#FactCheck – Human Helicopter or AI Illusion? The Truth Behind the Viral Flying Man Video
Executive Summary:
A viral video circulating on social media shows a man attempting to fly using a helicopter like fan attached to his body, followed by a crash onto a parked car. The clip was widely shared with humorous captions, suggesting it depicts a real life incident. Given the unusual nature of the visuals, the video was subjected to technical verification using AI content detection tools. Analysis using the AI detection platform indicates that the video is AI generated, and not a genuine real world event.
Claim:
A viral video (archive link) claims to show a person attempting to fly using a self made helicopter fan mechanism, briefly lifting off before crashing onto a car in a public setting. The video shows a man attempting to fly by strapping a helicopter like rotating fan to himself, essentially trying to imitate a human helicopter using a DIY mechanism. For a brief moment, it appears as if the device might work, but the attempt quickly fails due to lack of control, engineering support, and safety measures. Within seconds, the man loses balance and crashes down, landing on top of a parked car. The scene highlights a mix of overconfidence, unregulated experimentation, and risk taking carried out in a public space, with bystanders watching rather than intervening. The clip is shared humorously with the caption “India is not for beginners”.

Fact Check:
To verify the authenticity of the video, it was analyzed using the Hive Moderation AI detection tool, a widely used platform for identifying synthetic and AI generated media. The tool flagged the video with a high probability of AI generation, indicating that the visuals are not captured from a real physical event. Additional indicators such as unrealistic motion physics, inconsistent human object interaction further support the conclusion that the clip was artificially generated or heavily manipulated using generative AI techniques. No credible news reports or independent eyewitness sources corroborate the occurrence of such an incident.

Conclusion:
The claim that the video shows an individual attempting and failing to fly using a helicopter like device is false. Technical analysis confirms that the video is AI generated, and it should be treated as synthetic or fictional content rather than a real life incident. This case highlights how AI generated videos, when shared without context, can mislead audiences and be mistaken for real events, reinforcing the need for verification tools and critical evaluation of viral content.
- Claim: A viral video claims to show a person attempting to fly using a self made helicopter fan mechanism, briefly lifting off before crashing onto a car in a public setting
- Claimed On: X (Formally Twitter)
- Fact Check: False and Misleading
Related Blogs

In Delhi there is a bank branch where a lot of money was stolen from people over the country. This bank branch is where all the money disappeared. The people who did this did not wear masks. Break in at midnight. They just used a passbook a rubber stamp and a form that nobody checked carefully. This is the truth that the people who investigate cybercrime keep finding. The way that cybercriminals get away with the money is not by using a computer it is by using a bank account. The police in Delhi who investigate cybercrime have found that a lot of accounts were opened at bank branches. These accounts were opened using identity documents that were borrowed bought or stolen. Then these accounts were rented out to groups of criminals. One bank branch keeps coming up in complaints. This is not bad luck it is a sign of a bigger problem with how banks check who is opening an account.
These fake accounts, which are called " accounts" are controlled by criminal groups, not the people whose names are on the accounts. These accounts are a part of the cybercrime problem in India. The mistakes that bank branches make which allow these accounts to be opened raise a lot of questions. These questions are about how banks check who is opening an account how they prevent money laundering and how they work with groups to stop cybercrime. The bank accounts are the way that cybercriminals in India get away with the money they steal from people. The cybercrime investigators keep finding bank accounts like the ones at the bank branch, in Delhi, where the money was stolen.
The Anatomy of a Mule Account Network
The pattern is now familiar to investigators. A fraud complaint on the National Cyber Crime Reporting Portal traces a victim's stolen money to a beneficiary account. When police pull the account-opening file, the person named on the KYC documents often denies ever visiting the branch or signing the forms; signature verification frequently shows a mismatch. In one recent Delhi case, a cooperative bank's deputy manager was arrested after a single account he had helped open surfaced in 159 separate cyber fraud complaints from across the country, with transactions worth nearly Rs 68 crore routed through it before detection. Similar investigations have uncovered supply gangs that procure dozens of accounts at a time using POS machines, stacks of ATM cards, and cheque books belonging to different people and rent them out to fraudsters as ready-made conduits for stolen money.
What makes a single branch or a small cluster of accounts significant is what it reveals about entry-point failure. Investigators do not describe these as sophisticated hacking operations; they describe them as verification failures as are accounts opened without the mandatory in-person checks, video KYC, or document authentication that RBI rules require. When 96, or 700, or 8.5 lakh mule accounts are traced back through a handful of branches and intermediaries, the story is not really about the fraudsters at the far end of the chain. It is about the choke point where honest oversight should have stopped the account from ever existing.
Where the KYC Framework Is Breaking Down
The RBI's Know Your Customer Master Direction requires banks to establish customer identity, verify a genuine business relationship, and apply risk-based due diligence before allowing an account to operate. In practice, investigators have repeatedly found accounts opened through complicit or negligent bank staff, business correspondents, and third-party agents who bypass these checks entirely. Analysts note that mule accounts systematically exploit gaps in customer onboarding, KYC verification, transaction monitoring, and dormant-account surveillance, with criminals using forged or stolen identity documents and layering funds across multiple accounts to escape detection. Economically vulnerable individuals who are daily-wage workers, students, the unemployed are frequently paid a small commission to hand over their documents or existing accounts, often without understanding that they could face criminal liability for transactions they never authorised.
This is compounded by a financial-inclusion paradox that regulators themselves acknowledge: India has expanded banking access faster than it has expanded financial and digital literacy, leaving a population that is easy to recruit knowingly or unknowingly into mule networks. The result is a KYC regime that looks robust on paper but is only as strong as its weakest branch-level implementation, and weak implementation has proved trivially easy for organised networks to locate and exploit at scale.
The Regulatory and Institutional Response
RBI: From Static Compliance to Active Detection
The Reserve Bank of India has moved beyond periodic KYC audits toward technology-driven detection. It has directed banks to tighten onboarding controls, strengthen transaction monitoring, and report suspicious activity more proactively, and it has proposed additional safeguards, including limits on aggregate credits into accounts where a satisfactory business relationship has not yet been established. Its most significant intervention is MuleHunter.ai, an AI and machine-learning system built to flag suspected mule accounts from transaction-behaviour patterns rather than static KYC data alone; the platform is already operational across roughly two dozen banks and is being expanded. The RBI Innovation Hub has also begun working directly with the Indian Cyber Crime Coordination Centre (I4C) to share fraud-risk intelligence and coordinate detection in near real time.
FIU-IND and the PMLA Framework
The Prevention of Money Laundering Act, 2002 (PMLA) is the backbone of India's AML architecture. It mandates KYC verification, Customer Due Diligence, record maintenance, and timely reporting of suspicious transactions to the Financial Intelligence Unit–India (FIU-IND). Banks are required to file Suspicious Transaction Reports (STRs) and Cash Transaction Reports with FIU-IND, which in turn analyses financial intelligence and shares it with law enforcement and regulators. On paper, this creates a feedback loop between banks, the RBI, and enforcement agencies; in practice, the sheer volume of mule-linked transactions are hundreds of thousands of accounts flagged nationally has strained the capacity of this reporting chain to generate timely, actionable freezes before funds are withdrawn or converted to cryptocurrency.
The IT Act, CERT-In, and Cyber Enforcement
The Information Technology Act, 2000, together with provisions of the Bharatiya Nyaya Sanhita, provides the criminal-law basis for prosecuting mule account operators, aggregators, and the fraudsters who direct them. CERT-In's role sits slightly upstream of the banking layer: it issues advisories on phishing, fake payment gateways, and compromised digital infrastructure that fraud syndicates use to recruit mule account holders and move money. The Ministry of Home Affairs' I4C coordinates the National Cyber Crime Reporting Portal and the 1930 helpline, which allow victims to report fraud and trigger a limited window for freezing beneficiary accounts. I4C has also issued direct public alerts against illegal payment gateways built on mule accounts, warning citizens not to rent or sell their bank credentials to intermediaries.
The Coordination Gap
None of these institutions is short of legal authority. The gap is operational: banks, the RBI, FIU-IND, state police cyber cells, the CBI, and I4C each hold a piece of the picture, but no single agency has a real-time, end-to-end view of an account from opening to fraud to freeze. A mule account can be flagged by one bank's internal monitoring, reported through a completely different victim's complaint in another state, and investigated by a third jurisdiction's cyber police with each step introducing delay. The Indian Banks' Association has publicly pushed for the RBI to be given clearer power to directly freeze accounts flagged as mule accounts, rather than requiring each bank to act unilaterally or wait for a police request, precisely because this fragmentation lets fraudsters withdraw or launder funds within hours of a transaction.
Policy Recommendations
1. Mandatory video-KYC and biometric re-verification for all new accounts opened through business correspondents and third-party agents, with personal liability for verifying bank officials found complicit.
2. A statutory, RBI-backed mechanism allowing banks to freeze accounts flagged by MuleHunter.ai-type systems or FIU-IND intelligence within hours, rather than only after a formal police complaint.
3. A unified, interoperable case database linking the National Cyber Crime Reporting Portal, FIU-IND's STR system, and state cyber cells, so that an account flagged once is visible to every agency instantly.
4. Stronger due-diligence audits of banking correspondents and cooperative banks, which recur disproportionately in mule account cases relative to their share of total accounts.
5. Public financial-literacy campaigns targeted at the economically vulnerable groups most often recruited as unwitting mule account holders, paired with clear legal guidance distinguishing victims from willing participants.
Conclusion
The branch-level mule account cases surfacing across Delhi and other cities are not isolated policing stories; they are a live audit of India's AML and KYC architecture. The RBI, FIU-IND, CERT-In, and law enforcement agencies each have credible tools and legal mandates like MuleHunter.ai, PMLA reporting, IT Act prosecutions, and I4C's coordination portal chief among them but fraud syndicates continue to outpace the system by exploiting the seams between institutions rather than any single point of failure. Closing that gap requires less new law and more operational integration: faster account freezes, verified accountability at the point of account opening, and a shared, real-time picture of mule networks across every agency involved. Until banks, regulators, and investigators can act as one system rather than several disconnected ones, every dismantled racket will simply be replaced by the next.
References
- https://aninews.in/news/national/general-news/delhi-police-arrests-bank-deputy-manager-in-83776792-crore-mule-account-case-linked-to-159-cyber-fraud-complaints20260610130737/
- https://the420.in/delhi-bank-manager-mule-account-cyber-fraud-case/
- https://www.business-standard.com/finance/news/what-are-mule-accounts-cybercrime-banking-layer-india-fraud-rbi-126062400855_1.html
- https://www.business-standard.com/india-news/centre-freezes-450-000-mule-bank-accounts-used-in-cyber-fraud-schemes-124111200320_1.html
- https://www.medianama.com/2025/04/223-iba-rbi-cyber-fraud-measures-freeze-bank-accounts-cybercrime/
- https://www.deccanherald.com/amp/story/india%2Fcentre-warns-of-illegal-payment-gateways-and-mule-accounts-3252723
- https://www.deccanherald.com/india/over-85-lakh-mule-accounts-in-700-bank-branches-used-by-cyber-criminals-cbi-3604229
- https://website.rbi.org.in/en/web/rbi/-/notifications/master-direction-know-your-customer-kyc-direction-2016-updated-as-on-may-04-2023-lt-span-gt-11566
- https://www.indiacode.nic.in/bitstream/123456789/15402/1/moneylaunderingact2002.pdf
- https://www.indiacode.nic.in/bitstream/123456789/13116/1/it_act_2000_updated.pdf
- https://www.mha.gov.in/en/division_of_mha/cyber-and-information-security-cis-division/Details-about-Indian-Cybercrime-Coordination-Centre-I4C-Scheme
.webp)
Executive Summary:
A video is being shared on social media showing a man running rapidly in a river with water bottles tied to both his feet. Users are circulating the video claiming that the man is attempting to run on water using the support of the bottles. CyberPeace’s research found the viral claim to be false. Our research revealed that the video being shared on social media is not real but has been generated using artificial intelligence (AI).
Claim :
The claim was shared by a Facebook user on February 5, 2026, who wrote that a man was running on water using water bottles tied to his feet, calling it a unique attempt and questioning whether humans can run on water. Links to the post, its archived version, and screenshots are provided below.

Fact Check:
To verify the claim, we searched relevant keywords on Google but did not find any credible media reports supporting the incident. A closer examination of the viral video revealed several visual irregularities, raising suspicion that it may have been AI-generated. The video was then scanned using the AI detection tool Hive Moderation. According to the tool’s results, the video is 99 percent likely to be AI-generated.

Conclusion:
Our research confirms that the viral video does not depict a real incident and has been falsely shared as a genuine attempt to run on water.
.webp)
Executive Summary:
In late 2024 an Indian healthcare provider experienced a severe cybersecurity attack that demonstrated how powerful AI ransomware is. This blog discusses the background to the attack, how it took place and the effects it caused (both medical and financial), how organisations reacted, and the final result of it all, stressing on possible dangers in the healthcare industry with a lack of sufficiently adequate cybersecurity measures in place. The incident also interrupted the normal functioning of business and explained the possible economic and image losses from cyber threats. Other technical results of the study also provide more evidence and analysis of the advanced AI malware and best practices for defending against them.
1. Introduction
The integration of artificial intelligence (AI) in cybersecurity has revolutionised both defence mechanisms and the strategies employed by cybercriminals. AI-powered attacks, particularly ransomware, have become increasingly sophisticated, posing significant threats to various sectors, including healthcare. This report delves into a case study of an AI-powered ransomware attack on a prominent Indian healthcare provider in 2024, analysing the attack's execution, impact, and the subsequent response, along with key technical findings.
2. Background
In late 2024, a leading healthcare organisation in India which is involved in the research and development of AI techniques fell prey to a ransomware attack that was AI driven to get the most out of it. With many businesses today relying on data especially in the healthcare industry that requires real-time operations, health care has become the favourite of cyber criminals. AI aided attackers were able to cause far more detailed and damaging attack that severely affected the operation of the provider whilst jeopardising the safety of the patient information.
3. Attack Execution
The attack began with the launch of a phishing email designed to target a hospital administrator. They received an email with an infected attachment which when clicked in some cases injected the AI enabled ransomware into the hospitals network. AI incorporated ransomware was not as blasé as traditional ransomware, which sends copies to anyone, this studied the hospital’s IT network. First, it focused and targeted important systems which involved implementation of encryption such as the electronic health records and the billing departments.
The fact that the malware had an AI feature allowed it to learn and adjust its way of propagation in the network, and prioritise the encryption of most valuable data. This accuracy did not only increase the possibility of the potential ransom demand but also it allowed reducing the risks of the possibility of early discovery.
4. Impact
- The consequences of the attack were immediate and severe: The consequences of the attack were immediate and severe.
- Operational Disruption: The centralization of important systems made the hospital cease its functionality through the acts of encrypting the respective components. Operations such as surgeries, routine medical procedures and admitting of patients were slowed or in some cases referred to other hospitals.
- Data Security: Electronic patient records and associated billing data became off-limit because of the vulnerability of patient confidentiality. The danger of data loss was on the verge of becoming permanent, much to the concern of both the healthcare provider and its patients.
- Financial Loss: The attackers asked for 100 crore Indian rupees (approximately 12 USD million) for the decryption key. Despite the hospital not paying for it, there were certain losses that include the operational loss due to the server being down, loss incurred by the patients who were affected in one way or the other, loss incurred in responding to such an incident and the loss due to bad reputation.
5. Response
As soon as the hotel’s management was informed about the presence of ransomware, its IT department joined forces with cybersecurity professionals and local police. The team decided not to pay the ransom and instead recover the systems from backup. Despite the fact that this was an ethically and strategically correct decision, it was not without some challenges. Reconstruction was gradual, and certain elements of the patients’ records were permanently erased.
In order to avoid such attacks in the future, the healthcare provider put into force several organisational and technical actions such as network isolation and increase of cybersecurity measures. Even so, the attack revealed serious breaches in the provider’s IT systems security measures and protocols.
6. Outcome
The attack had far-reaching consequences:
- Financial Impact: A healthcare provider suffers a lot of crashes in its reckoning due to substantial service disruption as well as bolstering cybersecurity and compensating patients.
- Reputational Damage: The leakage of the data had a potential of causing a complete loss of confidence from patients and the public this affecting the reputation of the provider. This, of course, had an effect on patient care, and ultimately resulted in long-term effects on revenue as patients were retained.
- Industry Awareness: The breakthrough fed discussions across the country on how to improve cybersecurity provisions in the healthcare industry. It woke up the other care providers to review and improve their cyber defence status.
7. Technical Findings
The AI-powered ransomware attack on the healthcare provider revealed several technical vulnerabilities and provided insights into the sophisticated mechanisms employed by the attackers. These findings highlight the evolving threat landscape and the importance of advanced cybersecurity measures.
7.1 Phishing Vector and Initial Penetration
- Sophisticated Phishing Tactics: The phishing email was crafted with precision, utilising AI to mimic the communication style of trusted contacts within the organisation. The email bypassed standard email filters, indicating a high level of customization and adaptation, likely due to AI-driven analysis of previous successful phishing attempts.
- Exploitation of Human Error: The phishing email targeted an administrative user with access to critical systems, exploiting the lack of stringent access controls and user awareness. The successful penetration into the network highlighted the need for multi-factor authentication (MFA) and continuous training on identifying phishing attempts.
7.2 AI-Driven Malware Behavior
- Dynamic Network Mapping: Once inside the network, the AI-powered malware executed a sophisticated mapping of the hospital's IT infrastructure. Using machine learning algorithms, the malware identified the most critical systems—such as Electronic Health Records (EHR) and the billing system—prioritising them for encryption. This dynamic mapping capability allowed the malware to maximise damage while minimising its footprint, delaying detection.
- Adaptive Encryption Techniques: The malware employed adaptive encryption techniques, adjusting its encryption strategy based on the system's response. For instance, if it detected attempts to isolate the network or initiate backup protocols, it accelerated the encryption process or targeted backup systems directly, demonstrating an ability to anticipate and counteract defensive measures.
- Evasive Tactics: The ransomware utilised advanced evasion tactics, such as polymorphic code and anti-forensic features, to avoid detection by traditional antivirus software and security monitoring tools. The AI component allowed the malware to alter its code and behaviour in real time, making signature-based detection methods ineffective.
7.3 Vulnerability Exploitation
- Weaknesses in Network Segmentation: The hospital’s network was insufficiently segmented, allowing the ransomware to spread rapidly across various departments. The malware exploited this lack of segmentation to access critical systems that should have been isolated from each other, indicating the need for stronger network architecture and micro-segmentation.
- Inadequate Patch Management: The attackers exploited unpatched vulnerabilities in the hospital’s IT infrastructure, particularly within outdated software used for managing patient records and billing. The failure to apply timely patches allowed the ransomware to penetrate and escalate privileges within the network, underlining the importance of rigorous patch management policies.
7.4 Data Recovery and Backup Failures
- Inaccessible Backups: The malware specifically targeted backup servers, encrypting them alongside primary systems. This revealed weaknesses in the backup strategy, including the lack of offline or immutable backups that could have been used for recovery. The healthcare provider’s reliance on connected backups left them vulnerable to such targeted attacks.
- Slow Recovery Process: The restoration of systems from backups was hindered by the sheer volume of encrypted data and the complexity of the hospital’s IT environment. The investigation found that the backups were not regularly tested for integrity and completeness, resulting in partial data loss and extended downtime during recovery.
7.5 Incident Response and Containment
- Delayed Detection and Response: The initial response was delayed due to the sophisticated nature of the attack, with traditional security measures failing to identify the ransomware until significant damage had occurred. The AI-powered malware’s ability to adapt and camouflage its activities contributed to this delay, highlighting the need for AI-enhanced detection and response tools.
- Forensic Analysis Challenges: The anti-forensic capabilities of the malware, including log wiping and data obfuscation, complicated the post-incident forensic analysis. Investigators had to rely on advanced techniques, such as memory forensics and machine learning-based anomaly detection, to trace the malware’s activities and identify the attack vector.
8. Recommendations Based on Technical Findings
To prevent similar incidents, the following measures are recommended:
- AI-Powered Threat Detection: Implement AI-driven threat detection systems capable of identifying and responding to AI-powered attacks in real time. These systems should include behavioural analysis, anomaly detection, and machine learning models trained on diverse datasets.
- Enhanced Backup Strategies: Develop a more resilient backup strategy that includes offline, air-gapped, or immutable backups. Regularly test backup systems to ensure they can be restored quickly and effectively in the event of a ransomware attack.
- Strengthened Network Segmentation: Re-architect the network with robust segmentation and micro-segmentation to limit the spread of malware. Critical systems should be isolated, and access should be tightly controlled and monitored.
- Regular Vulnerability Assessments: Conduct frequent vulnerability assessments and patch management audits to ensure all systems are up to date. Implement automated patch management tools where possible to reduce the window of exposure to known vulnerabilities.
- Advanced Phishing Defences: Deploy AI-powered anti-phishing tools that can detect and block sophisticated phishing attempts. Train staff regularly on the latest phishing tactics, including how to recognize AI-generated phishing emails.
9. Conclusion
The AI empowered ransomware attack on the Indian healthcare provider in 2024 makes it clear that the threat of advanced cyber attacks has grown in the healthcare facilities. Sophisticated technical brief outlines the steps used by hackers hence underlining the importance of ongoing active and strong security. This event is a stark message to all about the importance of not only remaining alert and implementing strong investments in cybersecurity but also embarking on the formulation of measures on how best to counter such incidents with limited harm. AI is now being used by cybercriminals to increase the effectiveness of the attacks they make and it is now high time all healthcare organisations ensure that their crucial systems and data are well protected from such attacks.