#FactCheck - Viral Postcard Attributing Fake UGC Statement to Keshav Prasad Maurya Is False
Executive Summary
A postcard claiming that Uttar Pradesh Deputy Chief Minister Keshav Prasad Maurya commented on the Supreme Court’s stay on the new UGC regulations is being widely shared on social media. The viral postcard suggests that Maurya stated the Modi government would “fight till its last breath” to implement the UGC law and appealed to Dalit, backward and tribal communities to trust the government as their true well-wisher. However, an research by the CyberPeace has found that the viral postcard is fake. Keshav Prasad Maurya has not made any such statement.
Claim
A Facebook user shared the postcard with the caption:“Now read it yourself. Statement of Deputy CM Keshav Prasad Maurya — the Modi government will fight till its last breath to implement the UGC law. An appeal to Dalit, backward and tribal communities to trust the government, calling it their true well-wisher.”
(Archived version of the post available here.)

Fact Check:
During the research, we did not find any credible news reports mentioning such a statement by Deputy Chief Minister Keshav Prasad Maurya regarding the UGC regulations or the Supreme Court’s order. A closer examination of the viral postcard revealed several inconsistencies. Notably, the text on the postcard lacks proper punctuation, such as commas and full stops, which is unusual for professionally designed news graphics. The postcard carries the logo of Navbharat Times (NBT). However, when compared with genuine NBT postcards, the font style used in the viral image does not match NBT’s official design. We also traced the original NBT postcard that appears to have been edited to create the fake one. In the authentic postcard, shared by NBT on January 20, Keshav Prasad Maurya is quoted as saying: Where the lotus has bloomed, it will continue to bloom, and where it has not, under the guidance of PM Modi and the leadership of Nitin Nabin, the lotus will bloom.”

The original statement was digitally altered, and a fabricated quote was inserted to create the viral postcard.
Conclusion
CyberPeace research clearly establishes that the viral postcard is fake. The original Navbharat Times postcard has been tampered with, and Keshav Prasad Maurya’s actual statement has been replaced with a fabricated quote, which is now being circulated with a misleading claim.
Related Blogs

Introduction
In this age, when our data stands as the key to all resources, espionage has moved from dark alleys and trench coats to keyboards and code. In this era of active digital espionage, where intelligence is stolen through invisible cyberattacks that target computer networks. Cyber espionage and spying have become the most critical threat in the hyper-connected world of today. As governments, corporations, and individuals store an immense amount of confidential information online, the grounds of espionage have shifted from land and sea to the silent realm of cyberspace.
What is Cyber Espionage?
Cyber espionage refers to the unauthorised access of confidential data for strategic, political, military, and financial gain, unlike cybercrime, which is mostly about money. Cyber espionage is about gaining information power. The very first documented case dates back to 1986-87, when a group of German hackers breached the US military establishment and the defence systems and sold that stolen data to the Soviets and the KGB. This was the beginning of a new era where classified intelligence could be gathered even without entering a building.
Cyber espionage is mostly carried out by trained espionage professionals, elite hackers, and corporate spies whose sole purpose is to target the government, research organisations, military establishments, and other critical infrastructures.
The Objective
The act of Cyber Espionage is being driven by three major objectives, such as;
- Stealing of Intellectual Property- Starting from information and data related to military establishments to pharmaceutical patents, stealing innovation is cheaper than funding R&D.
- Political and Diplomatic Advantage- As government networks are hacked to access state secrets, negotiation strategies, and classified communications.
- Military Intelligence- Cyber spies also work to steal data on weapons troop movements, defence systems, and war systems, often years before conflict breaks out.
In a world being shaped by digital power, information is not just about knowledge. Rather, it is all about ensuring dominance.
The arsenal of modern digital spies is more sophisticated, and most importantly, they are used covertly rather than the spy gadgets that are shown in spy movies. Some of the tactics resorted to by the cyber spies can be recognised as;
- Phishing Attacks through fake emails that lure victims to click on malicious links or sharing of passwords.
- Persisting Advanced Threats through long-term stealth attacks in a network for more than a month or a year.
- Malware and Spyware are invisible software that logs keystrokes, records screens, or steals files silently.
- Deepfake Manipulations by creating AI-generated fake videos that can influence political developments in the country.
Anything that makes cyber espionage terrifying is not just the theft, but the fact that it goes undetected.
What Differentiates Cyber Espionage and Cyber Warfare
Cyber espionage is a silent and stealthy tactic that is carried out with utmost secrecy, being a long-term effort for intelligence gathering. It mostly focuses on the stealing of data, whereas Cyber warfare is an open and destructive tactic that is used to create an immediate and visible impact to create disruption. However, espionage is an act that prepares the battlefield for the warfare of the future.
Taking instances of real instances of cyber espionage, we can refer to examples such as;
- Operation Aurora was conducted in 2010, where Chinese Hackers based in Beijing tried to steal IP data from Google and American tech giants.
- The Stuxnet attack in 2010 was another cyber weapon that was developed to sabotage Iran’s nuclear centrifuges.
- SolarWinds Attack of 2020 was an instance of cyber espionage where a supply chain hack was carried out to target multiple US federal government agencies.
As most of these instances reflect that they were battles without guns, but with the use of codes. Several sources raise the question of whether cyber-attacks can be stopped. The answer lies in the fact that they cannot be stopped completely, but can be minimised to some extent, by developing capabilities to counter and deter cyber-attacks with the help of equal cyber defence capabilities.
Conclusion
From the Cold War era to the present Code War, espionage has evolved with technology. An effort that was once taken solely by spies and human assets, with the passing of time enhancement of technologies it is now expanded to malware, phishing, social engineering, and remote digital inflation. In this age of information warfare, espionage is faster, cheaper, and harder to trace than ever before. The enemies of a nation may never cross its borders, but they may already be inside its systems. However, the world has now officially entered a new battlefield, without boundaries, uniforms, and bombs. It is now being fought through bytes, breaches, and invisible enemies.
References
- https://www.sentinelone.com/cybersecurity-101/threat-intelligence/cyber-espionage/
- https://www.espiamos.com/en/content/espionage-in-the-digital-world-threats-and-opportunities.html
- https://www.apu.apus.edu/area-of-study/information-technology/resources/what-is-cyber-warfare/
- https://pride-security.co.uk/the-rise-of-digital-warfare-understanding-the-evolution-of-cyber-espionage/

SVIMS Director and Vice-Chancellor B. Vengamma lighting a lamp to formally launch the cybercrime awareness programme conducted by the police department for the medical students in Tirupati on Wednesday.
An awareness meet on safe Internet practices was held for the students of Sri Venkateswara University University (SVU) and Sri Venkateswara Institute of Medical Sciences (SVIMS) here on Wednesday.
“Cyber criminals on the prowl can easily track our digital footprint, steal our identity and resort to impersonation,” cyber expert I.L. Narasimha Rao cautioned the college students.
Addressing the students in two sessions, Mr. Narasimha Rao, who is a Senior Manager with CyberPeace Foundation, said seemingly common acts like browsing a website, and liking and commenting on posts on social media platforms could be used by impersonators to recreate an account in our name.
Turning to the youth, Mr. Narasimha Rao said the incognito mode and Virtual Private Network (VPN) used as a protected network connection do not ensure total privacy as third parties could still snoop over the websites being visited by the users. He also cautioned them tactics like ‘phishing’, ‘vishing’ and ‘smishing’ being used by cybercriminals to steal our passwords and gain access to our accounts.
“After cracking the whip on websites and apps that could potentially compromise our security, the Government of India has recently banned 232 more apps,” he noted.
Additional Superintendent of Police (Crime) B.H. Vimala Kumari appealed to cyber victims to call 1930 or the Cyber Mitra’s helpline 9121211100. SVIMS Director B. Vengamma stressed the need for caution with smartphones becoming an indispensable tool for students, be it for online education, seeking information, entertainment or for conducting digital transactions.

Introduction
On 27 July 2026, Bank of Baroda admitted to experiencing a cybersecurity attack, officially confirming many hours of chatter and speculation amongst Bank of Baroda customers and information security professionals. According to a statement by the bank issued through regulatory filing, the breach came about due to unauthorised access into some of its data via compromise of an employee’s email account; however, not much beyond these details was disclosed. In the meantime, allegations of a major large-scale data leak flooded into various platforms and forums of the cybersecurity world along with mainstream news outlets and, eventually, mainstream social networks. It’s now critically important for us to attempt to differentiate factual from unverified details about Bank of Baroda’s recent cybersecurity incident.
We will analyse and list what the bank has released, what our community research has discovered and also what questions are still left unanswered.
The bank's version
Bank of Baroda said the breach traced back to a single compromised employee email account, which gave an unknown party unauthorised access to "certain data". Crucially, the bank maintains that its core banking systems, that is, the infrastructure that actually moves customer money, were never touched. It says the incident was detected and contained quickly and that it is working with law enforcement and regulators while a forensic investigation continues. That's a fairly narrow admission compared with what had already surfaced on the dark web.
What the hackers claim
Days before the bank's statement, a relatively new ransomware and data-extortion group calling itself ‘TripleX’ listed Bank of Baroda on its dark web leak site, dated July 24. The group claimed to have pulled roughly 1 terabyte of data and, unusually, released the entire cache for free rather than holding it for ransom, framing the move on its leak page as punishment for the bank's weak passwords and security lapses.
Independent researcher Srikanth Lakshmanan, founder of the digital-rights group 'CashlessConsumer', examined samples of the leaked material before alerting the bank and authorities. He told India Today Tech that what he reviewed included internal branch audit files, loan appraisal documents, vigilance investigation records, audit reports tied to the bank's bob World mobile app, and customer account-opening forms.
Several outlets also reported that sample files appeared to contain Aadhaar numbers, customer photographs, and NetBanking details, alongside corporate and NRI banking records. It's worth being precise here, though: Reuters and other outlets have emphasised that the exact contents and true scale of the leak haven't been independently verified, and Bank of Baroda itself hasn't confirmed which specific data categories were exposed. Estimates of the dataset's size have also varied anywhere from around 700 gigabytes to a full terabyte, depending on the source.
A repeat offender
TripleX isn't new to targeting state-owned banks. The gang first appeared in May 2026, and only weeks before targeting Bank of Baroda, it claimed responsibility for hacking PT Bank Negara Indonesia – the largest of Indonesia's state-owned banks, which stole nearly 2 terabytes of documents, including contracts, IDs and transaction histories. Both compromises follow a familiar pattern. Identify one point of entry, extract widely, and instead of working in the background to negotiate for a ransom, publish everything for the largest damage possible.
This represents a notable break from typical ransomware attacks. Groups such as TripleX forego encryption, simply relying solely on the public pressure of (or actuality of) imminent disclosure to extort victims. It is the extortion component of "double extortion" with little incentive to pursue payment.
The regulatory clock
India's banking sector doesn't get much slack when something like this happens. The Reserve Bank of India's Cyber Security Framework for Banks requires an initial incident report within two to six hours of detection, and India's Computer Emergency Response Team (CERT-In) mandates reporting of specified incidents within six hours. Bank of Baroda has also reportedly filed a preliminary notice under a cyber-insurance programme arranged through National Insurance, offering total coverage of roughly $78 million, though it's far too early to know whether it will actually be paid out or how much will actually be paid out.
Looking ahead, India's Digital Personal Data Protection Rules are due to take effect in May 2027, which will tighten breach-notification obligations further. This incident lands right at the edge of that regulatory transition, arguably a preview of what's at stake for the next bank that gets hit.
A History of Data Security Missteps
This is not the first time banks’ technology has raised a red flag. In 2023, an investigation by The Reporters’ Collective and Al Jazeera discovered that bank employees had inserted the mobile numbers of unauthorised agents (including those belonging to staff and security guards) and other businesses into their customers' profiles to drive enrolment on the bank’s app – BoB World. Several of the bank's customers were later victims of fraud due to the unauthorised association of mobile numbers, and the bank had its own internally reported data issues that later led to the RBI mandating an audit and then prohibiting the bank from onboarding new Bob World users temporarily. Even though the two issues are not related, it serves as context; in the case of banks handling more than $300 billion in their global operations through over 8,400 domestic locations, room for security errors is marginal, and the damage, both public and regulatory, escalates from there on.
What it means for customers
For those who bank with the Bank of Baroda, the common-sense approach is checking statements for any unfamiliar transactions; beware unsolicited calls/messages referencing account details (which typically follow after identity document leaks are being used as a basis for secondary scams); and as a security precaution, change your NetBanking password and app PIN while no core systems of the bank are reported to have been breached; even so, it is advisable to apply. Because Aadhaar, if it has been really compromised, cannot be reset like a password, which is why a compromised identity document is typically of longer-term risk than a stolen password.
Conclusion
The bigger story here isn't just one bank's bad week. It's a reminder that in a system where a single compromised employee inbox can cascade into hundreds of gigabytes of exposed customer data, "our core systems weren't affected" is true and reassuring and, for anyone whose loan documents or ID numbers may now be sitting on a dark web forum, somewhat beside the point.
Sources
- Bank of Baroda confirms cyber incident after hackers claim data theft — The Record (Recorded Future News): https://therecord.media/india-bank-of-baroda-reports-cybersecurity-incident
- Bank of Baroda Data Leak: What We Know So Far — Gulf News: https://gulfnews.com/business/banking/bank-of-baroda-data-leak-what-we-know-so-far-about-alleged-cyber-breach-1.500621898
- Bank of Baroda Breach Tests Disclosure Readiness — GovInfoSecurity (ISMG): https://www.govinfosecurity.com/bank-baroda-breach-tests-disclosure-readiness-a-32335
- India's Bank of Baroda Faces Alleged 1TB Data Leak on Dark Web — Yahoo Finance / India Today Tech: https://finance.yahoo.com/technology/ai/articles/india-bank-baroda-faces-alleged-113047992.html
- Bank of Baroda Data Breach Exposes Customer Records — The Asian Banker: https://www.theasianbanker.com/updates-and-articles/india-s-bank-of-baroda-data-breach-exposes-customer-records-after-employee-email-compromise
- India's Bank of Baroda Expose Worsens: Agents Steal Money From Accounts (2023 background) — Al Jazeera: https://www.aljazeera.com/economy/2023/10/12/indias-bank-of-baroda-expose-worsens-agents-steal-money-from-accounts
- 'Immediate Containment Measures Implemented': Bank of Baroda Issues Clarity on Alleged 1TB Data Leak — Republic World: https://www.republicworld.com/business/immediate-containment-measures-implemented-bank-of-baroda-issues-clarity-on-1tb-data-leak-2026-07-27-133590