#FactCheck - Misleading Video of Dubai Airport Attack Circulates Online, Found AI-Generated
Executive Summary
Amid rising tensions in the Middle East following attacks on Iran by the United States and Israel, a video is being shared on social media claiming that it shows a recent attack at Dubai International Airport. Research by the CyberPeace found the viral claim to be false. Our research revealed that the viral video is not real but has been created using artificial intelligence technology.
Claim:
An Instagram user shared the viral video on March 1, 2026, claiming it shows an attack at Dubai Airport. The link to the post, the archive link, and a screenshot are provided below.

Fact Check:
To verify the viral claim, we searched Google using relevant keywords. However, we did not find any credible media report confirming the claim.On closely examining the viral video, we noticed several unusual visuals and technical inconsistencies, raising suspicion that it might be AI-generated. To verify this, we scanned the video using the AI detection tool Sightengine. According to the results, around 74 percent of the video shows the likelihood of being AI-generated.

Conclusion:
Our research found that the viral video is not real but has been created using artificial intelligence technology.
Related Blogs

Introduction
Insurance companies hold a huge amount of sensitive data. Medical history, bank account numbers, identity proofs, years of claims records — all of it sits on insurer servers, waiting. That makes the sector an easy target. India saw close to 370 million malware attacks in a single recent year. Banking, financial services and insurance firms bore the brunt of it. That got the attention of the Insurance Regulatory and Development Authority of India (IRDAI). On 6 April 2026, it released a new set of Information and Cyber Security Guidelines. These replace the old 2023 rules and ask insurers to take much stronger responsibility for protecting their systems, and their customers' data.
Who Must Follow These New Rules
The updated guidelines are not limited to large insurance companies alone. They apply to life, general and health insurers. They also apply to foreign reinsurance branches operating in India, and to intermediaries such as brokers, corporate agents, web aggregators and third-party administrators. Insurance repositories and the Insurance Information Bureau of India fall within scope too. Individual insurance agents, point-of-sale persons and surveyors are not covered directly. But insurers must still make sure these people follow a basic security framework approved by their board. Foreign reinsurance branches get a little more room — they can depart from a specific rule, but only if they can justify it properly to the regulator. Why cast such a wide net in the first place? Because breaches rarely start at the big insurer with the well-staffed Information Technology (IT) team. They start with the small broker or corporate agent who never got around to updating a password policy.
A Stronger Role for the Boardroom
An Independent CISO (Chief Information Security Officer)
The clearest change sits right at the top. A Chief Information Security Officer (CISO) can no longer report to the Head of Information Technology (IT). Nor can the CISO (Chief Information Security Officer) be handed sales targets or any other business goal. Why does this matter so much? Picture a CISO (Chief Information Security Officer) who answers to the same person pushing hard for a product launch next week. Flagging a serious vulnerability suddenly becomes an awkward, career-risking conversation. The IRDAI (Insurance Regulatory and Development Authority of India) has simply removed that awkwardness by rule.
More Frequent Oversight
The Information Security Risk Management Committee used to meet only twice a year. Now it must meet at least once every quarter. A new Information Technology (IT) Steering Committee has also been set up to handle day-to-day technology decisions. This frees the risk committee to focus purely on oversight. There's also a new seat at the table: at least one outside cybersecurity expert must now join the Risk Management Committee. Someone with no stake in internal politics, no department to protect, just technical judgement.
Faster Action When Something Goes Wrong
A Six-Hour Reporting Deadline
No system is completely safe from attack. So the guidelines also focus heavily on how insurers respond once something goes wrong. Every cybersecurity incident now has to reach the Indian Computer Emergency Response Team within six hours of being spotted, with the IRDAI (Insurance Regulatory and Development Authority of India) and other regulators looped in at the same time. Six hours is a tight deadline. It means insurers need detection and escalation systems that work round the clock, not just during office hours.
Testing and Exceptions
Business continuity and disaster recovery plans must be tested at least once a year, and not through some comfortable, pre-planned shutdown either — the test has to feel like a real disaster. Exceptions to security policy are also handled with far more discipline now. A short exception of up to three months can be approved by the CISO (Chief Information Security Officer) alone. One lasting between three months and a year needs sign-off from the risk committee. Anything longer needs approval from the board itself. Gaps found during audits must be closed within twelve months, with the board tracking progress at every stage.
Looking Ahead to Tomorrow's Risks
The guidelines do not stop at today's threats. More insurers are moving their operations to the cloud. So the rules now demand stronger contracts with cloud vendors, and a clear plan for what happens to customer data once a vendor relationship ends. Third-party risk gets close attention too. Many security breaches in the financial sector start with a vendor, not with the insurer's own systems. Before hiring any vendor, insurers must now check their security properly. Every contract must include audit rights and a clause requiring the vendor to report incidents. One of the most forward-looking additions is early preparation for a post-quantum world. Insurers must keep a clear list of their cryptographic assets. In simple terms, this is a map of where and how encryption is used across their systems. It helps them get ready once stronger encryption standards become necessary. Quantum computers capable of breaking today's encryption are still some years away, by most estimates. Mapping out those cryptographic assets now is a lot cheaper than scrambling to do it after the threat has already landed.
Conclusion
Where does all this leave things? Cybersecurity in Indian insurance isn't a server-room problem anymore — it sits squarely in the boardroom now. Directors now own this risk, not just Information Technology (IT) managers tucked away in a basement office. Policyholders benefit too, since their data now sits behind stronger locks, watched more closely and reported on far more often than before. Insurers who treat this as a paperwork exercise will struggle to keep up. Those who actually build these habits into daily operations will likely spend less time firefighting breaches five years from now, and more time competing on service and price instead.
References
3. Medianama, 'IRDAI Updates Cybersecurity Rules, Mandates DPDP Compliance', April 2026.
4. DSCI, brief on IRDAI's Information and Cyber Security Guidelines, 2026, April 2026.
7. Deloitte India, 'IRDAI Tightens Cyber Net: Wake-up Call for Insurers'.

Introduction
With the increasing reliance on digital technologies in the banking industry, cyber threats have become a significant concern. Cyberlaw plays a crucial role in safeguarding the banking sector from cybercrimes and ensuring the security and integrity of financial systems.
The banking industry has witnessed a rapid digital transformation, enabling convenient services and greater access to financial resources. However, this digitalisation also exposes the industry to cyber threats, necessitating the formulation and implementation of effective cyber law frameworks.
Recent Trends in the Banking Industry
Digital Transformation: The banking industry has embraced digital technologies, such as mobile banking, internet banking, and financial apps, to enhance customer experience and operational efficiency.
Open Banking: The concept of open banking has gained prominence, enabling data sharing between banks and third-party service providers, which introduces new cyber risks.

How Cyber Law Helps the Banking Sector
The banking sector and cyber crime share an unspoken synergy due to the mass digitisation of banking services. Thanks to QR codes, UPI and online banking payments, India is now home to 40% of global online banking transactions. Some critical aspects of the cyber law and banking sector are as follows:
Data Protection: Cyberlaw mandates banks to implement robust data protection measures, including encryption, access controls, and regular security audits, to safeguard customer data.
Incident Response and Reporting: Cyberlaw requires banks to establish incident response plans, promptly report cyber incidents to regulatory authorities, and cooperate in investigations.
Customer Protection: Cyberlaw enforces regulations related to online banking fraud, identity theft, and unauthorised transactions, ensuring that customers are protected from cybercrimes.
Legal Framework: Cyberlaw provides a legal foundation for digitalisation in the banking sector, assuring customers that regulations protect their digital transactions and data.
Cybersecurity Training and Awareness: Cyberlaw encourages banks to conduct regular training programs and create awareness among employees and customers about cyber threats, safe digital practices, and reporting procedures.

RBI Guidelines
The RBI, as India’s central banking institution, has issued comprehensive guidelines to enhance cyber resilience in the banking industry. These guidelines address various aspects, including:
Technology Risk Management
Cyber Security Framework
IT Governance
Cyber Crisis Management Plan
Incident Reporting and Response
Recent Trends in Banking Sector Frauds and the Role of Cyber Law
Phishing Attacks: Cyberlaw helps banks combat phishing attacks by imposing penalties on perpetrators and mandating preventive measures like two-factor authentication.
Insider Threats: Cyberlaw regulations emphasise the need for stringent access controls, employee background checks, and legal consequences for insiders involved in fraudulent activities.
Ransomware Attacks: Cyberlaw frameworks assist banks in dealing with ransomware attacks by enabling legal actions against hackers and promoting preventive measures, such as regular software updates and data backups.
Master Directions on Cyber Resilience and Digital Payment Security Controls for Payment System Operators (PSOs)
Draft of Master Directions on Cyber Resilience and Digital Payment Security Controls for Payment System Operators (PSOs) issued by the Reserve Bank of India (RBI). The directions provide guidelines and requirements for PSOs to improve the safety and security of their payment systems, with a focus on cyber resilience. These guidelines for PSOs include mobile payment service providers like Paytm or digital wallet payment platforms.
Here are the highlights-
The Directions aim to improve the safety and security of payment systems operated by PSOs by providing a framework for overall information security preparedness, with an emphasis on cyber resilience.
The Directions apply to all authorised non-bank PSOs.
PSOs must ensure adherence to these Directions by unregulated entities in their digital payments ecosystem, such as payment gateways, third-party service providers, vendors, and merchants.
The PSO’s Board of Directors is responsible for ensuring adequate oversight over information security risks, including cyber risk and cyber resilience. A sub-committee of the Board may be delegated with primary oversight responsibilities.
PSOs must formulate a Board-approved Information Security (IS) policy that covers roles and responsibilities, measures to identify and manage cyber security risks, training and awareness programs, and more.
PSOs should have a distinct Board-approved Cyber Crisis Management Plan (CCMP) to detect, contain, respond, and recover from cyber threats and attacks.
A senior-level executive, such as a Chief Information Security Officer (CISO), should be responsible for implementing the IS policy and the cyber resilience framework and assessing the overall information security posture of the PSO.
PSOs need to define Key Risk Indicators (KRIs) and Key Performance Indicators (KPIs) to identify potential risk events and assess the effectiveness of security controls. The sub-committee of the Board is responsible for monitoring these indicators.
PSOs should conduct a cyber risk assessment when launching new products, services, technologies, or significant changes to existing infrastructure or processes.
PSOs, including inventory management, identity and access management, network security, application security life cycle, security testing, vendor risk management, data security, patch and change management life cycle, incident response, business continuity planning, API security, employee awareness and training, and other security measures should implement various baseline information security measures and controls.
PSOs should ensure that payment transactions involving debit to accounts conducted electronically are permitted only through multi-factor authentication, except where explicitly permitted/relaxed.

Conclusion
The relationship between cyber law and the banking industry is crucial in ensuring a secure and trusted digital environment. Recent trends indicate that cyber threats are evolving and becoming more sophisticated. Compliance with cyber law provisions and adherence to guidelines such as those provided by the RBI is essential for banks to protect themselves and their customers from cybercrimes. By embracing robust cyber law frameworks, the banking industry can foster a resilient ecosystem that enables innovation while safeguarding the interests of all stakeholders or users.

Introduction
A recent massive scam has been uncovered in the Indian state of Gujarat, where the Criminal Investigation Department (CID) has blacklisted 30,000 SIM cards that were used for illegal activities. The scam has created a huge uproar in the state, and its implications are significant. In this blog, we will discuss the details of the Gujarat scam and its impact on the state.
What is sim card fraud?
Sim card fraud occurs when someone uses a fake or cloned sim card to impersonate someone else. This allows the fraudster to gain access to sensitive information or conduct transactions on behalf of the victim. The use of fraudulent sim cards has become increasingly common in recent years, with scammers targeting individuals and businesses around the world.
The Gujarat Scam: The Gujarat scam involves the use of SIM cards for illegal activities such as extortion, blackmail, and cybercrime. The CID has identified that the SIM cards were obtained using fake documents and were used for illegal activities. The scam has been happening for a while, involving several individuals, including businessmen, politicians, and government officials.
The CID has conducted raids across the state and has arrested several individuals involved in the scam. They have also seized a significant amount of cash, mobile phones, and other electronic devices used for illegal activities. The investigation is ongoing, and more arrests are expected in the coming days.
The Gujarat scam is not an isolated incident, as similar scams have been reported in other parts of the country. The Telecom Regulatory Authority of India (TRAI) has also reported that several telecom operators are not following the regulations and are not verifying the authenticity of documents used to obtain SIM cards.
Impact on the State: The Gujarat scam has caused significant damage to the state’s reputation, and it has also affected the economy. The scam has highlighted the lack of regulation in the telecom industry, and it has exposed the loopholes in the system that criminals are exploiting.
The blacklisting of 30,000 SIM cards will affect several individuals who may have obtained them legally but were unaware of their use for illegal activities. The blacklisting may also impact businesses that rely on mobile phones for their operations.
The scam has also raised concerns about personal information and data safety. With the use of fake documents to obtain SIM cards, it is evident that personal information is not secure and can be easily misused. The government needs to take steps to ensure that personal information is protected and that the telecom industry is regulated to prevent such scams from happening in the future.
Steps Taken by the Government: The Gujarat scam has prompted the government to take action to prevent such incidents from happening in the future. The government has announced that it will implement stricter regulations in the telecom industry to prevent the misuse of SIM cards. The government has also announced that it will introduce a system to verify the authenticity of documents used to obtain SIM cards.
The government has also urged citizens to be vigilant and report any suspicious activity related to the misuse of SIM cards. The government has assured citizens that it will take strict action against those involved in the scam and that it will ensure the safety of personal information and data.
The TRAI has also taken steps to address the issue. It has directed telecom operators to verify the authenticity of documents used to obtain SIM cards and to follow the regulations. The TRAI has also introduced a new system to identify and deactivate inactive SIM cards.
Here are some key takeaways from the Gujarat Sim scam: These takeaways should be kept in mind to prevent such incidents from happening in the future and to ensure the safety of citizens and businesses.
Need for Stricter Regulations: The Gujarat Sim scam has highlighted the need for stricter regulations in the telecom industry. The government needs to ensure that telecom operators follow the regulations and verify the authenticity of documents used to obtain SIM cards. This will help prevent the misuse of SIM cards and illegal activities.
Importance of Personal Information Security: The scam has raised concerns about personal information and data safety. It is important to ensure that personal information is protected and that the telecom industry is regulated to prevent such scams from happening in the future.
Impact on Reputation and Economy: The Gujarat scam has caused significant damage to the state’s reputation, and it has also affected the economy. The blacklisting of 30,000 SIM cards will impact several individuals who may have obtained them legally but were unaware of their use for illegal activities. The scam has also raised concerns about the safety of businesses that rely on mobile phones for their operations.
Need for Vigilance: The government has urged citizens to be vigilant and report any suspicious activity related to the misuse of SIM cards. It is important for citizens to be aware of the regulations and to report any illegal activities to prevent such incidents from happening in the future.
Strong Action Against Criminals: The blacklisting of 30,000 SIM cards and the arrests made by the CID sends a strong message to those involved in illegal activities that they will not be spared. It is important for the government to take strict action against those involved in the scam to deter others from engaging in such activities.
Conclusion
The Gujarat scam has exposed vulnerabilities in the telecom industry and highlighted the need for stricter regulations to prevent such incidents from happening in the future. The blacklisting of 30,000 SIM cards has sent a strong message to those involved in illegal activities that they will not be spared. The government’s efforts to implement stricter regulations and ensure the safety of personal information and data are commendable. It is now up to the citizens to be vigilant and report any suspicious activity to prevent such incidents from happening in the future.
The telecom industry plays a vital role in the country’s development, and it is important to ensure that it is regulated to prevent the misuse of its services. Overall, the Gujarat Sim scam has highlighted the need for stricter regulations, personal information security, vigilance, and strong action against criminals.