#FactCheck - Misleading Claims Spread With Old Ram Idol Vandalism Video
Executive Summary
A video circulating on social media has sparked controversy, showing a man allegedly vandalising an idol of Lord Ram. Users sharing the clip claim that the incident recently took place in Ayodhya, Uttar Pradesh. The posts further allege that a Muslim individual climbed the idol and attempted to damage it. However, research by the CyberPeace found the viral claim to be misleading. The research revealed that the video is not recent but nearly three years old. At the time of the incident, the police had already arrested the accused. Social media users are now resharing the old video with false claims that it is a recent event.
Claim:
On February 14, 2026, a Facebook user shared the viral video claiming that the incident occurred in Ayodhya, where a large religious gathering was underway. The post alleged that a man identified as Mohammad Mukhtar Mandal climbed the idol of Lord Ram and attempted to break it. The post was widely circulated with inflammatory remarks. (Link and archived version of the post were provided along with a screenshot.)

Fact Check
To verify the authenticity of the claim, we extracted key frames from the viral video and conducted a reverse image search using Google Lens. During the search, we found a report published on January 30, 2024, on the Hindi website of Patrika, which carried visuals matching the viral footage. According to the report, a video had surfaced showing a man climbing an idol of Lord Ram in Ayodhya and attempting to damage it. The video had gone viral at the time, following which police registered a case against the accused, Mukhtar Ali Mandal, and arrested him.

Further research led us to another Facebook post featuring the same video. In the comment section of that post, Uttar Pradesh Police clarified that the incident dated back to January 2024. The Ayodhya police had registered a case against the accused shown in the video and sent him to jail.

Conclusion:
The research confirms that the viral video is not recent but an old incident from January 2024. The accused was arrested at the time. The video is being reshared with misleading claims falsely presenting it as a recent event.
Related Blogs

Introduction
At 4 pm on August 3, 2026, representatives of Meta, X, Snapchat and Google walked into a room in Parliament to face India's Standing Committee on Communications and Information Technology. On paper, it looked like one more instance of a routine that has repeated for half a decade: a Big Tech company gets called in, questioned, and sent away with a warning. But this summons, and the fortnight of scrutiny that has followed it, reveals something different about the direction of India's digital governance in 2026. The government's question has stopped being, "Will you take this post down?" It has increasingly become, "How does your platform actually work, and can we redesign the parts we don't like?"
The trigger: A technical glitch that became a systemic complaint
The proximate cause of the August 3 hearing was almost trivial by itself. On July 23, Prime Minister Narendra Modi posted a video on Instagram and Facebook about the government's crackdown on examination paper leaks. Meta briefly restricted the Facebook version before restoring it, blaming the removal on a technical error in its automated filters.
That explanation didn't satisfy the Ministry of Electronics and Information Technology (MEITY), which called it inadequate, and the incident became the occasion for a much broader reckoning. Committee chairperson Nishikant Dubey summoned Meta, X, Snapchat and Google to examine three things: the online safety of women and children; the data privacy of ordinary citizens, including farmers and labourers; and how far platforms actually comply with India's law-and-order requirements. Days later, MeitY brought Meta's global team in for two days of direct questioning that stretched into a third day of technical discussions covering child sexual abuse material (CSAM), deepfakes, bot accounts and, notably, the design of Instagram's content-recommendation algorithm itself.
From takedown notices to systems audits
For most of the last decade, India's approach to online harm ran through blocking orders and the "notice-and-takedown" machinery built into the IT Rules, 2021: a court or government authority flags a specific URL or post, the platform has a fixed window to act, and non-compliance risks the loss of legal immunity. It was a model built around individual pieces of content.
What is unfolding now looks structurally different. Officials aren't only asking Meta to remove a video; they are asking why its recommendation systems keep resurfacing flagged material, why "verified" accounts belonging to prominent or official figures don't have extra layers of human review before restriction, and why bot-detection and CSAM-screening pipelines aren't catching harmful content before it spreads. The Supreme Court-monitored committee tracking "digital arrest" fraud has gone further still, directing MeitY, the Department of Telecommunications and the Indian Cyber Crime Coordination Centre (I4C) to study time-based restrictions on audio and video calls altogether, a proposal that touches the basic architecture of how calling features work, not any single conversation.
Parliament's committee has separately pushed for a national registration system that would require every intermediary operating in India to publicly list its grievance officer, nodal contact and compliance officer as a response to law enforcement's repeated difficulty simply reaching a platform when something goes wrong. It has also asked for tighter regulation of digital advertising, which officials say is routinely exploited for cyber fraud, and for rules under Section 67C of the IT Act governing how long intermediaries must preserve user data. None of this is about any one post; it is about redesigning the infrastructure platforms use to operate in India.
Messaging apps and the encryption problem
Nowhere is the shift from "content" to "architecture" clearer than in the government's dealings with peer-to-peer messaging platforms. WhatsApp has spent years contesting the traceability requirement under Rule 4(2) of the IT Rules in the Delhi High Court, arguing it would rather exit India than build a permanent capability to identify the "first originator" of every message since doing so would mean re-engineering its end-to-end encryption for all users, not just suspects.
That fight has resurfaced in a new form. In a submission to the parliamentary committee, WhatsApp argued that new rules requiring platforms to detect and label AI-generated "synthetic" content cannot technically apply inside encrypted chats because no one outside a conversation "not even WhatsApp" can see what's inside it. Signal has proven even harder to engage with: MeitY told the committee it has struggled to establish formal contact with the app, which does not publicly list a grievance officer, exposing how little leverage the government currently has over encrypted, minimally staffed platforms compared with advertising-funded giants like Meta and Google. The proposal to cap or restrict call durations to fight "digital arrest" scams is, in effect, an attempt to regulate a messaging feature rather than any message sent through it, perhaps the clearest sign yet that the fight has moved from posts to plumbing.
The future of "safe harbour"
Underpinning all of this is Section 79 of the IT Act, the "safe harbour" clause that shields platforms from liability for what their users post, provided they exercise due diligence. That protection is now being squeezed from three directions at once. The parliamentary committee has unanimously recommended withdrawing safe harbour from platforms that don't comply with Indian law and said it should be pulled specifically from Meta unless its CEO apologises over the PM's video takedown, though a committee cannot itself revoke a statutory protection; only Parliament can amend Section 79. Separately, the Supreme Court-monitored panel on digital-arrest fraud is examining an explicit provision making intermediaries liable for the misuse of their platforms so that fraud victims could claim compensation directly. And MeitY's draft Second Amendment Rules, circulated in March 2026, go furthest of all: they propose making safe harbour conditional on real-time compliance with executive directions, rather than a general protection available to any platform that follows published rules, which is a more direct, command-driven model than even the European Union's Digital Services Act.
Why this matters beyond the headlines
For the ordinary internet user, none of this is abstract. A registration-and-disclosure regime, together with faster and more accountable grievance handling, could make it easier to get genuinely harmful content addressed. But architecture-level intervention cuts both ways. Rules aimed at traceability or at labelling encrypted content risk weakening the very privacy protections that make messaging apps trustworthy in the first place, and a safe harbour that hinges on obeying informal executive directions, rather than settled published law, hands the government far more day-to-day leverage over what stays online. The Supreme Court has listed the digital-arrest matter for September 16; how it, and Parliament, ultimately treat Section 79 will decide whether India's platforms remain neutral pipes carrying other people's speech or become extensions of state enforcement.
Conclusion
India’s digital-governance battle is no longer confined to individual posts or takedown orders. It is increasingly about the architecture beneath the internet: recommendation engines, encryption, verification, data retention and safe-harbour protections. That shift may strengthen accountability and user safety, but it also expands the state’s influence over digital infrastructure. As Parliament and the Supreme Court confront these questions, India faces a fundamental choice: regulate platforms or reshape how they operate.
Sources
- Parliament panel summons Meta, X, Google, Snapchat over digital safety — Hindustan Times
- Parliamentary panel summons Meta, Google, X and Snapchat over social media regulation — Economic Times
- Parliamentary Panel Summons Meta, X, Google on Digital Safety Rules — Asianet Newsable
- Panel Summons Meta, X, Snapchat, Google for Safety Review — New Kerala
- Meta, X, Google and Snapchat summoned by parliamentary panel on August 3 — BestMediaInfo

Introduction
"Artificial Intelligence may be the new charlatan in town"
There is something almost wonderfully Indian about our current relationship with artificial intelligence. We are simultaneously afraid of it, fascinated by it, regulating it, funding it, using it and occasionally asking it to write the regulation meant to control it. In contrast, artificial intelligence seems to have figured out the oldest trick in the book: create an issue and then figure out how to solve it. Both the deepfake and the deepfake detector can be produced by it. It has the ability to both generate and detect false information. It can both authenticate and mimic your voice. It can create a fake image and determine if it is fake. The machine ,in other words, is increasingly becoming both the burglar and the security system. We now refer to this as innovation. Perhaps nothing better captures this peculiar moment than India’s most recent regulatory actions. The government has strengthened regulations pertaining to synthetic content such as requiring labelling and expediting the removal of illegal AI-generated information. After a legitimate government or court order, platforms are expected to take action within three hours, significantly reducing the removal window for some content. It took years for the internet to become ubiquitous. There are now three hours for the law to become transitory. This is the first great paradox of AI governance. Technology operates at the speed of creation. Law operates at the speed of procedure. The citizen is seated between the two.
The Age of the Digital Double
Indian courts are already dealing with this issue in more tangible ways. Cricket player Yuvraj Singh recently received relief from the Delhi High Court in a personality-rights case involving deepfakes created by AI and unlawful use of his identity. Courts have intervened against AI-generated and modified content in similar cases involving other public individuals. As a result, the law faces an odd dilemma: What exactly belongs to a person? In the past, humans used comparatively stable identifiers to understand identity, such as a name, portrait, signature, or voice. That simplicity has been disrupted by AI. You can now detach your face from your body. You may separate your throat from your voice. It is possible to distinguish between your emotions and your expressions. It is possible to fabricate your political beliefs without engaging in politics. The legitimacy of a person's existence is being requested to be protected by the law, not just their property which is a far more difficult issue.
When Artificial Intelligence Enters the Courtroom
The irony becomes richer when AI enters the courtroom itself. Courts are creating guidelines for the use of AI in the courtroom, just as they are being challenged to decide what happens when AI creates reality outside of it. Human primacy, accountability, transparency, data protection and judicial independence are highlighted in the Supreme Court’s proposed rules on the use of AI in courts. After all, there is one situation in which the justification that “the AI said so” should never be accepted. A hallucinated judgment is more than just a mistake in technology. It may turn into a mistake of authority in a legal system. A precedent can be confidently created by a machine. It can be cited with confidence by a lawyer and maybe then brought before a court for consideration. All of a sudden, we have created a flawless little bureaucratic ecology where everyone has been duped despite no one's intention to do so. It's not inevitable that machines will turn malevolent, but rather that people will grow unduly reliant on machines that seem authoritative.
The Great AI Contradiction
We asked, "What can AI do?" for years.What can AI do for us, we then enquired? We are starting to wonder what AI might do to humans. The following query ought to be more challenging: When it does, who is at fault? Because AI systems don't cleanly fit into the legal frames we inherited, that question becomes very challenging. Developers, model providers, data providers, deployers, platforms, and end users are among them. There may occasionally be a middleman. There is a victim occasionally. Surprisingly, there can occasionally be multiple roles at once. This point is made in a recent working paper on AI and consumer rights in India: while current consumer protection laws may apply to AI harms, the conventional division of accountability among manufacturers, sellers, and service providers becomes challenging when AI systems involve a much more dispersed value chain.
The Misunderstanding on AI’s Intelligence
This is the point at which our sense for policy sometimes fails. We are concerned that AI will develop superintelligence. The more imminent threat can be much less dramatic. It is not necessary for AI to surpass human intelligence in order to wreak great harm. All it needs to do is become more convincing, quicker, and less expensive than human verification. Artificial general intelligence is not necessary for a fraudster to con an elderly person. A supercomputer is not necessary for a political manipulator to create a candidate's voice. A stalker can create an intimate deepfake without being conscious. A pupil can file a hallucinated case citation without the assistance of a robot attorney. Ordinary human wrongdoing magnified by incredible technical magnitude is what it is.
The Real Test of AI Governance
The number of standards we create, the number of committees we form, or the number of compliance boxes platforms check will not ultimately determine the success of AI regulation. Something considerably simpler will be used to measure it. Can the legal system advise a regular citizen where to go, what to do, and who will be held accountable when an AI system impersonates, defrauds, surveils, manipulates, or denies them a service?
The presence of accountability following failure, not the absence of failure.
Sometimes the most advanced piece of technology in the room is still an old-fashioned institution: a law that works, a regulator that responds, a court that understands the technology and a human being willing to take responsibility. Because if AI is going to be both the fire and the fire extinguisher, we should at least make sure that someone other than the machine owns the building.
References
- https://economictimes.indiatimes.com/news/india/government-tightens-deepfake-rules-mandates-ai-content-labels-and-three-hour-takedown-timeline/articleshow/133011656.cms?utm_source=chatgpt.com&from=mdr
- https://theleaflet.in/law-and-technology/explained-the-supreme-court-of-indias-draft-regulations-for-use-of-artificial-intelligence-in-courts-2026
- https://www.bananaip.com/intellepedia/yuvraj-singh-personality-rights-ai-deepfakes-delhi-high-court/

Introduction
On 27 July 2026, Bank of Baroda admitted to experiencing a cybersecurity attack, officially confirming many hours of chatter and speculation amongst Bank of Baroda customers and information security professionals. According to a statement by the bank issued through regulatory filing, the breach came about due to unauthorised access into some of its data via compromise of an employee’s email account; however, not much beyond these details was disclosed. In the meantime, allegations of a major large-scale data leak flooded into various platforms and forums of the cybersecurity world along with mainstream news outlets and, eventually, mainstream social networks. It’s now critically important for us to attempt to differentiate factual from unverified details about Bank of Baroda’s recent cybersecurity incident.
We will analyse and list what the bank has released, what our community research has discovered and also what questions are still left unanswered.
The bank's version
Bank of Baroda said the breach traced back to a single compromised employee email account, which gave an unknown party unauthorised access to "certain data". Crucially, the bank maintains that its core banking systems, that is, the infrastructure that actually moves customer money, were never touched. It says the incident was detected and contained quickly and that it is working with law enforcement and regulators while a forensic investigation continues. That's a fairly narrow admission compared with what had already surfaced on the dark web.
What the hackers claim
Days before the bank's statement, a relatively new ransomware and data-extortion group calling itself ‘TripleX’ listed Bank of Baroda on its dark web leak site, dated July 24. The group claimed to have pulled roughly 1 terabyte of data and, unusually, released the entire cache for free rather than holding it for ransom, framing the move on its leak page as punishment for the bank's weak passwords and security lapses.
Independent researcher Srikanth Lakshmanan, founder of the digital-rights group 'CashlessConsumer', examined samples of the leaked material before alerting the bank and authorities. He told India Today Tech that what he reviewed included internal branch audit files, loan appraisal documents, vigilance investigation records, audit reports tied to the bank's bob World mobile app, and customer account-opening forms.
Several outlets also reported that sample files appeared to contain Aadhaar numbers, customer photographs, and NetBanking details, alongside corporate and NRI banking records. It's worth being precise here, though: Reuters and other outlets have emphasised that the exact contents and true scale of the leak haven't been independently verified, and Bank of Baroda itself hasn't confirmed which specific data categories were exposed. Estimates of the dataset's size have also varied anywhere from around 700 gigabytes to a full terabyte, depending on the source.
A repeat offender
TripleX isn't new to targeting state-owned banks. The gang first appeared in May 2026, and only weeks before targeting Bank of Baroda, it claimed responsibility for hacking PT Bank Negara Indonesia – the largest of Indonesia's state-owned banks, which stole nearly 2 terabytes of documents, including contracts, IDs and transaction histories. Both compromises follow a familiar pattern. Identify one point of entry, extract widely, and instead of working in the background to negotiate for a ransom, publish everything for the largest damage possible.
This represents a notable break from typical ransomware attacks. Groups such as TripleX forego encryption, simply relying solely on the public pressure of (or actuality of) imminent disclosure to extort victims. It is the extortion component of "double extortion" with little incentive to pursue payment.
The regulatory clock
India's banking sector doesn't get much slack when something like this happens. The Reserve Bank of India's Cyber Security Framework for Banks requires an initial incident report within two to six hours of detection, and India's Computer Emergency Response Team (CERT-In) mandates reporting of specified incidents within six hours. Bank of Baroda has also reportedly filed a preliminary notice under a cyber-insurance programme arranged through National Insurance, offering total coverage of roughly $78 million, though it's far too early to know whether it will actually be paid out or how much will actually be paid out.
Looking ahead, India's Digital Personal Data Protection Rules are due to take effect in May 2027, which will tighten breach-notification obligations further. This incident lands right at the edge of that regulatory transition, arguably a preview of what's at stake for the next bank that gets hit.
A History of Data Security Missteps
This is not the first time banks’ technology has raised a red flag. In 2023, an investigation by The Reporters’ Collective and Al Jazeera discovered that bank employees had inserted the mobile numbers of unauthorised agents (including those belonging to staff and security guards) and other businesses into their customers' profiles to drive enrolment on the bank’s app – BoB World. Several of the bank's customers were later victims of fraud due to the unauthorised association of mobile numbers, and the bank had its own internally reported data issues that later led to the RBI mandating an audit and then prohibiting the bank from onboarding new Bob World users temporarily. Even though the two issues are not related, it serves as context; in the case of banks handling more than $300 billion in their global operations through over 8,400 domestic locations, room for security errors is marginal, and the damage, both public and regulatory, escalates from there on.
What it means for customers
For those who bank with the Bank of Baroda, the common-sense approach is checking statements for any unfamiliar transactions; beware unsolicited calls/messages referencing account details (which typically follow after identity document leaks are being used as a basis for secondary scams); and as a security precaution, change your NetBanking password and app PIN while no core systems of the bank are reported to have been breached; even so, it is advisable to apply. Because Aadhaar, if it has been really compromised, cannot be reset like a password, which is why a compromised identity document is typically of longer-term risk than a stolen password.
Conclusion
The bigger story here isn't just one bank's bad week. It's a reminder that in a system where a single compromised employee inbox can cascade into hundreds of gigabytes of exposed customer data, "our core systems weren't affected" is true and reassuring and, for anyone whose loan documents or ID numbers may now be sitting on a dark web forum, somewhat beside the point.
Sources
- Bank of Baroda confirms cyber incident after hackers claim data theft — The Record (Recorded Future News): https://therecord.media/india-bank-of-baroda-reports-cybersecurity-incident
- Bank of Baroda Data Leak: What We Know So Far — Gulf News: https://gulfnews.com/business/banking/bank-of-baroda-data-leak-what-we-know-so-far-about-alleged-cyber-breach-1.500621898
- Bank of Baroda Breach Tests Disclosure Readiness — GovInfoSecurity (ISMG): https://www.govinfosecurity.com/bank-baroda-breach-tests-disclosure-readiness-a-32335
- India's Bank of Baroda Faces Alleged 1TB Data Leak on Dark Web — Yahoo Finance / India Today Tech: https://finance.yahoo.com/technology/ai/articles/india-bank-baroda-faces-alleged-113047992.html
- Bank of Baroda Data Breach Exposes Customer Records — The Asian Banker: https://www.theasianbanker.com/updates-and-articles/india-s-bank-of-baroda-data-breach-exposes-customer-records-after-employee-email-compromise
- India's Bank of Baroda Expose Worsens: Agents Steal Money From Accounts (2023 background) — Al Jazeera: https://www.aljazeera.com/economy/2023/10/12/indias-bank-of-baroda-expose-worsens-agents-steal-money-from-accounts
- 'Immediate Containment Measures Implemented': Bank of Baroda Issues Clarity on Alleged 1TB Data Leak — Republic World: https://www.republicworld.com/business/immediate-containment-measures-implemented-bank-of-baroda-issues-clarity-on-1tb-data-leak-2026-07-27-133590