#FactCheck - Suryakumar Yadav–Salman Ali Agha Handshake Row: Viral Image Found AI-Generated
Executive Summary
An image circulating on social media claims to show Suryakumar Yadav, captain of the Indian cricket team, extending his hand to greet Pakistan’s skipper Salman Ali Agha, who allegedly refused the gesture during the India–Pakistan T20 World Cup match held on February 15. Users shared the image as evidence of a real incident from the high-profile clash. However, a research by CyberPeace found that the image is AI-generated and was falsely circulated to mislead viewers.
Claim
On February 15, an X account named “@iffiViews,” reportedly operated from Pakistan, shared the image claiming it was taken during the India–Pakistan T20 World Cup match at the R. Premadasa Stadium in Colombo. The viral image appeared to show Yadav attempting to shake hands with Agha, who seemed to decline the gesture. The post quickly gained significant traction online, attracting around one million views at the time of reporting. Here is the link and archive link to the post, along with a screenshot.
- https://x.com/iffiViews/status/2023024665770484206?s=20
- https://archive.ph/xvtBs

Fact Check:
To verify the authenticity of the image, researchers closely examined the visual and identified a watermark associated with an AI image-generation tool. This raised strong indications that the image was digitally created and did not depict an actual event.

The image was further analysed using an AI detection tool, which indicated a 99.9 percent probability that the content was artificially generated or manipulated.

Researchers also conducted keyword searches to check whether the two captains had exchanged a handshake during the match. The search revealed media reports confirming that the traditional handshake between players has been discontinued since the Asia Cup 2025 in both men’s and women’s cricket. A report published by The Times of India on February 15 confirmed that no such customary exchange took place during the match between the two teams in Colombo.

Conclusion
The viral image claiming to show Suryakumar Yadav attempting to shake hands with Salman Ali Agha is not authentic. The visual is AI-generated and has been shared online with misleading claims.
Related Blogs

Executive Summary:
A viral video claiming the crash site of Air India Flight AI-171 in Ahmedabad has misled many people online. The video has been confirmed not to be from India or a recent crash, but was filmed at Universal Studios Hollywood on a TV or movie set meant to look like a plane crash set piece for a movie.

Claim:
A video that purportedly shows the wreckage of Air India Flight AI-171 after crashing in Ahmedabad on June 12, 2025, has circulated among social media users. The video shows a large amount of aircraft wreckage as well as destroyed homes and a scene reminiscent of an emergency, making it look genuine.

Fact check:
In our research, we took screenshots from the viral video and used reverse image search, which matched visuals from Universal Studios Hollywood. It became apparent that the video is actually from the most famous “War of the Worlds" set, located in Universal Studios Hollywood. The set features a 747 crash scene that was constructed permanently for Steven Spielberg's movie in 2005. We also found a YouTube video. The set has fake smoke poured on it, with debris scattered about and additional fake faceless structures built to represent a scene with a larger crisis. Multiple videos on YouTube here, here, and here can be found from the past with pictures of the tour at Universal Studios Hollywood, the Boeing 747 crash site, made for a movie.


The Universal Studios Hollywood tour includes a visit to a staged crash site featuring a Boeing 747, which has unfortunately been misused in viral posts to spread false information.

While doing research, we were able to locate imagery indicating that the video that went viral, along with the Universal Studios tour footage, provided an exact match and therefore verified that the video had no connection to the Ahmedabad incident. A side-by-side comparison tells us all we need to know to uncover the truth.


Conclusion:
The viral video claiming to show the aftermath of the Air India crash in Ahmedabad is entirely misleading and false. The video is showing a fictitious movie set from Universal Studios Hollywood, not a real disaster scene in India. Spreading misinformation like this can create unnecessary panic and confusion in sensitive situations. We urge viewers to only trust verified news and double-check claims before sharing any content online.
- Claim: Massive explosion and debris shown in viral video after Air India crash.
- Claimed On: Social Media
- Fact Check: False and Misleading
.webp)
Introduction to Grooming
The term grooming is believed to have been first used by a group of investigators in the 1970s to describe patterns of seduction of an offender towards a child. It eventually evolved and began being commonly used by law enforcement agencies and has now replaced the term seduction for this behavioural pattern. At its core, grooming refers to conditioning a child by an adult offender to further their wrong motives. In its most popular sense, it refers to the sexual victimisation of children whereby an adult befriends a minor and builds an emotional connection to sexually abuse, exploit and even trafficking such a victim. The onset of technology has shifted the offline physical proximity of perpetrators to the internet, enabling groomers to integrate themselves completely into the victim’s life by maintaining consistent contact. It is noted that while grooming can occur online and offline, groomers often establish online contact before moving the ‘relationship’ offline to commit sexual offences.
Underreporting and Vulnerability of Teenagers
Given the elusive nature of the crime, cyber grooming remains one of the most underreported crimes by victims, who are often unaware or embarrassed to share their experiences. Teenagers are particularly more susceptible to cyber grooming since they not only have more access to the internet but also engage in more online risk-taking behaviours such as posting sensitive and personal pictures. Studies indicate that individuals aged 18 to 23 often lack awareness regarding the grooming process. They frequently engage in relationships with groomers without recognising the deceptive and manipulative tactics employed, mistakenly perceiving these relationships as consensual rather than abusive.
Rise of Cyber Grooming incidents after COVID-19 pandemic
There has been an uptick in cyber grooming after the COVID-19 pandemic, whereby an adult poses as a teenager or a child and befriends a minor on child-friendly websites or social media outlets and builds an emotional connection with the victim. The main goal is to obtain intimate and personal data of the minor, often in the form of sexual chats, pictures or videos, to threaten and coerce them into continuing such acts. The grooming process usually begins with seemingly harmless inquiries about the minor's age, interests, and family background. Over time, these questions gradually shift to topics concerning sexual experiences and desires. Research and data indicate that online grooming is primarily carried out by males, who frequently choose their victims based on attractiveness, ease of access, and the ability to exploit the minor's vulnerabilities.
Beyond Sexual Exploitation: Ideological and Commercial Grooming
Grooming is not confined to sexual exploitation. The rise of technology has expanded the influence of extremist ideological groups, granting them access to children who can be coerced into adopting their beliefs. This phenomenon, known as ideological grooming, presents significant personal, social, national security, and law enforcement challenges. Additionally, a new trend, termed digital commercial grooming, involves malicious actors manipulating minors into procuring and using drugs. Violent extremists are improving their online recruitment strategies, learning from each other to target and recruit supporters more effectively and are constantly leveraging children’s vulnerabilities to reinforce anti-government ideologies.
Policy Recommendations to Combat Cyber Grooming
To address the pervasive issue of cyber grooming and child recruitment by extremist groups, several policy recommendations can be implemented. Social media and online platforms should enhance their monitoring and reporting systems to swiftly detect and remove grooming behaviours. This includes investing in AI technologies for content moderation and employing dedicated teams to respond to reports promptly. Additionally, collaborative efforts with cybersecurity experts and child psychologists to develop educational campaigns and tools that teach children about online safety and identify grooming tactics should be mandated. Legislation should also be strengthened to include provisions specifically addressing cyber grooming, ensuring strict penalties for offenders and protections for victims. In this regard, international cooperation among law enforcement agencies and tech companies is essential to create a unified approach to tackling cross-border online threats to children's safety and security.
References:
- Lanning, Kenneth “The Evolution of Grooming: Concept and Term”, Journal of Interpersonal Violence, 2018, Vol. 33 (1) 5-16. https://www.nationalcac.org/wp-content/uploads/2019/05/The-evolution-of-grooming-Concept-and-term.pdf
- Jonie Chiu, Ethel Quayle, “Understanding online grooming: An interpretative phenomenological analysis of adolescents' offline meetings with adult perpetrators”, Child Abuse & Neglect, Volume 128, 2022, 105600, ISSN 0145-2134,https://doi.org/10.1016/j.chiabu.2022.105600. https://www.sciencedirect.com/science/article/pii/S014521342200120X
- “Online child sexual exploitation and abuse”, Sharinnf Electronic Resources on Laws and Crime, United Nations Office for Drugs and Crime. https://sherloc.unodc.org/cld/en/education/tertiary/cybercrime/module-12/key-issues/online-child-sexual-exploitation-and-abuse.html
- Mehrotra, Karishma, “In the pandemic, more Indian children are falling victim to online grooming for sexual exploitation” The Scroll.in, 18 September 2021. https://scroll.in/magazine/1005389/in-the-pandemic-more-indian-children-are-falling-victim-to-online-grooming-for-sexual-exploitation
- Lorenzo-Dus, Nuria, “Digital Grooming: Discourses of Manipulation and Cyber-Crime”, 18 December 2022 https://academic.oup.com/book/45362
- Strategic orientations on a coordinated EU approach to prevention of radicalisation in 2022-2023 https://home-affairs.ec.europa.eu/system/files/2022-03/2022-2023%20Strategic%20orientations%20on%20a%20coordinated%20EU%20approach%20to%20prevention%20of%20radicalisation_en.pdf
- “Handbook on Children Recruited and Exploited by Terrorist and Violent Extremist Groups: The Role of the Justice System”, United Nations Office on Drugs and Crime, 2017. https://www.unodc.org/documents/justice-and-prison-reform/Child-Victims/Handbook_on_Children_Recruited_and_Exploited_by_Terrorist_and_Violent_Extremist_Groups_the_Role_of_the_Justice_System.E.pdf

Introduction
On 27 July 2026, Bank of Baroda admitted to experiencing a cybersecurity attack, officially confirming many hours of chatter and speculation amongst Bank of Baroda customers and information security professionals. According to a statement by the bank issued through regulatory filing, the breach came about due to unauthorised access into some of its data via compromise of an employee’s email account; however, not much beyond these details was disclosed. In the meantime, allegations of a major large-scale data leak flooded into various platforms and forums of the cybersecurity world along with mainstream news outlets and, eventually, mainstream social networks. It’s now critically important for us to attempt to differentiate factual from unverified details about Bank of Baroda’s recent cybersecurity incident.
We will analyse and list what the bank has released, what our community research has discovered and also what questions are still left unanswered.
The bank's version
Bank of Baroda said the breach traced back to a single compromised employee email account, which gave an unknown party unauthorised access to "certain data". Crucially, the bank maintains that its core banking systems, that is, the infrastructure that actually moves customer money, were never touched. It says the incident was detected and contained quickly and that it is working with law enforcement and regulators while a forensic investigation continues. That's a fairly narrow admission compared with what had already surfaced on the dark web.
What the hackers claim
Days before the bank's statement, a relatively new ransomware and data-extortion group calling itself ‘TripleX’ listed Bank of Baroda on its dark web leak site, dated July 24. The group claimed to have pulled roughly 1 terabyte of data and, unusually, released the entire cache for free rather than holding it for ransom, framing the move on its leak page as punishment for the bank's weak passwords and security lapses.
Independent researcher Srikanth Lakshmanan, founder of the digital-rights group 'CashlessConsumer', examined samples of the leaked material before alerting the bank and authorities. He told India Today Tech that what he reviewed included internal branch audit files, loan appraisal documents, vigilance investigation records, audit reports tied to the bank's bob World mobile app, and customer account-opening forms.
Several outlets also reported that sample files appeared to contain Aadhaar numbers, customer photographs, and NetBanking details, alongside corporate and NRI banking records. It's worth being precise here, though: Reuters and other outlets have emphasised that the exact contents and true scale of the leak haven't been independently verified, and Bank of Baroda itself hasn't confirmed which specific data categories were exposed. Estimates of the dataset's size have also varied anywhere from around 700 gigabytes to a full terabyte, depending on the source.
A repeat offender
TripleX isn't new to targeting state-owned banks. The gang first appeared in May 2026, and only weeks before targeting Bank of Baroda, it claimed responsibility for hacking PT Bank Negara Indonesia – the largest of Indonesia's state-owned banks, which stole nearly 2 terabytes of documents, including contracts, IDs and transaction histories. Both compromises follow a familiar pattern. Identify one point of entry, extract widely, and instead of working in the background to negotiate for a ransom, publish everything for the largest damage possible.
This represents a notable break from typical ransomware attacks. Groups such as TripleX forego encryption, simply relying solely on the public pressure of (or actuality of) imminent disclosure to extort victims. It is the extortion component of "double extortion" with little incentive to pursue payment.
The regulatory clock
India's banking sector doesn't get much slack when something like this happens. The Reserve Bank of India's Cyber Security Framework for Banks requires an initial incident report within two to six hours of detection, and India's Computer Emergency Response Team (CERT-In) mandates reporting of specified incidents within six hours. Bank of Baroda has also reportedly filed a preliminary notice under a cyber-insurance programme arranged through National Insurance, offering total coverage of roughly $78 million, though it's far too early to know whether it will actually be paid out or how much will actually be paid out.
Looking ahead, India's Digital Personal Data Protection Rules are due to take effect in May 2027, which will tighten breach-notification obligations further. This incident lands right at the edge of that regulatory transition, arguably a preview of what's at stake for the next bank that gets hit.
A History of Data Security Missteps
This is not the first time banks’ technology has raised a red flag. In 2023, an investigation by The Reporters’ Collective and Al Jazeera discovered that bank employees had inserted the mobile numbers of unauthorised agents (including those belonging to staff and security guards) and other businesses into their customers' profiles to drive enrolment on the bank’s app – BoB World. Several of the bank's customers were later victims of fraud due to the unauthorised association of mobile numbers, and the bank had its own internally reported data issues that later led to the RBI mandating an audit and then prohibiting the bank from onboarding new Bob World users temporarily. Even though the two issues are not related, it serves as context; in the case of banks handling more than $300 billion in their global operations through over 8,400 domestic locations, room for security errors is marginal, and the damage, both public and regulatory, escalates from there on.
What it means for customers
For those who bank with the Bank of Baroda, the common-sense approach is checking statements for any unfamiliar transactions; beware unsolicited calls/messages referencing account details (which typically follow after identity document leaks are being used as a basis for secondary scams); and as a security precaution, change your NetBanking password and app PIN while no core systems of the bank are reported to have been breached; even so, it is advisable to apply. Because Aadhaar, if it has been really compromised, cannot be reset like a password, which is why a compromised identity document is typically of longer-term risk than a stolen password.
Conclusion
The bigger story here isn't just one bank's bad week. It's a reminder that in a system where a single compromised employee inbox can cascade into hundreds of gigabytes of exposed customer data, "our core systems weren't affected" is true and reassuring and, for anyone whose loan documents or ID numbers may now be sitting on a dark web forum, somewhat beside the point.
Sources
- Bank of Baroda confirms cyber incident after hackers claim data theft — The Record (Recorded Future News): https://therecord.media/india-bank-of-baroda-reports-cybersecurity-incident
- Bank of Baroda Data Leak: What We Know So Far — Gulf News: https://gulfnews.com/business/banking/bank-of-baroda-data-leak-what-we-know-so-far-about-alleged-cyber-breach-1.500621898
- Bank of Baroda Breach Tests Disclosure Readiness — GovInfoSecurity (ISMG): https://www.govinfosecurity.com/bank-baroda-breach-tests-disclosure-readiness-a-32335
- India's Bank of Baroda Faces Alleged 1TB Data Leak on Dark Web — Yahoo Finance / India Today Tech: https://finance.yahoo.com/technology/ai/articles/india-bank-baroda-faces-alleged-113047992.html
- Bank of Baroda Data Breach Exposes Customer Records — The Asian Banker: https://www.theasianbanker.com/updates-and-articles/india-s-bank-of-baroda-data-breach-exposes-customer-records-after-employee-email-compromise
- India's Bank of Baroda Expose Worsens: Agents Steal Money From Accounts (2023 background) — Al Jazeera: https://www.aljazeera.com/economy/2023/10/12/indias-bank-of-baroda-expose-worsens-agents-steal-money-from-accounts
- 'Immediate Containment Measures Implemented': Bank of Baroda Issues Clarity on Alleged 1TB Data Leak — Republic World: https://www.republicworld.com/business/immediate-containment-measures-implemented-bank-of-baroda-issues-clarity-on-1tb-data-leak-2026-07-27-133590