#FactCheck- AI-Generated Video of Alleged Iranian Attack on US Helicopter Goes Viral with False Claims
Executive Summary
A video is being widely shared on social media showing armed personnel attacking a helicopter. The video is being circulated with the claim that Iranian soldiers shot down a US military helicopter near the Strait of Hormuz amid rising tensions between the United States and Iran. CyberPeace Research Wing research found the claim to be false. The viral video is AI-generated and is being shared with misleading context.
Claim:
An X (formerly Twitter) user shared the video on June 10, 2026, with the caption: “This is great cinema. Breaking News: Iran used a $150 weapon to bring down a $1 billion US military aircraft. For the first time, America has met its real enemy.”
Post link and archive link can be seen below:
https://x.com/TheIncNews/status/2064758088012607544?s=20
https://archive.ph/LUDUz

Fact-Check
To verify the claim, we conducted a keyword search on Google. However, no credible media reports were found supporting this claim.

On closely examining the video, we suspected it to be AI-generated. We then analyzed it using the AI detection tool HIVE MODERATION. The results indicated that the video is 98% likely to be AI-generated.

In the next step, we further analyzed the video using another AI detection tool, SIGHTENGINE. The results showed a 99% probability of the video being AI-generated.

Conclusion:
Our research confirms that the viral video is AI-generated and does not depict any real-world incident. The content is being circulated with a misleading and false narrative, falsely linking it to ongoing geopolitical tensions, despite there being no credible evidence or verified reports supporting such a claim.
Related Blogs

Introduction
On August 8, 2026, Hyderabad Police Commissioner V.C. Sajjanar posted an unusual warning on X: colourful posters offering a "handsome guy" to join you for coffee or a movie at 50% off: it was not a quirky dating startup but a calculated cyber fraud. Within hours, the "Rent Boyfriend" alert had gone viral, pulling back the curtain on a scam that blends India's growing loneliness economy, classic confidence tricks, and AI-generated imagery. Here is what's actually happening, why it works, and how to protect yourself.
A Trend Growing Fast: In India and Worldwide
Paid-companionship culture itself isn't new. "Rent a friend" services began in Japan and later China, where apps let people hire a company for a movie, a walk, or a family event without romantic or sexual expectations. The idea reached India as early as 2018, when Mumbai's "Rent A Guy" app began recruiting men for casual outings; by 2022, similar pages like "Toy Boy" and "Hire a Friend" had spread to Bengaluru, and Valentine's Day 2025 saw ₹389 "rent a boyfriend" posters plastered across the city. Fraudsters have now hijacked this recognisable, socially normalised idea and weaponised it: the Hyderabad ads promised specific packages, ₹499 for a coffee date, ₹1,249 for a movie, ₹1,999 for a wedding, and ₹4,499 for ten hours collected via QR codes and wallets, then vanished. The underlying numbers show why this template is so attractive to criminals. Complaints filed on India's National Cyber Crime Reporting Portal jumped from roughly 4.5 lakh in 2021 to about 2.3 million by 2026, and the country now logs an estimated 4,000-plus cybercrime complaints a day. Globally, romance and "confidence fraud" are some of the costliest online crimes: the FBI's Internet Crime Complaint Center recorded 23,159 romance-fraud complaints in 2025 worth $929.3 million, which is a 38% jump over 2024, while the UK logged over £102 million in losses and Australia and Canada reported tens of millions more. Crucially, IC3's 2025 report flagged AI as an accelerant for the first time, attributing roughly $19 million in romance-scam losses directly to AI-generated profiles, images and chat exactly the "AI-generated photographs" Hyderabad Police say the Rent Boyfriend network used.
Case Studies
The Rent Boyfriend network is one data point in a wider, well-documented pattern in India:
- Hyderabad, August 2026: Fraudsters ran Instagram, Telegram and Facebook pages using stock or AI-generated photos of "attractive men", collected advance payments and security deposits, and then blocked victims, the case that prompted this advisory.
- Jaipur, 2026: A honey-trap and extortion ring allegedly used AI-manipulated videos and images to blackmail a businessman out of nearly ₹90 lakh, with police examining how far synthetic media was used to fabricate compromising content.
- Mumbai: A gang was arrested for cheating a woman out of ₹16.18 lakh in gold and cash after promising to "reunite" her with a lost partner, a variant that exploits the same emotional vulnerability through a different pretext.
- Gujarat, 2025: A social media influencer with over 10 lakh followers was arrested for allegedly honey-trapping and blackmailing a builder, illustrating how organised such rackets have become.
These sit alongside a global backdrop where FBI data shows confidence and romance fraud disproportionately drains people over 60 (63% of US losses in 2025) even as India's version increasingly targets young women and students, a sign the tactic is being localised for different demographics rather than disappearing.
Why It Works: The Psychology of Loneliness and Grooming
Researchers who study romance-fraud victims consistently find that loneliness, a tendency toward idealised romantic beliefs, and a need for social connection are the strongest predictors of victimisation. Scammers exploit this through a well-rehearsed grooming arc: rapid, excessive flattery ("love bombing") to create instant intimacy; mirroring the target's interests and values to seem like a perfect match; gently discouraging outside opinions so doubts don't surface; and only then introducing a financial ask, framed as something small and reasonable — a booking fee or a security deposit precisely because it feels low-stakes compared to a direct cash demand. The "package" pricing in the Rent Boyfriend ads (₹499 for coffee, scaling up to ₹4,499) mimics legitimate e-commerce, which lowers a target's guard further. Once payment is made and blocked, many victims feel too embarrassed to report it — a shame response researchers and police repeatedly flag as the biggest reason such scams are under-reported.
Red Flags and What To Do?
Red flags to watch for:
- Companionship or dating offers with attractive stock/AI-style photos and steep "discounts"
- Contact only through DMs, with no verifiable business identity, address or reviews.
- Requests for advance payment, "security deposits", or booking fees via UPI/QR code before any service is delivered.
- Reluctance to do a video call or a video call that looks slightly off (a common AI/deepfake tell).
- Pressure to move fast, share personal photos, or keep the interaction secret from friends and family.
Precautions:
- Never send money to confirm a booking with an unverified individual or page.
- Avoid sharing personal photographs, phone numbers, addresses or financial details with strangers online.
- Don't meet anyone in person whom you've only interacted with through such ads.
- Parents should stay engaged with what their children see and who they talk to on social media.
If you suspect a scam or have lost money: Don't panic and don't pay more to "fix" it. Stop all contact, save screenshots and payment records, and call the 1930 cybercrime helpline or file a complaint at cybercrime.gov.in immediately — reporting within the first "golden hour" significantly improves the chance of freezing transferred funds before they're withdrawn.
The Government, Platform and Legal Angle
India already has legal tools for this, though enforcement lags the pace of the fraud. Cheating by personation online is punishable under Section 66D of the IT Act, 2000 (up to three years' imprisonment plus fine), often paired with Section 66C on identity theft; the Bharatiya Nyaya Sanhita's cheating provisions (replacing IPC Sections 420/419) apply where money is dishonestly induced. Under the IT (Intermediary Guidelines) Rules, 2021, platforms like Instagram, Facebook and Telegram must appoint a grievance officer, acknowledge complaints within 24 hours, and take down unlawful content within 36 hours of a court or government notification obligation. Hyderabad's cybercrime wing can invoke to force the removal of these ad networks. Larger "significant social media intermediaries" carry added duties around traceability and proactive monitoring.
The gap is upstream: platforms currently do little to verify who is running a commercial-sounding page before it reaches thousands of users, and AI-generated "profile" images are not systematically flagged. A stronger response would combine faster platform-side KYC for pages soliciting payment, proactive detection of AI-generated advertising imagery, and continued expansion of the 1930 golden-hour fund-freezing mechanism paired with public advisories like Hyderabad's, which remain one of the fastest ways to blunt a scam before it scales.
Conclusion
Loneliness is not something anyone should be ashamed of, but it is exactly what these networks are built to exploit. No genuine companionship service needs an advance QR payment before you've even met the person.
Sources
- Deccan Herald — Hyderabad Police Commissioner cautions young women over 'rent boyfriend' offers
- Republic World — 'Rent Boyfriend' Offers On Social Media?
- Newsdrum — What is 'Rent Boyfriend' trap?
- IndiaSpend — How India's Cyber Crime Incidence Is Rising
- FBI IC3 2025 Annual Report Brochure

Introduction
In today’s digital environment, national security challenges extend well beyond traditional military domains. One growing concern is the unauthorised extraction of information, which is increasingly being used through subtle and gradual methods rather than overt force. Recent advisories point to a rising pattern in which foreign organisations seek to recruit individuals to collect and handle sensitive material, often using financial cybercrime networks as part of their operational ecosystem. This trend has implications for journalists, defence personnel, researchers, students, and academics working in strategic, geopolitical, and security-related fields. The core risk lies in the fact that these activities can proceed quietly and without coercion, with participants sometimes unaware that their actions may contribute to intelligence gathering efforts.
Digital Platforms as Vectors for Targeted Recruitment
Professional networking and job portals have become central to modern career development. The same visibility that supports professional advancement is being misused by others. Foreign entities reportedly use these platforms to identify individuals with experience in journalism, defence services, strategic studies, cybersecurity, and international relations.
Early-career professionals and students from reputed Higher Education Institutions (HEIs) are particularly vulnerable because they seek freelance work, research experience and international partnerships. Initial outreach is often framed as legitimate consultancy, research assistance, or content development work, which creates the impression of professional credibility through normal business operations.
Task-Based Information Extraction
The organisation assigns writing and research duties to new employees, which seem simple to perform. The topics of source-based articles and analytical pieces include the following two subjects about India.
- The first subject examines India's foreign relations with its strategic partnerships.
- The second subject investigates how armed forces operate through different military movements.
- The third subject focuses on defence procurement activities, which include weapon system development and modernisation projects.
- The fourth subject investigates military activities through joint training exercises and war simulation exercises.
The public possesses most of this knowledge, but its threat emerges from the process of collecting and interpreting data with contextual information. The collection of insights from various sources enables organisations to identify operational patterns, strategic priorities and capacity evaluations which go beyond particular data points.
The Financial Cybercrime Nexus
The financial system that pays contributors presents itself as a major problem for this activity. Payments are often routed through:
- Indian bank accounts, including student accounts
- Funds originating from cyber fraud or financial crimes
- Occasional overseas transfers structured to avoid scrutiny
The system establishes a direct connection between financial cybercrime activities and the theft of confidential information, which brings unintentional danger of legal issues and public image damage to those involved. The Indian legal system considers all connections to illegal financial activities as serious offenses even when the person involved did not intend to commit any crime.
Concealed Identities and Data Harvesting
The entities that conduct recruitment activities willfully hide their real identities. The organisation uses intermediaries for their operations, which they present as foreign consulting firms, think tanks and analytics companies. Contributors who have defence or security experience will face requests to provide their personal data, which includes their PAN and Aadhaar information.
The collection of such data raises significant concerns. The system creates permanent privacy hazards that permit unauthorised access to personal data and identity theft and coercive practices. The ultimate use of this information often remains opaque to the individuals providing it.
Why Incremental Leakage Matters
The threat operates silently because it lacks the visibility of major cyberattacks. The combined effect of all articles and research notes becomes dangerous because no single element can cause harm. Hostile organisations can use incremental information leakage to undermine national security because they can analyse their gathered data to create:
- maps of strategic capabilities,
- defence readiness evaluations,
- security and foreign policy narrative control.
The process of information sovereignty erosion occurs through the establishment of undefined boundaries between journalism and academic research, and consultancy and strategic analysis. The lack of clear boundaries between journalism and academic research, consultancy and strategic analysis makes it difficult to determine who is responsible for research outcomes.
The Role of Institutions and Individuals
The universities and media outlets, together with the professional organizations have essential functions in their quest to diminish environmental effects. The organisation should perform the following proactive steps:
- The organisation should organise training programs which will educate people about its services.
- The organisation should require researchers to conduct thorough investigations before they accept paid assignments for research work and writing tasks.
- The organisation should recommend that people do not share their identity documents except when their institution requires it for authentication purposes.
- The organisation should create specific methods to report any suspicious activities that people might encounter.
Students and professionals need to understand that their specialised knowledge and trustworthiness can be used against them. People must protect their digital identities through three actions, which include verifying their affiliations and assessing the complete effects of their daily activities.
Conclusion
Cyber enabled threats to national security increasingly operate in grey zones, which makes their legality, legitimacy, and true intent difficult to assess. The convergence of foreign recruitment efforts, financial cybercrime, and covert information gathering creates a persistent risk that is still not widely recognised or fully understood. The state does not bear exclusive responsibility for protecting sensitive information. National resilience in an interconnected knowledge economy requires organisations to develop three core capacities, which include institutional awareness and restraint and institutional vigilance. Cyber resilience depends on two essential factors, which include secure systems and informed citizens, because data continues to determine power relationships.
References
- https://reports.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2025.pdf
- https://www.cyber-espionage.ch/
- https://www.theguardian.com/world/2025/nov/18/mi5-issues-alert-to-mps-and-peers-over-chinese-espionage
- http://cybercrimejournal.com/menuscript/index.php/cybercrimejournal/article/download/263/92
- https://www.researchgate.net/publication/368461675_Cyber_Espionage_Consequences_as_a_Growing_Threat

A video circulating widely on social media claims to show former US President Donald Trump issuing a threat to India over its relationship with Russia. In the clip, Trump is allegedly heard warning New Delhi that if it does not cut bilateral ties with Moscow, the United States would “treat India the same way Pakistan did during the May war.”
The reference to the “May war” appears to point to the India-Pakistan military escalation in May 2025, which followed the Pahalgam terror attack and India’s retaliatory strikes under Operation Sindoor targeting terror infrastructure.
However, research done by the Cyber Peace Foundation has found that the video is misleading and digitally manipulated.
The visuals used in the viral clip are genuine and were taken from a press briefing addressed by Donald Trump on January 3, 2026. However, the audio track accompanying the video has been fabricated and falsely superimposed to
misrepresent his remarks. In the original address, Trump was speaking about a US-led military operation in Caracas that reportedly resulted in the capture of Venezuelan President Nicolás Maduro and his wife. He made no reference to India, Russia, or any geopolitical warning involving New Delhi.
Claim:
On January 10, an X (formerly Twitter) user, Niki Chiri (@cutehunmee), shared a video claiming it showed Donald Trump threatening India over its ties with Russia.
In the clip, Trump is purportedly heard stating that unless India severed its relationship with Moscow, the United States would respond in a manner similar to Pakistan’s actions during the May conflict.
The post quickly gained traction, with several users amplifying the claim. Iink,archive link and screenshot
Research:
To verify the authenticity of the video, the Cyber Peace Foundation conducted a reverse image and video analysis. A Google Lens search led investigators to a longer version of the same footage uploaded on the official YouTube channel of The Wall Street Journal, a prominent US-based news outlet.
A comparison confirmed that both videos shared identical visuals, background elements, and camera angles, establishing that the viral clip was sourced from the same press address.
A review of the full speech, however, showed that Trump did not issue any warning to India, nor did he mention Russia or the May conflict. His remarks were strictly focused on developments in Venezuela.
This confirmed that the viral video had been digitally altered. Here is the link to the original video, along with a screenshot:

In the next phase of the research, the audio track from the viral clip was extracted and analysed using the AI-based voice detection tool Aurigin. The results indicated a high likelihood that the voice in the video was artificially generated, further confirming that the audio did not originate from Trump’s original speech. A screenshot of the result is provided below.

Conclusion
The claim that a video shows Donald Trump threatening India over its ties with Russia is false. The Cyber Peace Foundation found that while the visuals were taken from a real press address, the audio was fabricated and overlaid to falsely attribute threatening statements to Trump. The manipulated video was circulated online to mislead viewers and spread disinformation.