#FactCheck-Old Video of Dangerous Auto-Rickshaw Stunt on Delhi’s Signature Bridge Falsely Linked to Prayagraj
Executive Summary
A picture is rapidly going viral on social media, showing Indian cricketer Virat Kohli and actor Anushka Sharma having breakfast together. Users are sharing this photo, presenting it as a "candid" (real) moment.
Research by the CyberPeace Research Wing revealed that the photo of Virat Kohli and Anushka Sharma having breakfast is completely fake. This image does not depict a real moment, but has been created using Artificial Intelligence (AI).
Claim
A picture is rapidly going viral on social media, showing Indian cricketer Virat Kohli and actor Anushka Sharma having breakfast together. Users are sharing this photo, presenting it as a "candid" (real) moment.
https://www.facebook.com/reel/951138134598230

Fact Check
We extracted several keyframes from the viral video and searched them using the Google Lens tool. We found that this video was also quite viral on X (formerly Twitter). Responding to users, the official X handle of DCP Yamuna Nagar, Prayagraj, stated, “Upon a detailed research of the said matter/video, it has been found that it is not from the Naini Yamuna Bridge, but is a 2.5-year-old video from Delhi’s Signature Bridge. Please do not spread misleading information, otherwise legal action will be initiated against it.”

During our search, we found a post on the official X handle of the Delhi Police. Sharing the viral video, they wrote that taking cognizance of the auto-rickshaw stunt incident on the Signature Bridge, the Delhi Traffic Police seized the auto-rickshaw and issued a challan totaling ₹32,000 under various sections of the Motor Vehicles Act.
https://x.com/DelhiPolice/status/1735268792434057352?s=20

Conclusion
In our research, the viral post turned out to be fake. A video of an incident that took place on Delhi's Signature Bridge in 2023 is now being falsely circulated to spread misinformation as an incident from a bridge in Prayagraj. No such incident has taken place on the Naini Bridge in Prayagraj.
Related Blogs

Introduction
The trajectory of India's digital economy is growing at an unprecedented rate, and so is India's cybercrime ecosystem. Parliamentary data tabled before the Rajya Sabha in May 2024 by the MHA suggests an overwhelming 900% growth in cybercrime complaints from 2021 to '25, while annual losses crossed 22,800 crore in 2024. The structural issues like the low victim restitution rate, the lack of forensic infrastructure, issues of jurisdiction related to offshore fraud factories targeting Indian citizens, and the huge disparity in awareness levels amongst India's youngest online citizens continue to exist. This brief brings out the clear trends in cybercrime, the role of institutional mechanisms in its prevention and response, failure points, and recommends appropriate policy interventions from the perspective of CyberPeace.
The Data Imperative
Since its operationalisation in 2019 by the Indian Cyber Crime Coordination Centre (I4C), the NCRP serves as India's most significant institutional apparatus for cybercrime reporting and response. Data placed before the Rajya Sabha by the Ministry of Home Affairs on 30 July 2025 show that, with almost no exception, complaints of cybercrime have increased far more quickly than most traditional indicators of public safety. Between 2021 and June 2025, the NCRP received 6.59 million complaints, evidence of both a sustained and escalating expansion of India's cyber threat profile. Complaints per year more than quadrupled from 4.52 lakh in 2021 to 19.18 lakh in 2024 (324% over the period); by 2025, the NCRP had received 28.15 lakh complaints, a 523 percent rise compared with the 2021 baseline:

Clearly, cyber-enabled crime is no longer an occasional crisis but a systemic governance issue requiring consistent regulation and institution-building.
The financial fallout has also accelerated dramatically. Figures indicate that reported financial losses due to cybercrime jumped from 2,290 crore in 2022 to 22,812 crore in 2024 a 895% leap in two years:

Though response mechanisms such as the Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS) successfully blocked or recovered close to 8,690 crore as of January 2026, victims appear to get back only about 2.18 percent of the losses they report.
In most areas, reporting and response have expanded greatly, but both the rate and scale of cyber-enabled financial fraud continue to outstrip India's remediation and law enforcement capacity.
Threat Typology of India’s Fraud Ecosystem
The nature of cyber crime in India has evolved from an opportunistic volume-based activity to a layered transnational criminal environment. I4C intelligence as tabled in Parliament reveals investment scams as the biggest threat: they accounted for 76% of the financial fraud lost in 2025 (although only 35% of complaints were filed, thus, a very high value per case was lost).

Digital arrest frauds, which tap on citizens' unawareness that "digital arrest" is not permissible under Indian law, rose from 39,925 cases (91 crore) in 2022 to 123,672 cases (1,935crore) in 2024.

The fast rise in the number of incidents as well as in the volume of fraud clearly points out that digital arrest fraud has moved away from the phase of novel scam typology to a formidable cyber-extortion landscape. The main orchestrators of investment, trading, dating, and digital arrest scams targeting Indian citizens were recently identified by the I4C CEO Rajesh Kumar as transnational criminal scam networks in Cambodia, Myanmar, and Laos. Hence, this issue does not only fall within the domain of domestic law enforcement but constitutes a transnational cybercrime requiring parallel financial intelligence, diplomatic initiative, platform responsibility, and international investigative collaboration.

Geographic Concentration
Maharashtra and UP register the highest volumes in total complaints at 3.03 lakh and 3.01 lakh, owing to them being the financial capital and most populous state, respectively. Karnataka, Gujarat, Delhi, WB, Telangana, TN, Rajasthan, and Haryana register above 1 lakh complaints each. However, the critical information that is being missed is that while complaint rate growth is the fastest in Tier 2 and 3 geographies (Haryana leads per-capita complaint rate with 381/100k people in 2023; Telangana (261); Uttarakhand (243)), this signifies rural digital growth as a risk multiplier.

Institutional Architecture: Mechanisms and Performances
India's institutional response to cybercrime, led by the Ministry of Home Affairs' Indian Cyber Crime Coordination Centre (I4C), is one of the world's largest real-time fraud detection and prevention ecosystems. The backbone of this is the Citizen Financial Cyber Fraud Reporting and Management System (CFCFRMS), which has onboarded over 700 banks, payment service providers, e-commerce portals, digital wallets, and, since the Standard Operating Procedure was issued on 2nd January 2026, virtual asset service providers and crypto exchanges. This interconnected network allows for prompt freezing of funds and timely fraud intervention during the 'golden hour' of a cybercrime report.
Institutional capacity is robust, with approximately 8,690 crore saved via the CFCFRMS since its inception for over 24.65 lakh complaints. The national cybercrime helpline (1930) receives close to 10,000 calls daily, while the Suspect Registry has enabled the rejection of 9,519 crore via the detection of 23.05 lakh suspect entities and 27.37 lakh mule accounts. In parallel, the CyTrain platform has expanded training by registering 151,081 police and judicial officers and issuing 142,025 certificates. Cyberforensic labs in all 33 States and Union Territories have received central assistance totalling 132.93 crore, and data-driven interstate crime analytics and offender linkages through the Samanvaya and Pratibimb platforms have led to 21,857 arrests.
Ecosystem Gaps
Through I4C, CFCFRMS, CyTrain, and the establishment of forensic infrastructure in states, India’s cybercrime ecosystem has greatly grown. But due to the rapid proliferation of cybercrime, systemic shortcomings are revealed regarding the restoration of victims, investigation, forensic capacity, cross-border enforcement, awareness, and stakeholder coordination:
- Victim Restitution Deficit: Although the total of ₹ 8,690 crore frozen has increased, the refund for victim compensation is limited to only ₹ 167 crore (2.18%) due to lengthy restoration processes relying on court orders.
- Forensic Capacity Limitations: 2 national, state-level, unevenly equipped cyber forensic labs can’t match the needs of over 10 million cybercrime complaints per year.
- Low conviction rate: The investigations of cybercrimes suffer from evidence collection and criminal proceedings, leading to limited conviction rates.
- Cross-border enforcement challenges: Many of the investment and digital arrest scams, in fact, are originating from Cambodia, Myanmar, and Laos, rendering the cybercrime response mechanisms of India helpless.
- Lack of Awareness: First-time digital users are quite prone to online scams and fraud, and many of the victims continue not reporting due to social stigma and lack of confidence.
- Partial Stakeholder Integration: Banks and small financial institutions, small companies, and emerging virtual asset providers not yet on board allow the money to slip through without being tracked.
CyberPeace Insights: Strategic Way Forward
India has already built a relatively mature response structure for cybercrime with I4C, CFCFRMS, and CyTrain and is coordinating the financial sector on it. The way ahead lies in outcome-oriented improvements and not just in the ability to report and intercept more. Here are the priority interventions that address the most important institutional shortcomings identified in the current ecosystem:
- Fast-track victim restoration: Introduce time-bound victim restoration mechanisms for low-value incidents through simplified processes and mandate national-level roll-out of successful Lok Adalat-based settlement mechanisms.
- District-level cyber forensics: Establish cyber forensic support units at the district level and enhance access to mobile, cloud, and blockchain forensic capabilities.
- AI-powered fraud prevention: Mandate deep-fake and voice-clone detection mechanisms across all financial institutions and telecom networks; embed predictive risk analytics into transaction screening frameworks.
- Cyber Suraksha Gram initiative: Increase digital fraud awareness across all common service centres, Jan Dhan enrollment schemes, and rural banking channels, and tackle the awareness asymmetry.
- Regional cybercrime coordination: Establish real-time, operational intelligence-sharing mechanisms with Southeast Asian economies, which have become home to large scam networks preying on Indian citizens.
- Specialised cyber prosecution ecosystem: Develop exclusive cyber courts, standardise digital evidence procedures, and broaden the scope of CyTrain to include the development of specialised cadres of investigators and prosecutors capable of handling increasingly complex cybercrime cases.
Conclusion
The 22,812 crore lost due to cybercrime in 2024 was more than a mere figure; it signifies a serious concern regarding citizen trust, economic security, and digital inclusion. Though India's institutional response to cybercrime is one of the largest, with an operational I4C and a CFCFRMS functioning in real time, the victim compensation and prosecution mechanism falls short. It's time for implementation: faster recovery of resources, increased enforcement, a larger scale of awareness, and finally, translating the institutional innovations into concrete justice for victims nationwide.
References
- https://sansad.in/getFile/annex/270/AU1341_tmaxdx.pdf?source=pqars
- https://www.mha.gov.in/MHA1/Par2017/pdfs/par2025-pdfs/LS02122025/452.pdf
- https://www.pib.gov.in/PressReleasePage.aspx?PRID=2244504®=3&lang=2
- https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/oct/doc2025107659501.pdf
- https://www.medianama.com/2025/08/223-india-cybercrime-500-percent-increase-2021-2024/
- https://theprint.in/india/cybercrime-saw-24-spike-in-2025-indians-lost-rs-22495-crore-mainly-in-investment-scams/2859930/

Introduction
Search Engine Optimisation (SEO) is a process through which one can improve website visibility on search engine platforms like Google, Microsoft Bing, etc. There is an implicit understanding that SEO suggestions or the links that are generated on top are the more popular information sources and, hence, are deemed to be more trustworthy. This trust, however, is being misused by threat actors through a process called SEO poisoning.
SEO poisoning is a method used by threat actors to attack and obtain information about the user by using manipulative methods that position their desired link, web page, etc to appear at the top of the search engine algorithm. The end goal is to lure the user into clicking and downloading their malware, presented in the garb of legitimate marketing or even as a valid result for Google search.
An active example of attempts at SEO poisoning has been discussed in a report by the Hindustan Times on 11th November, 2024. It highlights that using certain keywords could make a user more susceptible to hacking. Hackers are now targeting people who enter specific words or specific combinations in search engines. According to the report, users who looked up and clicked on links at the top related to the search query “Are Bengal cats legal in Australia?” had details regarding their personal information posted online soon after.
SEO Poisoning - Modus Operandi Of Attack
There are certain tactics that are used by the attackers on SEO poisoning, these are:
- Keyword stuffing- This method involves overloading a webpage with irrelevant words, which helps the false website appear higher in ranking.
- Typosquatting- This method involves creating domain names or links similar to the more popular and trusted websites. A lack of scrutiny before clicking would lead the user to download malware, from what they thought was a legitimate site.
- Cloaking- This method operates by showing different content to both the search engines and the user. While the search engine sees what it assumes to be a legitimate website, the user is exposed to harmful content.
- Private Link Networks- Threat actors create a group of unrelated websites in order to increase the number of referral links, which enables them to rank higher on search engine platforms.
- Article Spinning- This method involves imitating content from other pre-existing, legitimate websites, while making a few minor changes, giving the impression to search engine crawlers of it being original content.
- Sneaky Redirect- This method redirects the users to malicious websites (without their knowledge) instead of the ones the user had intended to click.
CyberPeace Recommendations
- Employee Security Awareness Training: Security awareness training can help employees familiarise themselves with tactics of SEO poisoning, encouraging them to either spot such inconsistencies early on or even alert the security team at the earliest.
- Tool usage: Companies can use Digital Risk Monitoring tools to catch instances of typosquatting. Endpoint Detection and Response (EDR) tools also help keep an eye on client history and assess user activities during security breaches to figure out the source of the affected file.
- Internal Security Measures: To refer to lists of Indicators of Compromise (IOC). IOC has URL lists that show evidence of the strange behaviour of websites, and this can be used to practice caution. Deploying Web Application Firewalls (WAFs) to mitigate and detect malicious traffic is helpful.
Conclusion
The nature of SEO poisoning is such that it inherently promotes the spread of misinformation, and facilitates cyberattacks. Misinformation regarding the legitimacy of the links and the content they display, in order to lure users into clicking on them, puts personal information under threat. As people trust their favoured search engines, and there is a lack of awareness of such tactics in use, one must exercise caution while clicking on links that seem to be popular, despite them being hosted by trusted search engines.
References
- https://www.checkpoint.com/cyber-hub/cyber-security/what-is-cyber-attack/what-is-seo-poisoning/
- https://www.vectra.ai/topics/seo-poisoning
- https://www.techtarget.com/whatis/definition/search-poisoning
- https://www.blackberry.com/us/en/solutions/endpoint-security/ransomware-protection/seo-poisoning
- https://www.coalitioninc.com/blog/seo-poisoning-attacks
- https://www.sciencedirect.com/science/article/abs/pii/S0160791X24000186
- https://www.repindia.com/blog/secure-your-organisation-from-seo-poisoning-and-malvertising-threats/
- https://www.hindustantimes.com/technology/typing-these-6-words-on-google-could-make-you-a-target-for-hackers-101731286153415.html

Overview:
After the blackout on July 19, 2024, which affected CrowdStrike’s services worldwide, cybercriminals began to launch many phishing attacks and distribute malware. These activities mainly affect CrowdStrike customers, using the confusion as a way to extort information through fake support sites. The analysis carried out by the Research Wing of CyberPeace and Autobot Infosec has identified several phishing links and malicious campaigns.
The Exploitation:
Cyber adversaries have registered domains that are similar to CrowdStrike’s brand and have opened fake accounts on social media platforms. These are fake platforms that are employed to defraud users into surrendering their personal and sensitive details for use in other fraudulent activities.
Phishing Campaign Links:
- crowdstrike-helpdesk[.]com
- crowdstrikebluescreen[.]com
- crowdstrike-bsod[.]com
- crowdstrikedown[.]site
- crowdstrike0day[.]com
- crowdstrikedoomsday[.]com
- crowdstrikefix[.]com
- crashstrike[.]com
- crowdstriketoken[.]com
- fix-crowdstrike-bsod[.]com
- bsodsm8r[.]xamzgjedu[.]com
- crowdstrikebsodfix[.]blob[.]core[.]windows[.]net
- crowdstrikecommuication[.]app
- fix-crowdstrike-apocalypse[.]com
- supportportal-crowdstrike-com[.]translate[.]goog
- crowdstrike-cloudtrail-storage-bb-126d5e[.]s3[.]us-west-1[.]amazonaws[.]com
- crowdstrikeoutage[.]info
- clownstrike[.]co[.]uk
- crowdstrikebsod[.]com
- whatiscrowdstrike[.]com
- clownstrike[.]co
- microsoftcrowdstrike[.]com
- crowdfalcon-immed-update[.]com
- crowdstuck[.]org
- failstrike[.]com
- winsstrike[.]com
- crowdpass[.]com
In one case, a PDF file is being circulated with CrowdStrike branding, saying ‘Download The Updater,’ which is a link to a ZIP file. The ZIP file is a compressed file that has an executable file with a virus. This is a clear sign that the hackers are out to take advantage of the current situation by releasing the malware as an update.




In another case, there is a malicious Microsoft Word document that is currently being shared, which claims to offer a solution on how to deal with this CrowdStrike BSOD bug. But there is a hidden risk in the document. When users follow the instructions and enable the embedded macro, it triggers the download of an information-stealing malware from a remote host. This is a form of malware that is used to steal information and is not well recognized by most security software. Also it sends the stolen data to the samesame remote host but with different port number, which likey works as the CnC server for the campaign.
- Name New_Recovery_Tool_to_help_with_CrowdStrike_issue_impacting_Windows[.]docm
- MD5 dd2100dfa067caae416b885637adc4ef
- SHA-1 499f8881f4927e7b4a1a0448f62c60741ea6d44b
- SHA-256 803727ccdf441e49096f3fd48107a5fe55c56c080f46773cd649c9e55ec1be61
- URLS http://172.104.160[.]126:8099/payload2.txt, http://172.104.160[.]126:5000/Uploadss


Recent Outage Impact:
On July 19, 2024, CrowdStrike faced a global outage that originated from an update of its Falcon Sensor security software. This outage affected many government organizations and companies in different industries, such as finance, media, and telecommunications. The event led to numerous complaints from the users who experienced problems like blue screen of death and system failure. Although, CrowdStrike has admitted to the problem and is in the process of fixing it.
Preventive Measures:
- Organize regular awareness sessions to educate the employees about the phishing techniques and how they can avoid the phishing scams, emails, links, and websites.
- MFA should be used for login to the sensitive accounts and systems for an improvement on the security levels.
- Make sure all security applications including the antivirus and anti-malware are up to date to help in the detection of phishing scams.
- This includes putting in place of measures such as alert on account activity or login patterns to facilitate early detection of phishing attempts.
- Encourage employees and users to inform the IT department as soon as they have any suspicions regarding phishing attempts.
Conclusion:
The recent CrowdStrike outage is a perfect example of how cybercriminals take advantage of the situation and user’s confusion and anxiety. Thus, people and organizations can keep themselves from these threats and maintain the confidentiality of their information by being cautious and adhering to the proper standards. To get the current information on the BSOD problem and the detailed instructions on its solution, visit CrowdStrike’s support center. Reported problems should be handled with caution and regular backup should be made to minimize the effects.
References:
- https://app.any.run/tasks/2c0ffc87-4059-4d6f-8306-1258cf33aa54/
- https://app.any.run/tasks/48e18e33-2007-49a8-aa60-d04c21e8fa11
- https://www.virustotal.com/gui/file/19001dd441e50233d7f0addb4fcd405a70ac3d5e310ff20b331d6f1a29c634f0/relations
- https://www.virustotal.com/gui/file/803727ccdf441e49096f3fd48107a5fe55c56c080f46773cd649c9e55ec1be61/detection
- https://www.joesandbox.com/analysis/1478411#iocs