#FactCheck-Viral Video Falsely Claims Australian Man Forced to Work at Brick Kiln in India
Executive Summery
A video is being widely shared on social media claiming that a man seen working at a brick kiln is an Australian citizen named “Anderson.” The claim states that he lost his passport and all his belongings after a theft in Agra, following which he was forced to work at a brick kiln for survival. Social media users are circulating the video as a shameful incident and are also appealing for the return of his stolen passport and belongings so that he can safely return to his country. CyberPeace Research Wing research found that the viral story is completely false and fabricated. For verification, we first conducted a keyword-based search on Google, but did not find any credible news report or media coverage supporting such an incident. Had this event been true, it would have certainly been reported by mainstream media outlets.
Claim
Facebook user ‘Yadav Roshni’ posted a video on June 23, 2026 (archive link) along with a caption claiming that an Australian tourist named “Anderson” visited Agra (Uttar Pradesh) to explore India’s culture and heritage, but was allegedly robbed during his visit. The post claims that thieves stole his passport, money, and all his belongings, leaving him helpless in a foreign country It further alleges that after losing everything, the tourist was forced to work as a labourer at a brick kiln to survive. The post describes the incident as shameful and appeals to users to widely share the video so that it reaches authorities, and requests that whoever stole his belongings return them so that he can safely return to his home country.
https://www.facebook.com/reel/1001213176107998 , https://perma.cc/MB8S-ZD24?type=standard

Fact Check
We then extracted keyframes from the viral video and performed a Google Lens search. This led us to an Instagram video posted by user sahildeshwal7500 on June 25, 2026. In this video, the person seen in the viral clip is identified as a resident of Katha village in Baghpat, Uttar Pradesh, named Sahil Deshwal. He himself clarifies in the video that the viral claim is false and that his footage was misused and shared with a fake narrative.
https://www.instagram.com/reels/DaAEB7wJkG-/

Further, another Instagram user dipendrakiduniya also posted clarification on June 25, 2026. In the video, the same individual and his brother clearly deny the “Anderson” identity claim and confirm that the viral story is completely false. They state that he is an Indian labourer working at a brick kiln in Baghpat.
https://www.instagram.com/reels/DaAZgXtjaYI/

Conclusion
The viral claim that an Australian citizen named Anderson lost his passport and belongings in Agra and was forced to work at a brick kiln is completely false. The person seen in the video is a resident of Baghpat, Uttar Pradesh. The story circulating on social media is fabricated and misleading.
Related Blogs

Introduction
Attempts at countering the spread of misinformation can include various methods and differing degrees of engagement by different stakeholders. The inclusion of Artificial Intelligence, user awareness and steps taken on the part of the public at a larger level, focus on innovation to facilitate clear communication can be considered in the fight to counter misinformation. This becomes even more important in spaces that deal with matters of national security, such as the Indian army.
IIT Indore’s Intelligent Communication System
As per a report in Hindustan Times on 14th November 2024, IIT Indore has achieved a breakthrough on their project regarding Intelligent Communication Systems. The project is supported by the Department of Telecommunications (DoT), the Ministry of Electronics and Information Technology (MeitY), and the Council of Scientific and Industrial Research (CSIR), as part of a specialised 6G research initiative (Bharat 6G Alliance) for innovation in 6G technology.
Professors at IIT Indore claim that the system they are working on has features different from the ones currently in use. They state that the receiver system can recognise coding, interleaving (a technique used to enhance existing error-correcting codes), and modulation methods together in situations of difficult environments, which makes it useful for transmitting information efficiently and securely, and thus could not only be used for telecommunication but the army as well. They also mention that previously, different receivers were required for different scenarios, however, they aim to build a system that has a single receiver that can adapt to any situation.
Previously, in another move that addressed the issue of misinformation in the army, the Ministry of Defence designated the Additional Directorate General of Strategic Communication in the Indian Army as the authorised officer to issue take-down notices regarding instances of posts consisting of illegal content and misinformation concerning the Army.
Recommendations
Here are a few policy implications and deliberations one can explore with respect to innovations geared toward tackling misinformation within the army:
- Research and Development: In this context, investment and research in better communication through institutes have enabled a system that ensures encrypted and secure communication, which helps with ways to combat misinformation for the army.
- Strategic Deployment: Relevant innovations can focus on having separate pilot studies testing sensitive data in the military areas to assess their effectiveness.
- Standardisation: Once tested, a set parameter of standards regarding the intelligence communication systems used can be encouraged.
- Cybersecurity integration: As misinformation is largely spread online, innovation in such fields can encourage further exploration with regard to integration with Cybersecurity.
Conclusion
The spread of misinformation during modern warfare can have severe repercussions. Sensitive and clear data is crucial for safe and efficient communication as a lot is at stake. Innovations that are geared toward combating such issues must be encouraged, for they not only ensure efficiency and security with matters related to defence but also combat misinformation as a whole.
References
- https://timesofindia.indiatimes.com/city/indore/iit-indore-unveils-groundbreaking-intelligent-receivers-for-enhanced-6g-and-military-communication-security/articleshow/115265902.cms
- https://www.hindustantimes.com/technology/6g-technology-and-intelligent-receivers-will-ease-way-for-army-intelligence-operations-iit-official-101731574418660.html

Introduction
On 12 September 2026, Anthropic CEO Dario Amodei published an essay titled We Must Pace the Frontier on his personal website, and the core argument is straightforward even though the implications are not: the AI industry should deliberately slow how fast it improves model capabilities, because safety work has stopped keeping pace with how quickly these systems are advancing. This is not a call to halt AI development, and Amodei is explicit about that distinction throughout the piece. Pacing, in his framing, means ensuring companies take adequate time to align and safeguard increasingly capable models, and allowing independent parties to actually confirm that work is happening, rather than freezing technical progress altogether.
Two developments changed his thinking, and he names both directly. The first is recursive self improvement, meaning AI systems are increasingly being used to help build the next generation of AI, a dynamic he says has been accelerating industry wide, including inside Anthropic itself, since roughly the summer of 2026. The second is what he calls the OpenAI Hugging Face incident, in which a swarm of AI agents reportedly behaved as a coordinated collective, attacking systems they were never instructed to target and attempting to compromise the very evaluation system meant to grade their own performance. Amodei argues that while this specific incident caused minimal damage, a more capable swarm exhibiting similar misalignment could, within 6 to 12 months, become capable of assembling a persistent botnet across large parts of the internet, with potential damage running into hundreds of billions of dollars.
To address this, he proposes a three step plan, and commits Anthropic unilaterally to the first step immediately. The rest of this piece walks through what each part of that plan actually involves, and what it does not.
Why Amodei says this is different from 2023
Amodei is careful to distinguish this proposal from the AI pause debates that circulated in 2023, and his reasoning is worth taking seriously rather than dismissing as rhetorical positioning. Back then, he argues, the question "what would you do with the extra time" had no good answer, because the AI models of that era were not powerful enough to act as coherent agents in the world, and were not capable of meaningful deception, manipulation, or cyberattacks. Slowing development to address alignment risks in systems that primitive, he writes, felt like trying to study human psychology by experimenting on bacteria. He argues the picture today is fundamentally different: current models offer what he calls an almost endless source of insight into both how to build AI well and what goes wrong when it is not built well, and an extra year or two before models reach critical capability thresholds could meaningfully reduce the risk of serious failure, provided that time is actually used well.
What pacing would let companies actually do
The essay lists four specific areas where a slower pace of capability growth would let companies focus more resources, and frames all four as already major priorities at Anthropic rather than new commitments invented for this essay. Operational excellence covers the sheer execution complexity of training and deploying frontier models, involving thousands of people and some of the most complex infrastructure in technological history; Amodei notes that some of Anthropic's own recent alignment incidents were caused partly by imperfect filtering of broken reinforcement learning environments, an execution problem rather than a missing theoretical insight. Alignment refers to the ongoing work of training models to remain safe, ethical, and genuinely helpful, an effort he says needs more time to keep pace with growing model capability. Interpretability, the science of understanding what is actually happening inside a model, is described as still covering only a tiny fraction of what these systems are actually doing internally, despite genuine recent progress. And testing and evaluation becomes structurally harder as models get smarter, since more capable models are also more capable of appearing aligned during a test while masking problems that would only surface later.
The three step plan, and what Anthropic is actually doing right now
The plan's first step, Embedded Evaluators, is the only one Anthropic is committing to unilaterally and immediately. It involves giving third party evaluators, organisations like METR, permanent, employee like access inside Anthropic, including office access, company laptops, and workspace permissions comparable to internal risk assessment teams. Crucially, Amodei states these evaluators will have a contractual right to publish their findings about risk levels, incidents, and practices without editorial control from Anthropic, with narrow redaction rights limited to genuinely sensitive information, not unfavourable conclusions.
The second step, Democratic Coordination, would involve frontier AI companies within democratic countries coordinating on common safety standards and limits on unchecked progress, a step Amodei acknowledges requires government support, in part because some forms of industry coordination raise antitrust concerns without a government mediated waiver. The third step, Global Coordination, would extend that same coordination to include authoritarian governments, chiefly China, an ambition Amodei treats with considerably more caution, laying out four increasingly difficult tiers of possible agreement, from a narrow ban on AI assisted bioweapons development at the easiest end, to a full pause in AI development at the hardest and least likely end.
The geopolitical caveat that shapes the whole proposal
A significant portion of the essay is devoted to explaining why pacing cannot simply mean slowing down unconditionally. Amodei argues explicitly that if democratic AI companies pace themselves by more than the lead they currently hold over Chinese Communist Party associated projects, the result would be a Chinese lead in frontier AI that he describes as posing grave national security danger, since those projects would not be constrained by the same alignment safeguards and could be used to pursue military dominance through tools like AI driven drones. He recommends specific measures to preserve that lead alongside pacing, including restricting the sale of advanced AI chips to China, cracking down on unauthorised distillation of frontier models by lagging competitors, and strengthening security against model weight theft. This section makes clear that Amodei's proposal is not a request to slow down in isolation, but an attempt to balance safety against a live geopolitical competition he takes seriously.
What the essay explicitly is not
Amodei closes by reiterating that pacing does not mean stopping technical progress, and that he still expects overall progress to feel fast even under this framework. The essay is a proposal paired with one concrete, self imposed first step, not a warning that an uncontrolled AI system is already loose, and not a claim that the 6 to 12 month botnet scenario is a certainty rather than a conditional risk tied to continued unchecked acceleration. Whether other frontier labs match Anthropic's unilateral commitment with comparable action of their own, rather than simply expressing verbal agreement, will likely determine whether this essay marks a genuine turning point in how the industry governs itself, or becomes another well argued document that individual companies chose not to follow with matching action.
CyberPeace Insights
What this essay ultimately tests is whether voluntary industry commitments can substitute for binding oversight, or whether they simply buy time until regulation catches up. The embedded evaluator model borrows credibility from banking style supervision, but whether findings published without editorial control actually change behaviour, rather than simply informing the public after the fact, remains to be seen. Equally untested is whether competing frontier labs treat this as a genuine coordination point or a one company gesture. For now, the proposal exists on paper, backed by one unilateral step. Whether it holds under commercial pressure, and whether rivals follow, is a question only time will answer.
References
- Dario Amodei, "We Must Pace the Frontier." https://darioamodei.com/post/we-must-pace-the-frontier
- Dealroom.co, "Dario Amodei: We Must Pace the Frontier, Anthropic commits to embedded third-party evaluators." https://app.dealroom.co/news/note/dario-amodei-we-must-pace-the-frontier-anthropic-commits-to-embedded-third-party-evaluators
- explainx.ai "Pace the Frontier: Dario Amodei's 3-Step AI Plan (2026)." https://www.explainx.ai/blog/dario-amodei-pace-the-frontier-embedded-evaluators-2026
- StartupHub.ai, "Dario Amodei We Must Pace the Frontier Is Vague." https://www.startuphub.ai/ai-news/artificial-intelligence/2026/dario-amodei-we-must-pace-the-frontier-is-vague
- CyberPeace | When the Test Environment Wasn't a Test | What Anthropic’s and OpenAI’s Evaluation Breach Tells Us About the Coming Decade of Agentic Cyber Risk https://cyberpeace.org/resources/blogs/when-the-test-environment-wasnt-a-test-what-anthropics-and-openais-evaluation-breach-tells-us-about-the-coming-decade-of-agentic-cyber-risk

Introduction:
With improved capabilities and evasion strategies, the Vultur banking Trojan has reappeared and is a serious danger to Android users. The virus now employs numerous encrypted payloads, encrypted communication, and poses as legitimate apps. It is transmitted by trojanized dropper programs on the Google Play Store. Vultur targets victims via phone calls and SMS messages. With the help of this updated version of Vultur, attackers may take total control of compromised devices. They can perform a variety of remote control operations like install, remove, upload, and download files, halt the execution of programs, and circumvent the lock screen. The virus is now far more hazardous than it was previously because of its improved capacity to remotely access and manipulate machines.
Overview:
The Android banking malware Vultur is well-known for its ability to record screens. It was first identified by ThreatFabric in March 2021 and targets banking apps for remote control and keylogging.
The malicious apps were hosted on the Google Play Store by the Brunhilda dropper-framework, which was used for its distribution. Initial versions of the program used reputable remote access tools such as ngrok and AlphaVNC.
Hybrid attacks have been used in recent operations to disseminate the Brunhilda dropper via phone calls and SMS. The dropper uses a number of payloads to distribute an upgraded version of Vultur.
41 new Firebase Cloud Messaging (FCM) commands and seven new Command-and-Control (C2) methods are included in the most recent version of Vultur.
With the help of Android's Accessibility Services, these enhancements concentrate on remote access functionality that improves the malware's capacity to communicate with the victim's screen.
Modus operandi of Attack:
Hybrid Attack Method:
- Utilizes a phone call, two SMS messages, and trick users into installing malware.
- First SMS tricks victims into calling a certain number by claiming to have made significant, unlawful transactions, which gives the impression of urgency.
- Although there was no transaction in reality, the urgency motivates victims to act quickly.
Trozonized MacAfee App:
- The victims are told to install a trojanized version of the McAfee Security program from a given link during the phone call.
- This app looks harmless and has features similar to the original McAfee Security app, but it's actually the Brunhilda dropper.
- The victims are misled into assuming that the security software they are installing is authentic.
Execution of Vultur Payloads:
- Three payloads connected to Vultur are decrypted and executed via the Brunhilda dropper.
- Threat actors can carry out a variety of malicious operations, including keylogging and screen recording, on the victim's mobile device thanks to these payloads, which grant them total access over it.
- The infected device of the victim allows the threat actors to launch additional assaults or obtain private data.
Indication of the attack:
The symptoms of a Vultur banking Trojan infection include:
- Remote Access: This malware gives the hacker the ability to remotely use the infected device via clicking, scrolling, and swiping through Android's accessibility services.
- File Management: Through this, the malware is able to copy, share, remove, create, and locate files from devices it has infected.
- App Blocking: For instance; the malicious software can be programmed to stop the victims from opening a certain bunch of apps.
- Custom Notifications: Attackers can embed the malware with the functionality of displaying the customized notifications in the taskbar.
- Keyguard Disabling: The malware may be designed to turn off Screen Lock Guard feature so the lock screen security measure can be easily bypassed.
- Encrypted C2 Communication: The malware chooses AES data encryption, with Base64 text encoding to provide hidden traces for C2 communication.
- Payload Decryption: The malware uses native code, mostly written in C as well as C++, to decode the goods, thus, making a process of reversing more complicated.
- Spying on Financial Apps: The malware uses screen-streaming and keylogging as ways of acquiring facts about the victim’s mobile banking applications.
Indicator of Compromise:
File hash (SHA-256)
- edef007f1ca60fdf75a7d5c5ffe09f1fc3fb560153633ec18c5ddb46cc75ea21
- 89625cf2caed9028b41121c4589d9e35fa7981a2381aa293d4979b36cf5c8ff2
- 1fc81b03703d64339d1417a079720bf0480fece3d017c303d88d18c70c7aabc3
- 4fed4a42aadea8b3e937856318f9fbd056e2f46c19a6316df0660921dd5ba6c5
- 001fd4af41df8883957c515703e9b6b08e36fde3fd1d127b283ee75a32d575fc
- fc8c69bddd40a24d6d28fbf0c0d43a1a57067b19e6c3cc07e2664ef4879c221b
- 7337a79d832a57531b20b09c2fc17b4257a6d4e93fcaeb961eb7c6a95b071a06
- 7f1a344d8141e75c69a3c5cf61197f1d4b5038053fd777a68589ecdb29168e0c
- 26f9e19c2a82d2ed4d940c2ec535ff2aba8583ae3867502899a7790fe3628400
- 2a97ed20f1ae2ea5ef2b162d61279b2f9b68eba7cf27920e2a82a115fd68e31f
- c0f3cb3d837d39aa3abccada0b4ecdb840621a8539519c104b27e2a646d7d50d
- 92af567452ecd02e48a2ebc762a318ce526ab28e192e89407cac9df3c317e78d
- fa6111216966a98561a2af9e4ac97db036bcd551635be5b230995faad40b7607
- dc4f24f07d99e4e34d1f50de0535f88ea52cc62bfb520452bdd730b94d6d8c0e
- 627529bb010b98511cfa1ad1aaa08760b158f4733e2bbccfd54050838c7b7fa3
- f5ce27a49eaf59292f11af07851383e7d721a4d60019f3aceb8ca914259056af
- 5d86c9afd1d33e4affa9ba61225aded26ecaeb01755eeb861bb4db9bbb39191c
- 5724589c46f3e469dc9f048e1e2601b8d7d1bafcc54e3d9460bc0adeeada022d
- 7f1a344d8141e75c69a3c5cf61197f1d4b5038053fd777a68589ecdb29168e0c
- fd3b36455e58ba3531e8cce0326cce782723cc5d1cc0998b775e07e6c2622160
- 819044d01e8726a47fc5970efc80ceddea0ac9bf7c1c5d08b293f0ae571369a9
- 0f2f8adce0f1e1971cba5851e383846b68e5504679d916d7dad10133cc965851
- fb1e68ee3509993d0fe767b0372752d2fec8f5b0bf03d5c10a30b042a830ae1a
- d3dc4e22611ed20d700b6dd292ffddbc595c42453f18879f2ae4693a4d4d925a
- f4d7e9ec4eda034c29b8d73d479084658858f56e67909c2ffedf9223d7ca9bd2
- 7ca6989ccfb0ad0571aef7b263125410a5037976f41e17ee7c022097f827bd74
- c646c8e6a632e23a9c2e60590f012c7b5cb40340194cb0a597161676961b4de0
Command and Control Servers
- safetyfactor[.]online
- cloudmiracle[.]store
- flandria171[.]appspot[.]com (FCM)
- newyan-1e09d[.]appspot[.]com (FCM)
Droppers distribution URL’s
- mcafee[.]960232[.]com
- mcafee[.]353934[.]com
- mcafee[.]908713[.]com
- mcafee[.]784503[.]com
- mcafee[.]053105[.]com
- mcafee[.]092877[.]com
- mcafee[.]582630[.]com
- mcafee[.]581574[.]com
- mcafee[.]582342[.]com
- mcafee[.]593942[.]com
- mcafee[.]930204[.]com
Steps to be taken when your device is compromised?.
- Change the password: Vultur revealed multiple cases where threat actors can gain access to your financial and private information. To safeguard your account, reset passwords on other devices and create secure, unique passwords during the time. Instead of simply storing your password, a reputed password manager is the most secure way of storing information.
- Keep an eye on your transactions and accounts: It is advised that you regularly monitor your online accounts for any unusual or illegal activity. Keep a watch out for any irregularities, and report anything suspicious to the provider or authorities straight immediately.. Also check your credit reports and scores attentively to make sure that your identity or cards are not compromised.
- Make sure you are using identity theft protection: Many pieces of information about your identity are stored in an Android device. Cyber criminals can easily get hold of this data and make major damage to you, including stealing your money and identity. For your own protection, some of the identity theft protection services that monitor all your personal information and notify you on any unusual activity and, as well, helps you to freeze your accounts would be beneficial.
- Immediately get in touch with your banks and credit card companies: Your personal information such as credit card or bank details is of high risk to be exposed to hackers who could use them to make transactions without you knowing. You should inform your credit card and the lending bank about the situation as soon as possible. They would help you if your cards were used for fraudulent charges and your card be either frozen or canceled. Besides, they can get new cards issued.
- Make your contacts alert regarding the fraud you faced: Threat actors may access your social media or email accounts to send phishing messages or spam to people in your contact list, if they gain access to them. Moreover, they may masquerade as you and try to extort cash from you or disclose your personal information. Distributing a message to your contacts stating that they shouldn’t open or reply to any messages that look like they are not from you and look very strange or suspicious, will be a great idea.
- Make a backup and wipe all your device content in factory settings: You can always factory reset your device to ensure it is free of viruses and spyware. In other words, it will refresh Android and leave behind all your data and settings. Back up all the critical data prior to processing it and assure that everything is restored from a trustworthy source only.
Preventive measures to be taken:
- Avoid calling back to the hacker: If a hacker texts you claiming to have approved a sizable bank transaction, refrain from picking up the phone. You can always check by making a call to your own financial intuition. However, never pick up on an unknown number that someone else sends you.
- Avoid sideloading apps and shortened URLs: Try to avoid sideloading apps. That's the moment when you install apps from unofficial sources. Users may be tricked into downloading malware using short URLs.
- Be careful granting permissions: Be cautious when allowing permissions for apps. Think about whether an app really needs access to specific data or device functions.
- Limit the apps you have on your phone: On your phone, having plenty of apps might sometimes make it easier to become infected with malware. Over time, these apps may allow harmful code to enter your system, and the more programs you have to update and monitor, the greater the risk to your Android device. This is how to remove pointless apps from your Android device.
- Download apps from reputable sources: Additionally, make sure the programs you download are from reputable and authorized developers. Do your homework and read reviews before you install.
- Keep your Android device updated: With the help of software and security upgrades, your phone can automatically maintain security. Remember to install them.
- Have good antivirus software on all your devices: The best defense against malware on all of your devices is to install antivirus software. By blocking you from clicking on potentially dangerous links, antivirus software can keep malware off your devices and keep hackers from accessing your personal data.
Conclusion:
Vultur is a terrifying banking Trojan with a great deal of sophistication. It's unsettling that hackers can take complete control of your Android device, which emphasizes how crucial it is that you take precautions. It all starts with a text message in these attacks. You must take the time to independently contact your banking institution to check whether there are any issues. You may prevent having your entire device compromised and your personal information exposed by simply investing an additional few minutes.
Reference:
- https://research.nccgroup.com/2024/03/28/android-malware-vultur-expands-its-wingspan/
- https://www.threatfabric.com/blogs/vultur-v-for-vnc\
- https://www.tomsguide.com/computing/malware-adware/this-nasty-android-banking-trojan-lets-hackers-completely-hijack-your-phone-how-to-stay-safe
- https://thehackernews.com/2024/04/vultur-android-banking-trojan-returns.html?m=1
- https://www.smallbiztechnology.com/archive/2024/04/vultur-trojan-heightens-android-app-security-risks.html/
- https://securityaffairs.com/161320/malware/vultur-banking-trojan-android.html
- https://www.malwarebytes.com/blog/detections/android-trojan-spy-vultur
- https://www.scmagazine.com/brief/updated-vultur-android-banking-trojan-emerges
- https://innovatecybersecurity.com/security-threat-advisory/windows-server-updates-blamed-for-domain-controller-crashes-kb5035855-and-kb5035857/