Online Hate Speech and Harassment Monitoring Targeting Afghans in Pashto, Dari and English
Ariana Nexus monitors public online content that targets Afghans: hate speech, harassment, threats, doxxing and coordinated abuse, in Pashto, Dari and English, in Arabic script and in Latin letters. Platforms, regulators, civil society organizations and researchers receive lexicons, alerts, reports, labeled data and evidence records prepared by native-speaker analysts.
The work is delivered in-house from Washington, D.C., for clients in the United States, Europe and worldwide.
The first 72 hours of a hate campaign against Afghans
- Hour 0
Trigger
OnlineAn attack, a deportation order, a verdict or an edict is reported. The person at the center is described as Afghan.MonitoringSurge protocol opens. Surfaces, terms and spelling variants for the event are loaded in Pashto, Dari and English. - Hour 1
First wave
OnlinePosts blame Afghans as a group. Old videos and unrelated crimes circulate as new.MonitoringFirst read of the highest-reach posts. False claims are logged with the hate content they feed. - Hour 6
Organization
OnlineHashtags settle. Accounts created the same week post identical text. Calls for expulsion appear.MonitoringCoordinated accounts are mapped. A Level 4 alert goes to the client with evidence records. - Hour 24
Peak
OnlineVolume peaks. In the December 2025 case in the United States, anti-Afghan hate peaked within 24 hours. [2]MonitoringDaily brief: volume, severity mix, narratives, platforms, targets and what was escalated. - Hour 48
Personal targeting
OnlineCommunity leaders, shop owners, students and journalists are singled out. Addresses and photographs are posted.MonitoringDoxxing alerts within four hours. Notices prepared under private-information policies. - Hour 72
New baseline
OnlineThe spike falls but does not return to the earlier level. [2]MonitoringSurge report: prevalence before, during and after, lexicon additions and recommendations.
Documented surges of online hate against Afghans, 2021 to 2025
Each entry is a published finding by another organization. None is our own client data.
Hate speech against Afghans online: what the evidence shows
Three published findings explain why platforms, regulators and Afghan diaspora organizations now ask for monitoring in Pashto and Dari, and why speed matters.
- 217%
Rise in abuse of Afghan women
Increase in posts combining gendered hate speech terms with the names of prominent Afghan women, June to December 2022 against the same months of 2021. Afghan Witness reviewed more than 78,000 posts written in Dari and Pashto. [1] - 60%+
Sexualized abuse
Share of the 2022 posts in the same study that contained sexualized terms aimed at Afghan women. [1] - 8,785
Anti-Afghan posts in eight days
Posts with explicit anti-Afghan hate found on X, Facebook and Instagram between November 26 and December 3, 2025, after the shooting in Washington, D.C. Volume peaked within 24 hours and the baseline stayed higher afterward. [2] - 24 hours
Review window in the EU
Time in which signatories to the EU Code of Conduct+ commit to review most hate speech notices from monitoring reporters. The code joined the Digital Services Act framework on January 20, 2025. [3]
Surges follow events: a deportation drive, an attack attributed to an Afghan national, a new edict on Afghan women. In Iran, more than 1.5 million Afghans were deported in 2025 [5], officials used dehumanizing language about them [6] and anti-Afghan posts surged on Persian-language social media [7]. A monitoring program has to be staffed before the event, not after it.
The Digital Services Act asks very large platforms to report their moderation staff by official EU language. Pashto and Dari are not official EU languages, so they appear in no report [4][8]. Research on those reports finds users posting in languages with no dedicated human review at all [9].
What is online hate speech and harassment monitoring?
Online hate speech and harassment monitoring is the ongoing review of public posts, comments, videos and live audio to find content that attacks people because of who they are, or that targets a named person with abuse or threats. It is social media monitoring with a single purpose: to measure how much of this content exists, where it spreads, who it targets and how severe it is, and to send the urgent cases to the people who can act.
For Afghans, that content is written in Pashto, Dari and English. Much of it is typed in Latin letters, and much of it uses coded terms that keyword filters and English-trained classifiers do not catch. It targets Afghan refugees and migrants, Afghan women in public life, ethnic and religious communities, journalists, and people who worked with U.S. and NATO forces during the war in Afghanistan.
Key facts
- Languages
- Pashto, Dari, English
- Scripts
- Arabic script and Latin letters
- Outputs
- Lexicon, alerts, reports, labeled data, evidence records
- Frameworks
- DSA, Code of Conduct+, Online Safety Act, Rabat
- Delivery
- In-house, Washington, D.C.
- Last reviewed
- September 20, 2026
What we monitor: hate speech, harassment and threats targeting Afghans
Eight categories, defined in writing before monitoring starts and mapped to your policy or to the law that applies.
Hate speech against Afghans as a group
Content that dehumanizes Afghans, Afghan refugees or Afghan migrants, or calls for their exclusion, expulsion or harm. Anti-Afghan hate is written in English and in host-country languages as well as in Pashto and Dari.Ethnic, regional and sectarian hate
Content attacking people as Pashtun, Tajik, Hazara, Uzbek, Turkmen, Baloch, Nuristani or another community, or as Shia, Sunni, Sikh, Hindu or non-believers. Read by analysts from more than one community, to one standard.Gendered hate and harassment of Afghan women
Sexualized abuse, threats and smear campaigns against Afghan women journalists, activists, politicians, athletes, students and professionals. Often called technology-facilitated gender-based violence.Threats and incitement to violence
Statements that threaten a person or a group, or urge others to harm them, assessed for credibility and imminence.Doxxing and exposure of people at risk
Publication of names, photographs, addresses, workplaces or family details of former officials, soldiers, interpreters, journalists, human rights defenders, LGBTQ Afghans and converts, for whom exposure can be fatal.Coordinated harassment
Pile-ons, hashtag campaigns, mass false reporting, impersonation and networks of accounts acting together against one person or one community.Dehumanizing rumors and false claims
False or distorted claims about crime, disease, loyalty or religion that are used to justify hostility toward Afghans.Abuse in live audio and video
Abuse spoken in Pashto and Dari in live rooms, streams and video comments, where no text exists to filter.
What is not hate speech
Why Pashto and Dari hate speech goes undetected
Pashto and Dari are low-resource languages for machine learning. The tools that find hate speech in English were never built for them.
Few labeled datasets
The public Pashto datasets we know of label posts only as offensive or not offensive [10][11]. None records who is targeted, how severe the content is or which policy it breaks. We know of no public hate speech dataset for Dari as it is written in Afghanistan. Persian datasets are drawn from Iranian social media.One word, many spellings
Pashto has letters that Arabic and Persian keyboards lack, so writers substitute. Pashto and Dari are also typed in Latin letters with no agreed spelling. One term can appear in a dozen forms, and a filter built on one form misses the rest.Several languages in one post
A single comment can move between Pashto, Dari, English and Urdu. Language identification fails, and the post is routed to no reviewer at all.Dialect and region
Insults differ between Kandahar and Nangarhar, and between Kabul, Herat, Mazar-e-Sharif and Hazarajat. A reviewer from one region can miss what is obvious to another.Context decides meaning
The same word can be a neutral description, a reclaimed term or a slur, depending on who says it to whom. Afghani is the name of the currency. Applied to a person it is widely heard as demeaning, and in some host countries it is used as an insult. Machine translation removes exactly this information.Coded and religious framing
Abuse is carried by proverbs, poetry, nicknames, emoji and religious accusation. An accusation of apostasy can work as a call to violence without a single violent word.Dari is not Iranian Persian
Tools trained on Iranian Persian misread Afghan usage, and the reverse. Anti-Afghan content written in Iran uses vocabulary an Afghan reader recognizes at once and a general Persian model does not.Speech, not text
Live rooms and video carry abuse that never becomes text, so text classifiers never see it.
One word, many spellings
- مهاجرDari and Pashto
- مهاجرینPlural
- مهاجرینوPashto oblique plural
- کډوالPashto
- کډوالوPashto oblique plural
- muhajirLatin letters
- mohajerLatin letters
- muhajerLatin letters
- mohajirLatin letters
- kadwalLatin letters
- kadwaalLatin letters
- m0hajerAltered
- مـهـاجـرStretched
- م.ه.ا.ج.رSeparated
Platforms, languages and scripts covered
Public content only, collected within each platform's terms and the law that applies, or data the client lawfully holds and provides, such as its own review queues.
- X
- TikTok
- YouTube
- Telegram public channels
- News site comment sections
- Live audio rooms
How severity is graded and how fast threats are escalated
Response targets are written into each engagement. These are our standard terms.
Level 1. Derogatory
Insults and stereotypes with no call to action.Counted and trended. Reported in cycle.Level 2. Dehumanizing
Content that denies the humanity of Afghans or of a community, or calls for exclusion or expulsion.Reported in cycle. Flagged the same day when volume rises.Level 3. Targeted harassment
Sustained abuse of a named person.Reported within one business day.Level 4. Doxxing or coordinated campaign
Exposure of a person at risk, or accounts acting together.Alert within four hours.Level 5. Credible threat or incitement
A threat to a person or group, or a call to violence that meets the Rabat test.Alert within one hour of detection, at any hour under the crisis tier.
How we monitor: from scope to evidence
Eight steps, the same in every engagement. Each one leaves a record a regulator or an auditor can follow.
Scope and policy alignment
We agree the target groups, surfaces, languages, legal frameworks and your policy definitions. A human rights, conflict and data protection check is completed before any work starts.Lexicon and taxonomy
We build a living lexicon of terms, spelling variants, Latin-letter forms and coded expressions, each with context, severity and false-positive notes, mapped to a written taxonomy.Collection
Public content is collected from the named surfaces within platform terms, or received from the client. Private groups and private messages are never entered.Native-speaker review
Analysts who are native speakers of Pashto or Dari classify each item by category, target, severity, language, script and dialect. Automated tools collect and sort. People decide.Second read and adjudication
Severe and borderline items go to a second analyst who does not see the first label. A senior reviewer settles disagreements, and agreement scores are reported.Severity grading
Every item is graded on a five-level scale. Incitement is assessed against the six-part test of the Rabat Plan of Action: context, speaker, intent, content and form, extent, and likelihood of harm, including imminence. [12]Escalation
Threats, doxxing and coordinated campaigns are sent to your named contacts within the agreed time, with the content, translation, context and recommended action.Reporting and feedback
Weekly, monthly and quarterly reporting with methods and limits stated. Labels, error analysis and lexicon updates go back into your classifiers and reviewer guidelines.
What an alert and a lexicon entry look like
- Reference
- Sample alert
- Severity
- Level 4. Doxxing of a person at risk
- Platform
- X
- Language and script
- Dari, Latin letters
- Target
- Woman journalist in exile. Not named in this sample
- Content
- Withheld here. Original, transliteration and translation are provided to the client
- Why it matters
- The post gives the district and street of her parents' home in Afghanistan. Fourteen accounts shared it within two hours. Three were created this week
- Recommended action
- Report under the private information policy. Preserve evidence. Inform the newsroom's security contact
- Evidence
- URL, capture, timestamp and file hash recorded
- Sent
- 42 minutes after detection
- Term
- Withheld
- Language
- Pashto
- Forms recorded
- 4 in Arabic script, 7 in Latin letters, 3 altered
- Target
- An ethnic community
- Default severity
- Level 2
- Context note
- Neutral when members of the community use it about themselves. Demeaning from outsiders. Check speaker and target
- False positives
- Also a place name. Exclude when followed by district terms
- Policy mapping
- Client policy section and tier. Illegal only where national law criminalizes it
- Last reviewed
- Monthly
What you receive
Eight deliverables. Most programs use five or six of them.
How engagements are structured
Baseline assessment
A fixed-scope study of hate speech and harassment targeting Afghans on the surfaces you name: a prevalence estimate, the first version of the lexicon and a gap analysis of current detection.Four to six weeksContinuous monitoring
A standing program with a named engagement lead, agreed severity targets, monthly reporting and a quarterly review.Twelve-month termCrisis surge
Monitoring stood up around an event, such as an attack, a deportation order, an election or a verdict, with extended hours and a daily brief.Stood up within 24 hours for program clientsData and evaluation project
Labeled Pashto and Dari data and an error analysis for a classifier, a moderation vendor or an AI model.Scoped per dataset
Programs are scoped with a named lead and a stated method. We do not sell review by the item or by the hour.
How monitoring supports DSA, Online Safety Act and human rights obligations
This table maps the service to each framework. It is not legal advice.

What this service does not do
We do not remove content.
We report. The platform, the regulator or the court decides.We do not monitor Afghans.
We monitor content that targets them. We build no profiles of community members and keep no watchlists.We do not unmask anyone.
No covert accounts, no entry to private groups or private messages, no attempts to identify anonymous users.We do not work against Afghans.
No client whose purpose is to identify, locate or silence Afghans. Nothing is routed through the de facto authorities in Afghanistan.We do not publish the lexicon.
A public list of slurs teaches evasion and spreads the terms.We do not police opinion.
Political, religious and policy criticism is not hate speech, and our taxonomies say so.We do not act as lawyers or police.
Threats reach law enforcement through the client's lawful route. Imminent danger to life is escalated to the client at once, at any hour.
Data protection, safety of targeted people and analyst wellbeing
Data protection
Public content only. Data minimization, pseudonymized reporting by default and retention limits set in the agreement. European engagements run under GDPR and UK GDPR with a data processing agreement.People who are targeted
Our practice is survivor-centered. We do not contact a targeted person without the client's agreement and a plan for their safety, and reports repeat abuse only as far as evidence requires.Analysts
Exposure to severe content is limited in every shift, rotation is mandatory, and debriefing follows a protocol set and reviewed by Diana Ayubi, Psy.D. Analysts are never named in public.
Why Ariana Nexus: native analysts, one standard, in-house delivery
Who reads the content
Native speakers of Pashto and Dari with university degrees, trained on your policy and on the law that applies. They read the dialect, the script, the Latin-letter spelling and the subtext.How we deliver
Every engagement is delivered by our own people under one engagement lead. Nothing goes to subcontractors or crowd platforms. Severe items are read twice, disagreements go to a senior reviewer and agreement scores are reported.How we are different
General content moderation vendors staff hundreds of languages and treat Pashto and Dari as two more queues. The Afghan context is the only context we work in: 24 Afghan languages, the communities, the history and the events that set off each surge. We apply one standard across every Afghan community, and we state in writing what we will not do. No certification exists for reviewing hate speech in Pashto or Dari. We wrote the standard we work to, and we train our analysts to it.
- 24Afghan languages in our practice
- 2Analysts on every severe item
- 0Subcontractors or crowd workers
- 1Standard across every community
The team behind this service
The people accountable for this service are named below. The analysts who read threats and abuse every day are not. They are described by role and training, and their names stay off public pages for their safety.
Why this team is different
Ariana Nexus is led by alumni and scholars of Cornell University, the University of Chicago, the University of British Columbia and Otto von Guericke University Magdeburg, trained in public health, law, engineering and computer science. They grew up in the languages and communities this service protects. Monitoring hate speech in Pashto and Dari needs both academic method and native reading. Bilingual staff alone cannot supply the first, and outside experts cannot supply the second.

Hassan Ukasha
- B.S.Cornell University
- M.P.H.Cornell University
Hassan Ukasha oversees the firm's operations and this program. He approves every client under the firm's human rights and conflict check, reviews each monitoring program with its engagement lead every quarter, and is the senior point of escalation for clients.

Zeba Haqbani
- B.Sc.University of British Columbia

Hussain Ahmad
- M.Eng.Cornell University
- Ph.D.University of Chicago

Wasil Peroz
- B.A.Milli University
- M.Sc.Otto-von-Guericke University Magdeburg

Maryam Safi
- B.A.Cornell University
Who is accountable for what on this service
Pashto and Dari analysts
This service in Pashto and Dari
د افغانانو پر ضد د آنلاین کرکهخپرونې او ځورونې څارنه — په پښتو، دري او انګلیسي
تحلیلګران مو اصلي ویونکي دي؛ لهجه، لیکدود، په لاتیني تورو لیکل شوې پښتو او پټه مانا پېژني.
نظارت بر نفرتپراکنی و آزار و اذیت آنلاین علیه افغانها — به پشتو، دری و انگلیسی
تحلیلگران ما گویندگان بومیاند؛ لهجه، رسمالخط، دری نوشتهشده با حروف لاتین و معنای پنهان را میشناسند.
How this differs from keyword filters, machine translation and general moderation vendors
Questions buyers ask about hate speech monitoring in Pashto and Dari
What counts as hate speech targeting Afghans?
Content that attacks or dehumanizes people because they are Afghan, or because of their ethnicity, religion, gender or another part of who they are. It includes anti-Afghan hate aimed at refugees and migrants, ethnic and sectarian hate between communities, and gendered abuse of Afghan women. Criticism of governments, authorities, policies or religions is not hate speech.
Can AI detect hate speech in Pashto and Dari?
Partly. Published models score well on small test sets that label posts as offensive or not offensive. They are not trained to say who is targeted, how severe the content is or whether it breaks a policy, and they struggle with Latin-letter text, mixed languages and coded terms. We use automated tools to collect and sort, and native-speaker analysts to decide. The labeled data and error analysis we deliver are what improve a classifier.
Do you monitor private groups or private messages?
No. We monitor public content, or data a client lawfully holds and provides, such as a platform's own review queues. We do not use covert accounts and we do not try to identify anonymous users.
Do you remove content or report it to platforms?
We do not remove content. We send alerts and evidence to the client, and we prepare translated notices that the client or a trusted flagger can submit. The platform, the regulator or the court decides what happens to the content.
Is Ariana Nexus a trusted flagger under the Digital Services Act?
No. Trusted flagger status is awarded by the Digital Services Coordinator of an EU member state to organizations established there. We provide the Pashto and Dari expertise that trusted flaggers, monitoring reporters and platform teams often lack, and we prepare notices they can submit.
How does monitoring support a DSA systemic risk assessment or an Online Safety Act risk assessment?
Both regimes ask platforms to understand the risk of illegal and harmful content on their services. For Pashto and Dari most platforms have little evidence. We supply prevalence estimates, severity and target analysis, detection gap analysis and tests of mitigation, documented so an auditor or a regulator can follow the method.
How quickly are threats and doxxing escalated?
Under our standard terms a credible threat or incitement to violence is alerted within one hour of detection, and doxxing or a coordinated campaign within four hours. Targets are written into each engagement, and the crisis tier adds coverage at any hour.
How do you handle Pashto and Dari written in Latin letters, mixed languages and dialects?
Analysts read them natively. Every spelling we meet is recorded in the lexicon with its language, script, dialect and context, so that collection tools and classifiers can find the same term next time. Items are labeled by language, script and dialect.
Do you cover anti-Afghan content in Persian, Urdu or other languages?
Anti-Afghan content written in Iran is in Persian, which our Dari analysts read natively. Urdu and other host-country languages are scoped by engagement. English is part of every program.
How do you protect the people in the data and your analysts?
Reports are pseudonymized by default, data is minimized and retention limits are set in the agreement. We do not contact a targeted person without the client's agreement and a safety plan. Analysts work with exposure limits, mandatory rotation and debriefing, and are never named in public.
How is this different from outsourced content moderation?
Content moderation reviews what a platform sends to a queue. Monitoring looks for what no one has flagged yet, measures it and explains it. We scope programs with a named lead and a stated method, and we do not sell review by the item.
How does an engagement start?
With a scoping call under a non-disclosure agreement, a conflict and human rights check, and a written scope naming surfaces, languages, severity targets and deliverables. A baseline assessment of four to six weeks usually comes first.
Terms used on this page
- Hate speech
- Communication that attacks or demeans a person or group because of who they are, such as nationality, ethnicity, religion or gender.
- Online harassment
- Repeated or severe abuse aimed at a named person.
- Incitement
- Speech that urges discrimination, hostility or violence against a group, assessed under the Rabat test.
- Doxxing
- Publishing private or identifying details about a person without consent.
- Coordinated harassment
- Accounts acting together against one target. Also called a pile-on or brigading.
- Technology-facilitated gender-based violence
- Abuse of women and girls carried out through digital tools and platforms.
- Coded language
- Words, images or references that carry a hostile meaning for insiders and look harmless to others.
- Lexicon
- A maintained list of terms and their variants, with context, severity and false-positive notes.
- Prevalence
- The share of sampled content that is hate speech or harassment.
- Analyst agreement
- How often two analysts give the same label to the same item. Reported as Krippendorff's alpha or Cohen's kappa.
- Trusted flagger
- An organization given priority notice status under Article 22 of the Digital Services Act.
- Systemic risk assessment
- The yearly assessment very large platforms carry out under Article 34 of the Digital Services Act.
Sources
- [1]Afghan Witness, Centre for Information Resilience. Violence behind a screen: rising online abuse silences Afghan women. November 2023. info-res.org
- [2]Afghan-American Foundation and Center for the Study of Organized Hate. Statement on anti-Afghan online hate following the D.C. shooting. December 5, 2025. afghanamericans.org
- [3]European Commission. First results published under the revised Code of Conduct on Countering Illegal Hate Speech Online+. April 10, 2026. digital-strategy.ec.europa.eu
- [4]Regulation (EU) 2022/2065, Digital Services Act. Articles 16, 22, 34, 35 and 42. eur-lex.europa.eu
- [5]Center for Human Rights in Iran. Over 1,300 activists demand end to Iran's anti-Afghan crackdown. August 5, 2025. iranhumanrights.org
- [6]Amnesty International Canada. Stop the mass deportations of Afghans. August 5, 2025. amnesty.ca
- [7]Iran International. Iran steps up Afghan deportation drive. July 1, 2025. iranintl.com
- [8]Digital Forensic Research Lab. Learning more about platforms from the first Digital Services Act transparency disclosures. December 6, 2023. dfrlab.org
- [9]Language Disparities in Moderation Workforce Allocation by Social Media Platforms. ACM Conference on Fairness, Accountability, and Transparency, 2026. doi.org
- [10]Haq, Qiu, Guo and Tang. Pashto offensive language detection: a benchmark dataset and monolingual Pashto BERT. PeerJ Computer Science, 2023. doi.org
- [11]Khan and others. Offensive Language Detection for Low Resource Language Using Deep Sequence Model. IEEE, 2023. ieeexplore.ieee.org
- [12]Office of the UN High Commissioner for Human Rights. Rabat Plan of Action, A/HRC/22/17/Add.4. 2013. ohchr.org
- [13]Ofcom. A safer life online for women and girls. Guidance, November 25, 2025. ofcom.org.uk
- [14]United Nations. Strategy and Plan of Action on Hate Speech. 2019. un.org
- [15]Afghan Witness. Increase in online hate speech directed at influential Afghan women since Taliban takeover. 2022. afghanwitness.org
Discuss a monitoring program
Scoping conversations are held under a non-disclosure agreement.