A viral online video claims Canadian Prime Minister Justin Trudeau promotes an investment project. However, the CyberPeace Research Team has confirmed that the video is a deepfake, created using AI technology to manipulate Trudeau's facial expressions and voice. The original footage has no connection to any investment project. The claim that Justin Trudeau endorses this project is false and misleading.
Claims:
A viral video falsely claims that Canadian Prime Minister Justin Trudeau is endorsing an investment project.
Upon receiving the viral posts, we conducted a Google Lens search on the keyframes of the video. The search led us to various legitimate sources featuring Prime Minister Justin Trudeau, none of which included promotion of any investment projects. The viral video exhibited signs of digital manipulation, prompting a deeper investigation.
We used AI detection tools, such as TrueMedia, to analyze the video. The analysis confirmed with 99.8% confidence that the video was a deepfake. The tools identified "substantial evidence of manipulation," particularly in the facial movements and voice, which were found to be artificially generated.
Additionally, an extensive review of official statements and interviews with Prime Minister Trudeau revealed no mention of any such investment project. No credible reports were found linking Trudeau to this promotion, further confirming the video’s inauthenticity.
Conclusion:
The viral video claiming that Justin Trudeau promotes an investment project is a deepfake. The research using various tools such as Google Lens, AI detection tool confirms that the video is manipulated using AI technology. Additionally, there is no information in any official sources. Thus, the CyberPeace Research Team confirms that the video was manipulated using AI technology, making the claim false and misleading.
Claim: Justin Trudeau promotes an investment project viral on social media.
A viral post on X (formerly twitter) shared with misleading captions about Gautam Adani being arrested in public for fraud, bribery and corruption. The charges accuse him, his nephew Sagar Adani and 6 others of his group allegedly defrauding American investors and orchestrating a bribery scheme to secure a multi-billion-dollar solar energy project awarded by the Indian government. Always verify claims before sharing posts/photos as this came out to be AI-generated.
Claim:
An image circulating of public arrest after a US court accused Gautam Adani and executives of bribery.
Fact Check:
There are multiple anomalies as we can see in the picture attached below, (highlighted in red circle) the police officer grabbing Adani’s arm has six fingers. Adani’s other hand is completely absent. The left eye of an officer (marked in blue) is inconsistent with the right. The faces of officers (marked in yellow and green circles) appear distorted, and another officer (shown in pink circle) appears to have a fully covered face. With all this evidence the picture is too distorted for an image to be clicked by a camera.
A thorough examination utilizing AI detection software concluded that the image was synthetically produced.
Conclusion:
A viral image circulating of the public arrest of Gautam Adani after a US court accused of bribery. After analysing the image, it is proved to be an AI-Generated image and there is no authentic information in any news articles. Such misinformation spreads fast and can confuse and harm public perception. Always verify the image by checking for visual inconsistency and using trusted sources to confirm authenticity.
Claim: Gautam Adani arrested in public by law enforcement agencies
Claimed On: Instagram and X (Formerly Known As Twitter)
Amid heightened tensions in West Asia following the conflict involving the United States, Israel and Iran, a video showing a large explosion behind a building is being widely shared on social media.
Users claim that the footage shows an Iranian missile strike on a US military base in Kuwait. However, CyberPeace Research Wing research found the claim to be misleading. The viral video is actually from an Israeli airstrike in southern Lebanon. While Kuwait said its air defence systems intercepted missiles and drones during regional hostilities, the viral footage has no connection to any alleged attack on a US base in Kuwait.
Claim
An Instagram user, “indiscope24hr,” shared the video on May 28, 2026, with text overlaid on the clip stating:“Iran launches a deadly missile attack on a US base in Kuwait.”The caption claimed that Iran targeted a US airbase in retaliation for American military action and that Kuwait’s air defence systems were intercepting incoming missiles and drones.
To verify the claim, we extracted key frames from the viral video and conducted a reverse image search using Google Lens. This led us to a post shared on May 28, 2026, by the Instagram account “iltv_israel,” which identified the footage as an Israeli Air Force strike on a Hezbollah target in the southern Lebanese city of Tyre.
Further research found the same footage in a video report uploaded by the New York Post’s YouTube channel on May 28, 2026. According to the report, Israel carried out strikes targeting Hezbollah positions in Tyre, southern Lebanon.
We also found the clip in a video report published by NBC News. The report stated that Israel intensified strikes in southern Lebanon despite an existing ceasefire agreement.
The matching visuals across these reports confirm that the viral footage originated from Lebanon and not from Kuwait.
Conclusion
The viral claim is misleading. The video does not show an Iranian missile strike on a US military base in Kuwait. It actually depicts an Israeli airstrike carried out in the Lebanese city of Tyre on May 28, 2026, and is being shared with a false context on social media.
After the blackout on July 19, 2024, which affected CrowdStrike’s services worldwide, cybercriminals began to launch many phishing attacks and distribute malware. These activities mainly affect CrowdStrike customers, using the confusion as a way to extort information through fake support sites. The analysis carried out by the Research Wing of CyberPeace and Autobot Infosec has identified several phishing links and malicious campaigns.
The Exploitation:
Cyber adversaries have registered domains that are similar to CrowdStrike’s brand and have opened fake accounts on social media platforms. These are fake platforms that are employed to defraud users into surrendering their personal and sensitive details for use in other fraudulent activities.
In one case, a PDF file is being circulated with CrowdStrike branding, saying ‘Download The Updater,’ which is a link to a ZIP file. The ZIP file is a compressed file that has an executable file with a virus. This is a clear sign that the hackers are out to take advantage of the current situation by releasing the malware as an update.
Image Source: AnyRun
Image Source: VirusTotal
In another case, there is a malicious Microsoft Word document that is currently being shared, which claims to offer a solution on how to deal with this CrowdStrike BSOD bug. But there is a hidden risk in the document. When users follow the instructions and enable the embedded macro, it triggers the download of an information-stealing malware from a remote host. This is a form of malware that is used to steal information and is not well recognized by most security software. Also it sends the stolen data to the samesame remote host but with different port number, which likey works as the CnC server for the campaign.
Name New_Recovery_Tool_to_help_with_CrowdStrike_issue_impacting_Windows[.]docm
On July 19, 2024, CrowdStrike faced a global outage that originated from an update of its Falcon Sensor security software. This outage affected many government organizations and companies in different industries, such as finance, media, and telecommunications. The event led to numerous complaints from the users who experienced problems like blue screen of death and system failure. Although, CrowdStrike has admitted to the problem and is in the process of fixing it.
Preventive Measures:
Organize regular awareness sessions to educate the employees about the phishing techniques and how they can avoid the phishing scams, emails, links, and websites.
MFA should be used for login to the sensitive accounts and systems for an improvement on the security levels.
Make sure all security applications including the antivirus and anti-malware are up to date to help in the detection of phishing scams.
This includes putting in place of measures such as alert on account activity or login patterns to facilitate early detection of phishing attempts.
Encourage employees and users to inform the IT department as soon as they have any suspicions regarding phishing attempts.
Conclusion:
The recent CrowdStrike outage is a perfect example of how cybercriminals take advantage of the situation and user’s confusion and anxiety. Thus, people and organizations can keep themselves from these threats and maintain the confidentiality of their information by being cautious and adhering to the proper standards. To get the current information on the BSOD problem and the detailed instructions on its solution, visit CrowdStrike’s support center. Reported problems should be handled with caution and regular backup should be made to minimize the effects.
Your institution or organization can partner with us in any one of our initiatives or policy research activities and complement the region-specific resources and talent we need.