#FactCheck- Old March Strike Video from Tehran Falsely Linked to Recent Iran–Israel Attacks
Executive Summary
Following recent escalations between Iran and Israel, where both countries reportedly exchanged missile strikes over the weekend, a video is now circulating on social media claiming to show the latest attacks between the two nations. However, CyberPeace Research Wing research found that the viral video is not related to the recent developments. The footage is actually from a March incident involving reported US-Israeli strikes in Tehran’s Jannat Abad area.
Claim
An X (formerly Twitter) user shared the viral video with the caption:“Israel, ignoring Trump’s advice, has carried out a major retaliatory strike on Tehran, Karaj, Tabriz, and Kermanshah.”
https://x.com/ocjain4/status/2063844698138239357?s=20
The video is being widely shared with claims that it shows recent Iran–Israel missile exchanges following Sunday’s reported attacks.

Fact Check
To verify the claim, we extracted keyframes from the viral video and conducted a reverse image search. The research led us to a post from BBC Persian journalist Ghoncheh Habibiazad’s X account dated 3 March. The video was shared with a caption describing it as showing a strike in Tehran attributed to US-Israeli action.
https://x.com/GhonchehAzad/status/2028632595156598874?s=20

Further verification found the same footage published by Sky News and uploaded on Al Arabiya’s YouTube channel on 3 March 2026. The accompanying descriptions referred to smoke rising from Tehran’s District 5 and near the Hemmat Expressway following the strike.
https://news.sky.com/video/smoke-seen-rising-after-strike-in-tehran-13514731
https://www.youtube.com/shorts/AceFmYiBkuA


Additionally, a comparison using Google Satellite View confirmed that the location seen in the viral video matches the same area shown in the earlier March footage shared by BBC-affiliated reporting.

Conclusion
Our research confirms that the viral video has no connection to the recent Iran–Israel missile exchanges. The footage is from a March incident showing reported strikes in Tehran’s Jannat Abad area, and is being misleadingly shared as a recent escalation between the two countries.
Related Blogs

Introduction
For years, the story of terror recruitment in Jammu & Kashmir followed a familiar arc: physical infiltration across the Line of Control, local Over Ground Workers (OGWs) acting as couriers, and recruitment pitches on mainstream apps like WhatsApp and Facebook Messenger. Indian security agencies built entire surveillance architectures around that arc. Now, officials say, the architecture is being outflanked in a way few anticipated: through pornography and dating platforms.
The New Front: Chat Rooms Nobody Is Watching
According to officials cited in recent reporting, Pakistan-based terror handlers working in coordination with Pakistan's ISI have begun exploiting the real-time chat features built into pornography and dating websites to reach recruits in Jammu & Kashmir. These pornography platforms feature real-time chat tools that operate under the guise of helping users find dates nearby, and handlers are exploiting that feature to broadcast messages and coordinate activities. It's a strikingly mundane pivot for an organisation engaged in violent extremism, but that is precisely the point that nobody expects a counter-terror dragnet to be watching a dating chatbox.
Officials say the tactic is designed to evade the surveillance that has become standard on conventional social media platforms, allowing handlers to convey instructions to recruits while staying off the radar of established monitoring tools. WhatsApp, Signal and Facebook Messenger have all, in various ways, become known quantities to Indian intelligence subject to legal intercepts, metadata analysis and years of institutional familiarity. A chat window buried inside an adult content site is not.
Tor, Encrypted Nodes, and Apps Built to Disappear
Other than porn sites, investigators have also flagged a cluster of niche, privacy-first messaging apps that route traffic through Tor-based, encrypted nodes to mask user identity. Security agencies have placed a wide array of specialised digital tools under scrutiny, with terror handlers relying on Tor-based messaging applications like Coatex and Conion to route data through encrypted nodes and obscure user identities. Access to at least one of these apps' installation files is reportedly already restricted within India, though enforcement against sideloaded Android packages remains an uphill battle.
What makes these platforms attractive to handlers isn't unique code so much as the design philosophy behind privacy-first messaging generally. Some of these apps offer only basic encryption, while others go further with end-to-end encryption, self-destructing messages, and strong on-device encryption algorithms that keep data processing off any third-party server. Several reportedly allow account creation without a phone number or SIM verification, stripping away one of the most basic identity anchors that Indian telecom-linked surveillance depends on.
There's also an operational, almost logistical, reason for the shift: connectivity. Officials note that some of these applications provide end-to-end encryption, self-destructing messages and registration without a phone number or email, making it difficult for security agencies to trace users, even as terror networks also shift away from commonly used platforms. In the hilly, forested and often poorly connected terrain of Jammu's border districts, apps engineered to function on weak 2G or EDGE networks have an obvious tactical advantage over data-hungry mainstream platforms.
VPNs, Banned Apps, and a Cat-and-Mouse Game
Virtual Private Networks add another layer of obfuscation, letting operatives access apps banned in India and mask the geographic origin of their traffic. This isn't new tradecraft, but its pairing with adult-content chat infrastructure and Tor-routed messaging represents a genuinely novel combination in the Kashmir context, according to the officials describing the pattern to reporters.
The broader trend line, officials say, is a steady migration away from platforms Indian agencies have learned to monitor. Terror networks are increasingly moving away from mainstream, commonly used platforms in favour of more obscure alternatives, forcing intelligence agencies into a perpetual game of catch-up: each time a monitoring capability matures against one platform, handlers migrate to the next.
This is not the first time investigators have flagged this cat-and-mouse dynamic. Reporting on a recent case in Jammu's Bathindi area described a 19-year-old allegedly radicalised through the encrypted app. Session the same platform reportedly linked to suspects in a Delhi bomb plot investigation after months of contact with Pakistan-based handlers. Investigators in that case noted that terror organisations have increasingly turned to multi-layered encrypted messaging services specifically to evade monitoring by intelligence agencies.
The Virtual SIM Problem
Alongside app-layer evasion, foreign-issued virtual SIM cards remain a persistent headache for investigators. The most cited example remains the 2019 Pulwama attack investigation, in which agencies reportedly traced more than 40 virtual SIM cards to the Jaish-e-Mohammed suicide bomber and his network numbers that could be provisioned and abandoned without ever touching an Indian telecom's KYC system. That case became something of a template for how virtual and foreign-registered numbers can be used to build communication chains that are extremely difficult to map after the fact, since there is no physical SIM, no retail purchase record, and often no domestic carrier data trail at all.
More recent J&K cases echo the same pattern in a different form. Police investigating a cross-border radicalisation network noted that intelligence agencies now suspect unauthorised SIM card distribution is being used by terrorists to communicate with handlers across the border, part of a broader push to choke off the logistical and communication backbone that keeps sleeper modules alive even when direct physical contact with a local handler is minimal or non-existent.
How Agencies Are Responding
To their credit, security agencies aren't standing still. Officials say cyber-surveillance frameworks are actively being redesigned to map and intercept these "off-grid" communication channels, a phrase that itself signals how far outside traditional monitoring territory this recruitment method has moved. Agencies say they continue to adapt their cyber-surveillance frameworks specifically to map and intercept these off-grid communication channels. That has included moving to restrict access to specific APKs, tightening scrutiny of virtual number providers, and, as seen in recent CIK (Counter Intelligence Kashmir) operations, proactively disrupting online propaganda networks before recruitment pitches can mature into operational plots. One recent CIK operation, for instance, intercepted attempts to recruit two teenage boys who were allegedly being fed terror content in the direction of a Pakistan-based handler, underlining how young the target pool for these campaigns has become.
Conclusion
What this episode really illustrates isn't a single clever trick but a structural truth about counter-terror surveillance: it is inherently reactive. Every time agencies build competence around a platform, handlers find a low-attention, high-friction-to-monitor alternative: first fringe messaging apps, then Tor-routed clients, and now the sprawling, largely unregulated back-end of adult content platforms, which few people would ever think to associate with national security. It's a reminder that the fight against radicalisation online is no longer confined to obviously "extremist" corners of the internet; it can hide in plain sight, inside the most ordinary-looking corners of the web.
Sources
- New J-K terror tactic: Pornography apps, Tor network used for secret messaging — The Tribune
- New J&K terror tactic: Handlers turn to porn sites, encrypted apps to contact recruits — Deccan Herald
- Terrorists using porn website, encrypted apps for chats with recruits — Organiser
- New J&K Terror Tactic: Pornography Apps, Tor Network Used For Secret Messaging — Kashmir Dot Com
- From WhatsApp to Porn Sites: Terror Groups Adopt New Digital Tactic in J&K — Jammu Kashmir Now
- Jammu teenager's arrest exposes cross-border radicalisation network — The Tribune
- After OGW network, J&K cops target communication channel of terrorists — The Tribune
- CIK busts online radical network, foils recruitment of two minors — The Tribune

Executive Summary:
Assembly elections are underway in several Indian states, including West Bengal, Assam, Kerala, Tamil Nadu, and Puducherry. While voting has already taken place in Assam, Kerala, and Puducherry, polling is still pending in West Bengal. In view of the elections, central security forces have been deployed across West Bengal. Amid this, a video showing a group of people pelting stones at a security vehicle is being widely shared on social media. Some users claim that the incident took place in West Bengal and allege that Muslims attacked an army vehicle. However, research by CyberPeace found the claim to be false. The viral video is from Pakistan and has no connection to West Bengal.
Claim
A social media user shared the video on April 5, 2026, claiming that an army vehicle was attacked in West Bengal.
Post links:

Fact Check
To verify the claim, we extracted keyframes from the viral video and conducted a reverse image search using Google Lens. This led us to a video posted on a Facebook page on October 13, 2025. The caption of that post indicated that the video was from Lahore, showing clashes between members of Tehreek-e-Labbaik and the police.

Further clues in the video also pointed to Pakistan. A shop sign reading “Lovely Drink Corner” is visible in the footage. A Google search confirmed that this establishment is located in Lahore, Pakistan.

Conclusion
The viral claim is misleading. Although central forces have been deployed in West Bengal for the ongoing elections, the video showing stone-pelting on a security vehicle is not from the state. It is an old video from Lahore, Pakistan, and is being falsely shared with a communal angle to mislead users.

Executive Summary
A video is rapidly going viral on social media, with the claim that transgender women assaulted an Indian Army officer in Thailand. The post further claims that the officer had failed to pay the agreed amount, following which the incident took place. A research by CyberPeace’s research wing found that the viral video is fake. In fact, the video shows an incident that took place in Pattaya, Thailand, in December 2025. The 52-year-old Indian national, Raj Jasuja, was allegedly assaulted by a group of transgender women following a dispute over payment for sexual services. Therefore, the claim made in the post is false.
Claim:
A video shared on social media claims that transgender women assaulted an Indian Army general in Thailand.
https://x.com/navyhato/status/2094322001490116659
https://archive.ph/Scfgd

Fact Check:
To verify the claim, we conducted a Google search using relevant keywords but found no credible media reports confirming that Indian Army Lieutenant General Rajiv Kumar Sahni was involved in the incident. During the subsequent research, we compared the viral screenshot with the original report published by The Times of India. The comparison revealed that the original headline, “Indian national Raj Jasuja thrashed by transwomen in Thailand after allegedly refusing to pay for escort service,” had been digitally altered to read, “Indian Army Lieutenant General Rajiv Kumar Sahni thrashed by transwomen in Thailand after allegedly refusing to pay for escort service.” Further, both the viral screenshot and the original report display the same breadcrumb trail — “News / Indian National Raj Jasuja Thrashed By Transwomen In T…”. This provides further evidence that the headline in the viral screenshot was digitally manipulated.

After establishing the context of the viral claim, we conducted a Google search using relevant keywords. During the search, we found a report published on The Indian Express website on January 5, 2026, which featured the same visuals as those seen in the viral video. According to the report, a 52-year-old Indian tourist was allegedly assaulted by a group of transgender women in Pattaya, Thailand. The incident reportedly stemmed from a dispute over an unpaid fee for sexual services. The viral video, recorded on December 27, shows three transgender women allegedly assaulting the man with slippers. According to the report, the dispute escalated after the man allegedly refused to pay the amount demanded and attempted to leave the spot in a car. One of the transgender women reportedly accused him of refusing to make the payment. He was subsequently kicked and beaten before emergency responders intervened.

In the next step of our research, we found another report published on the India Today website on January 5, 2026. The report featured the same visuals as those seen in the viral video. According to the report, the incident took place on the morning of December 27, 2025, in the Walking Street area of Pattaya, Thailand.

Conclusion:
Our research found that the claim that Indian Army Lieutenant General Rajiv Kumar Sahni was assaulted in Thailand is false. The viral video actually shows an incident that took place in Pattaya, Thailand, in December 2025, in which 52-year-old Indian national Raj Jasuja was allegedly assaulted by a group of transgender women following a dispute over payment for sexual services. The viral post falsely links the incident to an Indian Army officer, thereby misrepresenting the identity of the person involved.