#FactCheck- Brigadier Assault in Delhi Not Linked to Dance Club or Military Operation
Research Wing
Innovation and Research
PUBLISHED ON
Apr 15, 2026
10
Executive Summary
Misleading claims related to an incident in Delhi are being widely circulated on social media. Several posts allege that an Indian Army brigadier and his son were assaulted while returning from a “dance club party.” The posts further claim that the attack was triggered by remarks related to “Operation Sindoor.” However, research by the CyberPeace found that these claims are completely false and fabricated.
Claim
On social media platform X, some users (including @ManipurPost5) shared posts claiming that an Indian Army brigadier and his son were attacked after returning from a dance club. The posts also alleged that the altercation escalated after someone mocked “Operation Sindoor.”
To verify the claim, we conducted keyword searches on Google and found a report published by Republic World on April 14, 2026, which included visuals similar to those being circulated.
According to the report, the victims were identified as Brigadier Parminder Singh Arora, a serving Indian Army officer, and his son Tejas Arora. At the time of the incident, they were taking a walk near their residence after dinner. Reports state that they noticed a group of individuals consuming alcohol inside a parked car in a public place and objected to it. This led to an argument, which later escalated into a violent assault. Around 7–8 individuals allegedly attacked the brigadier and his son, with the son sustaining more serious injuries. Questions have also been raised about the role of police personnel present at the scene. Following the complaint, a case was registered, one police constable was suspended, and two accused individuals have been arrested so far. The vehicle involved has also been seized. Further verification led us to another report published by India Today on April 14, 2026, which corroborated the same details of the incident.
The viral claim is misleading and entirely false.The incident has no connection to any “dance club party” or to “Operation Sindoor.” In reality, the altercation began after the brigadier objected to public drinking near his residence.
A video clip bearing the logo of News18 is being widely shared on social media with the claim that a serving Indian Army brigadier and his son were attacked in Delhi by an RSS-supporting mob for criticising the government over “Operation Sindoor.” The clip features an anchor allegedly explaining the motive behind the assault. However, research by the CyberPeace Research Wing found the claim to be false. The viral video has been digitally manipulated, with its audio altered to include misleading information.
Claim
An X user (@Mohammad776157) shared a video clip from Network18 on April 13, claiming that a serving Indian Army brigadier and his son were attacked in Delhi by an RSS-supporting mob for criticising the government over “Operation Sindoor.”
To verify the claim, we extracted multiple keyframes from the viral video using the InVid tool and conducted reverse image searches via Google Lens. The same clip was found circulating across several social media platforms with similar claims.
Since the video carried the News18 logo, we examined the outlet’s official social media handles. We found the original video on its X account, where the visuals matched the viral clip. However, a detailed analysis of the original footage showed that the anchor never stated that the brigadier and his son were attacked for criticising the government over “Operation Sindoor.”
In the authentic version, the anchor reported that the assault took place in Delhi’s Vasant Enclave after the brigadier objected to two individuals consuming alcohol inside a car parked outside his residence. This clearly indicates that the audio in the viral clip was tampered with to insert a false narrative.
For further verification, we extracted the audio segment from the viral clip and analysed it using Resemble AI. The tool indicated that the portion describing the motive behind the attack had been digitally manipulated.
Conclusion
The viral claim is false. The video has been altered by modifying its audio to mislead viewers. In reality, the assault was not related to “Operation Sindoor” but occurred after the brigadier objected to public drinking near his residence.
The Department of Telecommunications (DoT) changed course just 48 hours after the directive dated December 1, 2025, sparked controversy. On December 3, 2025, the department publicly reversed its directive to smartphone manufacturers to pre-install the Sanchar Saathi app starting in March of the following year. The withdrawal marked the ending of a tumultuous, quick-paced event that highlighted how dynamic digital policy can be in a democracy.
The DoT explained its move in calculated terms. The government said that the first mandate was no longer necessary due to an abrupt increase in voluntary app downloads brought on by the public furore. The agency stated , “The mandate to install the app was meant to accelerate the process because the number of users has been growing rapidly.”
The app in question is not new. When it was first introduced in 2023, it was intended to be a public safety where people could report suspicious calls, identify numbers registered in their name, block stolen devices using their IMEI, confirm the authenticity of their handset, and report fraudulent international calls that were disguised as Indian numbers. The platform has quietly expanded over the past two years with features like utilities to check mobile connections, as well as Chakshu for reporting fraud. When used freely, it has helped numerous people in navigating the increasingly complex web of online scams.
Balancing Protection and Personal Freedom
In India, there isn’t much precedent for requiring all phones to have a certain government backed app installed. While operators supported TRAI’s DND app in 2018 and emergency numbers were integrated during the pandemic, they did not go into the territory of compulsory pre-installation.
Legal experts have time and again pointed out that although the government can control telecommunications for security reasons, any mandatory action pertaining to personal devices may be subject to constitutional review under the right to privacy, as stated in the Puttaswamy ruling. Not because the app is flawed in and of itself, but rather because every transition from voluntary adoption to mandatory compliance necessitates a higher standard of necessity, proportionality, and protections.
The Pulse of the Policy
The DoT’s stated rationale was clear: fake, duplicated or spoofed IMEIs represent a major cyber-security threat. India currently faces some of the world’s highest levels of SIM misuse, digital impersonation, online extortion, and device cloning crimes. Even a small fraction of compromised devices can do great harm in a nation with over a billion active mobile users.
The DoT’s AI and Digital Intelligence Unit, a small seven-person team in charge of SIM security, fighting illicit telecom setups, and collaborating with financial regulators on quickly changing fraud patterns, issued the Sanchar Saathi directive as part of a larger set of security-focused measures. One order required platforms such as WhatsApp to make sure that web sessions were terminated after six hours and that accounts only functioned when the registered SIM card was present in the device.
When taken as a whole, these orders indicate a clear strategic goal, the government is working to close systemic gaps that organised crime, particularly identity theft and device-level fraud, exploits. However, they also highlight the complex relationship between public opinion and security requirements. The government’s quick reversal in the Sanchar Saathi case demonstrated a crucial realization: digital safety mechanisms can only be effective when people feel educated, valued, and in charge.
CyberPeace Perspective & The Middle Path
CyberPeace stated that whenever a digital tool comes into contact with identity, data, or mobile access, public concern is inevitable. However, it is also emphasised that Sanchar Saathi is not a surveillance tool, instead can empower citizens.
Even with the rolled back mandate, it is reaffirmed that cornerstones of digital trust are accountability, openness, audits, and unambiguous permissions. India can maintain both safety and rights through responsible implementation, ethical design, and open communication.
All citizens are using tech to their advantage, and so we see a lot of upskilling among the population leading to innovation in India. As we go deeper into cyberspace, we must maintain our cyber security efficiently and effectively. When bad actors use technology to their advantage, we often see data loss or financial loss of the victim, In this blog, we will shine light upon two new forms of cyber attacks, causing havoc upon the innocent. The “Daam” Malware and a new malicious app are the two new issues.
Daam Botnet
Since 2021, the DAAM Android botnet has been used to acquire unauthorised access to targeted devices. Cybercriminals use it to carry out different destructive actions. Using the DAAM Android botnet’s APK binding service, threat actors can combine malicious code with a legitimate application. Keylogging, ransomware, VOIP call records, runtime code execution, browser history collecting, incoming call recording, PII data theft, phishing URL opening, photo capture, clipboard data theft, WiFi and data status switching, and browser history gathering are just a few of the functions offered by the DAAM Android botnet. The DAAM botnet tracks user activity using the Accessibility Service and stores keystrokes it has recorded together with the name of the programme package in a database. It also contains a ransomware module that encrypts and decrypts data on the infected device using the AES method.
Additionally, the botnet uses the Accessibility service to monitor the VOIP call-making features of social media apps like WhatsApp, Skype, Telegram, and others. When a user engages with these elements, the virus begins audio recording.
The Malware
CERT-IN, the central nodal institution that reacts to computer security-related issues, claims that Daam connects with various Android APK files to access a phone. The files on the phone are encrypted using the AES encryption technique, and it is distributed through third-party websites.
It is claimed that the malware can damage call recordings and contacts, gain access to the camera, change passwords, take screenshots, steal SMS, download/upload files, and perform a variety of other things.
Safeguards and Guidelines by Cert-In
Cert-In has released the guideline for combating malware. These were issued in the public interest. The recommendations by Cert-In are as follows-
Only download from official app stores to limit the risk of potentially harmful apps.
Before downloading an app, always read the details and user reviews; likewise, always give permissions that are related to the program’s purpose.
Install Android updates solely from Android device vendors as they become available.
Avoid visiting untrustworthy websites or clicking on untrustworthy
Install and keep anti-virus and anti-spyware software up to date.
Be cautious if you see mobile numbers that appear to be something other than genuine/regular mobile numbers.
Conduct sufficient investigation Before clicking on a link supplied in a communication.
Only click on URLs that clearly display the website domain; avoid abbreviated URLs, particularly those employing bit.ly and tinyurl.
Use secure browsing technologies and filtering tools in antivirus, firewall, and filtering services.
Before providing sensitive information, look for authentic encryption certificates by looking for the green lock in your browser’s URL information, look for authentic encryption certificates by looking for the green lock in your browser’s URL bar.
Any ‘strange’ activity in a user’s bank account must be reported immediately to the appropriate bank.
New Malicious App
From the remote parts of Jharkhand, a new form of malicious application has been circulated among people on the pretext of a bank account closure. The bad actors have always used messaging platforms like Whatsapp and Telegram to circulate malicious links among unaware and uneducated people to dupe them of their hard-earned money.
They send an ordinary-looking message on Whatsapp or Telegram where they mention that the user has a bank account at ICICI bank and, due to irregularity with the credentials, their account is being deactivated. Further, they ask users to update their PAN card to reactivate their account by uploading the PAN card on an application. This app, in turn, is a malicious app that downloads all the user’s personal credentials and shares them with the bad actors via text message, allowing them to bypass banks’ two-factor authentication and drain the money from their accounts. The Jharkhand Police Cyber Cells have registered numerous FIRs pertaining to this type of cybercrime and are conducting full-scale investigations to apprehend the criminals.
Conclusion
Malware and phishing attacks have gained momentum in the previous years and have become a major contributor to the tally of cybercrimes in the country. DaaM malware is one of the examples brought into light due to the timely action by Cert-In, but still, a lot of such malware are deployed by bad actors, and we as netizens need to use our best practices to keep such criminals at bay. Phishing crimes are often substantiated by exploiting vulnerabilities and social engineering. Thus working towards a rise in awareness is the need of the hour to safeguard the population by and large.
Become a part of our vision to make the digital world safe for all!
Numerous avenues exist for individuals to unite with us and our collaborators in fostering global cyber security
Awareness
Stay Informed: Elevate Your Awareness with Our Latest Events and News Articles Promoting Cyber Peace and Security.
Your institution or organization can partner with us in any one of our initiatives or policy research activities and complement the region-specific resources and talent we need.