#FactCheck-AI-Generated Audio Falsely Added to Dharmendra Pradhan Video to Claim His Resignation as Education Minister
Executive Summary
A video featuring Union Education Minister Dharmendra Pradhan is being widely shared on social media, claiming that he has resigned from his post. In the viral video, Pradhan can be seen addressing a press conference and is allegedly heard saying, “I am resigning from the post of Education Minister due to personal reasons. I thank everyone for this opportunity.” CyberPeace Research Wing’s research found that the claim is misleading. The research revealed that an AI-generated audio clip was added to an old video of Dharmendra Pradhan, falsely attributing a resignation statement to him. The video was digitally altered using a short segment from Pradhan’s press conference held in May 2026 regarding the NEET UG 2026 re-examination.
Claim:
A user on social media platform X, with the username @sumitjaiswal02, shared the viral video on July 25, 2026, claiming that “Dharmendra Pradhan has officially resigned from the post of Education Minister.” In the video, Pradhan is allegedly heard saying, “I am resigning from the post of Education Minister due to personal reasons. I thank everyone for this opportunity.”
The link, archive link and screenshot of the post are provided below
https://x.com/sumitjaiswal02/status/2080947511150448868?s=20

Fact Check:
To verify the viral claim, the Desk conducted an open-source search. During the research, several reports related to Dharmendra Pradhan’s resignation were found on credible news platforms and official sources. However, no authentic video was found on any official platform or verified news outlet showing Pradhan making the resignation statement heard in the viral clip.The research did find his resignation letter, which he shared through his official social media account. However, no official video statement announcing his resignation was available. Dharmendra Pradhan’s X post regarding his resignation can be accessed here:
https://x.com/dpradhanbjp/status/2080938216505667663?s=20

Further research involved extracting key frames from the viral video and conducting a reverse image search using Google Lens. This led the Desk to a video uploaded on Dharmendra Pradhan’s official YouTube channel on May 15, 2026. The video showed Pradhan addressing a press conference regarding the NEET UG 2026 re-examination. The video link and screenshot are provided below:
https://www.youtube.com/watch?v=XkcYnwOAj0M

After analysing the audio of the viral video, the PTI Fact Check Desk extracted the audio track and examined it using the AI audio detection tool Resemble AI. The analysis indicated that the audio used in the viral video was AI-generated and did not contain Dharmendra Pradhan’s original voice or any genuine statement made by him.

Conclusion:
Based on the research, the Desk concluded that the viral video has been digitally altered by adding AI-generated audio to falsely attribute a resignation statement to Union Education Minister Dharmendra Pradhan. The research found that the video uses a short segment from Pradhan’s May 2026 press conference on the NEET UG 2026 re-examination, which was modified by adding a fabricated AI-generated voice. The altered video is being circulated with a misleading claim about his resignation.
Related Blogs
.webp)
Introduction
It might seem too good to be true: free movies, live TV and sports without any subscription plan are deals that no one in India could actually refuse, and that’s precisely the explanation as to why applications such as Pikashow have gained tremendous traction in India and all over the world as well. However, cybersecurity authorities have a strong cause of concern: the threat that this type of application poses towards lakhs of Indians with malicious software, stealing information and even money. Pikashow may be a perfect case study to establish this problem, but in fact, it all ties down to how downloading anything without the recognised applications has certain risks attached to it.
The Pikashow Warning
With no monthly subscription fees, Pikashow is a popular free app for streaming movies, web series, live TV channels and sports programmes. Since its development, Pikashow has had a reputation for never being found on the Google Play Store or Apple’s App Store, which necessitates a process of side-loading. A side load, in this case, entails downloading the Pikashow APK file from an unofficial third-party source and manually installing the app, circumventing the security measures of official download channels.
The latter is significant because security experts who have analysed Pikashow argue that it acts as an informal content aggregator; movies and TV series are illegally scooped up from online streaming services, then shared via various third-party links and streamed without a content licence or any agreement with legitimate providers.
Without going through the rigorous checks conducted by Google or Apple, security researchers discovered that even while the app appeared to be working fine with its promised streams, hidden malware within the installer can run silently, leading to potentially significant security risks such as data theft of user logins, one-time passwords, and private files, including banking credentials. This has been cited to be so problematic for India that law enforcement agencies like the Indian Cyber Crime Coordination Centre under the Ministry of Home Affairs and the Cyber Dost platform are expected to have issued public advisories linking Pikashow to a proliferation of cases of cybercrime. Users should take into account the legal implications alongside security concerns, as using piracy apps may not only lead to device-compromising issues but can also be against the Copyright Act of India as well, thus increasing the risk of legal prosecution.
Why This Isn't Just a "Pikashow Problem"
This should not be viewed as a single warning concerning one app. Pikashow is merely an illustration of one app from millions that exists outside official app stores and is built with the same mechanics that make Pikashow dangerous and applicable to virtually any app, game, or "modded" file which is downloaded from a random website, third-party app store, or Telegram channel.
Some issues that persist are-
- Official app stores are like a filter that is not perfect, but it is still critical to the security on a user's device. Both Google and Apple's App stores run automatic and manual malware scanners, screen permissions for legitimate use, and have the ability to remove malicious developers as necessary. Empirical research has estimated just how important this is: more than fifty-times more malware exists on sideloaded, "unofficial" apps versus official. Mobile security firm Zimperium claims nearly 40% of all devices tested with malware were infected due to downloading an app from outside the official app stores; furthermore, nearly 80% of malicious, sideloaded apps contained riskware or trojans.
- Informational channels can also be used to gain the trust of users by mimicking familiar brands One frequently mentioned scheme is one where malicious actors repackage popular apps with a malignant intent to syphon the app, disguised as a free, trustworthy app. Often when these apps are available, they work exactly the same as the legitimate app, as a matter of fact, but quietly in the background steal passwords or log keystrokes; this was discovered to be occurring with a financial trojan called TeaBot, where bank details and login info were intercepted through the device's Accessibility Service.
- There is generally no recourse or legal liability that applies once something has gone wrong. While official app stores are official developers that can be identified to submit complaints against them, if a third-party download leads to damages, that developer generally cannot be located to establish liability or legal standing.
- Excessive app permissions will often go undetected This occurs for the similar reasons that a malicious actor can include such a clause as explained above. There's really nothing to stop the developer from asking to utilise one's SMS, call log, camera, microphone, storage or location when there's not one reason for one application to need access to everything on the device.
- Expired software has the same or more risk It's actually very common to see apps that receive security updates out in the wild that either don't have the appropriate update sent over to third-party app stores or third-party stores don't have the capacity to update the affected applications. That's why most official third-party app downloads should be of fairly new versions; for example, outdated versions of a banking app, which is being patched as well as receiving other updates from Google or Apple still, will continue to persist on third-party download sites for some time after patching, which could then be malicious.
- Even legitimate, globally recognised apps can and have been compromised The same vulnerability was noted for TikTok in 2023, which, when found on unofficial APK download sites, contained hidden data-tracking malware yet looked identical to the official app version.
How to Protect Yourself
The reassuring thing is that the vast majority of this risk can be eliminated through simple, repeatable habits. Use trusted sources like Google Play and Apple's App Store, which are not faultless, of course, but they remove many infected apps from circulation following review.
- Be sceptical of "free" premium-paid apps.
- If something in a file from a site you don't recognise offers content or features that are normally behind a paywall and they want nothing to do with it, that is a bad sign, not a good deal. Review app permissions when you go to install anything. A flashlight doesn't need access to your SMS messages or contacts, as one recently downloaded on a colleague's Android allegedly attempted to acquire them from the Google Play store. After sideloading any app that you do not fully trust, it's always a wise idea to uninstall it and scan the handset to ensure malicious files aren't still lingering around.
- Choose legitimate services to avoid malware.
- In entertainment terms this will apply most clearly to piracy but applies similarly elsewhere in many senses. Trusted sources that are licensed include YouTube, JioCinema, Hotstar, Netflix, Amazon Prime Video, and MX Player, among others, which will offer content similar to illegally acquired or pirated versions without the security, as well as the legal risks. If you have recently used the file installation route to any degree of caution on a sensitive device, then also monitor banking and payment apps.
- That is not least because the most reported consequence of infection from an illicit or unknown source is the theft of financial account login details.
Conclusion
Free entertainment can look tempting, but as cybersecurity experts keep pointing out, "free" often just means the cost has been shifted from your wallet to your data, your device, and potentially your bank account. The safest rule of thumb remains simple: if an app isn't on an official store, ask why and think twice before installing it.
Sources
- Pikashow app risky, may expose users to malware and data theft: Experts — Times of India
- Free OTT Hack or Cyber Trap? Pikashow Flagged for Serious Security Risks — The420.in
- Pikashow Warning: Free Movies Could Empty Your Bank Account, Government Issues Strong Alert — The420.in
- Is Pikashow Safe or Risky to Use in 2025? Expert's Advice — AiPlex AntiPiracy
- Why Pikashow May Not Be Safe for Your Device — AiPlex AntiPiracy
- Concerns Rise Over the Safety of Popular Streaming App Pikashow — openPR
- Beyond the App Store: The Hidden Risks of Sideloading Apps — Zimperium
- App Sideloading: Risks, Rules, and How IT Admins Respond — Trio
- What Are the Risks of Sideloading Apps on Your Smartphone? — Bitdefender
- Sideloading Risk: Alternative App Stores and Brand Protection — Allure Security
- Building a Trusted Ecosystem for Millions of Apps: A Threat Analysis of Sideloading — Apple

Introduction
There is a particular kind of fraud that security engineers have struggled with for years, precisely because it defeats every technical safeguard by design. It is the social engineering scam, where a caller poses as your bank's department, your tax office, or a relative in trouble, and walks you, step by step, into making a payment or changing your own account details. Two-factor authentication does not stop this. Strong passwords do not stop it. The account holder is doing everything correctly, except they have been persuaded to do the wrong thing by someone skilled at sounding legitimate. With iOS 27 and iPadOS 27, released in September 2026, Apple has built a feature aimed specifically at that gap, called Impersonation Risk Detection.
What the feature actually does
The mechanism is narrower and more specific than it might first sound. Impersonation Risk Detection does not run continuously in the background scanning for scam calls the way a caller ID app might. Instead, it activates only when a supported app, not Apple's own apps necessarily, but any third party app that chooses to integrate it, requests a real time risk assessment at the exact moment a user attempts a sensitive action. Apple's own examples are specific: making a payment, changing a password, or modifying other critical account security information.
At that moment, the operating system runs an on-device analysis built on what Apple calls its Trust Insights framework. It draws on device use patterns, including the approximate number of recent phone calls and emails, Apple Account information such as app download and purchase history, and what Apple describes as interaction patterns, timing, context and basic sensor data. Crucially, Apple has been explicit that the system does not read the contents of Photos, Messages or Mail, and it does not examine the actual point of intrusion, meaning it cannot tell you whether the phone call you are currently on is itself fraudulent. What it is assessing, instead, is whether the pattern of behaviour surrounding this specific sensitive action looks statistically consistent with how a genuine user behaves, or with the pressured, rushed, coached pattern typical of someone being actively scammed.
The output is deliberately minimal. The requesting app receives only one of three labels, unknown, medium or high risk, never the underlying data that produced it. An "unknown" rating means no suspicious signs were detected, though Apple is careful to note this does not confirm the action is actually safe, only that nothing suspicious surfaced. Apple itself never sees the underlying device data used to generate the assessment either, though it does learn what type of action triggered the request in the first place. What the app then does with that risk label, whether to add a waiting period, prompt identity verification, or display an outright warning, is left entirely to the app's own design, not dictated by Apple.
Why the defaults and the fine print matter
Two details in how Apple shipped this feature are worth paying close attention to, because they reveal a lot about the threat model Apple was actually designing against. First, the feature is off by default. Users must manually navigate to Settings, then Privacy & Security, then Impersonation Risk Detection, and toggle on Share with App Developers, often requiring an Apple Account sign-in to activate. Second, and more tellingly, Apple built in a mandatory 24 hour delay before the toggle, once enabled, can actually be switched off. Apple's own guidance states plainly that if someone contacts you and insists you turn this feature off, treat that as a red flag. That is not a generic privacy disclaimer. It is Apple directly anticipating that scammers, once this feature becomes widely known, will start coaching victims to disable it mid-call, and designing a specific friction point to blunt exactly that manipulation.
Apps that have requested an assessment appear under a Recent Activity log, where users can review the specific actions that triggered each request and revoke access app by app, through a section Apple labels Reasons for Access. As of launch, Apple has not published a list of which apps actually support the feature, meaning its real world usefulness depends entirely on third party developers choosing to integrate it, something Apple cannot mandate.
How this compares to what Google has shipped earlier
Apple is not the first to market here, and the framing in early coverage of this feature, "it was just a matter of time," reflects that fairly accurately. Google began rolling out Scam Detection on Pixel phones in beta in late 2024, expanding it through 2025 using its on-device Gemini Nano model to analyse both phone calls and text messages in real time. The approaches differ in a meaningful way, though. Google's feature listens to an entire live conversation for scam-like conversational patterns, playing an audible beep at the start of a monitored call so both parties know AI analysis is active, and can interrupt mid-call with a warning. Apple's feature does not listen to anything resembling the call itself; it evaluates behavioural and account signals around a specific sensitive action a user is about to take, regardless of whether that action was prompted by a phone call, a text, or an email. Google's model is built around catching the scam as it happens in conversation; Apple's is built around catching the moment the user is about to act, irrespective of the channel that pressured them there. Both are opt-in or off by default, and both emphasise on-device processing and limited data sharing, reflecting a shared industry recognition that scam detection tools built on reading private conversations need unusually strong privacy guarantees to earn user trust.
Why this matters well beyond the US
Google has already signalled that it sees markets like India as a genuine proving ground for this category of tool, having launched Pixel-based scam detection there in November 2025 specifically citing the scale of digital fraud losses in the country, alongside partnerships with Indian financial apps including Google Pay, Paytm and Navi to warn users during risky screen-sharing sessions, a common vector in Indian banking fraud. That context matters for Apple's rollout too. Social engineering scams impersonating banks, government tax departments and law enforcement are a dominant and rapidly growing fraud category across much of Asia, and a feature that specifically targets the moment someone is being walked through a fraudulent payment, rather than relying on the victim recognising the scam themselves, addresses exactly the mechanism that most existing fraud prevention tools miss.
The honest limitation
Apple has been careful, in its own language, to frame this as a supplementary safeguard rather than a complete solution to telecom and online fraud, and that caution lines up with what the broader behavioural analytics industry has already learned the hard way. The feature depends entirely on third party app adoption that has not yet been detailed, it is switched off by default so most users will never encounter it without deliberately enabling it, and an "unknown" risk rating explicitly does not mean an action is safe, only that nothing suspicious happened to surface.
The deeper issue is one every company working on behavioural fraud detection has run into before Apple did: these systems are only as reliable as the baseline of "normal" behaviour they are measuring against, and that baseline is not stable across every type of user. Industry data on behavioural biometrics, the broader category of technology Apple's system belongs to, puts typical false positive rates for flagging new device, location, or timing combinations in the range of 15 to 25 percent before careful tuning, and practitioners in the field note that elderly users in particular tend to show higher variance in their interaction patterns, which makes them statistically harder for these models to read correctly, not easier, despite being exactly the population most targeted by impersonation scams in the first place. The risk is not hypothetical or confined to finance. In eldercare technology more broadly, a documented case from a California pilot programme saw a fall detection system switched off entirely after it generated so many false alarms that it triggered repeated, unwanted social service visits to an older adult's home, a clear illustration of what happens when a protective automated system cannot adequately account for the exact population it was built to protect.
Apple has not published performance data on how Impersonation Risk Detection behaves across these edge cases, new phones, irregular usage patterns, older users less familiar with typical app behaviour, and that silence is worth noting rather than assuming away. What Impersonation Risk Detection represents is not a solved problem, but a genuine, technically serious first attempt by a major platform to intervene at the exact moment social engineering scams succeed, the point of action, rather than relying on users to have correctly identified the deception several steps earlier. Whether it meaningfully reduces fraud losses at scale will depend less on the underlying design, which appears carefully thought through, and more on two things outside Apple's direct control: how many developers actually build it into the apps people use for banking and account security, and how well the system holds up for exactly the users who need it most.
References
- Help Net Security, "Apple's new iOS 27 feature looks for signs you're being scammed." https://www.helpnetsecurity.com/2026/09/24/apple-ios-27-impersonation-risk-detection/
- 9to5Mac, "iOS 27 adds scam-prevention feature to iPhone, here's how to enable it." https://9to5mac.com/2026/09/16/ios-27-adds-scam-prevention-feature-to-iphone-heres-how-to-enable-it/
- 9to5Mac, "Security Bite: iOS 27 now lets apps ask your iPhone if you're being scammed." https://9to5mac.com/2026/09/21/security-bite-ios-27-now-lets-apps-ask-your-iphone-if-youre-being-scammed/
- Engadget, "Apple's new iPhone and iPad security feature can protect you from scammers." https://www.engadget.com/2271157/apple-iphone-ipad-impersonator-risk-detection-new-security-feature/
- gHacks Tech News, "iOS 27 Adds Impersonation Risk Detection to Help Protect Against Social Engineering Scams." https://www.ghacks.net/2026/09/21/ios-27-adds-impersonation-risk-detection-to-help-protect-against-social-engineering-scams/
- BigGo Finance, "Apple Rolls Out On-Device Scam Detection in iOS 27 Ahead of High-Risk Transactions." https://finance.biggo.com/news/89a0ae92-1603-4ac9-aef9-b8b466e6ac40
- MacObserver, "iOS 27 Impersonation Risk Detection: How Apple's anti-scam setting works." https://www.macobserver.com/news/ios-27-impersonation-risk-detection-anti-scam-setting/
- Google Blog, "New AI-Powered Scam Detection Features to Help Protect You on Android." https://blog.google/security/new-ai-powered-scam-detection-features/
- Digital Trends, "Google Pixel 9 is getting a scam detection upgrade you'll want on your phone." https://www.digitaltrends.com/phones/google-pixel-scam-detection-gemini-nano-ai-calls-messages-safety/
- Gulf News, "Google ramps up AI scam protection in India." https://gulfnews.com/technology/media/google-ramps-up-ai-scam-protection-in-india-1.500355149

Executive Summary:
Recently, we came upon some AI-generated deep fake videos that have gone viral on social media, purporting to show Indian political figures Prime Minister Narendra Modi, Home Minister Amit Shah, and External Affairs Minister Dr. S. Jaishankar apologizing in public for initiating "Operation Sindoor." The videos are fake and use artificial intelligence tools to mimic the leaders' voices and appearances, as concluded by our research. The purpose of this report is to provide a clear understanding of the facts and to reveal the truth behind these viral videos.
Claim:
Multiple videos circulating on social media claim to show Prime Minister Narendra Modi, Central Home Minister Amit Shah, and External Affairs Minister Dr. S. Jaishankar publicly apologised for launching "Operation Sindoor." The videos, which are being circulated to suggest a political and diplomatic failure, feature the leaders speaking passionately and expressing regret over the operation.



Fact Check:
Our research revealed that the widely shared videos were deepfakes made with artificial intelligence tools. Following the 22 April 2025 Pahalgam terror attack, after “Operation Sindoor”, which was held by the Indian Armed Forces, this video emerged, intending to spread false propaganda and misinformation.
Finding important frames and visual clues from the videos that seemed suspicious, such as strange lip movements, misaligned audio, and facial distortions, was the first step in the fact-checking process. By putting audio samples and video frames in Hive AI Content Moderation, a program for detecting AI-generated content. After examining audio, facial, and visual cues, Hive's deepfake detection system verified that all three of the videos were artificial intelligence (AI) produced.
Below are three Hive Moderator result screenshots that clearly flag the videos as synthetic content, confirming that none of them are authentic or released by any official government source.



Conclusion:
The artificial intelligence-generated videos that claim Prime Minister Narendra Modi, Home Minister Amit Shah, and External Affairs Minister Dr. S. Jaishankar apologized for the start of "Operation Sindoor" are completely untrue. A purposeful disinformation campaign to mislead the public and incite political unrest includes these deepfake videos. No such apology has been made by the Indian government, and the operation in question does not exist in any official or verified capacity. The public must exercise caution, avoid disseminating videos that have not been verified, and rely on reliable fact-checking websites. Such disinformation can seriously affect national discourse and security in addition to eroding public trust.
- Claim: India's top executives apologize publicly for Operation Sindoor blunder.
- Claimed On: Social Media
- Fact Check: AI Misleads