#FactCheck - Uncovered: Viral LA Wildfire Video is a Shocking AI-Generated Fake!
Executive Summary:
A viral post on X (formerly Twitter) has been spreading misleading captions about a video that falsely claims to depict severe wildfires in Los Angeles similar to the real wildfire happening in Los Angeles. Using AI Content Detection tools we confirmed that the footage shown is entirely AI-generated and not authentic. In this report, we’ll break down the claims, fact-check the information, and provide a clear summary of the misinformation that has emerged with this viral clip.

Claim:
A video shared across social media platforms and messaging apps alleges to show wildfires ravaging Los Angeles, suggesting an ongoing natural disaster.

Fact Check:
After taking a close look at the video, we noticed some discrepancy such as the flames seem unnatural, the lighting is off, some glitches etc. which are usually seen in any AI generated video. Further we checked the video with an online AI content detection tool hive moderation, which says the video is AI generated, meaning that the video was deliberately created to mislead viewers. It’s crucial to stay alert to such deceptions, especially concerning serious topics like wildfires. Being well-informed allows us to navigate the complex information landscape and distinguish between real events and falsehoods.

Conclusion:
This video claiming to display wildfires in Los Angeles is AI generated, the case again reflects the importance of taking a minute to check if the information given is correct or not, especially when the matter is of severe importance, for example, a natural disaster. By being careful and cross-checking of the sources, we are able to minimize the spreading of misinformation and ensure that proper information reaches those who need it most.
- Claim: The video shows real footage of the ongoing wildfires in Los Angeles, California
- Claimed On: X (Formerly Known As Twitter)
- Fact Check: Fake Video
Related Blogs

CERT-In, India's national cybersecurity agency, operates under mounting pressure. Cyberattacks in the country have doubled from 1.4 million in FY2022 to 2.9 million in FY2026, even as the window between a vulnerability's discovery and its exploitation continues to narrow. Rather than wait for access to the most advanced AI security tools, some of which face export restrictions, the agency has spent recent months building its own solution.
CERT-In has developed a new sandbox platform built with open-source AI, designed to identify cybersecurity gaps in public-sector systems. The sandbox functions as an isolated testing environment, allowing teams to safely evaluate software and applications without exposing the broader system to risk. Officials have framed this as a foundation rather than a substitute. MeitY Secretary S Krishnan described the platform as a step toward building a secure environment for eventual access to international AI models — suggesting the current approach is understood as an interim measure, not a permanent alternative to global tools.
This effort sits within a broader policy push: encouraging domestic AI development and tightening oversight of AI use in finance and online content. Taken together, these moves suggest a deliberate strategy of capacity-building through incremental, self-reliant steps, rather than a story about capability gaps or resource shortfalls.
A Crisis Measured in Millions
It helps to look at why this matters so much right now. A joint study by the Data Security Council of India and BCG found that recorded cyberattacks in the country roughly doubled in four years, from about 1.4 million in FY22 to 2.9 million in FY26. What's more worrying is how little time defenders now have to react to the average time it takes attackers to exploit a newly found vulnerability dropped from 745 days in FY22 to just 44 days in FY26, largely because attackers are using AI themselves to scout targets and build exploits faster. Banking, financial services, healthcare, telecom and government portals bear the brunt of this, with ransomware-as-a-service groups and state-linked actors increasingly slipping in through vendor portals and supply-chain weak points.
Turning Existing AI Into a Working Defence
CERT-In's Sandbox in Action
Instead of treating the lack of any one frontier model as a dealbreaker, CERT-In simply built its own closed trial platform officials have taken to calling it a "war room" where open-source and other AI models are set loose on software code to find vulnerabilities and shape secure workflows for India's top public sector companies, including in financial services. At a press conference, Meity secretary S. Krishnan pointed out that these substitute models already match roughly 60 to 70 per cent of the performance of the most advanced security-focused systems out there globally. That's a fairly substantial chunk of the capability, and it's coming from tools India can actually access today. The testing has stretched to core digital infrastructure like Aadhaar and government login systems, while some of the country's biggest tech firms are already using currently available AI models to patch widely used enterprise software, banking platforms included. The logic is simple enough: build the muscle now with whatever's on hand, so the enterprise environment is already in better shape by the time more capable tools eventually arrive.
Investing in Sovereign Capability
Arguably the more important move here is a longer-term one , India's bet on building its own frontier-grade security AI. The Centre has reportedly asked domestic AI developers Sarvam AI and BharatGen to build advanced cybersecurity capabilities of their own, hosted on the government's isolated computer infrastructure and eventually put to work protecting critical infrastructure. There's no public timeline yet for when these indigenous models will be ready, but the intent behind the move isn't hard to read: cut India's reliance on any single foreign provider for defending the systems that underpin banking, identity and public administration, while keeping sensitive testing and deployment on Indian soil. Officials have also signalled a preference for on-premises deployment of high-capability AI tools where the stakes are highest, rather than leaning entirely on overseas cloud infrastructure. It's a choice that points toward building lasting, self-reliant capacity rather than making a one-off purchase.
A Tightening Regulatory Net
RBI's Model Risk Guardrails
None of this is happening in a vacuum. On 24 June 2026, the Reserve Bank of India released draft guidance on model risk management that, for the first time, brings AI and machine learning systems used by banks, NBFCs and other regulated entities under a single, board-level governance framework. The draft asks institutions to keep a full inventory of every model they use, rank each one by risk, and build in human override and "kill-switch" mechanisms so a malfunctioning AI system can be shut down immediately. It also makes one thing very clear: banks can't shrug off accountability just because the technology came from a vendor.
MeitY's Deepfake and Synthetic-Content Rules
Around the same time, the Ministry of Electronics and Information Technology notified amendments to the IT Rules that formally define "synthetically generated information," require deepfakes and AI-altered media to carry clear, persistent labels and embedded provenance metadata, and cut the takedown window for unlawful synthetic content down to just three hours. Taken together, the RBI and MeitY rules form the regulatory backbone that CERT-In's technical sandbox is meant to plug into giving India a more coordinated response to both the defensive and the deceptive sides of AI.
One Chain of Command
Officials have gone out of their way to stress that all these moving parts aren't creating confusion in India's cybersecurity reporting structure. CERT-In director general Sanjay Bahl has said the National Security Council Secretariat remains the overarching body, with CERT-In as the top cyber reporting and investigations organisation across sectors, and that sectoral regulators like the RBI and SEBI still report into this one structure rather than running their own parallel systems.
Conclusion
Look at CERT-In's sandbox, the push for sovereign AI, and the tightening regulatory net together, and a clearer picture forms. This isn't really a story about a piece of technology India doesn't have. It's a story about capability being built, deliberately and in the open. The country is using the AI tools available right now to close real security gaps, backing homegrown alternatives for the long haul, and pairing both with governance rules that keep banks, platforms and public infrastructure honest. If there's a lesson in all this, it's that real resilience against a fast-moving cyberthreat landscape rarely arrives all at once. It gets built the way most lasting capability does piece by piece, mostly at home, without waiting for any single outside breakthrough to show up first.
References
- https://inc42.com/buzz/centre-asks-sarvam-ai-bharatgen-to-develop-mythos-like-cyber-ai-models/
- https://inc42.com/buzz/centre-asks-sarvam-ai-bharatgen-to-develop-mythos-like-cyber-ai-models/
- https://www.newkerala.com/news/a/govt-prioritises-access-anthropics-mythos-ai-model-strengthen-475.htm
- https://blog.qualys.com/product-tech/2026/06/24/cert-in-ai-vulnerability-blueprint-machine-speed-risk-operations
- https://www.business-standard.com/technology/tech-news/mythos-threat-govt-tech-firms-test-their-softwares-for-vulnerabilities-126052700386_1.html
- https://inc42.com/buzz/centre-asks-sarvam-ai-bharatgen-to-develop-mythos-like-cyber-ai-models/
- https://www.finextra.com/blogposting/32142/rbis-model-risk-management-guidance-2026--summary
- https://www.medianama.com/2026/06/223-rbi-ai-guidelines-2026-banks-kill-switch/
- https://www.freshfields.com/en/our-thinking/blogs/technology-quotient/india-targets-deepfakes-and-ai-generated-content-key-changes-under-meitys-2026-102mjwn

Executive Summary
Israel’s parliament, the Knesset, recently passed a bill allowing military courts to impose the death penalty on Palestinians convicted of killing Israelis. Amid this backdrop, a video has gone viral on social media showing men in black uniforms beating detainees inside a prison, with claims linking it to alleged torture by Israeli forces. However, a research by the CyberPeace found the claim to be false. The viral video is not related to Israel or any real incident, but is actually from an Iraqi television series titled “Beit Umm Layla.”
Claim
Sharing the video, a user on X (formerly Twitter) wrote:“Live footage: IDF soldiers always torture Palestinian hostages before executing them. Please don’t let us die in silence.”

Fact Check
To verify the claim, we extracted keyframes from the viral video and conducted a reverse image search. This led us to a longer version of the clip posted on March 9 by the Iraqi channel Al-Iraqiya on its Facebook and Instagram pages.


The posts clearly identified the footage as part of “Beit Umm Layla,” a popular Iraqi TV series. Further research showed that the full series is available on Al-Iraqiya’s official YouTube channel, where 25 episodes were uploaded between February 19 and March 20. The viral clip corresponds to Episode 16 of the show.

Additionally, information available on the Arabic entertainment website elCinema indicates that the series, released on February 18, is a socio-political drama focusing on prisoners and the psychological struggles faced by them and their families.
Conclusion
The viral claim is false and misleading. The video does not depict any real incident involving Israeli forces or Palestinian detainees. Instead, it is a fictional scene from an Iraqi television drama series.There is no credible evidence to support the claim that the footage shows torture by Israeli soldiers. The clip has been taken out of context and shared with a misleading narrative to provoke emotional reactions.

Modern international trade heavily relies on data transfers for the exchange of digital goods and services. User data travels across multiple jurisdictions and legal regimes, each with different rules for processing it. Since international treaties and standards for data protection are inadequate, states, in an effort to protect their citizens' data, have begun extending their domestic privacy laws beyond their borders. However, this opens a Pandora's box of legal and administrative complexities for both, the data protection authorities and data processors. The former must balance the harmonization of domestic data protection laws with their extraterritorial enforcement, without overreaching into the sovereignty of other states. The latter must comply with the data privacy laws in all states where it collects, stores, and processes data. While the international legal community continues to grapple with these challenges, India can draw valuable lessons to refine the Digital Personal Data Protection Act, 2023 (DPDP) in a way that effectively addresses these complexities.
Why Extraterritorial Application?
Since data moves freely across borders and entities collecting such data from users in multiple states can misuse it or use it to gain an unfair competitive advantage in local markets, data privacy laws carry a clause on their extraterritorial application. Thus, this principle is utilized by states to frame laws that can ensure comprehensive data protection for their citizens, irrespective of the data’s location. The foremost example of this is the European Union’s (EU) General Data Protection Regulation (GDPR), 2016, which applies to any entity that processes the personal data of its citizens, regardless of its location. Recently, India has enacted the DPDP Act of 2023, which includes a clause on extraterritorial application.
The Extraterritorial Approach: GDPR and DPDP Act
The GDPR is considered the toughest data privacy law in the world and sets a global standard in data protection. According to Article 3, its provisions apply not only to data processors within the EU but also to those established outside its territory, if they offer goods and services to and conduct behavioural monitoring of data subjects within the EU. The enforcement of this regulation relies on heavy penalties for non-compliance in the form of fines up to €20 million or 4% of the company’s global turnover, whichever is higher, in case of severe violations. As a result, corporations based in the USA, like Meta and Clearview AI, have been fined over €1.5 billion and €5.5 million respectively, under the GDPR.
Like the GDPR, the DPDP Act extends its jurisdiction to foreign companies dealing with personal data of data principles within Indian territory under section 3(b). It has a similar extraterritorial reach and prescribes a penalty of up to Rs 250 crores in case of breaches. However, the Act or DPDP Rules, 2025, which are currently under deliberation, do not elaborate on an enforcement mechanism through which foreign companies can be held accountable.
Lessons for India’s DPDP on Managing Extraterritorial Application
- Clarity in Definitions: GDPR clearly defines ‘personal data’, covering direct information such as name and identification number, indirect identifiers like location data, and, online identifiers that can be used to identify the physical, physiological, genetic, mental, economic, cultural, or social identity of a natural person. It also prohibits revealing special categories of personal data like religious beliefs and biometric data to protect the fundamental rights and freedoms of the subjects. On the other hand, the DPDP Act/ Rules define ‘personal data’ vaguely, leaving a broad scope for Big Tech and ad-tech firms to bypass obligations.
- International Cooperation: Compliance is complex for companies due to varying data protection laws in different countries. The success of regulatory measures in such a scenario depends on international cooperation for governing cross-border data flows and enforcement. For DPDP to be effective, India will have to foster cooperation frameworks with other nations.
- Adequate Safeguards for Data Transfers: The GDPR regulates data transfers outside the EU via pre-approved legal mechanisms such as standard contractual clauses or binding corporate rules to ensure that the same level of protection applies to EU citizens’ data even when it is processed outside the EU. The DPDP should adopt similar safeguards to ensure that Indian citizens’ data is protected when processed abroad.
- Revised Penalty Structure: The GDPR mandates a penalty structure that must be effective, proportionate, and dissuasive. The supervisory authority in each member state has the power to impose administrative fines as per these principles, up to an upper limit set by the GDPR. On the other hand, the DPDP’s penalty structure is simplistic and will disproportionately impact smaller businesses. It must take into regard factors such as nature, gravity, and duration of the infringement, its consequences, compliance measures taken, etc.
- Governance Structure: The GDPR envisages a multi-tiered governance structure comprising of
- National-level Data Protection Authorities (DPAs) for enforcing national data protection laws and the GDPR,
- European Data Protection Supervisor (EDPS) for monitoring the processing of personal data by EU institutions and bodies,
- European Commission (EC) for developing GDPR legislation
- European Data Protection Board (EDPB) for enabling coordination between the EC, EDPS, and DPAs
In contrast, the Data Protection Board (DPB) under DPDP will be a single, centralized body overseeing compliance and enforcement. Since its members are to be appointed by the Central Government, it raises questions about the Board’s autonomy and ability to apply regulations consistently. Further, its investigative and enforcement capabilities are not well defined.
Conclusion
The protection of the human right to privacy ( under the International Covenant on Civil and Political Rights and the Universal Declaration of Human Rights) in today’s increasingly interconnected digital economy warrants international standard-setting on cross-border data protection. In the meantime, States relying on the extraterritorial application of domestic laws is unavoidable. While India’s DPDP takes measures towards this, they must be refined to ensure clarity regarding implementation mechanisms. They should push for alignment with data protection laws of other States, and account for the complexity of enforcement in cases involving extraterritorial jurisdiction. As India sets out to position itself as a global digital leader, a well-crafted extraterritorial framework under the DPDP Act will be essential to promote international trust in India’s data governance regime.
Sources
- https://gdpr-info.eu/art-83-gdpr/
- https://gdpr-info.eu/recitals/no-150/
- https://gdpr-info.eu/recitals/no-51/
- https://www.meity.gov.in/static/uploads/2024/06/2bf1f0e9f04e6fb4f8fef35e82c42aa5.pdf
- https://www.eqs.com/compliance-blog/biggest-gdpr-fines/#:~:text=ease%20the%20burden.-,At%20a%20glance,In%20summary
- https://gdpr-info.eu/art-3-gdpr/
- https://www.legal500.com/developments/thought-leadership/gdpr-v-indias-dpdpa-key-differences-and-compliance-implications/#:~:text=Both%20laws%20cover%20'personal%20data,of%20personal%20data%20as%20sensitive.