#FactCheck- AI Video Fuels False Claims of Israeli Soldiers’ Death in Plane Crash
Executive Summary
A video circulating on social media is being linked to the ongoing tensions in West Asia involving the United States, Israel, and Iran. The clip shows an aircraft crashing into a residential area, with users claiming that a Dubai-bound plane carrying Israeli soldiers crashed near Tel Aviv airport, killing everyone on board. However, an research by the CyberPeace has found the claim to be false. The viral video is AI-generated, and no such incident has taken place in Israel.
Claim
An Instagram user “bebakawaaztv” shared the video on April 7, 2026, claiming that a Dubai aircraft carrying Israeli soldiers crashed near Tel Aviv airport in a residential area, allegedly after being hit by debris from an Iranian hypersonic missile.

Fact Check
To verify the claim, we closely examined the viral video. Several visual inconsistencies indicated that it was not real. The aircraft appears to be flying unusually low over a residential area—something that is highly improbable under normal aviation conditions. Its landing gear seems to touch rooftops without causing any visible damage. Additionally, the wings of the aircraft pass through structures like poles without any collision impact, which is physically impossible. These anomalies strongly suggested that the video was artificially created.
We further analyzed the video using the AI detection tool HIVE Moderation, which indicated a 99% probability that the content is AI-generated.

Another analysis using Sightengine also flagged the video as likely AI-generated.

Conclusion
The viral claim is false and misleading. There is no credible evidence or verified report confirming that any Dubai aircraft carrying Israeli soldiers crashed near Tel Aviv airport. No such incident has been reported by any reliable international or local media outlets. The video in question is digitally fabricated using AI technology, and the visual inconsistencies within the clip clearly indicate manipulation. Such content is often designed to exploit ongoing geopolitical tensions and spread misinformation at scale
Related Blogs

Executive Summary:
In the recent advisory the Indian Computer Emergency Response Team (CERT-In) has released a high severity warning in the older versions of the software across Apple devices. This high severity rating is because of the multiple vulnerabilities reported in Apple products which could allow the attacker to unfold the sensitive information, and execute arbitrary code on the targeted system. This warning is extremely useful to remind of the necessity to have the software up to date to prevent threats of a cybernature. It is important to update the software to the latest versions and cyber hygiene practices.
Devices Affected:
CERT-In advisory highlights significant risks associated with outdated software on the following Apple devices:
- iPhones and iPads: iOS versions that are below 18 and the 17.7 release.
- Mac Computers: All macOS builds before 14.7 (20G71), 13.7 (20H34), and earlier 20.2 for Sonoma, Ventura, Sequoia, respectively.
- Apple Watches: watchOS versions prior to 11
- Apple TVs: tvOS versions prior to 18
- Safari Browsers: versions prior to 18
- Xcode: versions prior to 16
- visionOS: versions prior to 2
Details of the Vulnerabilities:
The vulnerabilities discovered in these Apple products could potentially allow attackers to perform the following malicious activities:
- Access sensitive information: The attackers could easily access the sensitive information stored in other parts of the violated gadgets.
- Execute arbitrary code: The web page could be compromised with malcode and run on the targeted system which in the worst scenario would give the intruder full Administrator privileges on the device.
- Bypass security restrictions: Measures agreed to safeguard the device and information contained on it may be easily bypassed and the system left open to more proliferation.
- Cause denial-of-service (DoS) attacks: The vulnerabilities could be used to cause the targeted device or service to be unavailable to the rightful users.
- Perform spoofing attacks: There could be a situation where the attackers created fake entities or users or accounts to have a way into important information or do other unauthorized activities.
- Elevate privileges: It is also stated that weaknesses might be exploited to authorize the attacker a higher level of privileges in the system they are targets.
- Engage in cross-site scripting (XSS) attacks: Some of them make the associated Web applications/sites prone to XSS attacks by injecting hostile scripts into Web page code.
Vulnerabilities:
CVE-2023-42824
- Attack vector could allow a local attacker to elevate their privileges and potentially execute arbitrary code.
Affected System
- Apple's iOS and iPadOS software
CVE-2023-42916
- To improve the out of bounds read it was mitigated with improved input validation which was resolved later.
Affected System
- Safari, iOS, iPadOS, macOS, and Apple Watch Series 4 and later devices running watchOS 10.2
CVE-2023-42917
- leads to arbitrary code execution, and there have been reports of it being exploited in earlier versions of iOS.
Affected System
- Apple's Safari browser, iOS, iPadOS, and macOS Sonoma systems
Recommended Actions for Users:
To mitigate these risks, that users take immediate action:
- Update Software: Ensure all your devices are on the most current version of the operating systems they use. Repetitive updates have important security updates that fix identified weaknesses or flaws within the system.
- Monitor Device Activity: Stay vigilant if something doesn’t seem right; if your gadgets are accessed by someone who isn’t you.
- Always use strong, distinct passwords and use two-factor authentication.
- Install and update the antivirus and Firewall softwares.
- Avoid downloading any applications or clicking link from unknown sources
Conclusion:
The advisory from CERT-In, clearly demonstrates the fundamental need of keeping the software on all Apple devices up to date. Consumers need to act right away to patch their devices and apply best security measures like using multiple factors for login and system scanning. This advisory has come out when Apple has just released new products into the market such as the iPhone 16 series in India. When consumers embrace new technologies it is important for them to observe relevant measures of security precautions. Maintaining good cyber hygiene is a critical process for the protection against new threats.
Reference:
- https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES02&VLCODE=CIAD-2023-0043
- https://www.cve.org/CVERecord?id=CVE-2023-42916
- https://www.cve.org/CVERecord?id=CVE-2023-42917
- https://www.bizzbuzz.news/technology/gadjets/cert-in-issues-advisory-on-vulnerabilities-affecting-iphones-ipads-and-macs-1337253#google_vignette
- https://www.wionews.com/videos/india-warns-apple-users-of-high-severity-security-risks-in-older-software-761396

Introduction
As India moves full steam ahead towards a trillion-dollar digital economy, how user data is gathered, processed and safeguarded is under the spotlight. One of the most pervasive but least known technologies used to gather user data is the cookie. Cookies are inserted into every website and application to improve functionality, measure usage and customize content. But they also present enormous privacy threats, particularly when used without explicit user approval.
In 2023, India passed the Digital Personal Data Protection Act (DPDP) to give strong legal protection to data privacy. Though the act does not refer to cookies by name, its language leaves no doubt as to the inclusion of any technology that gathers or processes personal information and thus cookies regulation is at the centre of digital compliance in India. This blog covers what cookies are, how international legislation, such as the GDPR, has addressed them and how India's DPDP will regulate their use.
What Are Cookies and Why Do They Matter?
Cookies are simply small pieces of data that a website stores in the browser. They were originally designed to help websites remember useful information about users, such as your login session or what is in your shopping cart. Netscape initially built them in 1994 to make web surfing more efficient.
Cookies exist in various types. Session cookies are volatile and are deleted when the browser is shut down, whereas persistent cookies are stored on the device to monitor users over a period of time. First-party cookies are made by the site one is visiting, while third-party cookies are from other domains, usually utilised for advertisements or analytics. Special cookies, such as secure cookies, zombie cookies and tracking cookies, differ in intent and danger. They gather information such as IP addresses, device IDs and browsing history information associated with a person, thus making it personal data per the majority of data protection regulations.
A Brief Overview of the GDPR and Cookie Policy
The GDPR regulates how personal data can be processed in general. However, if a cookie collects personal data (like IP addresses or identifiers that can track a person), then GDPR applies as well, because it sets the rules on how that personal data may be processed, what lawful bases are required, and what rights the user has.
The ePrivacy Directive (also called the “Cookie Law”) specifically regulates how cookies and similar technologies can be used. Article 5(3) of the ePrivacy Directive says that storing or accessing information (such as cookies) on a user’s device requires prior, informed consent, unless the cookie is strictly necessary for providing the service requested by the user.
In the seminal Planet49 decision, the Court of Justice of the European Union held that pre-ticked boxes do not represent valid consent. Another prominent enforcement saw Amazon fined €35 million by France's CNIL for using tracking cookies without user consent.
Cookies and India’s Digital Personal Data Protection Act (DPDP), 2023
India's Digital Personal Data Protection Act, 2023 does not refer to cookies specifically but its provisions necessarily come into play when cookies harvest personal data like user activity, IP addresses, or device data. According to DPDP, personal data is to be processed for legitimate purposes with the individual's consent. The consent has to be free, informed, clear and unambiguous. The individuals have to be informed of what data is collected, how it will be processed.. The Act also forbids behavioural monitoring and targeted advertising in the case of children.
The Ministry of Electronics and IT released the Business Requirements Document for Consent Management Systems (BRDCMS) in June 2025. Although it is not binding by law, it provides operational advice on cookie consent. It recommends that websites use cookie banners with "Accept," "Reject," and "Customize" choices. Users must be able to withdraw or change their consent at any moment. Multi-language handling and automatic expiry of cookie preferences are also suggested to suit accessibility and privacy requirements.
The DPDP Act and the BRDCMS together create a robust user-rights model, even in the absence of a special cookie law.
What Should Indian Websites Do?
For the purposes of staying compliant, Indian websites and online platforms need to act promptly to harmonise their use of cookies with DPDP principles. This begins with a transparent and simple cookie banner providing users with an opportunity to accept or decline non-essential cookies. Consent needs to be meaningful; coercive tactics such as cookie walls must not be employed. Websites need to classify cookies (e.g., necessary, analytics and ads) and describe each category's function in plain terms under the privacy policy. Users must be given the option to modify cookie settings anytime using a Consent Management Platform (CMP). Monitoring children or their behavioural information must be strictly off-limits.
These are not only about being compliant with the law, they're about adhering to ethical data stewardship and user trust building.
What Should Users Do?
Cookies need to be understood and controlled by users to maintain online personal privacy. Begin by reading cookie notices thoroughly and declining unnecessary cookies, particularly those associated with tracking or advertising. The majority of browsers today support blocking third-party cookies altogether or deleting them periodically.
It is also recommended to check and modify privacy settings on websites and mobile applications. It is possible to minimise surveillance with the use of browser add-ons such as ad blockers or privacy extensions. Users are also recommended not to blindly accept "accept all" in cookie notices and instead choose "customise" or "reject" where not necessary for their use.
Finally, keeping abreast of data rights under Indian law, such as the right to withdraw consent or to have data deleted, will enable people to reclaim control over their online presence.
Conclusion
Cookies are a fundamental component of the modern web, but they raise significant concerns about individual privacy. India's DPDP Act, 2023, though not explicitly referring to cookies, contains an effective legal framework that regulates any data collection activity involving personal data, including those facilitated by cookies.
As India continues to make progress towards comprehensive rulemaking and regulation, companies need to implement privacy-first practices today. And so must the users, in an active role in their own digital lives. Collectively, compliance, transparency and awareness can build a more secure and ethical internet ecosystem where privacy is prioritised by design.
References
- https://prsindia.org/billtrack/digital-personal-data-protection-bill-2023
- https://gdpr-info.eu/
- https://d38ibwa0xdgwxx.cloudfront.net/create-edition/7c2e2271-6ddd-4161-a46c-c53b8609c09d.pdf
- https://oag.ca.gov/privacy/ccpa
- https://www.barandbench.com/columns/cookie-management-under-the-digital-personal-data-protection-act-2023#:~:text=The%20Business%20Requirements%20Document%20for,the%20DPDP%20Act%20and%20Rules.
- https://samistilegal.in/cookies-meaning-legal-regulations-and-implications/#
- https://secureprivacy.ai/blog/india-digital-personal-data-protection-act-dpdpa-cookie-consent-requirements
- https://law.asia/cookie-use-india/
- https://www.cookielawinfo.com/major-gdpr-fines-2020-2021/#:~:text=4.,French%20websites%20could%20refuse%20cookies.

Introduction
In a significant step, the Indian Army beefed up its information warfare capacity on June 25, 2026, with the operationalisation of @MythbusterXX, its dedicated fact-checking handle designed to counter any form of misinformation, disinformation, malinformation, and deepfakes on the army swiftly. Adopting the motto 'Verify Before You Amplify,' the service seeks to pivot from reactive statements to active cognitive warfare. In a milieu where manipulated narratives can be as decisive in shaping public perception as kinetic force is on the battlefield, truth itself has transformed into a critical national security objective.
This is clear proof that protecting India’s digital battleground will from now on be defined not just by troop deployments but also by its institutional verification capacities, swift attribution mechanisms, and public awareness.
When the Battlefield Went Digital
Today warfare extends to timelines, group chats, and prime-time graphics packages. The distinction between misinformation , disinformation , and malinformation is crucial to operations. After all, they necessitate different types of counters. Generative AI just exponentially increased their velocity, cost, and the creepy believability of synthesized audio, video, and images. Operation Sindoor, India's May 2025 military response to a Pahalgam terror attack, provides a blueprint for just how large it can get.
According to the fact-checking site BOOM, 68% of fact checks in May related to Operation Sindoor, describing the campaign as a misinformation superspreader, and, more directly, India's Chief of Defence Staff General Anil Chauhan lamented at last year’s Shangri-La Dialogue that roughly 15% of his military’s operational time was spent on countering false news. New Delhi matched this response level; the Ministry of Information and Broadcasting had blocked over 1,400 URLs, many bearing false information or communally inciteful narratives from accounts in Pakistan. These challenges won't be vanishing any time soon. Microsoft's July 2025 Digital Defence Report lists India among the top countries targeted for AI-powered state-backed hacking, noting the automation of attacks and generation of fake content used to influence opinion.
CyberPeace's regulatory tracking also indicates steps toward building infrastructure to mitigate this, a Rule 7 complaint system for deepfakes, and efforts to foster local detection capabilities under the IndiaAI mission signal it's now an infrastructural threat.
Why the Army Chose to Speak First
On 1 June 2026, the Indian government’s official fact-checking unit debunked a deepfake of former Army Chief General Dhiraj Seth talking about India’s engagement with the Taliban that emanated from Pakistan-affiliated propaganda sources, appearing within days of a change of military command. Barely days after General Dhiraj Seth was elevated to Chief of Army Staff, the 31st person to hold the post, another fabricated deepfake used spliced authentic footage with AI-cloned audio to falsely allege he had blamed the past army leadership for hiding the bodies of soldiers to protect their image.
Such a dual targeting of India’s army chiefs with deepfakes in such close succession is a testament as to why an authoritative, constantly running fact-check machine isn’t an optional extra but a strategic must-have.
Architecture is as important as architecture itself. India tried a statutory fact-checking model with a government-owned Fact Check Unit under the Information Technology (IT) Rules of 2023 through the Press Information Bureau (PIB). It had to retreat from the edge of the constitutional cliff. In September 2024, when the Bombay High Court struck down key provisions of these rules. It ruled it unconstitutional to empower the state to declare digital content relating to the state itself as fake, false, or misleading. A similar reading of the analysis by CyberPeace found that digital speech should be given the same protections as offline speech, and this should be the benchmark for any counter-misinformation policy.
MythbusterXX carefully avoids the constitutional controversy by acting as an institutional avenue that produces verified information and rebuttals in response to disinformation. There is a profound distinction between answering falsehoods with factual, credible speech versus shutting them down with state power, the very proportionality that civil libertarians have said must govern a democracy's approach to online misinformation.
Platforms as Accelerants, Not Just Conduits
Part of the issue lies upstream, with the algorithms and broadcasters that favor speedy falsehood over careful confirmation. A month’s supply of “false and misleading stories,” the Reuters Institute for the Study of Journalism observed, streamed online within hours of Operation Sindoor's onset: one fact-checker identified approximately seventy false claims by the close of day one. Meanwhile, on the small screen, graphics depicting escalating conflicts were being televised, with broadcasters forced to scramble under 24/7 competition.
Amplified manipulation of the crisis narrative is also a factor; studies show that thousands of accounts have been reposting exactly the same party content for three years, making crisis-induced viral narratives predictable rather than organic phenomena. For the most part, the platforms that manage these narratives and the algorithms that direct content on both sides of the divide are not just innocent delivery systems.
Digital Literacy as the First Line of Defence
Institutional rebuttals only go so far if citizens lack the reflex to pause before sharing, which is where CyberPeace's own work becomes directly relevant. Through a multi-year, Google.org-backed initiative, CyberPeace Foundation aims to reach over 40 million Indian internet users, including 9 million underserved beneficiaries, through a multilingual resource centre offering 650 hours of content, state-level helplines, and quick-response teams staffed by digital forensics and fact-checking experts. Longer-running efforts such as the Digital Shakti campaign and the annual eRaksha competition, run with NCERT, have built a culture of responsible digital citizenship among young and first-time internet users since 2019, while CyberPeace Corps, the foundation's volunteer arm, carries the same message into classrooms and campuses through cyber-awareness sessions run with universities and school networks nationwide. Notably, CyberPeace's own research on children's online safety had already flagged manipulated Army-related videos as a category of digital manipulation designed to cast doubt on official military positions, well before @MythbusterXX existed. The Army's tagline and CyberPeace's mission converge on the same insight: verification is a civic skill, not merely an institutional service.
A Season of Deepfakes
The history book of compromised defence material in the past year alone would be edifying. The International Federation of Journalists recorded one such deepfake widely circulated that relied on AI voice cloning and lip-sync tools to present the Pakistani PM conceding defeat, though the video actually contained his praise for the Pakistani air force’s performance following Operation Sindoor.
Other similar videos featured the Indian Prime Minister, External Affairs Minister, and Home Minister allegedly apologising to Pakistan and a deepfake with a foreign head of state in voice-cloned style applauding India’s armed forces. None needed a state’s resources, but just a laptop, voice cloning available readily, and a citizenry ready to spread rather than confirm the authenticity of any such sensational information before spreading it on to the masses.
Building the Verification Reflex
A resilient information ecosystem needs different actors playing complementary roles:
- Citizens: Do not equate virality with credibility. Verify all national security-related information through official sources, such as @MythbusterXX, before reposting or forwarding it.
- Journalists: Apply rigorous verification standards to live broadcasts, war-room graphics, and breaking reports, just as you would to print journalism, and avoid speculation during fast-moving military operations.
- Researchers and fact-checkers: Use open-source forensic and AI-detection technologies to authenticate questionable material. BOOM researchers, for instance, used Deepfake-o-meter to scrutinize misleading videos of political leaders before fact-checking and publishing them.
- Policymakers: Favored constitutionally proportional and carefully tailored regulations over broad-based takedown mandates. While the 2026 IT Amendment Rules require platforms to shift their obligations from compliance with takedowns towards preventive diligence on synthetic media, implementation should continue to be informed by judicial protections afforded to freedom of speech and due process.
Cyber Resilience Is National Security Now
Legal scholars examining Operation Sindoor have drawn a useful distinction between coordinated information warfare, which is strategic and intentional, and the diffuse, uncoordinated mis/disinformation that dominated timelines during the conflict, cautioning that disproportionate state responses to the latter can compromise citizens' right to know just as much as the falsehoods themselves. Getting that balance right, between speed and due process, between institutional voice and censorship, is the real test facing India's information ecosystem, in defence and far beyond it. CyberPeace has made a related argument in its own work on AI-enabled espionage: institutions such as the National Critical Information Infrastructure Protection Centre and the Defence Cyber Agency are already folding AI-based monitoring into their processes, yet no amount of institutional surveillance substitutes for a citizenry trained to spot manipulation on sight.
@MythbusterXX will not end deepfakes, and no single handle can. But it signals something CyberPeace has argued for years: resilience against synthetic and manipulated media requires authoritative institutional voices, digitally literate citizens, forensically equipped researchers, and proportionate policy, all pulling in the same direction. "Verify before you amplify" is not just an Army campaign. It is the operating discipline a democracy needs to protect its own information age.
Conclusion
@MythbusterXX can't possibly kill deepfakes and disinformation, but this marks a milestone shift towards developing an institutional resilience for India's info battlefield. For, after all, national security in the age of info warfare depends less on tech and more on robust institutions, constitutional balance in policymaking, responsible social platforms, and a citizenry that clicks "forward" only after clicking "verify."
* * * * *
This piece is part of CyberPeace's ongoing work on misinformation, disinformation, and digital citizenship in India. For more on CyberPeace's initiatives in digital literacy and cyber resilience, visit cyberpeace.org.
Key Sources
- Dynamite News, "Indian Army launches fact-check push against deepfake videos and fake military claims" (June 2026)
- ADG PI – Indian Army, official announcement on X (@adgpi)
- Press Information Bureau, Government of India, press release on countering misinformation during Operation Sindoor
- Reuters Institute for the Study of Journalism, "Truth is the casualty: How Indian fact-checkers debunked false claims during the India-Pakistan crisis"
- International Federation of Journalists, "AI, Deepfakes, and the Fog of War" and "Operation Sindoor and the Two Wars" (June 2025)
- Republic World, "Operation Sindoor Haunts Pakistan: Islamabad's Latest AI Deepfake Bid Against Indian Army Chief General Dhiraj Seth Exposed" (July 2026)
- TechPolicy Press, "Sanity Prevails as Bombay High Court Strikes Down India Government's Fact Check Unit", and LiveLaw, coverage of the tie-breaker verdict, on the IT Amendment Rules, 2023 (Fact-Check Unit)
- Dark Reading, "Indian Army Propaganda Spread by 1.4K AI-Powered Social Media Accounts"
- Inforrm, "(Dis)information warfare and the right to know: lessons from Operation Sindoor"
- CyberPeace Foundation, initiatives page and The CyberPeace Initiative (Google.org-backed digital literacy programme)
- CyberPeace Foundation, "AI-Powered Espionage: How India's Cybersecurity Strategy Must Evolve"
- CyberPeace Foundation, "From Deepfakes to Due Diligence – Decoding India's IT Amendment Rules"
- Wikipedia, CyberPeace Foundation (background on Digital Shakti and eRaksha)