#FactCheck -Misleading Social Media Claim Targets University Over Viral Video
Executive Summary
A video circulating on social media shows a woman using abusive language in front of a camera. Users sharing the clip claim that the woman is a professor at Galgotias University and that the video exposes her alleged reality. However, an research by CyberPeace found the claim to be misleading. The probe revealed that the woman seen in the viral video has no connection with Galgotias University and is not a professor there.Fact-checking further showed that the video is not recent but around seven years old. The woman featured in the clip was identified as Shubhrastha, who is a political strategist by profession.
Claim:
A user on X (formerly Twitter) shared the viral video on February 18, 2026, claiming: “A ‘class in abuse studies’ at Galgotias University? An obscene video of a professor teaching ethics has gone viral. Another shameful chapter has been added to the list of controversies surrounding Galgotias University.” The post further alleged that after falsely claiming a Chinese robot as its own, the university’s “Culture and Ethics” faculty member was seen publicly using abusive language in the viral clip. The post link and its archived version are provided below:

Fact Check:
To verify the authenticity of the viral claim, we extracted key frames from the video and conducted a reverse image search using Google Lens. During the research , we found the same video uploaded on the Indian Spectator’s YouTube channel on June 9, 2018

The video was also found on another YouTube channel, where it had been uploaded on June 12, 2018.

Conclusion
The research clearly establishes that the woman seen in the viral video has no association with Galgotias University and is not a professor there. The clip is also not recent but approximately seven years old. The woman in the video was identified as Shubhrastha, a political strategist.
Related Blogs

Overview:
‘Kia Connect’ is the application that is used to connect ‘Kia’ cars which allows the user control various parameters of the vehicle through the application on his/her smartphone. The vulnerabilities found in most Kias built after 2013 with but little exception. Most of the risks are derived from a flawed API that deals with dealer relations and vehicle coordination.
Technical Breakdown of Exploitation:
- API Exploitation: The attack uses the vulnerabilities in Kia’s dealership network. The researchers also noticed that, for example, the logs generated while impersonating a dealer and registering on the Kia dealer portal would be sufficient for deriving access tokens needed for next steps.
- Accessing Vehicle Information: The license plate number allowed the attackers to get the Vehicle Identification Number (VIN) number of their preferred car. This VIN can then be used to look up more information about the car and is an essential number to determine for the shared car.
- Information Retrieval: Having the VIN number in hand, attackers can launch a number of requests to backends to pull more sensitive information about the car owner, including:
- Name
- Email address
- Phone number
- Geographical address
- Modifying Account Access: With this information, attackers could change the accounts settings to make them a second user on the car, thus being hidden from the actual owner of the account.
- Executing Remote Commands: Once again, it was discovered that attackers could remotely execute different commands on the vehicle, which includes:some text
- Unlocking doors
- Starting the engine
- Monitoring the location of the vehicle in terms of position.
- Honking the horn
Technical Execution:
The researchers demonstrated that an attacker could execute a series of four requests to gain control over a Kia vehicle:
- Generate Dealer Token: The attacker sends an HTTP request in order to create a dealer token.
- Retrieve Owner Information: As indicated using the generated token, they make another request to another endpoint that returns the owner’s email address and phone number.
- Modify Access Permissions: The attacker takes advantage of the leaked information (email address and VIN) of the owner to change between users accounts and make himself the second user.
- Execute Commands: As the last one, they can send commands to perform actions on the operated vehicle.
Security Response and Precautionary Measures for Vehicle Owners
- Regular Software Updates: Car owners must make sure their cars receive updates on the recent software updates provided by auto producers.
- Use Strong Passwords: The owners of Kia Connect accounts should develop specific and complex passwords for their accounts and then update them periodically. They should avoid using numbers like the birth dates, vehicle numbers and simple passwords.
- Enable Multi-Factor Authentication: For security, vehicle owners should turn on the use of the secondary authentication when it is available to protect against unauthorized access to an account.
- Limit Personal Information Sharing: Owners of vehicles should be careful with the details that are connected with the account on their car, like the e-mail or telephone number, sharing them on social networks, for example.
- Monitor Account Activity: It is also important to monitor the account activity because of change or access attempts that are unauthorized. In case of any abnormality or anything suspicious felt while using the car, report it to Kia customer support.
- Educate Yourself on Vehicle Security: Being aware of cyber threats that are connected to vehicles and learning about how to safeguard a vehicle from such threats.
- Consider Disabling Remote Features When Not Needed: If remote features are not needed, then it is better to turn them off, and then turn them on again when needed. This can prove to help diminish the attack vector for would-be hackers.
Industry Implications:
The findings from this research underscore broader issues within automotive cybersecurity:
- Web Security Gaps: Most car manufacturers pay more attention to equipment running in automobiles instead of the safety of the websites that the car uses to operate thereby exposing automobiles that are connected very much to risks.
- Continued Risks: Vehicles become increasingly connected to internet technologies. Auto makers will have to carry cyber security measures in their cars in the future.
Conclusion:
The weaknesses found in Kia’s connected car system are a key concern for Automotive security. Since cars need web connections for core services, suppliers also face the problem of risks and need to create effective safeguards. Kia took immediate actions to tighten the safety after disclosure; however, new threats will emerge as this is a dynamic domain involving connected technology. With growing awareness of these risks, it is now important for car makers not only to put in proper security measures but also to maintain customer communication on how it safeguards their information and cars against cyber dangers. That being an incredibly rapid approach to advancements in automotive technology, the key to its safety is in our capacity to shield it from ever-present cyber threats.
Reference:
- https://timesofindia.indiatimes.com/auto/cars/hackers-could-unlock-your-kia-car-with-just-a-license-plate-is-yours-safe/articleshow/113837543.cms
- https://www.thedrive.com/news/hackers-found-millions-of-kias-could-be-tracked-controlled-with-just-a-plate-number
- https://www.securityweek.com/millions-of-kia-cars-were-vulnerable-to-remote-hacking-researchers/
- https://news24online.com/auto/kia-vehicles-hack-connected-car-cybersecurity-threat/346248/
- https://www.malwarebytes.com/blog/news/2024/09/millions-of-kia-vehicles-were-vulnerable-to-remote-attacks-with-just-a-license-plate-number
- https://informationsecuritybuzz.com/kia-vulnerability-enables-remote-acces/
- https://samcurry.net/hacking-kia

Introduction
Recently, the Delhi Police arrested a licensed telecom PoS agent, who identified himself as “Shivam Telecom," from a roadside kiosk adjacent to Hindu Rao Hospital. On the face of it, the headline may have simply read, “One man, one arrest." However, beneath that arrest is the unsettling story of a fully legitimate retail shop actively forging other people’s identification documents into weapons, one SIM card at a time, for as little as ₹500-600 each. This is not an account of an isolated offender; it is a peek into the vulnerability of SIM card security for typical end-users and the reasons why every mobile phone subscriber must pay attention to the unseen journey of his number.
Why SIM Security Matters Now
Erstwhile, a SIM card was only a simple device for sending text messages and making calls. Today, however, it’s also a direct link to most of our lives online, be it online banking to verify it through one-time passwords (OTP) or Unified Payments Interface (UPI); social media platforms; or email accounts to reset a forgotten password, two-factor authentications (2FA), or even numerous other online services. Therefore, losing a SIM card and getting it fraudulently issued under your name, or criminals accessing your identity to buy a SIM, can be a serious cause of concern, as they can then impersonate you, conduct various frauds, bypass checks, or commit acts that can lead to you being wrongly implicated.
According to the investigation, criminals were procuring SIM cards through the authorized outlets of telecom companies, not unlicensed dealers. This clearly proves a deficiency in the Know Your Customer (KYC) process for the SIM card activation. The situation, however, is worse and is also highlighted by the fact that more than 21 lakh mobile numbers from the more than 114 crore mobile numbers reviewed under the Sanchar Saathi initiative launched by the department of telecommunications (DoT) were associated with fake or invalid identity documents. A state police chief of Tamil Nadu claims that 90% of the cyber fraud cases involved SIM cards obtained through misused identity documents.
How Illegally Activated SIMs Fuel Everyday Scams?
Once a SIM is activated using someone else's identity documents or biometric data, without their knowledge, it becomes a disposable, hard-to-trace tool for criminals. Here's how that plays out in practice:
- Phishing and impersonation calls: Using an honest person’s details for a SIM registration allows the scammer to have a “clean” number that won’t tip off victims about a potential scam immediately when carrying out a fake bank call, fake delivery scam, or fake impersonation of an officer.
- OTP and account-takeover fraud: Since the SIM card is used as the anchor to OTP verification, an unauthorized SIM can be used to capture one-time passwords to activate new digital payments, create a new digital payments account, or use other personal information linked to your phone number to reset your service passwords.
- Financial fraud and money mule networks: According to the investigators, such SIMs were extensively being used to open digital payment accounts as well as to flow money across a number of fraud chains, thus enabling the fraudsters to build a layer of financial infrastructure that is not linked with their actual identities.
- Identity theft with real-world consequences: The identity of the Aadhaar holder (whose document was used to activate the SIM card) might be unaware that a SIM exists under his name until the fraud is uncovered during a loan default or a criminal investigation where he is forced to justify a crime committed using “his” number that he is oblivious to.
That is the anonymity that SIM-card fraud has: the fact that the SIM on the face of it seems genuine, but the one operating it and the registered owner have absolutely no relationship whatsoever.
Red Flags Every Mobile User Should Watch For
Most people won't know their identity has been misused until something goes visibly wrong. A few warning signs are worth taking seriously:
- Your SIM suddenly loses network connectivity or displays "No Service" for an extended period without any known outage, SIM replacement request, or billing issue.
- You stop receiving OTPs or verification messages for banking, UPI, or other online services, particularly if login attempts continue to occur on your accounts.
- You receive unexpected OTPs, verification codes, or account alerts for services you never signed up for, indicating that someone may be attempting to use your mobile number.
- You receive calls or messages intended for someone else or asking you to confirm activities you never performed, which may suggest your number has been misused or duplicated.
- Your bank or telecom provider notifies you of unusual account activity, failed identity verification, or changes that you did not authorize.
- You discover multiple mobile connections registered in your name that you never requested, a risk that often remains unnoticed unless you proactively check through the Department of Telecommunications' Sanchar Saathi portal.
None of these guarantee fraud, but any of them is a reason to check further rather than assume it's a glitch.
Practical Steps to Protect Yourself
The good news is that Indian users now have direct tools to check and control this exposure:
- Identify your SIMs: Via the Department of Telecom’s Sanchar Saathi website, you can access a list of all mobile numbers registered in your name. Report and get any SIMs you do not recognize deactivated promptly.
- Safeguard your identity documents and biometrics: Do not disclose your Aadhaar information, OTPs, or biometrics to unofficial persons or retail agents. Ensure your SIM is activated in your presence by an official dealer of the telecom company.
- Tighten the security of your accounts: Wherever possible, use the most secure multi-factor authentication methods; an authenticator app, rather than just SMS, would be ideal. Consider enabling account change or SIM swap notifications from your telecom provider.
- Stay vigilant about your bank accounts and financial activities. Watch for unusual OTP requests, password change requests, login notifications, and unrecognized devices being logged into your online accounts. Being observant early on helps minimize losses.
- Take swift action if a SIM stops working: Contact your telecom provider and report the misuse to the Sanchar Saathi website as well as your nearest cyber station, or file a complaint through the cybercrime helpline number.
A Shared Responsibility
Consumer vigilance is not enough to save the system. Telecom providers must verify customer authenticity and check their retail points sufficiently so that a roadside vendor of the likes of “Shivam Telecom” cannot have their retail outlet anywhere the retail outlets may not need to be established and can be run even from an abandoned car body on the street for weeks. Authorities are ensuring this by making all franchisees and PoS agents and distributors register, such that the individual activating each SIM is perfectly identifiable. Consumers should take precautions and report suspicious patterns and be vigilant for fraud detection and protect themselves by knowing the system, like the use of the Sanchar Saathi platform.
Conclusion
The Delhi fake SIM case proves that even sophisticated technologies are not enough to protect India’s telecom ecosystem. No amount of biometric validation, AI fraud prevention tools, or rigid KYC compliance can offset a single corrupt agent selling SIM cards over the counter. While law enforcement works to clamp down, the responsibility also falls upon consumers, who need to regularly monitor their SIM registrations, safeguard their identity, and report any suspicious transactions in time to minimize the threat of identity theft and SIM-based cybercrime.
Sources
- https://www.prokerala.com/news/articles/a1784141.html
- https://the420.in/dots-sanchar-saathi-initiative-exposes-21-lakh-sim-cards-activated-illegally
- https://www.sancharsaathi.gov.in/
- https://www.pib.gov.in/PressReleasePage.aspx?PRID=2113857
- https://www.business-standard.com/amp/industry/news/nearly-4-million-sims-deactivated-as-govt-cracks-down-on-digital-fraud-125080500300_1.html
- https://www.digit.in/news/telecom/here-are-5-new-sim-card-rules-implemented-by-dot-amid-rising-scams-and-frauds.html

Pretext
The Army Welfare Education Society has informed the Parents and students that a Scam is targeting the Army schools Students. The Scamster approaches the students by faking the voice of a female and a male. The scamster asks for the personal information and photos of the students by telling them they are taking details for the event, which is being organised by the Army welfare education society for the celebration of independence day. The Army welfare education society intimated that Parents to beware of these calls from scammers.
The students of Army Schools of Jammu & Kashmir, Noida, are getting calls from the scamster. The students were asked to share sensitive information. Students across the country are getting calls and WhatsApp messages from two numbers, which end with 1715 and 2167. The Scamster are posing to be teachers and asking for the students’ names on the pretext of adding them to the WhatsApp Groups. The scamster then sends forms links to the WhatsApp groups and asking students to fill out the form to seek more sensitive information.
Do’s
- Do Make sure to verify the caller.
- Do block the caller while finding it suspicious.
- Do be careful while sharing personal Information.
- Do inform the School Authorities while receiving these types of calls and messages posing to be teachers.
- Do Check the legitimacy of any agency and organisation while telling the details
- Do Record Calls asking for personal information.
- Do inform parents about scam calling.
- Do cross-check the caller and ask for crucial information.
- Do make others aware of the scam.
Don’ts
- Don’t answer anonymous calls or unknown calls from anyone.
- Don’t share personal information with anyone.
- Don’t Share OTP with anyone.
- Don’t open suspicious links.
- Don’t fill any forms, asking for personal information
- Don’t confirm your identity until you know the caller.
- Don’t Reply to messages asking for financial information.
- Don’t go to a fake website by following a prompt call.
- Don’t share bank Details and passwords.
- Don’t Make payment over a prompt fake call.