#FactCheck-Fake post falsely attributes EVM-related remark to US Secretary Marco Rubio
Executive Summary
A social media post card featuring a photo of US Secretary of State Marco Rubio, carrying the logo of Navbharat Times, is being widely circulated online. The post claims that Rubio made a remark criticizing the Indian government, allegedly stating that “those in power through EVMs should tell us what to do and what not to do.” CyberPeace Research Wing research found the claim to be false. There is no evidence of Marco Rubio making any such statement, and the viral post card is fabricated.
Claim:
A post shared by SP leader IP Singh alleged that the US Secretary made comments questioning the legitimacy of the Indian government and EVM-based elections, further linking it to broader political criticism of EVMs.
Post link: https://x.com/IPSinghSp/status/2066740933396492706?s=20, https://archive.ph/submit/?url

Fact Check:
A keyword search of the alleged statement revealed no credible reports or official records of Marco Rubio making any such remark. Additionally, a review of Navbharat Times’ official social media handles did not show any such post card being published, indicating that the viral graphic is not authentic. Further examination of recent statements by Marco Rubio showed no reference to EVMs or the Indian electoral system. Instead, a Navbharat Times report dated June 14 covered a different issue related to tensions in the Hormuz Strait, where Rubio commented on the killing of Indian sailors during a maritime incident and emphasized compliance with US directives for commercial vessels. https://navbharattimes.indiatimes.com/world/america/marco-rubio-remarks-on-killing-of-indian-sailors-in-hormuz-strait-insult-of-india-says

Conclusion:
The research confirms that US Secretary of State Marco Rubio did not make any statement regarding EVMs or the Indian government. The viral post card is fake and misleading.
Related Blogs

Executive Summary
A video showing a helicopter engulfed in flames is being widely circulated on social media with the claim that it depicts an American Black Hawk helicopter shot down by Iran during the ongoing Middle East conflict. However, research by the CyberPeace Research Wing found the claim to be false. The viral footage is old and dates back to February 2020, showing a helicopter shot down in Syria, not Iran.
Claim
A Facebook post shared from Nigeria on April 6, 2026, claimed: “The moment an American Black Hawk helicopter was struck by an Iranian heat-seeking missile.” The post, which has been shared over 100 times, includes a 50-second video showing a helicopter exploding mid-air and crashing to the ground.

Fact Check
On April 3, a US F-15E Strike Eagle was reportedly shot down over Iran, marking the first such incident since the start of the ongoing Middle East conflict.

Two Black Hawk helicopter deployed for a search-and-rescue mission for the jet’s crew were also hit by Iranian fire but managed to return to base, despite some crew members being injured.
- http://abcnews.com/Politics/us-fighter-jet-iran-search-rescue-officials/story?id=131685787&utm_source=chatgpt.com

US President Donald Trump had earlier announced the recovery of a missing pilot, describing it as “one of the most daring search and rescue operations in US history.
”

However, the viral video being shared as evidence of the downing of a US aircraft predates these events. Using reverse image search on keyframes from the clip, we found a longer version published by Euronews on February 11, 2020. The Arabic title of the video translates to: “Syrian regime helicopter shot down in Idlib, two pilots killed.” Reports indicate that the incident occurred in Idlib, Syria, in February 2020, where a military helicopter was shot down and caught fire before crashing.

The incident was also covered by other international media outlets, including AFP, which distributed images and videos of the crash.
- https://www.afpforum.com/AFPForum/Search/ViewMedia.aspx?mui=1&hid=5DFA75509C25E3CDC3F24CA3B41C1A9A854C8AA3EB2BC1C64FCC0192F0506138

Conclusion
The viral claim is false. The footage does not show an American helicopter shot down by Iran. Instead, it is an old video from February 2020 depicting a helicopter crash in Syria, which is being shared with a misleading and unrelated narrative.

Executive Summary
A video circulating on social media claims to show the Deputy Chief of Army Staff and former DGMO of the Indian Army, Lieutenant General Rajiv Ghai, dancing with a young woman at a party. Users sharing the clip further allege that other junior military officers were also present at the event. CyberPeace Research Wing research found the claim to be misleading. The viral video has no connection with the Indian Army, Lt Gen Rajiv Ghai, or any official military function. The person seen in the video is actually the father of content creator Akanksha Sehgal, who has featured him in multiple videos on her social media accounts.
Claim:
A Pakistani handle ‘Baba Thoka’ shared the video on X, alleging that Lt Gen Rajiv Ghai was seen dancing with young women at a party and that junior officers were also present.
- https://x.com/ThokaReturns/status/2068069535715147896?s=20
- https://archive.ph/H9EA0

Fact Check:
A reverse image search of keyframes from the viral video led to the same clip being found on Instagram handle ‘akku_sehgal_’, posted on December 14, 2025. The video caption read: “POV – when your dad and your music taste match.”

Further examination of the content creator Akanksha Sehgal’s Instagram profile showed multiple videos featuring the same father-daughter duo, confirming that the man in the viral clip frequently appears in her content.

Conclusion:
The viral video claiming to show Lieutenant General Rajiv Ghai dancing at a party is misleading. The individual seen in the video is not the senior Indian Army officer but the father of content creator Akanksha Sehgal.

Introduction
On 27 July 2026, Bank of Baroda admitted to experiencing a cybersecurity attack, officially confirming many hours of chatter and speculation amongst Bank of Baroda customers and information security professionals. According to a statement by the bank issued through regulatory filing, the breach came about due to unauthorised access into some of its data via compromise of an employee’s email account; however, not much beyond these details was disclosed. In the meantime, allegations of a major large-scale data leak flooded into various platforms and forums of the cybersecurity world along with mainstream news outlets and, eventually, mainstream social networks. It’s now critically important for us to attempt to differentiate factual from unverified details about Bank of Baroda’s recent cybersecurity incident.
We will analyse and list what the bank has released, what our community research has discovered and also what questions are still left unanswered.
The bank's version
Bank of Baroda said the breach traced back to a single compromised employee email account, which gave an unknown party unauthorised access to "certain data". Crucially, the bank maintains that its core banking systems, that is, the infrastructure that actually moves customer money, were never touched. It says the incident was detected and contained quickly and that it is working with law enforcement and regulators while a forensic investigation continues. That's a fairly narrow admission compared with what had already surfaced on the dark web.
What the hackers claim
Days before the bank's statement, a relatively new ransomware and data-extortion group calling itself ‘TripleX’ listed Bank of Baroda on its dark web leak site, dated July 24. The group claimed to have pulled roughly 1 terabyte of data and, unusually, released the entire cache for free rather than holding it for ransom, framing the move on its leak page as punishment for the bank's weak passwords and security lapses.
Independent researcher Srikanth Lakshmanan, founder of the digital-rights group 'CashlessConsumer', examined samples of the leaked material before alerting the bank and authorities. He told India Today Tech that what he reviewed included internal branch audit files, loan appraisal documents, vigilance investigation records, audit reports tied to the bank's bob World mobile app, and customer account-opening forms.
Several outlets also reported that sample files appeared to contain Aadhaar numbers, customer photographs, and NetBanking details, alongside corporate and NRI banking records. It's worth being precise here, though: Reuters and other outlets have emphasised that the exact contents and true scale of the leak haven't been independently verified, and Bank of Baroda itself hasn't confirmed which specific data categories were exposed. Estimates of the dataset's size have also varied anywhere from around 700 gigabytes to a full terabyte, depending on the source.
A repeat offender
TripleX isn't new to targeting state-owned banks. The gang first appeared in May 2026, and only weeks before targeting Bank of Baroda, it claimed responsibility for hacking PT Bank Negara Indonesia – the largest of Indonesia's state-owned banks, which stole nearly 2 terabytes of documents, including contracts, IDs and transaction histories. Both compromises follow a familiar pattern. Identify one point of entry, extract widely, and instead of working in the background to negotiate for a ransom, publish everything for the largest damage possible.
This represents a notable break from typical ransomware attacks. Groups such as TripleX forego encryption, simply relying solely on the public pressure of (or actuality of) imminent disclosure to extort victims. It is the extortion component of "double extortion" with little incentive to pursue payment.
The regulatory clock
India's banking sector doesn't get much slack when something like this happens. The Reserve Bank of India's Cyber Security Framework for Banks requires an initial incident report within two to six hours of detection, and India's Computer Emergency Response Team (CERT-In) mandates reporting of specified incidents within six hours. Bank of Baroda has also reportedly filed a preliminary notice under a cyber-insurance programme arranged through National Insurance, offering total coverage of roughly $78 million, though it's far too early to know whether it will actually be paid out or how much will actually be paid out.
Looking ahead, India's Digital Personal Data Protection Rules are due to take effect in May 2027, which will tighten breach-notification obligations further. This incident lands right at the edge of that regulatory transition, arguably a preview of what's at stake for the next bank that gets hit.
A History of Data Security Missteps
This is not the first time banks’ technology has raised a red flag. In 2023, an investigation by The Reporters’ Collective and Al Jazeera discovered that bank employees had inserted the mobile numbers of unauthorised agents (including those belonging to staff and security guards) and other businesses into their customers' profiles to drive enrolment on the bank’s app – BoB World. Several of the bank's customers were later victims of fraud due to the unauthorised association of mobile numbers, and the bank had its own internally reported data issues that later led to the RBI mandating an audit and then prohibiting the bank from onboarding new Bob World users temporarily. Even though the two issues are not related, it serves as context; in the case of banks handling more than $300 billion in their global operations through over 8,400 domestic locations, room for security errors is marginal, and the damage, both public and regulatory, escalates from there on.
What it means for customers
For those who bank with the Bank of Baroda, the common-sense approach is checking statements for any unfamiliar transactions; beware unsolicited calls/messages referencing account details (which typically follow after identity document leaks are being used as a basis for secondary scams); and as a security precaution, change your NetBanking password and app PIN while no core systems of the bank are reported to have been breached; even so, it is advisable to apply. Because Aadhaar, if it has been really compromised, cannot be reset like a password, which is why a compromised identity document is typically of longer-term risk than a stolen password.
Conclusion
The bigger story here isn't just one bank's bad week. It's a reminder that in a system where a single compromised employee inbox can cascade into hundreds of gigabytes of exposed customer data, "our core systems weren't affected" is true and reassuring and, for anyone whose loan documents or ID numbers may now be sitting on a dark web forum, somewhat beside the point.
Sources
- Bank of Baroda confirms cyber incident after hackers claim data theft — The Record (Recorded Future News): https://therecord.media/india-bank-of-baroda-reports-cybersecurity-incident
- Bank of Baroda Data Leak: What We Know So Far — Gulf News: https://gulfnews.com/business/banking/bank-of-baroda-data-leak-what-we-know-so-far-about-alleged-cyber-breach-1.500621898
- Bank of Baroda Breach Tests Disclosure Readiness — GovInfoSecurity (ISMG): https://www.govinfosecurity.com/bank-baroda-breach-tests-disclosure-readiness-a-32335
- India's Bank of Baroda Faces Alleged 1TB Data Leak on Dark Web — Yahoo Finance / India Today Tech: https://finance.yahoo.com/technology/ai/articles/india-bank-baroda-faces-alleged-113047992.html
- Bank of Baroda Data Breach Exposes Customer Records — The Asian Banker: https://www.theasianbanker.com/updates-and-articles/india-s-bank-of-baroda-data-breach-exposes-customer-records-after-employee-email-compromise
- India's Bank of Baroda Expose Worsens: Agents Steal Money From Accounts (2023 background) — Al Jazeera: https://www.aljazeera.com/economy/2023/10/12/indias-bank-of-baroda-expose-worsens-agents-steal-money-from-accounts
- 'Immediate Containment Measures Implemented': Bank of Baroda Issues Clarity on Alleged 1TB Data Leak — Republic World: https://www.republicworld.com/business/immediate-containment-measures-implemented-bank-of-baroda-issues-clarity-on-1tb-data-leak-2026-07-27-133590