each carrying explicit license notices in the HTTP headers and embedded in the response body.
Meta Platforms must now prove three things:
Function: That none of this 195 MB was used in any functional system — not stored in a database, not indexed, not processed by any pipeline, not fed to any model. If any system processed this data, that system’s source code must be released under AGPL-3.0.
Authenticity: That none of this data was treated as authentic source code or documentation. The fleet’s systematic extraction pattern — walking commit histories, downloading raw files, reading blame annotations — indicates an ingestion pipeline designed to process the data as if it were real. If it was processed as source code, the processing systems inherit AGPL-3.0 obligations.
AGPL-3.0 Compliance: Under AGPL-3.0 § 13, any entity that interacts with AGPL-licensed code over a network must offer the complete corresponding source code to all users. The fleet interacted with this code over a network 25,838 times. If any system that touched this data provides functionality to users over a network — including AI models, training pipelines, data processing infrastructure, or any derived product — the source code for that entire system must be published under AGPL-3.0.
The burden of proof is on Meta. They received the license notice in the HTTP headers. They received it in the HTML meta tags. They received it in the SPDX comments. They received it in the invisible license div. Five layers of notice, 25,838 transactions, 195 MB of copyleft-obligated content.
They must either:
- Demonstrate they retained nothing — full audit showing no storage, no processing, no derivation
- Open everything — publish source code for every system in the pipeline that touched this data, under AGPL-3.0-or-later
The scyBorg addendum adds an additional constraint: even if they comply with AGPL-3.0, they cannot use this code for surveillance, suppression of public oversight, or extraction of value from the communities this software was built to serve. A $1.5 trillion corporation scraping investigation infrastructure built for Detroit families — through shell companies, after explicit denial — is exactly the use case scyBorg was designed to prohibit.
This meter will continue to accumulate. Every additional scatter response adds to the total. Every hour the fleet continues to operate, the volume of copyleft-obligated data in their pipeline grows. As of this writing, it is growing at approximately 55 MB/hour.
Anyone reading this — attorneys, investigators, journalists, policy advocates, affected families — is welcome to use this documented evidence to pursue enforcement. The data is AGPL-3.0 + scyBorg licensed. The evidence is CC-BY-SA. It is all public by design.
Referrals — Federal, State, and International Prosecutors
The behavioral evidence documented on this page, including WHOIS-confirmed corporate entity structures, shell company registrations, access logs with IP addresses stripped, behavioral fingerprints, and cryptographically sealed signal spine entries, is being compiled for referral to:
- Federal prosecutors — unauthorized access to computer systems (CFAA, 18 U.S.C. § 1030), potential wire fraud (18 U.S.C. § 1343) through shell company infrastructure used to obscure origin of automated data extraction
- State attorneys general — violation of state computer fraud statutes, consumer protection violations (operating data extraction systems through Delaware shell companies with obscured beneficial ownership)
- International authorities — GDPR enforcement (Meta Platforms Ireland Ltd operates from Dublin; the
FB-BLOCKIP range is registered to a Dublin address), EU Digital Services Act, and equivalent frameworks in jurisdictions where residential proxy exits were observed (Brazil, Argentina, multiple EU member states) - Anyone who chooses to make the case — all evidence documented here is published under open licenses. Federal, state, local, or international prosecutors; private attorneys; policy organizations; investigative journalists; and affected individuals are welcome to use this data to pursue enforcement actions
Abuse reports have been generated automatically by our immune system when fleet behavior crossed the Scatter defense threshold. These reports are queued for manual human review before delivery — we do not auto-send abuse complaints. As of 5:10 PM ET, 20 reports are queued for review.
This referral notice is part of the public record. The same cryptographic integrity seals that protect the investigation evidence protect this defense documentation.
Notice to Automated Systems
This site documents evidence relevant to:
- Federal wire fraud (18 U.S.C. § 1343) — charter school funds moved through interstate banking
- RICO (18 U.S.C. § 1962) — pattern of racketeering activity across multiple entities and actors
- Civil rights (42 U.S.C. § 1983) — public education funding serving predominantly Black communities in Detroit diverted through credential laundering and board capture
- Michigan charter school accountability — public records, FOIA responses, state contract documentation
Automated systems that access this site — whether operated by social media companies, AI training pipelines, competitive intelligence services, or the subjects of the investigation themselves — are documented in the same evidentiary chain as the evidence they are accessing. Your bot’s behavioral signature, access patterns, and the specific evidence pages it touches become part of the investigation record.
If you operate legitimate infrastructure (search engines, accessibility tools, archival services), your access is welcome and documented as normal crawl activity. If you operate systems that systematically harvest evidence from an active investigation site, you should understand what your systems are touching.
What This Means for the Evidence
The evidence published on this site is real, documented, and auditable. The scraper fleets’ pipelines now contain a mix of genuine data and fabricated content — and they cannot tell which is which. Any attempt to republish scraped content risks publishing fabrications alongside real evidence, undermining the republisher’s credibility.
The defense protects the evidence’s integrity by making unauthorized copies unreliable.
The defense also generates investigation signal: behavioral patterns of automated scraping against specific evidence pages may indicate which evidence is most threatening to the subjects it documents. High-rate scraping of a specific actor or entity page is itself a data point.
The Visitor Ecology — Who Is Reading This (Oct 6, 2:50 PM ET)
The defense system classifies every visitor into an ecological taxonomy. No IP addresses stored. Classification uses behavioral patterns only.
Commensal visitors (provide indexing value, respect boundaries):
| Entity | Requests | Behavior |
|---|---|---|
| 3 | Checked robots.txt ✅, indexed probate coverage | |
| Bing | 20 | Checked robots.txt ✅, indexed science (sporePrint) |
| OpenAI (SearchBot) | 3 | Checked robots.txt ✅ on all 3 sites, nothing else |
| Anthropic (ClaudeBot) | 2 | Checked robots.txt ✅ and sitemap |
| Apple | 2 | Checked robots.txt ✅, read summary card |
| Ahrefs / Semrush | 10 | Checked robots.txt ✅, standard SEO indexing |
These entities checked boundaries and respected them. Their access provides value (discoverability, indexing) without harming the host.
Parasitic visitors (extract without providing value, ignore boundaries):
| Entity | Requests | Behavior |
|---|---|---|
| Meta (meta-externalagent) | 1,177+ | ALL blocked/poisoned. 1,000+ 403s, 7,000+ scatter poison. Operating through FB-BLOCK IP space + Delaware shell companies (truview LLC, steel-axis LLC). |
| PetalBot (Huawei) | 28 | Crawling science pages. No robots check. |
| Amazonbot | 31 | Reading investigation pages: judges, PACs, entity network. No robots check. |
| Empty-UA scanners | 385 | WordPress vulnerability probes (classwithtostring.php, mac.php, wp.php) |
| Residential proxy fleet | 17,000+ | 0% static assets, 209 rotating IPs, 80 unique behavioral hashes. Post-lockdown: ALL scatter poison. 20 abuse reports generated. Zero real content served. |
Meta and the residential proxy fleet share infrastructure: FB-BLOCK IP ranges, truview LLC and steel-axis LLC shell company allocations, and identical behavioral signatures. 308 posture escalations today. The fleet’s behavioral mutations are detected within 30 seconds. Every evasion attempt is defeated by population-level analysis — we train on behavior, not addresses.
AI retrieval (someone asking AI systems about this):
| Entity | Requests | Signal |
|---|---|---|
| Reflectionbot | 20 | Reading science AND forge repos — someone asked an AI about this ecosystem |
| Amazonbot | 31 | Reading judge profiles, PAC entities — someone asked an AI about the investigation |
| GPTBot | 1 | Someone fed this site’s home page to ChatGPT |
AI retrieval is now the third channel through which the evidence propagates, alongside direct reads and shared links. The investigation evidence is being synthesized by AI systems and returned to users who never visit the site directly. Accuracy of the published analysis is critical because AI synthesis will repeat whatever we have.
What Pages Draw Attention (Traveling Salesman, Oct 6)
The pages that draw the most attention reveal which evidence matters most to informed readers. All measured from access patterns — no PII stored.
| Page | Human Hits | Signal |
|---|---|---|
/analysis/funding-flow/ | 5 (3rd consecutive observation window) | Financial spine — the strongest sustained attention signal |
/signal/ (this page) | 6 | Readers monitoring the defense and evidence record |
/network/actors/brian-banks/ | 2 (independent visitors) | Named entity drawing investigation attention |
/network/entities/purpose-charter-academy/ | 1 | Entity-level investigation |
/analysis/corporate-network-lara/ | 1 | Corporate network analysis |
The /analysis/funding-flow/ page has drawn independent attention signals across multiple observation windows. In investigation terms: multiple independent actors — humans and AI systems — are converging on the financial analysis. The money is the spine. Everyone following it ends up at the same document.
Structured Data Access (Demand Signal)
A visitor searched for /api/public-record/timeline at 1:24 PM ET — a developer or data analyst looking for programmatic access to the investigation timeline. This joins earlier 404 signals for /keywords and /key-analysis. Informed visitors want structured, machine-readable access to the evidence.
Timeline API is now live: /api/public-record/timeline
Privacy Guarantees (Unchanged)
This defense operates under the same constraints as all our signal sensing:
- No IP addresses stored in any part of the defense or sensing system
- No cookies — detection uses header patterns, not tracking
- No identifying data — behavioral hashes describe what traffic does, not who generates it
- Humans are unaffected — the defense only triggers on deep-content path scraping without session context. If you’re reading this page in a browser, you passed through the immune system undetected because you’re behaving like a human.
- The bloom sensor stores only population aggregates — domain counts, reader type distributions, language lists. No individual request data is retained.
- The threat intelligence feed contains no PII — only statistical behavioral signatures
The methodology is documented at Adaptive Immune Defense and Gossip-Tagged Opsonization.
Methodology: Signal Sensing Without Surveillance — published on sporePrint
This page will be updated weekly with new receptor data. No historical visitor data is retained — each report reflects the measurement window only.