#FactCheck -Prayagraj Celebration Video Falsely Shared as BJP Victory Celebration in West Bengal
Executive Summary
Assembly election results for West Bengal, Assam, Kerala, Tamil Nadu and the Union Territory of Puducherry have been declared, with the Bharatiya Janata Party (BJP) set to form the government in West Bengal after defeating the Trinamool Congress (TMC). Amid celebrations and reports of violence in the state, several misleading videos and images are also circulating on social media. One such viral clip shows people waving the Indian tricolour and saffron flags during a street celebration. Social media users are claiming that the video captures people celebrating a political change and BJP’s victory in West Bengal. Research by CyberPeace Research Wing found that the claim is false. The viral video is not from West Bengal but from Prayagraj and actually shows celebrations after India’s victory in the ICC Men's T20 World Cup 2026.
Claim
An X user named “Ashok Shrivastav” shared the video on May 6, 2026, claiming that people in West Bengal were celebrating the departure of Mamata Banerjee and the TMC government. The user further claimed that people were waving only the national flag and saffron flags, not BJP flags.

Fact Check
To verify the claim, we extracted several keyframes from the viral video and conducted a reverse image search using Google Lens. The clip was found on multiple social media handles falsely linked to West Bengal.

However, the oldest version of the video was uploaded on March 8, 2026, by an Instagram page named “Streets of Sangam.” The caption identified the location as Prayagraj and included hashtags related to the World Cup and Loknath. During the comparison of the viral and original videos, we noticed a shop sign reading “Suman Ornaments.” Using Google Street View, we traced the location to Baba Loknath area in Prayagraj, where the same shop could be identified near Loknath Gate.

Conclusion
Our research confirms that the viral claim is fake. The video being shared as BJP victory celebrations in West Bengal is actually from Prayagraj, Uttar Pradesh, and dates back to March 2026, when locals celebrated Team India’s T20 World Cup victory. The old clip is now being misleadingly circulated with a false political narrative.
Related Blogs

Introduction
Insurance companies hold a huge amount of sensitive data. Medical history, bank account numbers, identity proofs, years of claims records — all of it sits on insurer servers, waiting. That makes the sector an easy target. India saw close to 370 million malware attacks in a single recent year. Banking, financial services and insurance firms bore the brunt of it. That got the attention of the Insurance Regulatory and Development Authority of India (IRDAI). On 6 April 2026, it released a new set of Information and Cyber Security Guidelines. These replace the old 2023 rules and ask insurers to take much stronger responsibility for protecting their systems, and their customers' data.
Who Must Follow These New Rules
The updated guidelines are not limited to large insurance companies alone. They apply to life, general and health insurers. They also apply to foreign reinsurance branches operating in India, and to intermediaries such as brokers, corporate agents, web aggregators and third-party administrators. Insurance repositories and the Insurance Information Bureau of India fall within scope too. Individual insurance agents, point-of-sale persons and surveyors are not covered directly. But insurers must still make sure these people follow a basic security framework approved by their board. Foreign reinsurance branches get a little more room — they can depart from a specific rule, but only if they can justify it properly to the regulator. Why cast such a wide net in the first place? Because breaches rarely start at the big insurer with the well-staffed Information Technology (IT) team. They start with the small broker or corporate agent who never got around to updating a password policy.
A Stronger Role for the Boardroom
An Independent CISO (Chief Information Security Officer)
The clearest change sits right at the top. A Chief Information Security Officer (CISO) can no longer report to the Head of Information Technology (IT). Nor can the CISO (Chief Information Security Officer) be handed sales targets or any other business goal. Why does this matter so much? Picture a CISO (Chief Information Security Officer) who answers to the same person pushing hard for a product launch next week. Flagging a serious vulnerability suddenly becomes an awkward, career-risking conversation. The IRDAI (Insurance Regulatory and Development Authority of India) has simply removed that awkwardness by rule.
More Frequent Oversight
The Information Security Risk Management Committee used to meet only twice a year. Now it must meet at least once every quarter. A new Information Technology (IT) Steering Committee has also been set up to handle day-to-day technology decisions. This frees the risk committee to focus purely on oversight. There's also a new seat at the table: at least one outside cybersecurity expert must now join the Risk Management Committee. Someone with no stake in internal politics, no department to protect, just technical judgement.
Faster Action When Something Goes Wrong
A Six-Hour Reporting Deadline
No system is completely safe from attack. So the guidelines also focus heavily on how insurers respond once something goes wrong. Every cybersecurity incident now has to reach the Indian Computer Emergency Response Team within six hours of being spotted, with the IRDAI (Insurance Regulatory and Development Authority of India) and other regulators looped in at the same time. Six hours is a tight deadline. It means insurers need detection and escalation systems that work round the clock, not just during office hours.
Testing and Exceptions
Business continuity and disaster recovery plans must be tested at least once a year, and not through some comfortable, pre-planned shutdown either — the test has to feel like a real disaster. Exceptions to security policy are also handled with far more discipline now. A short exception of up to three months can be approved by the CISO (Chief Information Security Officer) alone. One lasting between three months and a year needs sign-off from the risk committee. Anything longer needs approval from the board itself. Gaps found during audits must be closed within twelve months, with the board tracking progress at every stage.
Looking Ahead to Tomorrow's Risks
The guidelines do not stop at today's threats. More insurers are moving their operations to the cloud. So the rules now demand stronger contracts with cloud vendors, and a clear plan for what happens to customer data once a vendor relationship ends. Third-party risk gets close attention too. Many security breaches in the financial sector start with a vendor, not with the insurer's own systems. Before hiring any vendor, insurers must now check their security properly. Every contract must include audit rights and a clause requiring the vendor to report incidents. One of the most forward-looking additions is early preparation for a post-quantum world. Insurers must keep a clear list of their cryptographic assets. In simple terms, this is a map of where and how encryption is used across their systems. It helps them get ready once stronger encryption standards become necessary. Quantum computers capable of breaking today's encryption are still some years away, by most estimates. Mapping out those cryptographic assets now is a lot cheaper than scrambling to do it after the threat has already landed.
Conclusion
Where does all this leave things? Cybersecurity in Indian insurance isn't a server-room problem anymore — it sits squarely in the boardroom now. Directors now own this risk, not just Information Technology (IT) managers tucked away in a basement office. Policyholders benefit too, since their data now sits behind stronger locks, watched more closely and reported on far more often than before. Insurers who treat this as a paperwork exercise will struggle to keep up. Those who actually build these habits into daily operations will likely spend less time firefighting breaches five years from now, and more time competing on service and price instead.
References
3. Medianama, 'IRDAI Updates Cybersecurity Rules, Mandates DPDP Compliance', April 2026.
4. DSCI, brief on IRDAI's Information and Cyber Security Guidelines, 2026, April 2026.
7. Deloitte India, 'IRDAI Tightens Cyber Net: Wake-up Call for Insurers'.

A word rooted in medical terminology keeps getting mistaken for a word rooted in technology, and that confusion is not just semantic. On 6 August 2026, it sat at the heart of a case where police in Uttar Pradesh reportedly treated the absence of WhatsApp chats, call recordings, and social media material as grounds to disbelieve a sexual assault complaint altogether, before the Allahabad High Court intervened. For an organisation working at the intersection of digital literacy and public safety, this case is less a story about a legal term and more a case study in how assumptions about digital evidence, when left unchecked, can become a barrier to justice rather than a tool for it. "Digital" here refers to a finger, not a device, and the gap between what police expected and what the law actually required is exactly where this case becomes instructive. Digital rape has nothing to do with the internet. Digit simply means finger, and the word describes non-consensual penetration by a finger, thumb, toe, or similar body part or object. That basic clarification matters because the same investigating officers who were expected to know the law also appear to have leaned on a mistaken evidentiary standard, one where a complaint without a digital trail was treated as a complaint without merit. The judgment that followed says as much about how the criminal justice system treats sexual assault complaints, and how it treats digital evidence, as it does about legal terminology.
The case, in brief
The matter is Arpit Gupta v. State of U.P. and 2 others, 2026 LiveLaw (AB) 571, neutral citation 2026:AHC:168404-DB, decided by a Division Bench of Justice Chandra Dhari Singh and Justice Tarun Saxena. Arpit Gupta, the owner of a Noida based real estate firm, Parit Associates (OPC) Private Limited, approached the High Court under Article 226 of the Constitution seeking to quash an FIR registered against him at Wave City police station, Ghaziabad, alleging rape, sexual harassment, and criminal intimidation. The complainant, a former employee of Gupta's company, alleged sustained workplace sexual harassment culminating in an act legally categorised as digital penetration, along with subsequent threats and intimidation. She resigned in April 2026. What followed procedurally is where the case becomes significant: Gupta filed a separate extortion complaint against her, she was arrested and later released on bail, and only after that sequence did she attempt to formally report the sexual assault, a report the police initially declined to register.
What followed complicates the picture considerably, and is central to why the case reached the High Court at all. On 14 April 2026, Gupta filed his own FIR against the complainant alleging extortion, claiming she had demanded 10 crore rupees from him. She was arrested in connection with that case and secured bail on 21 May 2026. After her release, she attempted to register her own complaint of sexual assault, but police at Wave City station declined to register an FIR. A written complaint dated 7 July 2026 addressed directly to the Commissioner of Police, Ghaziabad, also produced no result. The police investigating officer's report, dated 16 July 2026, went further still, terming her allegations false and characterising the sexual assault complaint as a retaliatory counter-blast to Gupta's extortion case, citing in particular the absence of supporting electronic material such as WhatsApp chats, call recordings, or social media evidence. Only after she approached a Magistrate under Section 173(4) of the Bharatiya Nagarik Suraksha Sanhita, 2023, did the FIR finally get registered, by Magisterial order dated 20 July 2026.
The legal terminology: what "digital rape" actually means under BNS
Section 63 of the Bharatiya Nyaya Sanhita, 2023, which replaced Section 375 of the erstwhile Indian Penal Code, defines rape. Clause (b) of Section 63 extends that definition to cover non-penile penetrative acts, specifically insertion, to any extent, of any object or body part other than the penis into specified parts of a woman's body, done without her consent or against her will, subject to the circumstances of absent consent set out in the section. Digital penetration, meaning penetration by finger or thumb, falls squarely within this clause. There is no standalone offence in the BNS titled "digital rape"; the term is a widely used medico-legal shorthand, not a separate statutory category, and the offence itself is prosecuted and punished as rape under Section 64 BNS, which prescribes the punishment provisions. In this particular case, the FIR reportedly also invoked Sections 74, 75(2), and 76 BNS, provisions dealing with assault or use of criminal force with intent to outrage modesty, sexual harassment by a person in a position of authority, and related offences, alongside Section 351(3) BNS concerning criminal intimidation.
CyberPeace View
This is where the case circles back to the concern raised at the outset. The most instructive part of this judgment for the wider public may not be the definition of digital rape at all, but the police's original insistence on WhatsApp chats and call recordings before treating the complaint as credible. That reflex, a growing habit of associating the credibility of any complaint with the existence of a corresponding digital trail, reflects a wider and increasingly common misunderstanding about how evidence actually works in criminal law. Not every offence leaves an electronic footprint, and sexual assault, by its nature, frequently occurs without any accompanying digital record at all. Treating the absence of a chat log or a recording as evidence of falsehood inverts the legal presumption entirely, and risks turning digital literacy gaps within law enforcement into a structural barrier for genuine complainants who have no messages to produce because none were ever exchanged. As India's criminal justice system increasingly interacts with digital evidence, this case is a useful reminder that digital forensics should supplement an investigation, never gatekeep its starting point.
There is a genuinely technology rooted counterpart to this terminology confusion worth flagging, and it sits at the opposite end of the spectrum from where this case began. While "digital rape" has nothing to do with computers, "virtual rape" very much does, and it is an emerging harm India's legal framework is still catching up to. In January 2024, British police opened what was reported as the first investigation of its kind after a minor's avatar was allegedly gang assaulted by other avatars on Meta's metaverse platform, and similar incidents, avatars groped or sexually harassed within minutes of entering platforms like Horizon Worlds, have been documented repeatedly since, including a widely reported case involving psychotherapist Nina Jane Patel as far back as 2021. These incidents involve no physical contact whatsoever, yet researchers and legal scholars studying virtual reality note that immersive VR environments are specifically engineered to create a sense of embodiment, where the brain processes an avatar's violation as something closer to a real bodily experience than a typical online interaction, producing genuine trauma responses in victims. India's legal position here remains only partially settled. The POCSO Act's coverage of non-contact sexual abuse of minors likely extends to avatar based assaults on children, but adult victims of virtual sexual violence in India currently have no clearly dedicated statutory provision, leaving prosecutors to stretch existing harassment and outraging modesty provisions, originally drafted for a physical world, onto a form of harm the legislature has not yet explicitly addressed. As metaverse and VR platforms grow their user base in India, that gap is one worth closing before, rather than after, a case forces the question, much as this one forced the question of how police ought to treat digital evidence.
Conclusion
Two lessons run through this judgment. First, that the law's protection of bodily autonomy extends well beyond narrow, traditional definitions of penetration, a principle Section 63(b) BNS makes explicit. Second, that a complainant reporting a cognizable offence cannot be made to investigate her own case before the police will even open a file. FIR registration is not conviction, and conviction requires investigation, evidence, and trial to follow. What this case asks of the system is simpler than any of that: register the complaint, then do the work of finding out what happened.
References
- https://www.barandbench.com/news/digital-rape-allahabad-hc-orders-inquiry-against-senior-ghaziabad-police-officers-for-not-filing-fir
- https://www.livelaw.in/high-court/allahabad-high-court/allahabad-hc-police-cant-refuse-fir-sexual-complaint-non-production-evidence-545374

Introduction
Data Breaches have taken over cyberspace as one of the rising issues, these data breaches result in personal data making its way toward cybercriminals who use this data for no good. As netizens, it's our digital responsibility to be cognizant of our data and the data of one's organization. The increase in internet and technology penetration has made people move to cyberspace at a rapid pace, however, awareness regarding the same needs to be inculcated to maximise the data safety of netizens. The recent AIIMS cyber breach has got many organisations worried about their cyber safety and security. According to the HIPPA Journal, 66% of healthcare organizations reported ransomware attacks on them. Data management and security is the prime aspect of clients all across the industry and is now growing into a concern for many. The data is primarily classified into three broad terms-
- Personal Identified Information (PII) - Any representation of information that permits the identity of an individual to whom the information applies to be reasonably inferred by either direct or indirect means.
- Non-Public Information (NPI) - The personal information of an individual that is not and should not be available to the public. This includes Social Security Numbers, bank information, other personal identifiable financial information, and certain transactions with financial institutions.
- Material Non-Public Information (MNPI) - Data relating to a company that has not been made public but could have an impact on its share price. It is against the law for holders of nonpublic material information to use the information to their advantage in trading stocks.
This classification of data allows the industry to manage and secure data effectively and efficiently and at the same time, this allows the user to understand the uses of their data and its intensity in case of breach of data. Organisations process data that is a combination of the above-mentioned classifications and hence in instances of data breach this becomes a critical aspect. Coming back to the AIIMS data breach, it is a known fact that AIIMS is also an educational and research institution. So, one might assume that the reason for any attack on AIIMS could be either to exfiltrate patient data or could be to obtain hands-on the R & D data including research-related intellectual properties. If we postulate the latter, we could also imagine that other educational institutes of higher learning such as IITs, IISc, ISI, IISERs, IIITs, NITs, and some of the significant state universities could also be targeted. In 2021, the Ministry of Home Affairs through the Ministry of Education sent a directive to IITs and many other institutes to take certain steps related to cyber security measures and to create SoPs to establish efficient data management practices. The following sectors are critical in terms of data protection-
- Health sector
- Financial sector
- Education sector
- Automobile sector
These sectors are generally targeted by bad actors and often data breach from these sectors result in cyber crimes as the data is soon made available on Darkweb. These institutions need to practice compliance like any other corporate house as the end user here is the netizen and his/her data is of utmost importance in terms of protection.Organisations in today's time need to be in coherence to the advancement in cyberspace to find out keen shortcomings and vulnerabilities they may face and subsequently create safeguards for the same. The AIIMS breach is an example to learn from so that we can protect other organisations from such cyber attacks. To showcase strong and impenetrable cyber security every organisation should be able to answer these questions-
- Do you have a centralized cyber asset inventory?
- Do you have human resources that are trained to model possible cyber threats and cyber risk assessment?
- Have you ever undertaken a business continuity and resilience study of your institutional digitalized business processes?
- Do you have a formal vulnerability management system that enumerates vulnerabilities in your cyber assets and a patch management system that patches freshly discovered vulnerabilities?
- Do you have a formal configuration assessment and management system that checks the configuration of all your cyber assets and security tools (firewalls, antivirus management, proxy services) regularly to ensure they are most securely configured?
- Do have a segmented network such that your most critical assets (servers, databases, HPC resources, etc.) are in a separate network that is access-controlled and only people with proper permission can access?
- Do you have a cyber security policy that spells out the policies regarding the usage of cyber assets, protection of cyber assets, monitoring of cyber assets, authentication and access control policies, and asset lifecycle management strategies?
- Do you have a business continuity and cyber crisis management plan in place which is regularly exercised like fire drills so that in cases of exigencies such plans can easily be followed, and all stakeholders are properly trained to do their part during such emergencies?
- Do you have multi-factor authentication for all users implemented?
- Do you have a supply chain security policy for applications that are supplied by vendors? Do you have a vendor access policy that disallows providing network access to vendors for configuration, updates, etc?
- Do you have regular penetration testing of the cyberinfrastructure of the organization with proper red-teaming?
- Do you have a bug-bounty program for students who could report vulnerabilities they discover in your cyber infrastructure and get rewarded?
- Do you have an endpoint security monitoring tool mandatory for all critical endpoints such as database servers, application servers, and other important cyber assets?
- Do have a continuous network monitoring and alert generation tool installed?
- Do you have a comprehensive cyber security strategy that is reflected in your cyber security policy document?
- Do you regularly receive cyber security incidents (including small, medium, or high severity incidents, network scanning, etc) updates from your cyber security team in order to ensure that top management is aware of the situation on the ground?
- Do you have regular cyber security skills training for your cyber security team and your IT/OT engineers and employees?
- Do your top management show adequate support, and hold the cyber security team accountable on a regular basis?
- Do you have a proper and vetted backup and restoration policy and practice?
If any organisation has definite answers to these questions, it is safe to say that they have strong cyber security, these questions should not be taken as a comparison but as a checklist by various organisations to be up to date in regard to the technical measures and policies related to cyber security. Having a strong cyber security posture does not drive the cyber security risk to zero but it helps to reduce the risk and improves the fighting chance. Further, if a proper risk assessment is regularly carried out and high-risk cyber assets are properly protected, then the damages resulting from cyber attacks can be contained to a large extent.