#FactCheck - Edited Video of ‘India-India’ Chants at Republican National Convention
Executive Summary:
A video online alleges that people are chanting "India India" as Ohio Senator J.D. Vance meets them at the Republican National Convention (RNC). This claim is not correct. The CyberPeace Research team’s investigation showed that the video was digitally changed to include the chanting. The unaltered video was shared by “The Wall Street Journal” and confirmed via the YouTube channel of “Forbes Breaking News”, which features different music performing while Mr. and Mrs. Usha Vance greeted those present in the gathering. So the claim that participants chanted "India India" is not real.

Claims:
A video spreading on social media shows attendees chanting "India-India" as Ohio Senator J.D. Vance and his wife, Usha Vance greet them at the Republican National Convention (RNC).


Fact Check:
Upon receiving the posts, we did keyword search related to the context of the viral video. We found a video uploaded by The Wall Street Journal on July 16, titled "Watch: J.D. Vance Is Nominated as Vice Presidential Nominee at the RNC," at the time stamp 0:49. We couldn’t hear any India-India chants whereas in the viral video, we can clearly hear it.
We also found the video on the YouTube channel of Forbes Breaking News. In the timestamp at 3:00:58, we can see the same clip as the viral video but no “India-India” chant could be heard.

Hence, the claim made in the viral video is false and misleading.
Conclusion:
The viral video claiming to show "India-India" chants during Ohio Senator J.D. Vance's greeting at the Republican National Convention is altered. The original video, confirmed by sources including “The Wall Street Journal” and “Forbes Breaking News” features different music without any such chants. Therefore, the claim is false and misleading.
Claim: A video spreading on social media shows attendees chanting "India-India" as Ohio Senator J.D. Vance and his wife, Usha Vance greet them at the Republican National Convention (RNC).
Claimed on: X
Fact Check: Fake & Misleading
Related Blogs

Perth, Western Australia — For most of the past year, the name TeamPCP has circulated quietly within cybersecurity circles as shorthand for a particular kind of dread: not the dread of a phishing email or a suspicious link, but the dread of software you already trusted turning against you. This week, that quiet circulation became public record. The Australian Federal Police, working alongside the FBI and the Western Australia Police Force, arrested and charged two Western Australian men, aged 21 and 23, with a combined 14 offences over their alleged role in the group.
The arrests themselves are notable. The story behind them is more so.
A Campaign Built on Borrowed Trust
TeamPCP's alleged method was not to break down the front door. It was to compromise the door itself, the trusted mechanisms by which developers pull code into their own projects every day. The group has been linked to widespread supply-chain attacks that targeted open-source software and developer platforms to steal credentials, authentication secrets, and source code, with high-profile incidents affecting projects including Trivy, LiteLLM, Telnyx, SAP, and TanStack, alongside breaches at organisations such as the European Commission, Mistral AI, OpenAI, and GitHub. Reporting has also linked the campaign to ecosystems including GitHub Actions, Docker Hub, npm, PyPI and OpenVSX, the invisible plumbing through which most modern software is assembled.
The scale, as alleged by investigators, is difficult to overstate. Authorities say the malicious code potentially compromised over a thousand organisations worldwide, enabling the theft of roughly half a million credentials and the exfiltration of at least 300GB of data, figures that should be understood as allegations under active investigation rather than an independently verified victim count. The AFP itself has said the compromise of a small number of trusted software components had a significant global impact, with remediation costs estimated in the hundreds of millions of dollars.
Why This Attack Was So Hard to See Coming
The mechanics matter. Rather than tricking a user into clicking something malicious, the alleged operation worked by compromising the credentials developers use to publish legitimate software updates, then pushing tampered versions out through the same trusted distribution pipelines millions of applications rely on automatically. There is no obviously suspicious file, no rogue website, only a routine update, arriving exactly where it was expected.
Investigators also describe a cascading structure to the intrusions: credentials harvested from one compromised project reportedly opened the door to the next, turning isolated breaches into a chain reaction across the open-source ecosystem. TeamPCP has been described as running one of the most consequential campaigns of software supply-chain attacks investigators have tracked, and the group's reach extended notably into the AI stack — LiteLLM, one of the projects reportedly compromised, is an open-source gateway widely used to connect applications to large language model providers, meaning the attack's blast radius extended into the very infrastructure powering today's AI boom.
The Investigation and the Charges
The two men were charged following a joint investigation by the AFP and WAPF, working in parallel with the FBI, into what authorities describe as a sophisticated cybercrime syndicate accused of creating malicious open-source software to defraud thousands of global businesses. The charges span identity theft, unauthorised data modification, and money laundering, with maximum penalties ranging from three to twenty years' imprisonment. Search warrants were executed in Perth on 26 August 2026, and investigators seized electronic devices for forensic analysis after raids at properties in Cottesloe, Hamilton Hill, and Mandurah. FBI Cyber Division Assistant Director Brett Leatherman noted the significance of the international cooperation involved in the case, while investigators have not ruled out further arrests.
The Real Story: A Governance Problem, Not Just a Crime Story
It would be easy to file this under "hackers caught" and move on. But the more consequential story is structural. Modern organisations do not merely secure their own infrastructure, they inherit risk from every library, package, CI/CD pipeline, repository, vendor and developer tool they depend on, often without ever auditing that dependency chain directly. Guidance from the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on securing open-source software has increasingly emphasised managing these dependencies through software bills of materials (SBOMs), precisely because so few organisations can otherwise answer a basic question: what, exactly, is running inside our systems?
TeamPCP's alleged campaign is a case study in why that question can no longer be optional. If an organisation's security posture is only as strong as the thousands of components it silently trusts, then supply-chain security is not a developer problem to be quietly patched — it is a governance issue, deserving board-level attention, vendor accountability frameworks, and mandatory disclosure practices.
CyberPeace's Take
At CyberPeace, we've been watching campaigns like TeamPCP's less as isolated incidents and more as a pattern that keeps repeating with higher stakes each time. What stands out to our team isn't the sophistication of the code, open-source poisoning is, frankly, not a new technique, it's the sophistication of patience. Compromising a maintainer's publishing credentials and simply waiting for the next scheduled release to carry the payload downstream is a strategy built for an ecosystem that still largely operates on implicit trust rather than continuous verification. That gap between how fast software moves and how slowly trust is actually checked is precisely where operations like this thrive.
We'd also push back gently on treating this as a "developer hygiene" story. Most engineering teams pulling in a package from npm or PyPI are not, and should not be expected to be, forensically auditing every dependency update by hand, that isn't scalable, and it was never a realistic line of defence. The actual fix has to sit further upstream: provenance verification baked into CI/CD pipelines, signed commits and releases treated as non-negotiable rather than optional, and SBOMs that are actually queried during incident response rather than generated once and filed away.
Our broader concern, honestly, is about incentive alignment. Open-source maintainers are frequently unpaid or under-resourced volunteers holding publishing keys to software depended on by billion-dollar enterprises. Until organisations that consume open-source software at scale start meaningfully funding its security, not just its development, this pattern isn't going away. It will simply find its next entry point.
References
- Australian Federal Police. Two WA men charged following AFP-FBI-WAPF disruption of alleged global cybercrime syndicate. afp.gov.au
- Bleeping Computer. Australia arrests alleged TeamPCP hackers behind supply-chain attacks. bleepingcomputer.com
- CyberScoop. Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos. cyberscoop.com
- Cyber Daily. Busted! Alleged Aussie hackers linked to TeamPCP arrested in joint AFP-FBI-WAPF operation. cyberdaily.au
- Help Net Security. Two alleged TeamPCP hackers arrested over global supply chain attacks. helpnetsecurity.com
- Krebs on Security. Two Alleged 'TeamPCP' Hackers Arrested in Australia. krebsonsecurity.com
- TechCrunch. Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others. techcrunch.com
- The Hacker News. Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks. thehackernews.com
.webp)
Introduction
Delhi is Delhi-ing these days — whether it's the protest, the monsoon weather, the ongoing Monsoon Session of Parliament, metro disruptions, or just the general chaos of it all. Amid everything else, it's been over 30 days, starting from late June 2026, since the large public march organised in part by the group known as the Cockroach Janta Party (CJP) converged near Parliament and on Jantar Mantar, and the city hasn't quite exhaled since. Like every large, fast-moving public event, it's come with a parallel flood online: photos, video clips, injury claims, and hot takes pouring in from participants, bystanders, and news outlets alike, all competing for your instagram scroll.
CyberPeace is a non-partisan digital trust and safety organisation, and what we do care about is the online information environment building up around the event — helping people spot misinformation and manipulated media, and encouraging a bit more caution before hitting "share" while rumours are moving faster than facts.
Delhi Police has already made a public appeal along similar lines, asking citizens against online spread of unverified rumours, noting that misinformation could make an already tense situation worse. This advisory builds on that, with some practical guidance for everyday citizens navigating the protest in light of social media.
Why This Matters Right Now
30 plus days in, the story has layers: the original hunger strike, the march itself, police action, viral clips, and now a second wave of commentary reacting to the reactions. Old footage resurfaces relabelled as "live." Numbers get inflated or deflated depending on who's sharing them. Screenshots go around stripped of context. The longer a protest runs, the murkier the timeline gets for anyone just scrolling past — which is exactly when misinformation finds the most room to spread.
The internet access was also restricted in parts of the city during the march, which has itself become a point of attention.
Given how much unverified information is already circulating, it's worth treating any single account of "what actually happened". The full picture will likely take time to emerge through credible reporting and scrutiny.
Why This Moment Is Especially Prone to Misinformation
A few things are working together here to make mis-information spread faster than usual: Emotions are running high. Clashes, injuries, and confrontations naturally provoke strong reactions, and content that makes people angry or afraid tends to get shared quickly, with far less scrutiny than a calm, verified report would get.
There are information gaps. Reports of internet restrictions in parts of the city leave holes that get filled with speculation or worse, old footage recycled and passed off as live updates.
The event is politically charged, which means competing narratives are synthetically being pushed from multiple directions, sometimes deliberately, making it harder to find neutral ground.
There's simply a huge volume of content. Thousands of clips and photos are being posted from one event, which makes it easy for unrelated or out-of-context material to slip in alongside the real thing. And then there's satire. Part of this movement has roots in political satire, so parody posts and meme accounts can easily be mistaken for genuine news if they're shared without context.
Common Types of Misleading Content to Watch For
A few patterns tend to show up again and again during events like this:
- Old footage getting relabelled - Photos or videos from a completely different protest, city, or even country, re-shared with a caption claiming it's from this event.
- Clips taken out of context - A short moment, like a scuffle, shown without what happened right before or after it, changing how it reads.
- Doctored images - Photos edited to add, remove, or exaggerate people, banners, injuries, or crowd size.
- Fake official statements - Screenshots or graphics designed to look like they came from Delhi Police or a government department, but never actually issued.
- Made-up casualty numbers - Figures shared with no real source, often vaguely attributed to "eyewitnesses."
- Impersonation accounts - Handles designed to look like an official police or organiser account, sometimes just one letter off from the real one.
- AI-generated visuals - Fully or partly synthetic images and videos showing scenes or crowds that never actually happened.
- Rumours about shutdowns - Unverified claims about internet blackouts, road closures, or metro shutdowns that may be old, exaggerated, or simply untrue.
What Citizens Should Do:
- Pause before you forward. If a clip or claim makes you feel an instant, strong reaction, that's often the moment to slow down, not speed up.
- Check the timestamp and source. A five-day-old protest generates a lot of recycled footage. Reverse image/video search before assuming something is "breaking."
- Cross-check with more than one outlet. If only one account or page is reporting something dramatic, wait for corroboration.
- Be wary of numbers without sources. Injury counts, crowd sizes, and arrest figures are easy to exaggerate in either direction.
- Don't share unverified visuals of injuries or violence. Beyond accuracy concerns, this can also cause real harm to the people shown.
- When in doubt, don't repost — verify first, or simply sit it out.
How to Check a Claim Before You Share It:
A checklist goes a long way here:
- Pause for a second. Content built to provoke a strong reaction is often designed to get past your defenses before you think twice. Just slowing down is itself protective.
- Ask where it actually came from. Is this from a named journalist or outlet you can verify, or an anonymous forward with no clear origin? Messages that have clearly been passed around many times deserve extra suspicion.
- Look for more than one source. If something significant is genuinely true, you'll usually find several independent, reputable outlets reporting it not just one channel or account.
- Check the date and place. A quick reverse image or video search can tell you if a photo or clip has shown up online before, and what it was originally about.
- Wait for official confirmation. For anything involving police action, injuries, or arrests, check verified accounts like Delhi Police, PIB, established news wires before treating a claim as settled fact.
- Be suspicious of absolute language. Words like "confirmed," "breaking," or "exposed," used without naming any actual source, are a classic misinformation tell.
- Look at the account, not just the post. New accounts with no history, or ones that only ever post about this one topic, deserve a second look.
- Notice when something feels too satisfying. If a claim perfectly confirms what you already believed, that's exactly when you should slow down and check it; it's the content you're least likely to question on your own.
Reliable Fact-Checking Platforms and AI Detection Tools:
These resources can help you check specific claims, images, or videos:
- For fact-checking: PIB Fact Check (factcheck.pib.gov.in) for anything involving government statements or orders; Alt News (altnews.in) and BOOM Live (boomlive.in), two independent Indian outlets that regularly cover protest- and politics-related claims.
- For reverse image and video searches: Google Images, Google Lens, and TinEye can show you where a photo first appeared and in what context. InVID-WeVerify is a free browser plugin built for journalists that breaks videos into keyframes and lets you reverse-search individual frames.
- For AI and synthetic media detection: Hive Moderation and Sensity AI offer public tools for checking images and video. Deepware Scanner focuses specifically on deepfake video. And most major platforms like Meta, YouTube, X are now labeling some AI-generated content automatically, though the absence of a label doesn't mean something's real.
- A few terms worth knowing: A cheapfake is misleading media made with simple editing, cropping, slowing down, re-captioning rather than AI. These are still far more common than actual AI deepfakes. A deepfake is synthetic audio, video, or image content made with AI to convincingly show someone saying or doing something they didn't. Synthetic media is the broader umbrella term for any AI-generated content, whether or not it's being used to deceive.
Reporting Mechanism ~ If You Come Across Suspected Misinformation
Don't share it further, even to mock or correct it any engagement can boost its reach. Check it against the fact-checking tools above before deciding what you think is true. Report it directly on the platform. If it falls under the category of ‘Unlawful Content’ as per IT Rules, you can reach out to the grievance officer of the platform for removal of such content.
If it involves a government statement or order, send it to PIB Fact Check. If it looks like incitement, impersonation, extortion, or another cybercrime, report it to the National Cyber Crime Reporting Portal (cybercrime.gov.in) or call 1930.
Further Steps & helplines
- To file a cybercrime complaint: National Cyber Crime Reporting Portal - 1930 or cybercrime.gov.in
- To flag a fake government-related claim: PIB Fact Check - factcheck.pib.gov.in
- For an on-ground emergency: dial 100 / 112
- CyberPeace Helpline: +91 9570000066 or helpline@cyberpeace.net
- For fact check and debunking of any suspicious viral information, you can reach out to cyberpeace at helpline@cyberpeace.net
- If this advisory feels useful, consider sharing it in family WhatsApp groups, community networks, or student and youth organisations as it helps slow the spread of unverified content when more people are thinking about it.
CyberPeace's Message to Citizens
Being first to share something isn't the same as being right. In moments like this, the most useful thing any of us can do is slow down, verify before sharing, be a little suspicious of content that confirms exactly what we already believed, and trust named, accountable sources over anonymous forwards. Misinformation during civic unrest doesn't just mislead people; it can raise tensions, put individuals at risk, and chip away at trust in both the media and the institutions meant to maintain public order.Our goal is simply to help people navigate the information around it a little more safely and critically.
Conclusion
Protests and public unrest always generate a flood of information, and not all of it will be accurate. What keeps that information environment healthy isn't any single authority or platform, it's the everyday habits of the people deciding, one post at a time, whether to check something or just pass it along. Delhi's news cycle will keep moving, and this advisory isn't asking anyone to disengage from it. It's just a nudge to stay a little more careful with what you believe and what you pass on in this social media age. Pause. Verify. Scroll healthy. Stay CyberPeaceful.
References
- https://rajkaran.in/delhi-police-urges-calm-amid-cjp-protest-warns-against-rumours-as-clashes-erupt-during-chalo-sansad-march
- https://www.youtube.com/shorts/0kkSCYrjRGc
- https://factcheck.pib.gov.in/
- https://www.altnews.in/
- https://www.boomlive.in/
- https://www.vishvasnews.com/
- https://www.factcrescendo.com/
- https://cybercrime.gov.in/
Contributors
- Neeraj Soni, Sr. Research Analyst, Policy & Advocacy, CyberPeace
- Ritika Goswami, Intern - Policy & Advocacy, CyberPeace

Introduction
Governments worldwide are enacting cybersecurity laws to enhance resilience and secure cyberspace against growing threats like data breaches, cyber espionage, and state-sponsored attacks in the digital landscape. As a response, the EU Council has been working on adopting new laws and regulations under its EU Cybersecurity Package- a framework to enhance cybersecurity capacities across the EU to protect critical infrastructure, businesses, and citizens. Recently, the Cyber Solidarity Act was adopted by the Council, which aims to improve coordination among EU member states for increased cyber resilience. Since regulations in the EU play a significant role in shaping the global regulatory environment, it is important to keep an eye on such developments.
Overview of the Cyber Solidarity Act
The Act sets up a European Cyber Security Alert System consisting of Cross-Border Cyber Hubs across Europe to collect intelligence and act on cyber threats by leveraging emerging technology such as Artificial Intelligence (AI) and advanced data analytics to share warnings on cyber threats with other cyber data centres across the national borders of the EU. This is expected to assist authorities in responding to cyber threats and incidents more quickly and effectively.
Further, it provides for the creation of a new Cybersecurity Emergency Mechanism to enhance incident response systems in the EU. This will include testing the vulnerabilities in critical sectors like transport, energy, healthcare, finance, etc., and creating a reserve of private parties to provide mutual technical assistance for incident response requests from EU member-states or associated third countries of the Digital Europe Programme in case of a large-scale incident.
Finally, it also provides for the establishment of a European Cybersecurity Incident Review Mechanism to monitor the impact of the measures under this law.
Key Themes
- Greater Integration: The success of this Act depends on the quality of cooperation and interoperability between various governmental stakeholders across defence, diplomacy, etc. with regard to data formats, taxonomy, data handling and data analytics tools. For example, Cross-Border Cyber Hubs are mandated to take the interoperability guidelines set by the European Union Agency for Cybersecurity (ENISA) as a starting point for information-sharing principles with each other.
- Public-Private Collaboration: The Act provides a framework to govern relationships between stakeholders such as the public sector, the private sector, academia, civil society and the media, identifying that public-private collaboration is crucial for strengthing EUs cyber resilience. In this regard, National Cyber Hubs are proposed to carry out the strengthening of information sharing between public and private entities.
- Centralized Regulation: The Act aims to strengthen all of the EU's cyber solidarity by outlining dedicated infrastructure for improved coordination and intelligence-sharing regarding cyber events among member states. Equal matching contribution for procuring the tools, infrastructure and services is to be made by each selected member state and the European Cybersecurity Competence Centre, a body tasked with funding cybersecurity projects in the EU.
- Setting a Global Standard: The underlying rationale behind strengthening cybersecurity in the EU is not just to protect EU citizens from cyber-threats to their fundamental rights but also to drive norms for world-class standards for cybersecurity for essential and critical services, an initiative several countries rely on.
Conclusion
In the current digital landscape, governments, businesses, critical sectors and people are increasingly interconnected through information and network connection systems and are using emerging technologies like AI, exposing them to multidimensional vulnerabilities in cyberspace. The EU in this regard continues to be a leader in setting standards for the safety of participants in the digital arena through regulations regarding cybersecurity. The Cyber Solidarity Act’s design including cross-border cooperation, public-private collaboration, and proactive incident-monitoring and response sets a precedent for a unified approach to cybersecurity. As the EU’s Cybersecurity Package continues to evolve, it will play a crucial role in ensuring a secure and resilient digital future for all.
Sources
- https://www.consilium.europa.eu/en/press/press-releases/2024/12/02/cybersecurity-package-council-adopts-new-laws-to-strengthen-cybersecurity-capacities-in-the-eu/
- https://data.consilium.europa.eu/doc/document/PE-94-2024-INIT/en/pdf
- https://digital-strategy.ec.europa.eu/en/policies/cybersecurity-strategy
- https://www.weforum.org/stories/2024/10/cybersecurity-regulation-changes-nis2-eu-2024/