#FactCheck: Beware of Fake Emails Distributing Fraudulent e-PAN Cards
Executive Summary:
We have identified a post addressing a scam email that falsely claims to offer a download link for an e-PAN Card. This deceptive email is designed to mislead recipients into disclosing sensitive financial information by impersonating official communication from Income Tax Department authorities. Our report aims to raise awareness about this fraudulent scheme and emphasize the importance of safeguarding personal data against such cyber threats.

Claim:
Scammers are sending fake emails, asking people to download their e-PAN cards. These emails pretend to be from government authorities like the Income Tax Department and contain harmful links that can steal personal information or infect devices with malware.
Fact Check:
Through our research, we have found that scammers are sending fake emails, posing as the Income Tax Department, to trick users into downloading e-PAN cards from unofficial links. These emails contain malicious links that can lead to phishing attacks or malware infections. Genuine e-PAN services are only available through official platforms such as the Income Tax Department's website (www.incometaxindia.gov.in) and the NSDL/UTIITSL portals. Despite repeated warnings, many individuals still fall victim to such scams. To combat this, the Income Tax Department has a dedicated page for reporting phishing attempts: Report Phishing - Income Tax India. It is crucial for users to stay cautious, verify email authenticity, and avoid clicking on suspicious links to protect their personal information.

Conclusion:
The emails currently in circulation claiming to provide e-PAN card downloads are fraudulent and should not be trusted. These deceptive messages often impersonate government authorities and contain malicious links that can result in identity theft or financial fraud. Clicking on such links may compromise sensitive personal information, putting individuals at serious risk. To ensure security, users are strongly advised to verify any such communication directly through official government websites and avoid engaging with unverified sources. Additionally, any phishing attempts should be reported to the Income Tax Department and also to the National Cyber Crime Reporting Portal to help prevent the spread of such scams. Staying vigilant and exercising caution when handling unsolicited emails is crucial in safeguarding personal and financial data.
- Claim: Fake emails claim to offer e-PAN card downloads.
- Claimed On: Social Media
- Fact Check: False and Misleading
Related Blogs

Introduction
Cyberwarfare has evolved into one of the most decisive instruments of statecraft and conflict. The increasing digitisation of critical infrastructure like power grids, water systems, transportation systems, healthcare networks, and energy sources has made these systems new targets in the war of algorithms. Military logic is evolving to paralyse the nation’s critical infrastructure to keep its resources engaged in repairing them and thereby break the nation’s ability to deter and counter attacks, all without firing a single bullet.
From Ransomware to an Invisible Sabotage: The changing nature of warfare
The operational technology (OT) landscape has become the epicentre of cyber operations, all around the world. Once, which was insulated, related to industrial systems that controlled turbines, pipelines, or dams, they now stand connected to the Internet through supervisory control and data acquisition (SCADA) and the Internet of Things. These connections have also become gateways for attackers, besides enhancing the efficiency of the infrastructural lifelines of the nation.
Groups like Volt Typhoon, Sandworm, Laurionite, and Cyberavengers have transformed the art of digital infiltration into a strategic shift. Volt Typhoon, which is linked to China, has used “living-off-the-land” techniques to exploit the legitimate administrative tools to remain invisible while scanning the critical infrastructures in the US. Sandworm, which is aligned with Russia’s GRU (Glavnoye Razvedyvatelnoye Upravlenie) or Main Intelligence Directorate (in English), has demonstrated the power of cyber sabotage in real time, as its attacks on Ukraine’s power grids in 2015 and 2021 had left millions in darkness, coinciding with kinetic missile strikes. Meanwhile, the Iranian-affiliated Cyberavengers group, which has weaponised the AI-assisted malware, such as IOCONTROL, that are capable of hijacking water and energy control systems. Each of these systems used in these operations reflects a shift from direct espionage activities to a state of strategic paralysis.
In comparison to the traditional cybercrime activities that are aimed at stealing data and extortion of money, these campaigns repeatedly target the physical systems, which consist of the machinery that sustains civilian life and military preparedness.
The Military Logic behind Cyber Targeting: A Web of Vulnerabilities
A critical infrastructure is a complex ecosystem that covers power generation, transportation, communication, and manufacturing are all interconnected, which means a single compromised node can cascade into a national paralysis. For instance, a breach in the systems of the dam can flood an entire city, a grid shutdown can halt water supply to hospitals, and even affect air traffic. The 2015 Black Energy Malware attack in Ukraine has proved this possibility when three utilities were hacked, plunging thousands of homes into darkness. The Iranian hackers once again gained access to the Bowman Avenue Dam of New York and controlled its floodgates, which gave a chilling demonstration of the destructive reality of digital manipulation.
The systems remain vulnerable mainly for 3 reasons such as-
- Legacy Architectures: Many of these industrial systems were designed decades ago with no built-in cybersecurity mechanisms.
- Slow Patching and Segmentation Gaps: All updates and segmentation between IT and TO networks often lag, providing open entry points for attackers.
- Converging with IoT: The integration of smart sensors and cloud-based management tools has expanded the attack surface exponentially.
This interconnected fragility has turned our critical infrastructures into both a weapon and a target or a tool for coercion in modern hybrid warfare. Between 2023 and 2024, over 420 cyberattacks were witnessed in several critical global infrastructures, which averaged to 13 attacks per second, according to a news report. These were not just random acts of digital vandalism; they were deliberate and coordinated operational attempts by state-led actors from China, Russia, and Iran.
Developing a new Resilience as the new tool of Deterrence
Cyber deterrence no longer rests on the fear of retaliation, it relies on the need for resilience. Nations that can absorb attacks, maintain continuity, and recover rapidly would be the true superpowers of this digital age. Segmentation, real-time threat detection, and AI-assisted recovery models are vital pillars of this model of resilience. The logic of modern cyberwarfare is clear, which means that the more a nation digitizes, the more it will need to defend itself.
However, as the line between war and peace blurs, safeguarding critical infrastructure is no longer just an IT priority; rather, it is a national security doctrine. In this silent theatre of cyberwarfare, survival will depend not only on firepower, but on firewalls.
References
- https://rmcglobal.com/critical-infrastructure-under-siege-the-top-ot-threats-of-2025/
- https://ccdcoe.org/uploads/2018/10/Geers2009_The-Cyber-Threat-to-National-Critical-Infrastructures.pdf
- https://www.researchgate.net/publication/335752979_Cybersecurity_of_Critical_Infrastructure
- https://arxiv.org/html/2510.04118v1
- https://www.anapaya.net/blog/top-5-critical-infrastructure-cyberattacks

Introduction
In the hyperconnected world, cyber incidents can no longer be treated as sporadic disruptions; such incidents have become an everyday occurrence. The attack landscape today is very consequential and shows significant multiplication in its frequency, with ransomware attacks incapacitating a health system, phishing attacks hitting a financial institution, or state-sponsored attacks on critical infrastructures. Towards counteracting such threats, traditional ways alone are not enough, they gravely rely on manual research and human intellect. Attackers exercise speed, scale, and stealth, and defenders are always four steps behind. With such a widening gap, it is deemed necessary to facilitate incident response and crisis management with the intervention of automation and artificial intelligence (AI) for faster detection, context-driven decision-making, and collaborative response beyond human capabilities.
Incident Response and Crisis Management
Incident response is the structured way in which organisations deal with responding to detecting, segregating, and recovering from security incidents. Crisis management takes this even further, dealing not only with the technical fallout of a breach but also its business, reputation, and regulatory implications. Echelon used to depend on manual teams of people sorting through logs, cross-correlating alarms, and generating responses, a paradigm effective for small numbers but quickly inadequate in today's threat climate. Today's opponents attack at machine speed, employing automation to launch attacks. Under such circumstances, responding with slow, manual methods means delay and draconian consequences. The AI and automation introduction is a paradigm change that allows organisations to equate the pace and precision with which attackers initiate attacks in responding to incidents.
How Automation Reinvents Response
Cybercrime automation liberates cybercrime analysts from boring and repetitive tasks that consume time. An analyst manually detects potential threats from a list of hundreds each day, while automated systems sift through noise and focus only on genuine threats. Malware can automatically cause infected computers to be disconnected from the network to avoid spreading or may automatically have its suspicious account permissions removed without human intervention. The security orchestration systems move further by introducing playbooks, predefined steps describing how incidents of a certain type (e.g., phishing attempts or malware infections) should be handled. This ensures fast containment while ensuring consistency and minimising human error amid the urgency of dealing with thousands of alerts.
Automation takes care of threat detection, prioritisation, and containment, allowing human analysts to refocus on more complex decision-making. Instead of drowning in the sea of trivial alerts, security teams can now devote their efforts to more strategic areas: threat hunting and longer-term resilience. Automation is a strong tool of defence, cutting response times down from hours to minutes.
The Intelligence Layer: AI in Action
If automation provides speed, then AI is what allows the brain to be intelligent and flexible. Working with old and fixed-rule systems, AI-enabled solutions learn from experiences, adapt to changes in threats, and discover hidden patterns of which human analysts themselves would be unaware. For instance, machine learning algorithms identify normal behaviour on a corporate network and raise alerts on any anomalies that could indicate an insider attack or an advanced persistent threat. Similarly, AI systems sift through global threat intelligence to predict likely attack vectors so organisations can have their vulnerabilities fixed before they are exploited.
AI also boosts forensic analysis. Instead of searching forever for clues, analysts let AI-driven systems trace back to the origin of an event, identify vulnerabilities exploited by attackers, and flag systems that are still under attack. During a crisis, AI is a decision support that predicts outcomes of different scenarios and recommends the best response. In response to a ransomware attack, for example, based on context, AI might advise separating a single network segment or restoring from backup or alerting law enforcement.
Real-World Applications and Case Studies
Already, this mitigation has been provided in the form of real-world applications of automation and AI. Consider, for example, IBM Watson for Cybersecurity, which has been applied in analysing unstructured threat intelligence and providing analysts with actionable results in minutes, rather than days. Like this, systems driven by AI in DARPA's Cyber Grand Challenge demonstrated the ability to automatically identify an instant vulnerability, patch it, and reveal the potential of a self-healing system. AI-powered fraud detection systems stop suspicious transactions in the middle of their execution and work all night to prevent losses. What is common in all these examples is that automation and AI lessen human effort, increase accuracy, and in the event of a cyberattack, buy precious time.
Challenges and Limitations
While promising, the technology is still not fully mature. The quality of an AI system is highly dependent on the training data provided; poor training can generate false positives that drown teams or worse false negatives that allow attackers to proceed unabated. Attackers have also started targeting AI itself by poisoning datasets or designing malware that does not get detected. Aside from risks that are more technical, the operational and financial costs involved in implementing advanced AI-based systems present expensive threats to any company. Organisations will have to make expenditures not only on technology but also for the training of staff to best utilise these tools. There are some ethical and privacy issues to consider as well because systems may be processing sensitive personal data, so global data protection laws such as the GDPR or India's DPDP Act could come into conflict.
Creating a Human-AI Collaboration
The future is not going to be one of substitution by machines but of creating human-AI synergy. Automation can do the drudgery, AI can provide smarts, and human professionals can use judgment, imagination, and ethical decisions. One would want to build AI-fuelled Security Operations Centres where technology and human experts work in tandem. Continuous training must be provided to AI models to reduce false alarms and make them most resistant against adversarial attacks. Regular conduct of crisis drills that combine AI tools and human teams can ensure preparedness for real-time events. Likewise, it is worth integrating ethical AI guidelines into security frameworks to ensure a stronger defence while respecting privacy and regulatory compliance.
Conclusion
Cyber-attacks are an eventuality in this modern time, but the actual impact need not be so harsh. The organisations can maintain the programmatic method of integrating automation and AI into incident response and crisis management so that the response against the very threat can be shifted from reactive firefighting to proactive resilience. Automation gives speed and efficiency while AI gives intelligence and foresight, hence putting the defenders on par and possibly exceeding the speed and sophistication of the attackers. But an utmost system without human inquisitiveness, ethical reasoning, and strategic foresight would remain imperfect. The best defence is in that human-machine relationship symbiotic system wherein automation and AI take care of how fast and how many cyber threats come in, whereas human intellect ensures that every response is aligned with larger organizational goals. This synergy is where cybersecurity resiliency will reside in the future-the defenders won't just be reacting to emergencies but will rather be driving the way.
References
- https://www.sisainfosec.com/blogs/incident-response-automation/
- https://stratpilot.ai/role-of-ai-in-crisis-management-and-its-critical-importance/
- https://www.juvare.com/integrating-artificial-intelligence-into-crisis-management/
- https://www.motadata.com/blog/role-of-automation-in-incident-management/

Introduction
In a significant step, the Indian Army beefed up its information warfare capacity on June 25, 2026, with the operationalisation of @MythbusterXX, its dedicated fact-checking handle designed to counter any form of misinformation, disinformation, malinformation, and deepfakes on the army swiftly. Adopting the motto 'Verify Before You Amplify,' the service seeks to pivot from reactive statements to active cognitive warfare. In a milieu where manipulated narratives can be as decisive in shaping public perception as kinetic force is on the battlefield, truth itself has transformed into a critical national security objective.
This is clear proof that protecting India’s digital battleground will from now on be defined not just by troop deployments but also by its institutional verification capacities, swift attribution mechanisms, and public awareness.
When the Battlefield Went Digital
Today warfare extends to timelines, group chats, and prime-time graphics packages. The distinction between misinformation , disinformation , and malinformation is crucial to operations. After all, they necessitate different types of counters. Generative AI just exponentially increased their velocity, cost, and the creepy believability of synthesized audio, video, and images. Operation Sindoor, India's May 2025 military response to a Pahalgam terror attack, provides a blueprint for just how large it can get.
According to the fact-checking site BOOM, 68% of fact checks in May related to Operation Sindoor, describing the campaign as a misinformation superspreader, and, more directly, India's Chief of Defence Staff General Anil Chauhan lamented at last year’s Shangri-La Dialogue that roughly 15% of his military’s operational time was spent on countering false news. New Delhi matched this response level; the Ministry of Information and Broadcasting had blocked over 1,400 URLs, many bearing false information or communally inciteful narratives from accounts in Pakistan. These challenges won't be vanishing any time soon. Microsoft's July 2025 Digital Defence Report lists India among the top countries targeted for AI-powered state-backed hacking, noting the automation of attacks and generation of fake content used to influence opinion.
CyberPeace's regulatory tracking also indicates steps toward building infrastructure to mitigate this, a Rule 7 complaint system for deepfakes, and efforts to foster local detection capabilities under the IndiaAI mission signal it's now an infrastructural threat.
Why the Army Chose to Speak First
On 1 June 2026, the Indian government’s official fact-checking unit debunked a deepfake of former Army Chief General Dhiraj Seth talking about India’s engagement with the Taliban that emanated from Pakistan-affiliated propaganda sources, appearing within days of a change of military command. Barely days after General Dhiraj Seth was elevated to Chief of Army Staff, the 31st person to hold the post, another fabricated deepfake used spliced authentic footage with AI-cloned audio to falsely allege he had blamed the past army leadership for hiding the bodies of soldiers to protect their image.
Such a dual targeting of India’s army chiefs with deepfakes in such close succession is a testament as to why an authoritative, constantly running fact-check machine isn’t an optional extra but a strategic must-have.
Architecture is as important as architecture itself. India tried a statutory fact-checking model with a government-owned Fact Check Unit under the Information Technology (IT) Rules of 2023 through the Press Information Bureau (PIB). It had to retreat from the edge of the constitutional cliff. In September 2024, when the Bombay High Court struck down key provisions of these rules. It ruled it unconstitutional to empower the state to declare digital content relating to the state itself as fake, false, or misleading. A similar reading of the analysis by CyberPeace found that digital speech should be given the same protections as offline speech, and this should be the benchmark for any counter-misinformation policy.
MythbusterXX carefully avoids the constitutional controversy by acting as an institutional avenue that produces verified information and rebuttals in response to disinformation. There is a profound distinction between answering falsehoods with factual, credible speech versus shutting them down with state power, the very proportionality that civil libertarians have said must govern a democracy's approach to online misinformation.
Platforms as Accelerants, Not Just Conduits
Part of the issue lies upstream, with the algorithms and broadcasters that favor speedy falsehood over careful confirmation. A month’s supply of “false and misleading stories,” the Reuters Institute for the Study of Journalism observed, streamed online within hours of Operation Sindoor's onset: one fact-checker identified approximately seventy false claims by the close of day one. Meanwhile, on the small screen, graphics depicting escalating conflicts were being televised, with broadcasters forced to scramble under 24/7 competition.
Amplified manipulation of the crisis narrative is also a factor; studies show that thousands of accounts have been reposting exactly the same party content for three years, making crisis-induced viral narratives predictable rather than organic phenomena. For the most part, the platforms that manage these narratives and the algorithms that direct content on both sides of the divide are not just innocent delivery systems.
Digital Literacy as the First Line of Defence
Institutional rebuttals only go so far if citizens lack the reflex to pause before sharing, which is where CyberPeace's own work becomes directly relevant. Through a multi-year, Google.org-backed initiative, CyberPeace Foundation aims to reach over 40 million Indian internet users, including 9 million underserved beneficiaries, through a multilingual resource centre offering 650 hours of content, state-level helplines, and quick-response teams staffed by digital forensics and fact-checking experts. Longer-running efforts such as the Digital Shakti campaign and the annual eRaksha competition, run with NCERT, have built a culture of responsible digital citizenship among young and first-time internet users since 2019, while CyberPeace Corps, the foundation's volunteer arm, carries the same message into classrooms and campuses through cyber-awareness sessions run with universities and school networks nationwide. Notably, CyberPeace's own research on children's online safety had already flagged manipulated Army-related videos as a category of digital manipulation designed to cast doubt on official military positions, well before @MythbusterXX existed. The Army's tagline and CyberPeace's mission converge on the same insight: verification is a civic skill, not merely an institutional service.
A Season of Deepfakes
The history book of compromised defence material in the past year alone would be edifying. The International Federation of Journalists recorded one such deepfake widely circulated that relied on AI voice cloning and lip-sync tools to present the Pakistani PM conceding defeat, though the video actually contained his praise for the Pakistani air force’s performance following Operation Sindoor.
Other similar videos featured the Indian Prime Minister, External Affairs Minister, and Home Minister allegedly apologising to Pakistan and a deepfake with a foreign head of state in voice-cloned style applauding India’s armed forces. None needed a state’s resources, but just a laptop, voice cloning available readily, and a citizenry ready to spread rather than confirm the authenticity of any such sensational information before spreading it on to the masses.
Building the Verification Reflex
A resilient information ecosystem needs different actors playing complementary roles:
- Citizens: Do not equate virality with credibility. Verify all national security-related information through official sources, such as @MythbusterXX, before reposting or forwarding it.
- Journalists: Apply rigorous verification standards to live broadcasts, war-room graphics, and breaking reports, just as you would to print journalism, and avoid speculation during fast-moving military operations.
- Researchers and fact-checkers: Use open-source forensic and AI-detection technologies to authenticate questionable material. BOOM researchers, for instance, used Deepfake-o-meter to scrutinize misleading videos of political leaders before fact-checking and publishing them.
- Policymakers: Favored constitutionally proportional and carefully tailored regulations over broad-based takedown mandates. While the 2026 IT Amendment Rules require platforms to shift their obligations from compliance with takedowns towards preventive diligence on synthetic media, implementation should continue to be informed by judicial protections afforded to freedom of speech and due process.
Cyber Resilience Is National Security Now
Legal scholars examining Operation Sindoor have drawn a useful distinction between coordinated information warfare, which is strategic and intentional, and the diffuse, uncoordinated mis/disinformation that dominated timelines during the conflict, cautioning that disproportionate state responses to the latter can compromise citizens' right to know just as much as the falsehoods themselves. Getting that balance right, between speed and due process, between institutional voice and censorship, is the real test facing India's information ecosystem, in defence and far beyond it. CyberPeace has made a related argument in its own work on AI-enabled espionage: institutions such as the National Critical Information Infrastructure Protection Centre and the Defence Cyber Agency are already folding AI-based monitoring into their processes, yet no amount of institutional surveillance substitutes for a citizenry trained to spot manipulation on sight.
@MythbusterXX will not end deepfakes, and no single handle can. But it signals something CyberPeace has argued for years: resilience against synthetic and manipulated media requires authoritative institutional voices, digitally literate citizens, forensically equipped researchers, and proportionate policy, all pulling in the same direction. "Verify before you amplify" is not just an Army campaign. It is the operating discipline a democracy needs to protect its own information age.
Conclusion
@MythbusterXX can't possibly kill deepfakes and disinformation, but this marks a milestone shift towards developing an institutional resilience for India's info battlefield. For, after all, national security in the age of info warfare depends less on tech and more on robust institutions, constitutional balance in policymaking, responsible social platforms, and a citizenry that clicks "forward" only after clicking "verify."
* * * * *
This piece is part of CyberPeace's ongoing work on misinformation, disinformation, and digital citizenship in India. For more on CyberPeace's initiatives in digital literacy and cyber resilience, visit cyberpeace.org.
Key Sources
- Dynamite News, "Indian Army launches fact-check push against deepfake videos and fake military claims" (June 2026)
- ADG PI – Indian Army, official announcement on X (@adgpi)
- Press Information Bureau, Government of India, press release on countering misinformation during Operation Sindoor
- Reuters Institute for the Study of Journalism, "Truth is the casualty: How Indian fact-checkers debunked false claims during the India-Pakistan crisis"
- International Federation of Journalists, "AI, Deepfakes, and the Fog of War" and "Operation Sindoor and the Two Wars" (June 2025)
- Republic World, "Operation Sindoor Haunts Pakistan: Islamabad's Latest AI Deepfake Bid Against Indian Army Chief General Dhiraj Seth Exposed" (July 2026)
- TechPolicy Press, "Sanity Prevails as Bombay High Court Strikes Down India Government's Fact Check Unit", and LiveLaw, coverage of the tie-breaker verdict, on the IT Amendment Rules, 2023 (Fact-Check Unit)
- Dark Reading, "Indian Army Propaganda Spread by 1.4K AI-Powered Social Media Accounts"
- Inforrm, "(Dis)information warfare and the right to know: lessons from Operation Sindoor"
- CyberPeace Foundation, initiatives page and The CyberPeace Initiative (Google.org-backed digital literacy programme)
- CyberPeace Foundation, "AI-Powered Espionage: How India's Cybersecurity Strategy Must Evolve"
- CyberPeace Foundation, "From Deepfakes to Due Diligence – Decoding India's IT Amendment Rules"
- Wikipedia, CyberPeace Foundation (background on Digital Shakti and eRaksha)