#FactCheck-Fake post falsely attributes EVM-related remark to US Secretary Marco Rubio
Executive Summary
A social media post card featuring a photo of US Secretary of State Marco Rubio, carrying the logo of Navbharat Times, is being widely circulated online. The post claims that Rubio made a remark criticizing the Indian government, allegedly stating that “those in power through EVMs should tell us what to do and what not to do.” CyberPeace Research Wing research found the claim to be false. There is no evidence of Marco Rubio making any such statement, and the viral post card is fabricated.
Claim:
A post shared by SP leader IP Singh alleged that the US Secretary made comments questioning the legitimacy of the Indian government and EVM-based elections, further linking it to broader political criticism of EVMs.
Post link: https://x.com/IPSinghSp/status/2066740933396492706?s=20, https://archive.ph/submit/?url

Fact Check:
A keyword search of the alleged statement revealed no credible reports or official records of Marco Rubio making any such remark. Additionally, a review of Navbharat Times’ official social media handles did not show any such post card being published, indicating that the viral graphic is not authentic. Further examination of recent statements by Marco Rubio showed no reference to EVMs or the Indian electoral system. Instead, a Navbharat Times report dated June 14 covered a different issue related to tensions in the Hormuz Strait, where Rubio commented on the killing of Indian sailors during a maritime incident and emphasized compliance with US directives for commercial vessels. https://navbharattimes.indiatimes.com/world/america/marco-rubio-remarks-on-killing-of-indian-sailors-in-hormuz-strait-insult-of-india-says

Conclusion:
The research confirms that US Secretary of State Marco Rubio did not make any statement regarding EVMs or the Indian government. The viral post card is fake and misleading.
Related Blogs

Introduction
The Department of Telecommunications on 28th October 2024 notified an amendment to the Flight and Maritime Connectivity Rules, 2018 (FMCR 2018).
Rule 9 of the principle rules in FMCR 2018 stated:
“Restrictions–(1) The IFMC service provider shall provide the operation of mobile communication services in aircraft at minimum height of 3000 meters in Indian airspace to avoid interference with terrestrial mobile networks. (2) Internet services through Wi-Fi in aircraft shall be made available when electronic devices are permitted to be used only in airplane mode.”
In 2022, an amendment was made to the attached form in the Rules for obtaining authorisation to provide IFMC services.
Subsequently, the 2024 amendment substitutes sub-rule (2), namely :
“ (2) Notwithstanding the minimum height in Indian airspace referred to in sub-rule (1), internet services through Wi-Fi in aircraft shall be made available when electronic devices are permitted to be used in the aircraft.”
Highlights of the Amendment
These rules govern the use of Wi-Fi in airplanes and ships within or above India or Indian territorial waters through In Flight and Maritime Connectivity (IFMC) services provided by IFMC service providers responsible for establishing and maintaining them.
Airplanes are equipped with antennas, onboard servers, and routers to connect to signals received from ground towers via Direct Air-to-Ground Communications (DA2GC) or through satellites. The DA2GC system offers connectivity through various communication methods, supporting services like in-flight Internet access and mobile multimedia. Licensed In-Flight Mobile Connectivity (IFMC) providers must adhere to standards set by international organizations such as the International Telecommunications Union (ITU), the European Telecommunications Standards Institute (ETSI), and the Institute of Electrical and Electronics Engineers (IEEE), or by international forums like the 3rd Generation Partnership Project (3GPP) to offer In-Flight Connectivity. Providers using Indian or foreign satellite systems must obtain approval from the Department of Space.
The IFMC service provider must operate mobile communication services on aircrafts at a minimum altitude of 3,000 meters within Indian airspace to prevent interference with terrestrial mobile networks. However, Wi-Fi access can be enabled at any point during the flight when device use is permitted, not just after reaching 3,000 meters. This flexibility is intended to allow passengers to connect to Wi-Fi earlier in the flight. This amendment aims to ensure that passengers can access the internet while maintaining the safety standards critical to in-flight communication systems.
Implications
- Increased Data Security Needs: There will be a need for robust cybersecurity measures against potential threats and data breaches.
- Increased Costs: Airplanes will have to incur the initial costs for installing antennae. Since airfare pricing in India is market-driven and largely unregulated, these costing changes might find their way into ticket prices, making flight tickets more expensive.
- Interference Management: A framework regarding the conditions under which Wi-FI must be switched off to avoid interference with terrestrial communication systems can be determined by stakeholders and communicated to passengers.
- Enhanced Connectivity Infrastructure: Airlines may need to invest in better flight-connectivity infrastructure to handle increased network traffic as more passengers access Wi-fi at lower altitudes and for longer durations.
Conclusion
The Flight and Maritime Connectivity (Amendment) Rules, 2024, enhance passenger convenience and align India with global standards for in-flight connectivity while complying with international safety protocols. Access to the internet during flights and at sea provides valuable real-time information, enhances safety, and offers access to health support during aviation and maritime operations. However, new challenges including the need for robust cybersecurity measures, cost implications for airlines and passengers, and management of interference with terrestrial networks will have to be addressed through a collaborative approach between airlines, IFMC providers, and regulatory authorities.
Sources
- https://dot.gov.in/sites/default/files/2018_12_17%20AS%20IFMC_2.pdf?download=1
- https://dot.gov.in/sites/default/files/Amendment%20dated%2004112024%20in%20flight%20and%20maritime%20connectivity%20rules%202018%20to%20IFMC%20Service%20Provider.pdf
- https://www.t-mobile.com/dialed-in/wireless/how-does-airplane-wifi-work
- https://tec.gov.in/public/pdf/Studypaper/DA2GC_Paper%2008-10-2020%20v2.pdf
- https://www.indiatoday.in/india/story/wifi-use-flights-no-longer-linked-altitude-now-subject-permission-2628118-2024-11-05
- https://pib.gov.in/Pressreleaseshare.aspx?PRID=1843408#:~:text=With%20the%20repeal%20of%20Air,issue%20directions%20to%20such%20airline.

Introduction
On 27 July 2026, Bank of Baroda admitted to experiencing a cybersecurity attack, officially confirming many hours of chatter and speculation amongst Bank of Baroda customers and information security professionals. According to a statement by the bank issued through regulatory filing, the breach came about due to unauthorised access into some of its data via compromise of an employee’s email account; however, not much beyond these details was disclosed. In the meantime, allegations of a major large-scale data leak flooded into various platforms and forums of the cybersecurity world along with mainstream news outlets and, eventually, mainstream social networks. It’s now critically important for us to attempt to differentiate factual from unverified details about Bank of Baroda’s recent cybersecurity incident.
We will analyse and list what the bank has released, what our community research has discovered and also what questions are still left unanswered.
The bank's version
Bank of Baroda said the breach traced back to a single compromised employee email account, which gave an unknown party unauthorised access to "certain data". Crucially, the bank maintains that its core banking systems, that is, the infrastructure that actually moves customer money, were never touched. It says the incident was detected and contained quickly and that it is working with law enforcement and regulators while a forensic investigation continues. That's a fairly narrow admission compared with what had already surfaced on the dark web.
What the hackers claim
Days before the bank's statement, a relatively new ransomware and data-extortion group calling itself ‘TripleX’ listed Bank of Baroda on its dark web leak site, dated July 24. The group claimed to have pulled roughly 1 terabyte of data and, unusually, released the entire cache for free rather than holding it for ransom, framing the move on its leak page as punishment for the bank's weak passwords and security lapses.
Independent researcher Srikanth Lakshmanan, founder of the digital-rights group 'CashlessConsumer', examined samples of the leaked material before alerting the bank and authorities. He told India Today Tech that what he reviewed included internal branch audit files, loan appraisal documents, vigilance investigation records, audit reports tied to the bank's bob World mobile app, and customer account-opening forms.
Several outlets also reported that sample files appeared to contain Aadhaar numbers, customer photographs, and NetBanking details, alongside corporate and NRI banking records. It's worth being precise here, though: Reuters and other outlets have emphasised that the exact contents and true scale of the leak haven't been independently verified, and Bank of Baroda itself hasn't confirmed which specific data categories were exposed. Estimates of the dataset's size have also varied anywhere from around 700 gigabytes to a full terabyte, depending on the source.
A repeat offender
TripleX isn't new to targeting state-owned banks. The gang first appeared in May 2026, and only weeks before targeting Bank of Baroda, it claimed responsibility for hacking PT Bank Negara Indonesia – the largest of Indonesia's state-owned banks, which stole nearly 2 terabytes of documents, including contracts, IDs and transaction histories. Both compromises follow a familiar pattern. Identify one point of entry, extract widely, and instead of working in the background to negotiate for a ransom, publish everything for the largest damage possible.
This represents a notable break from typical ransomware attacks. Groups such as TripleX forego encryption, simply relying solely on the public pressure of (or actuality of) imminent disclosure to extort victims. It is the extortion component of "double extortion" with little incentive to pursue payment.
The regulatory clock
India's banking sector doesn't get much slack when something like this happens. The Reserve Bank of India's Cyber Security Framework for Banks requires an initial incident report within two to six hours of detection, and India's Computer Emergency Response Team (CERT-In) mandates reporting of specified incidents within six hours. Bank of Baroda has also reportedly filed a preliminary notice under a cyber-insurance programme arranged through National Insurance, offering total coverage of roughly $78 million, though it's far too early to know whether it will actually be paid out or how much will actually be paid out.
Looking ahead, India's Digital Personal Data Protection Rules are due to take effect in May 2027, which will tighten breach-notification obligations further. This incident lands right at the edge of that regulatory transition, arguably a preview of what's at stake for the next bank that gets hit.
A History of Data Security Missteps
This is not the first time banks’ technology has raised a red flag. In 2023, an investigation by The Reporters’ Collective and Al Jazeera discovered that bank employees had inserted the mobile numbers of unauthorised agents (including those belonging to staff and security guards) and other businesses into their customers' profiles to drive enrolment on the bank’s app – BoB World. Several of the bank's customers were later victims of fraud due to the unauthorised association of mobile numbers, and the bank had its own internally reported data issues that later led to the RBI mandating an audit and then prohibiting the bank from onboarding new Bob World users temporarily. Even though the two issues are not related, it serves as context; in the case of banks handling more than $300 billion in their global operations through over 8,400 domestic locations, room for security errors is marginal, and the damage, both public and regulatory, escalates from there on.
What it means for customers
For those who bank with the Bank of Baroda, the common-sense approach is checking statements for any unfamiliar transactions; beware unsolicited calls/messages referencing account details (which typically follow after identity document leaks are being used as a basis for secondary scams); and as a security precaution, change your NetBanking password and app PIN while no core systems of the bank are reported to have been breached; even so, it is advisable to apply. Because Aadhaar, if it has been really compromised, cannot be reset like a password, which is why a compromised identity document is typically of longer-term risk than a stolen password.
Conclusion
The bigger story here isn't just one bank's bad week. It's a reminder that in a system where a single compromised employee inbox can cascade into hundreds of gigabytes of exposed customer data, "our core systems weren't affected" is true and reassuring and, for anyone whose loan documents or ID numbers may now be sitting on a dark web forum, somewhat beside the point.
Sources
- Bank of Baroda confirms cyber incident after hackers claim data theft — The Record (Recorded Future News): https://therecord.media/india-bank-of-baroda-reports-cybersecurity-incident
- Bank of Baroda Data Leak: What We Know So Far — Gulf News: https://gulfnews.com/business/banking/bank-of-baroda-data-leak-what-we-know-so-far-about-alleged-cyber-breach-1.500621898
- Bank of Baroda Breach Tests Disclosure Readiness — GovInfoSecurity (ISMG): https://www.govinfosecurity.com/bank-baroda-breach-tests-disclosure-readiness-a-32335
- India's Bank of Baroda Faces Alleged 1TB Data Leak on Dark Web — Yahoo Finance / India Today Tech: https://finance.yahoo.com/technology/ai/articles/india-bank-baroda-faces-alleged-113047992.html
- Bank of Baroda Data Breach Exposes Customer Records — The Asian Banker: https://www.theasianbanker.com/updates-and-articles/india-s-bank-of-baroda-data-breach-exposes-customer-records-after-employee-email-compromise
- India's Bank of Baroda Expose Worsens: Agents Steal Money From Accounts (2023 background) — Al Jazeera: https://www.aljazeera.com/economy/2023/10/12/indias-bank-of-baroda-expose-worsens-agents-steal-money-from-accounts
- 'Immediate Containment Measures Implemented': Bank of Baroda Issues Clarity on Alleged 1TB Data Leak — Republic World: https://www.republicworld.com/business/immediate-containment-measures-implemented-bank-of-baroda-issues-clarity-on-1tb-data-leak-2026-07-27-133590

Introduction
The Ministry of Electronics and Information Technology (MEITy) released the Draft Information Technology (Intermediary Guidelines and Digital Media Ethics Code) Second Amendment Rules, 2026 on March 30, 2026, inviting public comments with a response window closing on April 14. This is a limited 15-day period for public input on proposed rules that will have major constitutional impacts. The brevity and timing of this opportunity demonstrate debatable commitment to stakeholder engagement and meaningful consultation by the drafting agency.
While MEITY describes the proposed amendments as "clarificatory and procedural nature," an analysis shows they will have substantive effects. Collectively, the amended language changes significantly how online speech will be regulated in India by providing the executive with more concentrated regulatory authority, limiting the required transparency of content enforcement, mandating greater retention of data without proportionality-based safeguards, and placing excessive compliance burden on intermediaries. Each of these changes has consequences beyond just changes in process and together, these changes collectively raise substantial concerns regarding compliance with Articles 14, 19, and 21 of the Constitution of India.
The Constitutional Baseline: Shreya Singhal and the Limits of Intermediary Liability
India’s Supreme Court decision in Shreya Singhal v Union of India (2015) 5 SCC 1 provides the foundation for intermediary liability, wherein the Court read down Section 79(3)(b) of the IT Act, 2000, holding that intermediaries are required to act upon receiving actual knowledge only through a court order or a valid notification by the appropriate government authority. The Supreme Court’s decision intended to provide a constitutional protection to intermediaries from being subjected to informal, unverified executive pressure to take down content by requiring that any such order be subject to some level of legal objective credibility or threshold.
Rule 3(4) of the proposed amendments places that balance under significant strain. By requiring intermediaries to comply with advisories, directions, standard operating procedures, codes of practice, and guidelines issued by the Ministry — and tying non-compliance to the loss of safe harbour — the draft effectively lowers the constitutional threshold that Shreya Singhal was designed to maintain. Compliance obligations now potentially arise from instruments that carry no judicial sanction and no mandatory public disclosure.
Rule 3(4): Delegated Legislation or Executive Overreach
The rule-making power conferred on the Central Government under Section 87 of the IT Act is limited to carrying out the provisions of the Act. It does not authorise the creation of new substantive obligations. This principle has been consistently affirmed in Indian Express Newspapers v. Union of India (1985) 1 SCC 641 and Confederation of Ex-Servicemen Associations v. Union of India (2006) 8 SCC 399, where the Court held that delegated legislation must remain within the four corners of the parent statute.
Rule 3(4) tests those limits. It converts executive advisories into binding compliance instruments without a clear statutory foundation in either Section 79 or Section 87. Although the proposed rule requires that such instruments specify their legal basis, there is no requirement that they be published or made publicly accessible. This creates a framework in which legality risks becoming circular — instruments claimed to be lawful solely by reference to a provision that does not clearly authorise them, shielded from scrutiny by their own opacity. Justice Chandurkar’s judgment in Kunal Kamra v. Union of India identified precisely this defect in the Fact Check Unit amendment. Rule 3(4) replicates the structural problem in a broader form.
Compliance Pressure and the Logic of Over-Censorship
The practical consequence of Rule 3(4) lies not only in its legality but in how it reshapes incentive structures for platforms. An intermediary facing the permanent threat of safe harbour loss will not wait to assess the legal merit of each advisory. The rational calculation is to comply early, broadly, and without friction. Lawful content — particularly satire, political commentary, and journalism — becomes vulnerable not because it is unlawful, but because it presents regulatory risk.
This dynamic was visible on 18 March 2026, when stand-up comedian Pulkit Mani (@hunnywhoisfunny) found his satirical Instagram reel being restricted across India. The video had accumulated over 16.5 million views. Users encountered a notice citing Section 79(3)(b) of the IT Act. No reasons were publicly provided. No prior hearing was offered. The same night, several political parody and satire accounts were withheld on X.
Data Retention, Privacy, and the Proportionality Test
The amendments to Rules 3(1)(g) and 3(1)(h) extend data retention obligations by making them additional to requirements under any other law. The existing 180-day floor for retained user data — covering removed content, registration information, and associated records — becomes a minimum rather than a ceiling. No maximum is specified, and no proportionality requirement accompanies the extension.
This raises direct concerns under Article 21 as interpreted in Justice K.S. Puttaswamy v. Union of India (2017) 10 SCC 1, which held that any state intrusion into privacy must satisfy the triple test of legality, necessity, and proportionality. Undefined retention periods, with no statutory ceiling and no requirement of purpose limitation, risk failing all three. The longer user data is held, including metadata, device information, and records of removed content, the greater the exposure to surveillance, unauthorised access, and use beyond the original justification.
Circumventing Judicial Scrutiny Through Procedural Redesign
The Bombay High Court, in its August 2021 order, stayed provisions of the IT Rules’ oversight mechanism as prima facie violative of Article 19(1)(a). The Madras High Court in T.M. Krishna v. Union of India affirmed that stay, cautioning that government-controlled media oversight risked undermining press independence. Both matters remain pending before the Delhi High Court.
The amendments to Rules 8(1) and 14 restructure the same oversight machinery through a modified procedural design. By extending the Inter-Departmental Committee’s jurisdiction to cover “matters” referred by the Ministry with no requirement of a complainant, no defined subject matter, and no guaranteed prior hearing, the proposed rules effectively reconstitute what courts found constitutionally suspect. Individual users posting news and current affairs content are now brought within reach of blocking mechanisms originally designed for institutional publishers.
Conclusion
As seen above, the Draft IT Rules 2026 are unable to meet the constitutional and judicial requirements to regulate free speech. What the proposed amendments construct is a durable system in which platforms self-censor under liability pressure, data is retained without proportionate justification, and content oversight expands through procedural adjustment rather than parliamentary legislation. Regulation of the digital public sphere is both legitimate and necessary. But it must be anchored in law, not in the quiet authority of executive advisories. The law must ultimately remain anchored in constitutional values, guided by the enduring principles of justice, equity, and good conscience.
The comment period closes on 14 April 2026.
Submissions may be sent to itrules.consultation@meity.gov.in.
References
- https://www.meity.gov.in/static/uploads/2026/03/30591fc6e322dcbcc9dae84a0f02e9e7.pdf
- https://www.meity.gov.in/static/uploads/2026/03/a71a21d35c107f2e528363d3eb17646a.pdf
- https://www.meity.gov.in/static/uploads/2026/02/550681ab908f8afb135b0ad42816a1c9.pdf
- https://neopolitico.com/india/government-blocks-viral-satirical-reel-impersonating-pm-modi-raising-fresh-questions-on-free-speech-and-digital-regulation/
- https://internetfreedom.in/sound-the-alarm-iffs-first-read-on-meitys-draft-it-rules-second-amendment-2026/