#FactCheck-AI-Manipulated Video Falsely Attributes Statement on Operation Sindoor to Foreign Secretary Vikram Misri
Executive Summary
A video of Foreign Secretary Vikram Misri speaking to a reporter is being circulated on social media with the claim that he said the Indian government was forced to publicly acknowledge the soldiers killed during Operation Sindoor due to political pressure from the families of the deceased. Research conducted by the CyberPeace Research Wing found that the viral video had been manipulated using artificial intelligence (AI). Vikram Misri's voice was artificially cloned, meaning the audio heard in the clip is not genuine but has been generated and altered using AI technology.
Claim
The video was shared on X (formerly Twitter) with the following caption: "Breaking. Explosive revelations from Vikram Misri. Indian Government was forced to admit the fallen soldiers in Operation Sindoor due to political pressure from the families of victims. Previous CDS was made to resign because of the same reason."
https://x.com/InsiderWB/status/2071642756125008031

Fact Check
We conducted a reverse image search using Google Lens, which led us to a video uploaded on The Tribune's verified YouTube channel that matched the viral clip. In the original video, Vikram Misri clarified that the Government of India neither officially participated in, supported, nor was involved in any event related to India-Pakistan dialogue. He further stated that the government had taken no cognisance of such private events and that the retired dignitaries and diplomats present were expressing their personal views, not speaking on behalf of the Government of India.
https://www.youtube.com/watch?v=wCrv0Vcgp28

Since we found no evidence that Vikram Misri had ever made the statements attributed to him in the viral clip, we analysed the video using Hive Moderation's AI-generated content detection tool. The analysis indicated that the viral video is 96 per cent AI-generated.

To further verify the claim, we analysed the audio using Hiya Audio Intelligence. The tool concluded that the voice in the viral video appears to have been generated or modified using artificial intelligence.

Conclusion
The viral video is misleading. Our research found that the video of Foreign Secretary Vikram Misri had been manipulated using artificial intelligence. He never made any statement claiming that the Indian government disclosed the names of soldiers killed during Operation Sindoor due to pressure from their families. Therefore, the viral claim is false.
Related Blogs

Introduction
The world has been witnessing various advancements in cyberspace, and one of the major changes is the speed with which we gain and share information. Cyberspace has been declared as the fifth dimension of warfare, and hence, the influence of technology will go a long way in safeguarding ourselves and our nation. Information plays a vital role in this scenario, and due to the easy access to information, the instances of misinformation and disinformation have been rampant across the globe. In the recent Russia-Ukraine crisis, it was clearly seen how instances of misinformation can lead to major loss and harm to a nation and its subjects. All nations and global leaders are deliberating upon this aspect and efficient sharing of information among friendly nations and inter-government organisations.
What is IW?
IW, also known as Information warfare, is a critical aspect of defending our cyberspace. Information Warfare, in its broadest sense, is a struggle over the information and communications process, a struggle that began with the advent of human communication and conflict. Over the past few decades, the rapid rise in information and communication technologies and their increasing prevalence in our society has revolutionised the communications process and, with it, the significance and implications of information warfare. Information warfare is the application of destructive force on a large scale against information assets and systems, against the computers and networks that support the four critical infrastructures (the power grid, communications, financial, and transportation). However, protecting against computer intrusion, even on a smaller scale, is in the national security interests of the country and is important in the current discussion about information warfare.
IW in India
The aspects of misinformation have been recently seen in India in the form of the violence in Manipur and Nuh, which resulted in a massive loss of property and even human lives. A lot of miscreants or anti-national elements often seed misinformation in our daily news feed, and this is often magnified by social media platforms such as Instagram or X (formerly known as Twitter) and OTT-based messaging applications like WhatsApp or Telegram during the pandemic. It was seen nearly every week that some or the other new ways to treat COVID-19 were shared on Social media, which were false and inaccurate, especially in regard to the vaccination drive. A lot of posts and messages highlighted that the Vaccine is not safe, but a lot of this was a part of misinformation propaganda. Most of the time, the speed of spread of such episodes of misinformation is rapid and is often spread by the use of social media platforms and OTT messaging applications.
IW and Indian Army
Former Meta employees have recently come up with allegations that the Chinar Corp of the Indian Army had approached the social media giant to suppress some pages and channels which propagated content that may be objectionable. It is alleged that the formation made such a request to propagate its counterintelligence operations against Pakistan. The Chinar Corps is one of the most prestigious formations of the Indian Army and has the operational area of Kashmir Valley. The instances of online grooming and brainwashing have been common from the anti-national elements of Pakistan, as a faction of youth has been engaged in terrorist activities directly or indirectly. Various messaging and social media apps are used by the bad actors to lure in innocent youth on the fake and fabricated pretext of religion or any other social issue. The Indian Army had launched an anti-misinformation campaign in Kashmir, which aimed to protect Kashmiris from the propaganda of fake news and misinformation, which often led to radicalisation or even riots or attacks on defence forces. The aspect of net neutrality is often misused by bad actors in areas which are sociological, critical or unstable. The Indian Army has created special offices focusing on IW at all levels of formations, and the same is also used to eradicate all or any fake news or fake propaganda against the Indian Army.
Conclusion
Information has always been a source of power since the days of the Roman Empire. Control, dissemination, moderation and mode of sharing of information plays a vital role for any nation both in term of safety from external threats and to maintain National Security. Information Warfare is part of the 5th dimension of warfare, i.e., Cyberwar and is a growing concern for developed as well as developing nations. Information warfare is a critical aspect which needs to be incorporated in terms of basic training for defence personnel and law enforcement agencies. The anti-misinformation operation in Kashmir was primarily focused towards eradicating the bad elements after repealing Article 377, from cyberspace and ensuring harmony, peace, stability and prosperity in the state.
References
- https://irp.fas.org/eprint/snyder/infowarfare.htm
- https://www.thehindu.com/news/national/metas-india-team-delayed-action-against-army-led-misinfo-op-in-kashmir-us-news-report/article67352470.ece
- https://www.indiatoday.in/india/story/facebook-instagram-block-handles-of-chinar-corps-no-response-from-company-over-a-week-says-officials-1910445-2022-02-08

Executive Summary
The film ‘Yadav Ji Ki Love Story’, scheduled to release on February 27, has become embroiled in controversy over its title. Several organizations have expressed objections, registering their displeasure regarding the name of the film. Amid the row, a video is being widely circulated on social media. The footage shows a large crowd holding banners and posters while staging a protest. Users sharing the clip claim that it is from South India, where members of the Yadav community have allegedly launched a large-scale agitation against the film. However, research conducted by the CyberPeace found the viral claim to be false. Our research revealed that the video is not authentic but AI-generated, and is being shared with a misleading narrative.
Claim
On February 22, 2026, a Facebook user shared the viral video claiming it depicts protests by the Yadav community in South India against the film. The original and archived links to the post are provided below

Fact Check:
Upon closely examining the viral video, we noticed several anomalies in the visuals, crowd movements, and certain frames. The unnatural patterns and inconsistencies raised suspicions that the footage may have been generated using artificial intelligence. To verify this, we analyzed the video using the AI detection tool Aurigin AI, which indicated that the footage was AI-generated.

We further scanned the clip using another AI detection platform, Hive Moderation. The results showed a 99 percent probability that the video was AI-generated.

Conclusion
Our findings confirm that the viral video is not real. It has been artificially created using AI technology and is being circulated with a false and misleading claim.

Introduction
India is operating on digital rails today. Even as UPI is set to hit over 130 billion transactions by 2025, it already makes up around 80% of retail payments flow by volume. That volume is really what it is all about: a single extra transaction is simply another attack surface, and fraud has correspondingly scaled up. FY 2024-25 alone saw an estimated 485 crore in losses to UPI-related fraud through 632,000 reported frauds. The response from the RBI has not been a single rulebook but a layered and dynamic regulatory infrastructure that currently spans banks, NBFCs, payment aggregators, card networks, and, by extension, the fintechs that connect into all of these components. Knowing why the infrastructure is shaped the way it is and what actual enforcement looks like is far more crucial than having a checklist in mind. This write-up moves beyond summarising the rules to outlining the thinking behind them, the latest trends shaping the segment and the reality of an implementation roadmap.
Why Has RBI Cybersecurity Compliance Become Non-Negotiable?
Three forces are converging on regulated entities at once:
1. The threat surface has outgrown legacy controls: Core banking systems were never designed for an ecosystem of APIs, third-party payment gateways, and unregulated fintech partners sitting on top of them. Every integration is a potential entry point, and attackers know it.
2. Financial stability is now a cyber question, not just a credit question: a prolonged outage at a large payment system operator doesn't just hurt one bank's balance sheet; it can freeze retail payments for hundreds of millions of people. RBI treats this as systemic risk, which is why its post-2020 directions lean so heavily on resilience (the ability to keep operating through an attack) rather than just prevention.
3. Enforcement has escalated: The RBI's May 2025 single order penalised five different banks, including levying a 97.80 lakh penalty on ICICI Bank with one part attributable to its late reporting of a cybersecurity incident and another to a lapse in account alert systems; this demonstrates this rise in intensity. Remember, under Sections 46 and 47A of the Banking Regulation Act 1949, the RBI has the power to levy penalties irrespective of the occurrence of an actual breach if an individual fails to comply with procedures like not properly assessing vendor access or reporting incidents late or failing to update crisis plans or timely reports. Now this is a significant development, an issue even in the absence of a full-scale 'hack'.
The Regulatory Architecture: What Actually Applies to Whom
Rather than one framework, regulated entities are governed by several overlapping directions depending on their category:
- Banks: The original RBI Cyber Security Framework requires board-approved cybersecurity policies, 24x7 Security Operations Centres, and defined incident reporting timelines.
- NBFCs: NBFCs were initially governed under the Master Direction on IT Framework for NBFC Sector, which escalates accordingly as per size of asset – the framework underwent substantial change in shape with the RBI notifying Cybersecurity, Technology Risk, Resilience and Assurance Framework directions, 2026 for NBFCs, which lays specific obligations based on tier level (NBFC-Base Layer, Middle Layer, Upper Layer & Top Layer entities) on issues like MIS reporting, fraud analytics & impact of incident reporting.
- PSOs: Non-bank Payment system Operators PSOs have been regulated under the Master Direction on Cyber Resilience and Digital Payment Security Controls, 2024 (July 2024). Card networks, payment aggregators, PPI issuers and other PSOs come under its umbrella, with staged compliance based on the volume/business size (large – NPCI, card networks and the largest PPI issuers will meet requirements on April 1, 2025; medium ones by April 1, 2026; and small ones by April 1, 2028).
- Other Bodies: IT Governance (on all regulated entities broadly) The Master Direction on Information Technology Governance, Risk, Controls and Assurance Practices, 2023, became effective on April 1, 2024, and has set basic benchmarks for information technology (IT) strategy committees, IT risk management processes & IT assurance functions.
Overall trends' information across all these is clear: escalating tier requirements as per size and board-led controls are mandatory; a conscious acceptance that there will inevitably be data breaches in the future; and increasing emphasis on response and recovery.
Governance: Where RBI Compliance Actually Starts
A recurring theme across every RBI direction is that cybersecurity cannot be delegated entirely to the IT department. The Board of Directors is expected to own information security risk, with oversight typically delegated to a board subcommittee that meets at least quarterly. A board-approved information security policy, reviewed annually, must define the following:
- Roles and responsibilities across the Board, senior management, and the CISO
- Processes to identify, assess, monitor, and manage cyber risk
- Employee and stakeholder training and awareness programs
RBI's own 2022 thematic review of IT governance across 20 banks found unmanaged third-party vendor access, with vendors retaining privileged access to core systems long after a project ended at more than half the institutions reviewed. That kind of gap is a governance failure as much as a technical one: it happens because nobody owns the review cycle, not because the firewall is misconfigured.
Key Technical and Operational Controls
Once governance is in place, RBI's expectations translate into concrete control domains:
Infrastructure and access hardening: Network segmentation, endpoint protection, server hardening baselines, and multi-factor authentication for privileged access. Access reviews should be continuous or, at minimum, periodic, enforcing least privilege and separation of duties, not a one-time onboarding checkbox.
Vulnerability and patch management: Regular vulnerability scanning, risk-prioritised remediation, and a documented process for feeding vulnerability data into risk decisions, not just a scanner report sitting in an inbox.
Data security and localisation: Encryption at rest, in transit, and during processing; sound key management; data classification and masking; and adherence to the RBI's data localisation requirements for payment data.
Vendor and third-party risk: This has become one of the sharpest areas of regulatory focus. The 2024 PSO Master Directions explicitly require oversight of "unregulated entities" in the payment chain like payment gateways, third-party service providers, and vendors with due diligence, contractual security clauses, and ongoing monitoring baked in. For a bank or fintech, this means your compliance posture is only as strong as your weakest vendor's; the RBI increasingly holds the regulated entity accountable for its partners' failures, not just its own.
Security operations and incident response: 24x7 SOC capability, threat intelligence integration, and tested incident response plans via tabletop exercises and simulated attacks. A Cyber Crisis Management Plan (CCMP) drafted once and never rehearsed is, in practice, treated by RBI examiners as functionally absent.
Incident Reporting
This is where two separate regulatory clocks run in parallel, and conflating them is a common compliance mistake:
- RBI requirements: Regulated entities will normally have around 2-6 hours of detection to report most security incidents to the RBI with follow-up notifications as and when the nature of the incident unfolds.
- CERT-In's 6-hour rule: The CERT-In Directions dated April 2022 stipulate that every body corporate, which includes any bank, NBFC or payment aggregator, is obligated to report specified categories of cyber incidents to CERT-In within 6 hours of noticing them and not after fully confirming details at an additional 6 hours after noticing them. CERT-In directions also mandated that ICT system clocks are to be synced to NIC/NPL time servers, and system logs are to be maintained for a rolling 180 days within India.
- The Digital Personal Data Protection Act overlay: In the case of a data breach involving personal data, there will additionally be a 72-hour notification obligation from the data fiduciary to the Data Protection Board under the Digital Personal Data Protection Act, 2023, which runs in parallel to, and not in substitution of, the CERT-In time.
The practical consequences: If an SOP for incident response only maps one regime, then it would fail in an actual incident. We need a single intake process whereby multiple notification tracks are automatically triggered at the precise time an incident is detected, given that the inability to report "because we were still figuring it out" does not constitute an acceptable justification for a late notification under either regime.
Why Penetration Testing Sits at the Center of Compliance
RBI's VAPT (Vulnerability Assessment and Penetration Testing) mandate isn't a box-ticking annual scan. It's meant to validate, under real attack conditions, whether the governance and technical controls described above actually hold up. Automated scanning finds known vulnerabilities; penetration testing, ideally combining automated coverage with manual, business-context-aware testing, finds the logic flaws, chained exploits, and privilege escalation paths that scanners miss and that attackers actually use.
For most regulated entities, a realistic testing cadence looks like:
- Semi-annual vulnerability assessments across critical systems
- Annual (at minimum) penetration testing of applications, networks, and infrastructure supporting payment and customer-data systems
- Testing triggered by events before go-live, after major changes, and post-deployment.
- Documented remediation cycles and rescans, with reports mapped directly to the relevant compliance clauses for audit purposes
The Cost of Getting It Wrong
RBI's enforcement history grounds the financial impact of enforcement actions. In addition to the May 2025 fines levied on ICICI, Axis, IDBI, Bank of Baroda and Bank of Maharashtra, the RBI's published Enforcement Guidelines differentiate three levels of severity; procedural breaches such as delayed policy review or late incident notifications usually warrant 10 lakh to 1 crore fines plus formal reprimands and remediation orders with deadlines. Recurring governance breaches go farther than fines, resulting in restrictions on business activities and more stringent supervisory reporting, with egregious breaches leading to inclusion under the RBI's Prompt Corrective Action regime. Penalty orders are also publicly available, and the resulting toll on customer trust, partner trust, and investor confidence often dwarfs the fines.
A Practical Implementation Roadmap
For an organisation building or maturing its RBI compliance programme, a sensible sequence looks like this:
- Establish board-level ownership first: Form or formalise the Board IT/Risk sub-committee, appoint or empower a CISO with real authority, and get the information security policy formally approved, and this is the foundation every RBI examiner checks first.
- Mapping: A mid-sized NBFC, a large payment aggregator, and a scheduled commercial bank face different, overlapping obligations. Get this scoping wrong and you'll either over-engineer or leave gaps.
- Secure third-party access: Audit every vendor with system access, revoke stale privileges, and build vendor security clauses into contracts going forward, not retroactively.
- Build one incident response SOP: Run one compiled playbook that satisfies RBI, Cert-In and DPDP.
- Schedule and actually rehearse tabletop exercises: not just write a CCMP and file it away.
- Institutionalise VAPT as a continuous, risk-triggered programme rather than an annual compliance event, and ensure reports are structured to map directly onto RBI's compliance clauses for audit readiness.
- Track the regulatory calendar actively: 2024–2026 has brought new NBFC directions, PSO phase-ins, and ITG-RC&AP obligations in quick succession, and the pace shows no sign of slowing.
Conclusion
RBI's shift from perimeter-focused prevention to a risk-based, resilience-first model reflects a broader reality: in a digital payments ecosystem processing billions of transactions a month, breaches are not a hypothetical to plan around; they're an operational certainty to plan for. The frameworks discussed here, cyber resilience directions, IT governance mandates, CERT-In's reporting clock and the new NBFC cybersecurity directions aren't separate hurdles to clear individually. They're converging into a single expectation: that regulated entities can detect an incident quickly, contain it, recover fast, and prove with documentation, tested plans, and independent penetration test evidence that they were ready for it in the first place.
For banks, NBFCs, and fintechs operating in India today, that readiness is no longer just a regulatory requirement. It's the baseline cost of operating in the financial system at all.
References
Sources
- Astra Security — RBI Cybersecurity Compliance Checklist for Banks & NBFCs in 2026: https://www.getastra.com/blog/compliance/rbi-cybersecurity-compliance-checklist/
- TaxGuru — RBI Issues NBFC Cybersecurity and Technology Risk Directions, 2026: https://taxguru.in/rbi/rbi-issues-nbfc-cybersecurity-technology-risk-directions-2026-governance-framework.html
- Mondaq — Cyber Resilience and Digital Payment Security Governance (Master Directions, 2024): https://www.mondaq.com/india/fin-tech/1527836/cyber-resilience-and-digital-payment-security-governance-a-step-towards-secured-payments-systems
- TaxGuru — Master Directions on Cyber Resilience & Digital Payment Security Controls for Non-bank PSOs: https://taxguru.in/rbi/master-directions-cyber-resilience-digital-payment-security-controls-non-bank-payment-system-operators.html
- CyberNX — Ultimate Guide on RBI Master Directions for Cyber Resilience: https://www.cybernx.com/rbi-master-directions-guide/
- SIRI Law LLP — A Comprehensive Guide to India's CERT-In 6-Hour Cyber Incident Reporting Mandate: https://sirilawllp.com/a-comprehensive-guide-to-indias-cert-in-6-hour-cyber-incident-reporting-mandate/
- CreativeCyber — CERT-In 6-Hour Incident Reporting SOP for Indian Banks & NBFCs: https://creativecyber.in/resources/cert-in-6-hour-incident-reporting/
- BW Businessworld — RBI Slaps Penalties on ICICI, Axis and Three Others Over Compliance Failures (May 2025): https://www.businessworld.in/article/rbi-slaps-penalties-on-icici-axis-three-others-over-compliance-failures-555643
- FluxForce — RBI Cyber Framework: Banks' Requirements & Penalties: https://www.fluxforce.ai/regulations/rbi-cyber-security-framework-banks
- MYITMANAGER — RBI Cybersecurity Guidelines 2026: What Banks and NBFCs Must Do: https://myitmanager.in/rbi-cybersecurity-guidelines-2026-banks-nbfcs/