#FactCheck: AI Generated audio of CDS admitting that Pakistan Army is superior than Indian Army.
Executive Summary:
A viral social media claim alleges that India’s Chief of Defence Staff (CDS), General Anil Chauhan, praised Pakistan’s Army as superior during “Operation Sindoor.” Fact-checking confirms the claim is false. The original video, available on The Hindu’s official channel, shows General Chauhan inaugurating Ran-Samwad 2025 in Mhow, Madhya Pradesh. At the 1:22:12 mark, the genuine segment appears, proving the viral clip was altered. Additionally, analysis using Hiya AI Audio identified voice manipulation, flagging the segment as a deepfake with an authenticity score of 1/100. The fabricated statement was: “never mess with Pakistan because their army appears to be far more superior.” Thus, the viral video is doctored and misleading.
Claim:
A viral claim is being shared on social media (archived link) falsely claiming that India’s Chief of Defence Staff (CDS), General Anil Chauhan described Pakistan’s Army as superior and more advanced during Operation Sindoor.

Fact Check:
After performing a reverse image search we found a full clip on the official channel of The Hindu in which Chief of Defence Staff Anil Chauhan inaugurated ‘Ran-Samwad’ 2025 in Mhow, Madhya Pradesh.

In the clip on the time stamp of 1:22:12 we can see the actual part of the video segment which was manipulated in the viral video.
Also, by using Hiya AI Audio tool we got to know that the voice was manipulated in the specific segment of the video. The result shows Deepfake with an authenticity score 1/100, the result also shows the statement which is deepfake which was “ was to never mess with Pakistan because their army appears to be far more superior”.

Conclusion:
The viral video attributing remarks to CDS General Anil Chauhan about Pakistan’s Army being “superior” is fabricated. The original footage from The Hindu confirms no such statement was made, while forensic analysis using Hiya AI Audio detected clear voice manipulation, identifying the clip as a deepfake with minimal authenticity. Hence, the claim is baseless, misleading, and an attempt to spread disinformation.
- Claim: AI Generated audio of CDS admitting that the Pakistan Army is superior to the Indian Army.
- Claimed On: Social Media
- Fact Check: False and Misleading
Related Blogs
.webp)
Executive Summary:
In the end of January 2024, India sees an inauguration of Ram Mandir that is a historical event to which people came culturally and spiritually. All communities in the world acknowledge this point of life as a victory and also understand how it unites people. In the midst of this genuine joy over success, there has been a disconcerting increase in malpractices designed to exploit people’s enthusiasm. This report aims at providing awareness and guidelines on how one can avoid the fraud activities that could be circulating as a celebration of Ram Mandir inauguration. An example cited here is on scams that give fake free recharge to users making them connect with the Prime Minister of India and UP Chief Minister Yogi Adityanath.
False Claim:
According to the message passed in WhatsApp, as a commemoration of the inauguration of Ram Mandir in Ayodhya in January 2024, free Rs.749 mobile recharge for three months would be offered to all Indians across India by both the PM and UP CM. The message prompts the recipients to click on the blue link provided and then recharge their numbers.
The Deceptive Scheme:
We have been informed of a circulating link (https://mahacashhback[.]in/#1705296887543) stating that it offers ₹719 recharge in honor of the Ram Mandir inauguration. It is worth mentioning that this link does not belong to any legitimate movement concerning the inauguration; public excitement and trust were used for personal gain.
Analyzing the Fraudulent Campaign:
- Exploiting Emotional Significance:Scammers are using the cultural and religious significance of Ram mandir inauguration as a cover to fool people into participating in its fraudulent scheme.
- Fake Recharge Offers:The broadcasted link is offering a recharge pretending that they celebrate it’s inauguration. Such offers should be handled with care and established through authorized avenues.
- Bogus Landing Pages and Comments:The landing page linked to the link typically shows images of Ram Mandir and fake comments succeeding in a make-believe appearance. Legitimate projects linked to major events rely on official and trustworthy communication mechanisms.
- Data Collection Attempts:However, users may be asked for personal details like mobile numbers under the false pretext of winning a fake recharge. Legitimate organizations practice secure protocols for data collection and communication.
- Sharing for Activation:After the data entry, users are prompted to share a link in other people’s posts; it is said that this will help “activate” recharge. This is a popular trick among swindlers to keep the fraud going on due to sending misleading messages.
What do we Analyze?
- It is important to note that at this particular point, there has not been any official declaration or a proper confirmation of such offers on any official channel.
- The campaign is hosted on a third party domain instead of any official Government Website, this raised suspicion. Also the domain has been registered in very recent times.

- Domain Name: mahacashhback[.]in
- Registry Domain ID: D1FCF1B5751244310A2FA723B62CE83E9-IN
- Registrar URL: https://publicdomainregistry[.]com/
- Registrar: Endurance Digital Domain Technology LLP
- Registrar IANA ID: 801217
- Updated Date: 2024-01-18T08:09:00Z
- Creation Date: 2023-05-27T12:01:17Z
- Registry Expiry Date: 2024-05-27T12:01:17Z
- Registrant Organization: Sachin Kumar
- Registrant State/Province: Bihar
- Name Server: ns2.suspended-domain[.]com
- Name Server: ns1.suspended-domain[.]com
CyberPeace Advisory and Best Practices:
- Verify Authenticity:Authenticate any offers or promotions linked to the Ram Mandir inauguration through official channels.
- Exercise Caution with Links:Do not engage with questionable URLs, in particular those without secure encryption (HTTPS). Official announcements and initiatives are disseminated through secure outlets.
- Protect Personal Information:Do not provide personal information and do not respond to unsolicited offers on nonofficial platforms. Genuine organizations employ safe and official routes for communication.
- Report Fraudulent Activity:When you see scams or fraudulent activities, immediately report them to authorities and platforms so that no one falls into their trap.
Conclusion:
In the coming days, let us be cautious from such cheating strategies which would be misutilized or create false situations. Individuals should stay informed, verify sources and defend their personal information to ensure a safer world wide web. Official and secure channels are used to communicate authentic initiatives linked with notable events. When an offer sounds too favorable or attractive, exercise due caution and check its genuineness to avoid being defrauded. Thus by undertaking the research we found this campaign to be fake.

Introduction
The Digital Personal Data Protection (DPDP) Act 2023 of India is a significant transition for privacy legislation in this age of digital data. A key element of this new law is a requirement for organisations to have appropriate, user-friendly consent mechanisms in place for their customers so that collection, use or removal of an individual's personal data occurs in a clear and compliant manner. As a means of putting this requirement into practice, the Ministry of Electronics and Information Technology (MeitY) issued a comprehensive Business Requirements Document (BRD) in June 2025 to guide organizations, as well as Consent Managers, on how to create a Consent Management System (CMS). This document establishes the technical and functional framework by which organizations and individuals (Data Principals) will exercise control over the way their data is gathered, used and removed.
Understanding the BRD and Its Purpose
BRD represents an optional guide created as part of the "Code for Consent" programme run by MeitY in India. The purpose of the BRD is to provide guidance to startups, digital platforms and other enterprises on how to create a technology system that supports management of user consent per the requirements of the DPDP Act. Although the contents of the BRD do not carry any legal weight, it lays out a clear path for organisations to create their own consent mechanisms using best practices that align with the principles of transparency, accountability and purpose limitation in the DPDP Act.
The goal is threefold:
- Enable complete consent lifecycle management from collection to withdrawal.
- Empower individuals to manage their consents actively and transparently.
- Support data fiduciaries and processors with an interoperable system that ensures compliance.
Key Components of the Consent Management System
The BRD proposes the development of a modular Consent Management System (CMS) that provides users with secure APIs and user-friendly interfaces. This system will allow for a variety of features and modules, including:
- Consent Lifecycle Management – consent should be specific, informed and tied to an explicit purpose. The CMS will manage the collection, validation, renewal, updates and withdrawal of consent. Each transaction of consent will create a tamper-proof “consent artifact,” which will include the timestamp of creation as well as an ID identifying the purpose for which it was given.
- User Dashboard – A user will be able to view and modify the status of their active, expired or withdrawn consent and revoke access at any time via the multilingual user-friendly interface. This would make the system accessible to people from different regions and cultures.
- Notification Engine – The CMS will automatically notify users, fiduciaries and processors of any action taken with respect to consent, in order to ensure real-time updates and accountability.
- Grievance Redress Mechanism – The CMS will include a complaints mechanism that allows users to submit complaints related to the misuse of consent or the denial of their rights. This will enable tracking of the complaint resolution status, and will allow for escalation if necessary.
- Audit and Logging – As part of the CMS's internal controls for compliance and regulatory purposes, the CMS must maintain an immutable record of every instance of consent for auditing and regulatory review. The records must be encrypted, time-stamped, and linked permanently to a user and purpose ID.
- Cookie Consent Management – A separate module will enable users to manage cookie consent for websites separately from any other consents.
Roles and Responsibilities
The BRD identifies the various stakeholders involved and their associated responsibilities.
- Data Principals (Users): The user has full authority to give, withhold, amend, or revoke their consent for the use of their personal data, at any time.
- Data Fiduciaries (Companies): Companies (the fiduciaries) must collect the data principals' consents for each particular reason and must only begin processing a data subject's personal data after validating that consent through the CMS. Companies must also provide the data principals with any information or notifications needed, as well as how to resolve their complaints.
- Data Processors: Data Processors must strictly adhere to the consent stated in the CMS, and Data Processors may only process personal data on behalf of the Data Fiduciary.
- Consent Managers: The Consent Managers are independent entities that are registered with the Data Protection Board. They are responsible for administering the CMS, allowing users to manage their consent across different platforms.
This layered structure ensures transparency and shared responsibility for the consent ecosystem.
Technical Specifications and Security
The following principles of the DPDP Act must be followed to remain compliant with the DPDP Act.
- End-to-End Encryption: All exchanges of data with users must be encrypted using a minimum of TSL 1.3 and also encrypting within that standard.
- API-First Approach: API’s will be utilized to validate, withdraw and update consent in a secured manner using external sources.
- Interoperability/Accessibility: The CMS needs to allow for users to utilize several different languages (e.g. Hindi, Tamil, etc.) and be appropriate for use with various types of mobile devices and different abilities.
- Data Retention Policy: The CMS should also include automatic deletion of consent data (when the consent has expired or has been withdrawn) in order to maintain compliance with data retention limits.
Legal Relevance and Timelines
While the BRD itself is not enforceable, it is directly aligned with the upcoming enforcement of the DPDP Act, 2023. The Act was passed in August 2023 but is expected to come into effect in stages, once officially notified by the central government. Draft implementation rules, including those defining the role of Consent Managers, were released for public consultation in early 2025.
For businesses, the BRD serves as an early compliance tool—offering both a conceptual roadmap and technical framework to prepare before the law is enforced. Legal experts have described it as a critical resource for aligning data governance systems with emerging regulatory expectations.
Implications for Businesses
Organizations that collect and process user data will be required to overhaul their consent workflows:
- No blanket consents: Every data processing activity must have explicit, separate consent.
- Granular audit logs: Companies must maintain tamper-proof logs for every consent action.
- Integration readiness: Enterprises need to integrate their platforms with third-party or in-house CMS platforms via the specified APIs.
- Grievance redress and user support: Systems must be in place to handle complaints and withdrawal requests in a timely, verifiable manner.
Failing to comply once the DPDP Act is in force may expose companies to penalties, reputational damage, and potential regulatory action.
Conclusion
The BRD on Consent Management of India is a forward-looking initiative laying a technological framework that is an essential component of the DPDP Act concerning user consent; Although not yet a legal document, it provides an extent of going into all the necessary discipline for companies to prepare. As data protection grows in importance, developing consent mechanisms based on security, transparency, and the needs of the user is no longer just a regulatory requirement, but rather a requirement for the development of trust. This is the time for businesses to establish or implement CMS solutions that support this objective to be better equipped for the future of data governance in India.
References
- https://d38ibwa0xdgwxx.cloudfront.net/whatsnew-docs/8d5409f5-d26c-4697-b10e-5f6fb2d583ef.pdf
- https://ssrana.in/articles/ministry-releases-business-requirement-document-for-consent-management-under-the-dpdp-act-2023/
- https://dpo-india.com/Blogs/consent-dpdpa/
- https://corporate.cyrilamarchandblogs.com/2025/06/the-ghost-in-the-machine-the-recent-business-requirement-document-on-consent/
- https://www.mondaq.com/india/privacy-protection/1660964/analysis-of-the-business-requirement-document-for-consent-management-system

On 12 August 2026, President Donald Trump signed a National Security Presidential Memorandum titled Expanding Capabilities to Combat Transnational Cyber Enabled Crime. Stripped of its bureaucratic packaging, the document does something American law has resisted for three decades: it lets private companies, under close federal supervision, break into the systems of foreign criminal networks and, in some cases, disrupt or damage them.
That is a genuinely large policy shift, even if the memorandum itself is careful, almost defensive, about how it frames the shift. Understanding why requires separating what the text actually authorizes from the "hack back" headline that has attached itself to the story within days of signing.
The problem the memo says it is solving
The White House frames this as a response to scale, not ideology. Americans reported losing more than 20.8 billion dollars to cyber enabled crime in 2025, a sharp jump from the roughly 12.5 billion dollar figure cited when the administration's earlier March 2026 executive order on cybercrime, fraud, and predatory schemes was signed. Ransomware, phishing, financial fraud, sextortion, and impersonation scams sit at the center of that number, and the administration's own supporting material points to a grim detail buried in the numbers: one in seven young people who experienced sextortion as a minor reported harming themselves as a result.
Those crimes, the memorandum argues, are increasingly the work of organized, transnational groups operating from jurisdictions the FBI simply cannot reach. Domestic law enforcement, built for domestic crime, is structurally mismatched to a threat that lives across borders and inside encrypted infrastructure. The administration's answer is to formally recruit the resource it says is best positioned to close that gap: the American cybersecurity industry itself, which the memo describes as "the most innovative and technologically advanced in the world."
What the Program actually authorizes
The memorandum directs the National Coordination Center, a body first stood up under a 2025 executive order, to build a formal Program through which vetted Participating Companies can conduct two categories of activity against foreign Cyber Enabled Transnational Criminal Organizations, defined in the text as CE TCOs.
Cyber Surveillance Operations cover unauthorized access to a target's systems for the primary purpose of collecting information or intelligence, undertaken with the intent to remain undetected. Cyber Effects Operations go further: manipulating, disrupting, denying, degrading, or destroying information systems, the infrastructure those systems control, or the data resident on them.
Crucially, CE TCOs are defined narrowly. A foreign group only counts if it targets the US government, US persons, or US interests, and it must not be an institutional arm of a foreign state or wholly directed by one. The memo builds in a presumption of innocence at the state level too: a group is assumed not to be state controlled unless clear intelligence establishes otherwise. That distinction matters enormously, because it is the line meant to separate this Program from anything resembling private warfare against a nation state.
No operation happens unilaterally. Every proposed action must be approved in writing by two Program Executive Directors, one designated by the Attorney General and one by the Secretary of Homeland Security, coordinating with each other before signing off. Participating Companies must pass what the memo calls rigorous vetting, sign contractual agreements with DOJ or DHS, and in many cases post a bond or escrow of at least one million dollars, forfeited if they breach their agreement. Within 60 days of the memo's signing, the Program Executive Directors must publish detailed operating procedures covering everything from target adjudication to what happens if an operation accidentally hits a US person's system, in which case the company must stop, run minimization procedures, and immediately notify the Center.
There is also a hard ceiling built into the design. Operations expected to cause loss of life, serious injury, or conduct that would rise to the level of a use of force or armed attack under international law, termed Critical Outcomes in the text, cannot be approved by the Program Executive Directors at all. That ceiling is the memo's clearest attempt to keep this inside the bounds of law enforcement rather than sliding into something closer to conflict.
Multiple law firms tracking the rollout, including Wiley, have been explicit on one point worth repeating because so much coverage has blurred it: this is not a green light for companies to hack back on their own initiative. Every operation remains, on paper, an act of the federal government, merely executed through a contracted private hand.
Why experts are not popping champagne
Legal caution has not stopped a wave of professional anxiety. Cyber policy veterans interviewed by outlets like CyberScoop describe the memo as a genuine philosophical break in how Washington thinks about offense in cyberspace, and the debate that followed split fairly evenly between cautious optimism and open alarm.
The core worry, echoed across nearly every serious critique, is attribution. Cyber operations are hard to trace precisely because criminals exploit shared infrastructure, proxies, and compromised third party systems to hide, and that same fog does not lift just because a government contract sits behind the operator. A former senior CISA official, Michael Garcia, put the risk plainly: pressure to attribute quickly could push companies toward lower certainty judgments about who they are actually striking, with a realistic chance of hitting the wrong server, or worse, infrastructure tied to a foreign government rather than a criminal gang. A former Cyber Command official was blunter still, describing parts of the memo on social media as a structure that could reward companies for manufacturing billable threats rather than resolving them efficiently.
Paul Rosenzweig, a former DHS policy official, raised a separate and arguably more durable problem: jurisdiction. Whatever this memo authorizes under American law, the systems being accessed usually sit inside someone else's sovereign territory, governed by that country's own criminal statutes. Washington cannot legislate away a foreign hacking law simply by calling the American company that broke it a Participating Company.
None of this makes the memo indefensible. Supporters point out, correctly, that the private sector already does enormous amounts of active defense and threat disruption work informally, through botnet takedown litigation and coordinated infrastructure seizures, and that formalizing federal oversight over that activity is arguably safer than the current improvisation. The honest position, and probably the fair one, is that the memo trades one set of risks for another, and which set turns out worse will depend entirely on the operating procedures due inside sixty days, procedures the public has not yet seen.
CyberPeace Insights: what this means beyond America's borders
A significant share of the CE-TCO activity this memo is built to target, the ransomware crews, romance investment fraud operations, and sextortion rings running out of Southeast Asia, does not victimize Americans in isolation. The scam compounds clustered along the Myanmar, Cambodia, and Laos borders, repeatedly raided over the past two years, have held thousands of trafficked workers of dozens of nationalities, Indians consistently among the largest groups rescued, alongside Chinese, Filipino, and Malaysian nationals. India has run its own repatriation efforts out of Mae Sot in Thailand, bringing citizens home several hundred at a time, and has built its own institutional response to this threat through the Indian Cyber Crime Coordination Centre, which coordinates cybercrime enforcement across states and increasingly across borders.
That shared exposure gives India and the United States real common ground here. The criminal infrastructure this American Program is designed to disrupt is, in significant part, the same infrastructure that has trafficked and defrauded Indian citizens, which gives New Delhi genuine reason to watch this experiment closely and constructively. At the same time, the Program's underlying model, private companies conducting cross-border operations under one nation's legal authorization, is a genuinely new template in international cyber governance, and how it performs over its first year will likely shape how other major digital economies, India included, think about calibrating their own frameworks for public-private cooperation against transnational cybercrime. India and other nations should closely watch whether this becomes a template worth adapting or a cautionary tale worth avoiding.
It is pertinent to note that Justice and Homeland Security departments have 60 days to write detailed operating procedures covering everything from a target-vetting rubric to a classified operational workflow and 180 days to deliver the first status report to the White House.
References
- The White House. "Expanding Capabilities to Combat Transnational Cyber Enabled Crime." 12 August 2026. https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/
- Wiley Rein LLP. "Navigating the New Presidential Memorandum on Transnational Cyber Enabled Crime." August 2026. https://www.wiley.law/alert-Navigating-the-New-Presidential-Memorandum-on-Transnational-Cyber-Enabled-Crime
- SecureWorld. "Trump Memo Lets Private Firms Hack Back at Cybercriminals." August 2026. https://www.secureworld.io/industry-news/trump-authorizes-private-firms-offensive-cyber-operations
- CyberScoop. "A bold new strategy or a dangerous precedent? Experts are divided on Trump's memo." August 2026. https://cyberscoop.com/private-sector-hacking-presidential-memo-cybersecurity/
- CyberScoop. "Trump turns to private sector in offensive hacking operations memo." August 2026. https://cyberscoop.com/trump-memo-private-sector-offensive-hacking/
- CNN Politics. "Cyber privateers: Trump issues order allowing US companies to hack overseas groups under certain conditions." August 2026. https://www.cnn.com/2026/08/13/politics/cyber-privateers-trump-order-overseas-groups-hacking
- NPR. "Trump administration wants to allow companies to hack foreign cybercriminals." August 2026. https://www.npr.org/2026/08/15/nx-s1-5930311/trump-companies-hack-foreign-cybercriminals
- The Next Web. "President Donald Trump signs memo letting US agencies hack transnational crime groups abroad." August 2026. https://thenextweb.com/news/trump-cyber-memo-transnational-crime
- Machine News. "Security firms hit back at Trump's call to hack back against international crime gangs." August 2026. https://www.machine.news/security-firms-hit-back-at-trumps-call-to-hack-back-against-international-crime-gangs/
- Lawfare. "Trump Admin Cyber Strategy Centers Private Sector in Offensive Cyber Operations." March 2026. https://www.lawfaremedia.org/article/trump-admin-cyber-strategy-centers-private-sector-in-offensive-cyber-operations
- Lawfare. "Partners or Provocateurs? Private Sector Involvement in Offensive Cyber Operations." July 2025. https://www.lawfaremedia.org/article/partners-or-provocateurs--private-sector-involvement-in-offensive-cyber-operations
- Global Indian Network. "Pig Butchering Scams in India: The Dark Intersection of Social Media, AI, and Emotional Manipulation." January 2026. https://globalindiannetwork.com/pig-butchering-scams-in-india/
- The Tribune. "India brings home scammed 549 nationals from Myanmar in 2 days." 2025. https://www.tribuneindia.com/news/india/india-brings-home-scammed-549-nationals-from-myanmar-in-2-days
- Malay Mail. "India to repatriate 500 nationals fleeing Myanmar's cyber scam hub, says Thai PM." October 2025. https://www.malaymail.com/amp/news/world/2025/10/29/india-to-repatriate-500-nationals-fleeing-myanmars-cyber-scam-hub-says-thai-pm/196399
- NBC News. "260 foreigners rescued from virtual slavery in Myanmar's online scam centers are being repatriated." 2025. https://www.nbcnews.com/news/world/260-foreigners-rescued-virtual-slavery-myanmars-online-scam-centers-ar-rcna192180
- CyberPeace Foundation. "About Us." https://cyberpeace.org/about-us
Contributors
- Maj. Vineet Kumar, Founder & Global President, CyberPeace
- Mr. Neeraj Soni, Senior Research Analyst, Policy & Advocacy, CyberPeace
List of Abbreviations
- CE‑TCO — Cyber Enabled Transnational Criminal Organization
- DOJ — Department of Justice
- DHS — Department of Homeland Security
- FBI — Federal Bureau of Investigation
- CISA — Cybersecurity and Infrastructure Security Agency
- I4C — Indian Cyber Crime Coordination Centre
- US — United States
- IT — Information Technology