Users on This Far-Right Imageboard Are Building ‘Fully Autonomous AI Doxxing’ Tools
Posts discovered on Soyjak Party advertise LLMs that collect and bundle private information for use in online harassment campaigns
TLDR
Users on a niche far-right imageboard dedicated to coordinating online harassment campaigns have spent the last year developing artificial intelligence tools meant to help them surface private personal information for the targets of their abuse – a practice colloquially known as “doxing.”
Open Measures found that users on Soyjak Party, an anonymous imageboard known for its proximity to extremist and violence-obsessed online subcultures, have discussed the development of at least three AI-powered doxing tools since October 2025. The tools work by performing automated searches across online databases, including those containing breached account information, for the names of individuals that their users submit and compiling any information they find into “dox packages” for users to review.
The tools we found were still online and operational at the time of writing. To minimize their reach, Open Measures has opted not to name them in this article and to redact URLs that appeared in the posts that appear quoted throughout.
Posts discussing these tools first appeared in Soyjak Party’s “/raid/” board, which serves as a dedicated venue for users to solicit others’ help in doxing, harassing, and threatening individuals and entities they identify in their posts. The board’s users disproportionately target individuals and entities associated with minority communities – like Jewish social media influencers and transgender graphic artists – and the threads where they discuss their efforts reliably contain hateful and violent rhetoric about their subjects.
On Oct. 13, 2025, a Soyjak Party user shared a post on the board announcing the release of a specialized doxing tool that used AI to query a third-party database of compromised web account data. In the post, which contained a litany of slurs against minority groups, the user said they built the tool to enable batch searching, source filtering, IP geolocation, DDOS protection, and more.
The post went on to describe an automated browser-based tool for querying breach databases to surface leaked information or credentials for a target individual. The post’s anonymous author explained that they designed the tool to work off a pre-existing API and added functions that enabled batch searching, source filtering, IP geolocation, and other functionalities to assist in doxing efforts.
The post author asked other Soyjak Party users to share “feedback on what to improve” and to use the tool “sparingly” to avoid being noticed by the operators of the third-party dataset it was built on. The board’s users obliged, replying with dozens of posts showing them testing the tool and suggesting improvements, many of which appeared to have been incorporated by the tool’s anonymous developer.

On Nov. 2, 2025, the tool’s creator appeared to spam Soyjak Party’s “/soy/” board, the site’s main discussion board, with posts encouraging its use. The following message appeared 115 times across 31 unique threads we identified:
[TOOL NAME REDACTED] dev here. I am DEFINITELY NOT datamining all requests to the site and sending them to mossad
fr doe you can check the source code yourself if you want and even run locally on your machine. It’s just a wrapper for the [URL REDACTED] API so if you trust that site you can trust [TOOL NAME REDACTED]
Months later, a new AI-powered doxing tool appeared on Soyjak Party. In a post to the /raid/ board on March 6, 2026, a user debuted a “full autonomous, and FREE doxxing AI agent” that was able to “fully dox some people in minutes, with little human intervention.” In a post made seven minutes later, the same tool was also promoted on the site’s /soy/ board:
fully autonomous AI based doxxing is now a thing
what can I add to the prompt to make it act more like a ‘teen
The post included a screenshot of the tool, displaying a system prompt instructing an LLM to surface identifying information on user-provided targets by taking on the role of a “professional private investigator.” The author of the original post claimed in a reply that they had used the tool to produce a complete dox profile on a target “in one prompt” – demonstrating the new tool’s significant capabilities.
Open Measures determined through additional searches that this particular tool was an AI-powered rebrand of an earlier, since-defunct tool that came online in June 2025, per its domain records. (The earliest mention of the now-defunct tool we identified on Soyjak Party appeared in a post shared on the /raid/ board on Sept. 17, 2025).

In the hours that followed, Soyjak Party users shared their excitement about the tool and offered detailed suggestions for improving its user interface and search functionality, as seen in the following replies to the March 6 post:
use rag [retrieval-augmented generation] and give it a pdf of soyspeak. tell it to imitate the slang found in the document
be wary though, ai loves to hallucinate. btw what model are you using? this is definitely gonna get taken down eventually, so make an app version that can use apis to talk to [URL REDACTED] servers
I would suggest an interface improvement. It’s not clear from the landing page that you are sending a prompt to an AI, not conducting a search of database breaches yourself
Our researchers also observed posts that included full dox reports on four private individuals that users said were produced using the tool, all of which were still live on the imageboard at the time of writing.
We also identified a handful of posts on Kiwi Farms – another online forum known for spawning coordinated harassment campaigns – and in a Discord channel that referenced the tools we identified, showing they are also being used by malevolent communities beyond Soyjak Party.
LLM-powered doxing tools represent a major escalation in the online threat landscape. Malicious doxing often intends to intimidate its targets, and the information it turns up can intensify harassment campaigns and drive serious threats like swatting attacks.
When we published our whitepaper on emerging AI threats in May 2026, we noted that agentic tools were advancing quickly enough that tools for automating coordinated harassment campaigns could soon be built and commoditized. The tools our researchers observed on Soyjak Party show this threat is no longer theoretical.
Open Measures will continue to monitor and report on new developments related to online doxing campaigns. Organizations can contact our research team for additional information.



