#FactCheck - Misleading Claims Spread With Old Ram Idol Vandalism Video
Executive Summary
A video circulating on social media has sparked controversy, showing a man allegedly vandalising an idol of Lord Ram. Users sharing the clip claim that the incident recently took place in Ayodhya, Uttar Pradesh. The posts further allege that a Muslim individual climbed the idol and attempted to damage it. However, research by the CyberPeace found the viral claim to be misleading. The research revealed that the video is not recent but nearly three years old. At the time of the incident, the police had already arrested the accused. Social media users are now resharing the old video with false claims that it is a recent event.
Claim:
On February 14, 2026, a Facebook user shared the viral video claiming that the incident occurred in Ayodhya, where a large religious gathering was underway. The post alleged that a man identified as Mohammad Mukhtar Mandal climbed the idol of Lord Ram and attempted to break it. The post was widely circulated with inflammatory remarks. (Link and archived version of the post were provided along with a screenshot.)

Fact Check
To verify the authenticity of the claim, we extracted key frames from the viral video and conducted a reverse image search using Google Lens. During the search, we found a report published on January 30, 2024, on the Hindi website of Patrika, which carried visuals matching the viral footage. According to the report, a video had surfaced showing a man climbing an idol of Lord Ram in Ayodhya and attempting to damage it. The video had gone viral at the time, following which police registered a case against the accused, Mukhtar Ali Mandal, and arrested him.

Further research led us to another Facebook post featuring the same video. In the comment section of that post, Uttar Pradesh Police clarified that the incident dated back to January 2024. The Ayodhya police had registered a case against the accused shown in the video and sent him to jail.

Conclusion:
The research confirms that the viral video is not recent but an old incident from January 2024. The accused was arrested at the time. The video is being reshared with misleading claims falsely presenting it as a recent event.
Related Blogs

Overview:
After the blackout on July 19, 2024, which affected CrowdStrike’s services worldwide, cybercriminals began to launch many phishing attacks and distribute malware. These activities mainly affect CrowdStrike customers, using the confusion as a way to extort information through fake support sites. The analysis carried out by the Research Wing of CyberPeace and Autobot Infosec has identified several phishing links and malicious campaigns.
The Exploitation:
Cyber adversaries have registered domains that are similar to CrowdStrike’s brand and have opened fake accounts on social media platforms. These are fake platforms that are employed to defraud users into surrendering their personal and sensitive details for use in other fraudulent activities.
Phishing Campaign Links:
- crowdstrike-helpdesk[.]com
- crowdstrikebluescreen[.]com
- crowdstrike-bsod[.]com
- crowdstrikedown[.]site
- crowdstrike0day[.]com
- crowdstrikedoomsday[.]com
- crowdstrikefix[.]com
- crashstrike[.]com
- crowdstriketoken[.]com
- fix-crowdstrike-bsod[.]com
- bsodsm8r[.]xamzgjedu[.]com
- crowdstrikebsodfix[.]blob[.]core[.]windows[.]net
- crowdstrikecommuication[.]app
- fix-crowdstrike-apocalypse[.]com
- supportportal-crowdstrike-com[.]translate[.]goog
- crowdstrike-cloudtrail-storage-bb-126d5e[.]s3[.]us-west-1[.]amazonaws[.]com
- crowdstrikeoutage[.]info
- clownstrike[.]co[.]uk
- crowdstrikebsod[.]com
- whatiscrowdstrike[.]com
- clownstrike[.]co
- microsoftcrowdstrike[.]com
- crowdfalcon-immed-update[.]com
- crowdstuck[.]org
- failstrike[.]com
- winsstrike[.]com
- crowdpass[.]com
In one case, a PDF file is being circulated with CrowdStrike branding, saying ‘Download The Updater,’ which is a link to a ZIP file. The ZIP file is a compressed file that has an executable file with a virus. This is a clear sign that the hackers are out to take advantage of the current situation by releasing the malware as an update.




In another case, there is a malicious Microsoft Word document that is currently being shared, which claims to offer a solution on how to deal with this CrowdStrike BSOD bug. But there is a hidden risk in the document. When users follow the instructions and enable the embedded macro, it triggers the download of an information-stealing malware from a remote host. This is a form of malware that is used to steal information and is not well recognized by most security software. Also it sends the stolen data to the samesame remote host but with different port number, which likey works as the CnC server for the campaign.
- Name New_Recovery_Tool_to_help_with_CrowdStrike_issue_impacting_Windows[.]docm
- MD5 dd2100dfa067caae416b885637adc4ef
- SHA-1 499f8881f4927e7b4a1a0448f62c60741ea6d44b
- SHA-256 803727ccdf441e49096f3fd48107a5fe55c56c080f46773cd649c9e55ec1be61
- URLS http://172.104.160[.]126:8099/payload2.txt, http://172.104.160[.]126:5000/Uploadss


Recent Outage Impact:
On July 19, 2024, CrowdStrike faced a global outage that originated from an update of its Falcon Sensor security software. This outage affected many government organizations and companies in different industries, such as finance, media, and telecommunications. The event led to numerous complaints from the users who experienced problems like blue screen of death and system failure. Although, CrowdStrike has admitted to the problem and is in the process of fixing it.
Preventive Measures:
- Organize regular awareness sessions to educate the employees about the phishing techniques and how they can avoid the phishing scams, emails, links, and websites.
- MFA should be used for login to the sensitive accounts and systems for an improvement on the security levels.
- Make sure all security applications including the antivirus and anti-malware are up to date to help in the detection of phishing scams.
- This includes putting in place of measures such as alert on account activity or login patterns to facilitate early detection of phishing attempts.
- Encourage employees and users to inform the IT department as soon as they have any suspicions regarding phishing attempts.
Conclusion:
The recent CrowdStrike outage is a perfect example of how cybercriminals take advantage of the situation and user’s confusion and anxiety. Thus, people and organizations can keep themselves from these threats and maintain the confidentiality of their information by being cautious and adhering to the proper standards. To get the current information on the BSOD problem and the detailed instructions on its solution, visit CrowdStrike’s support center. Reported problems should be handled with caution and regular backup should be made to minimize the effects.
References:
- https://app.any.run/tasks/2c0ffc87-4059-4d6f-8306-1258cf33aa54/
- https://app.any.run/tasks/48e18e33-2007-49a8-aa60-d04c21e8fa11
- https://www.virustotal.com/gui/file/19001dd441e50233d7f0addb4fcd405a70ac3d5e310ff20b331d6f1a29c634f0/relations
- https://www.virustotal.com/gui/file/803727ccdf441e49096f3fd48107a5fe55c56c080f46773cd649c9e55ec1be61/detection
- https://www.joesandbox.com/analysis/1478411#iocs

Executive Summary
A post is rapidly going viral on social media claiming to show Sunrisers Hyderabad (SRH) captain Ishan Kishan, CEO Kavya Maran, and the team seeking blessings in front of a portrait of Jesus Christ at the Rajiv Gandhi International Cricket Stadium before a match. The image is being shared as a genuine pre-match moment. However, research by the CyberPeace found that the viral image is not real but generated using artificial intelligence (AI). There are no credible media reports or official updates from Sunrisers Hyderabad confirming any such pre-match activity. Further analysis using multiple AI detection tools also indicated that the image is likely synthetic. Therefore, the claim made in the viral post is false.
Claim
A Facebook user shared the image with the caption:“Preparation starts from within. Before taking the field at the Rajiv Gandhi Stadium, Ishan Kishan, Abhishek Sharma, and the SRH squad seek blessings. With Kavya Maran and the team united in faith, the Orange Army is ready for battle!”
- https://archive.ph/wip/dtbZ0
- https://www.facebook.com/13CricketNews/posts/preparation-starts-from-within-before-taking-the-field-at-the-rajiv-gandhi-stadi/1790225659038036/

Fact Check
A close inspection of the viral image revealed several inconsistencies. A cooler box in the image bears a sticker of Mumbai Indians, even though Mumbai Indians and Sunrisers Hyderabad had not played each other in IPL 2026 at the time implied by the claim. Their scheduled match is set for April 29, 2026, at Wankhede Stadium, not at the Hyderabad venue shown in the image.
- https://www.iplt20.com/teams/sunrisers-hyderabad/schedule

Additionally, the image incorrectly displays Dream11 as the title sponsor for SRH, whereas Shree Cement is the official title sponsor for the IPL 2026 season.

To further verify authenticity, the image was analysed using AI detection tools. Hive Moderation assigned it a 99.9% probability of being AI-generated, strongly indicating that it is not genuine.

Conclusion
The viral claim is false. The image showing Sunrisers Hyderabad players and their CEO praying before a match is AI-generated and does not depict a real event. It has been circulated with a misleading narrative and lacks any factual basis.

Somewhere in a compliance meeting right now, someone is saying "we have eighteen months, we're fine." That sentence is doing the same thing a snooze button does at 6 a.m.: technically buying time, while quietly making the actual wake up call worse. India's data protection law just started its countdown, and the 18 months everyone keeps citing is not a grace period to procrastinate through. It is closer to a runway before takeoff. Runways exist for one purpose: building up speed until the plane has no choice but to leave the ground. Standing still on one is not a strategy.
What actually got notified, and when
On 13 November 2025, the Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025, giving operational shape to the Digital Personal Data Protection Act that Parliament had passed back in August 2023. Alongside the Rules themselves, MeitY issued a separate Enforcement Notification setting out exactly when different provisions kick in, and a further notification establishing the Data Protection Board of India, headquartered in the National Capital Region with four members. The final Rules followed a genuinely deliberative process, MeitY had floated draft Rules in January 2025 for public consultation and received 6,915 individual inputs from startups, industry bodies, civil society groups, and citizens before finalising the version now in force. The headline structural decision, and the one causing the most confusion in boardrooms, is that the Rules do not commence all at once. They commence in three distinct phases spread across eighteen months, and different obligations become legally binding at each stage.
The phased timeline, laid out plainly

That third date, 13 May 2027, is the one that matters most for the vast majority of organisations, since it is where the bulk of actual operational obligations, the parts that touch product design, customer facing notices, and breach response, become enforceable. Legal commentary tracking the rollout has been consistent that this is described as a hard deadline with no grace period expected once it arrives, since the Data Protection Board is already operational and can begin receiving complaints well before Phase 3 obligations formally take effect.
Why "later" is a genuinely expensive plan
The financial stakes attached to Phase 3 non-compliance are not modest. The Schedule to the DPDP Act sets fixed penalty ceilings rather than turnover linked fines, which sounds gentler than Europe's GDPR model until you look at the actual numbers. Failure to implement reasonable security safeguards that results in a data breach can draw a penalty of up to 250 crore rupees per instance, the single highest tier in the Schedule. Failing to notify the Board or affected individuals after a breach occurs can draw up to 200 crore rupees, as can non-compliance with the Act's specific protections for children's data. Because these are assessed per instance rather than as a single capped exposure, a single incident that trips more than one obligation, say, inadequate safeguards that also delay breach notification, can compound into penalty exposure running into hundreds of crores from one event. All penalties collected go to the Consolidated Fund of India rather than to affected individuals directly, meaning the deterrent is aimed squarely at organisational behaviour, not compensation.
The part everyone keeps underestimating: this is not just a legal department problem
Perhaps the most consequential shift buried inside the DPDP framework is who actually has to own it. Reading the Rules as a checklist for the legal or privacy team alone misses how far the obligations actually reach. Building a compliant consent lifecycle touches product design. Security safeguards touch cybersecurity and IT infrastructure directly. Retention and deletion logic touches data governance and engineering. Third party risk review touches procurement. Breach preparedness touches internal audit and incident response. And increasingly, as organisations deploy AI systems that process personal data, AI governance enters the picture too, since a model trained or fine tuned on personal data inherits the same DPDP obligations as any other processing activity.
That cross functional reality is where most readiness programmes currently fall short. Treating DPDP compliance as a documentation exercise, updating a privacy policy PDF and calling it done, produces the appearance of compliance without the operational substance a Data Protection Board investigation would actually test. A breach response plan that exists only on paper and has never been rehearsed will not hold up against the 72 hour data principal notification window the Rules impose once Phase 3 lands. A consent mechanism bolted onto a website without corresponding backend logic to honour withdrawal requests will not satisfy an actual audit.
What a serious readiness posture looks like right now
Organisations that are ahead of this curve are already treating the eighteen month window as three overlapping workstreams rather than one deadline to hit at the end.
- The first is discovery: mapping what personal data exists, where it flows, who owns each system that touches it, and why it is collected in the first place, since compliance is structurally impossible without first knowing what you are protecting. This stage typically surfaces uncomfortable findings, shadow data sets nobody formally owns, vendor integrations nobody fully mapped, legacy systems still holding data well past any reasonable retention justification.
- The second is build: standing up the actual mechanisms, consent flows that can genuinely honour a withdrawal request end to end, rights request handling that does not depend on a single overworked employee checking an inbox, retention and deletion logic wired into the systems themselves rather than described only in a policy document, and security controls proportionate to the sensitivity of what is being protected.
- The third is proof: generating the internal evidence, audit trails, documented decisions, tested response procedures, that demonstrates governance was real rather than retrofitted after the fact. A Data Protection Board investigation, when it eventually happens, will not be satisfied by a well written policy; it will look for evidence that the policy was actually operational.
The actual question worth asking
The right question was never "when does DPDP become enforceable." Phase 1 already answered that; the law is live, and the Data Protection Board already exists and can act. The better question, the one worth taking into any leadership review between now and May 2027, is simpler and considerably less comfortable: will the organisation actually be ready when each phase's obligations become operational, or will readiness be assembled in a scramble once the deadline stops being theoretical. 18 months sounds long right up until the week it does not, and by the time Phase 3 lands, "we'll get to it" will no longer be a sentence any organisation gets to finish.
References
- Ministry of Electronics and Information Technology, Digital Personal Data Protection Rules, 2025, notified 13 November 2025. Press Information Bureau, "Digital Personal Data Protection Rules, 2025 Notified," 14 November 2025. https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf
- Shardul Amarchand Mangaldas & Co, "Enforcement of the DPDP Act and notification of the DPDP rules." https://www.amsshardul.com/insight/enforcement-of-the-dpdp-act-and-notification-of-the-dpdp-rules/
- S&R Associates, "India's Digital Personal Data Protection Regime Takes Effect." https://www.snrlaw.in/indias-digital-personal-data-protection-regime-takes-effect/
- Khurana & Khurana, "MeitY Notifies Rules Operationalising The DPDP Framework." https://www.khuranaandkhurana.com/update-meity-notifies-rules-operationalising-the-dpdp-framework-in-india
- Exchange4media, "DPDP Act 2025: Penalties for violations can reach Rs 250 crore." https://www.exchange4media.com/digital-news/dpdp-act-2025-penalties-for-confirmed-violations-can-reach-rs-250-crore-149360.html
- Seclore, "DPDP Rules 2025: India's Complete Compliance Guide." https://www.seclore.com/fundamentals/dpdp-rules-2025-compliance-guide/