#FactCheck: False Claim About Indian Flag Hoisted in Balochistan amid the success of Operation Sindoor
Executive Summary:
A video circulating on social media claims that people in Balochistan, Pakistan, hoisted the Indian national flag and declared independence from Pakistan. The claim has gone viral, sparking strong reactions and spreading misinformation about the geopolitical scenario in South Asia. Our research reveals that the video is misrepresented and actually shows a celebration in Surat, Gujarat, India.

Claim:
A viral video shows people hoisting the Indian flag and allegedly declaring independence from Pakistan in Balochistan. The claim implies that Baloch nationals are revolting against Pakistan and aligning with India.

Fact Check:
After researching the viral video, it became clear that the claim was misleading. We took key screenshots from the video and performed a reverse image search to trace its origin. This search led us to one of the social media posts from the past, which clearly shows the event taking place in Surat, Gujarat, not Balochistan.

In the original clip, a music band is performing in the middle of a crowd, with people holding Indian flags and enjoying the event. The environment, language on signboards, and festive atmosphere all confirm that this is an Indian Independence Day celebration. From a different angle, another photo we found further proves our claim.

However, some individuals with the intention of spreading false information shared this video out of context, claiming it showed people in Balochistan raising the Indian flag and declaring independence from Pakistan. The video was taken out of context and shared with a fake narrative, turning a local celebration into a political stunt. This is a classic example of misinformation designed to mislead and stir public emotions.
To add further clarity, The Indian Express published a report on May 15 titled ‘Slogans hailing Indian Army ring out in Surat as Tiranga Yatra held’. According to the article, “A highlight of the event was music bands of Saifee Scout Surat, which belongs to the Dawoodi Bohra community, seen leading the yatra from Bhagal crossroads.” This confirms that the video was from an event in Surat, completely unrelated to Balochistan, and was falsely portrayed by some to spread misleading claims online.

Conclusion:
The claim that people in Balochistan hoisted the Indian national flag and declared independence from Pakistan is false and misleading. The video used to support this narrative is actually from Surat, Gujarat, India, during “The Tiranga Yatra”. Social media users are urged to verify the authenticity and source of content before sharing, to avoid spreading misinformation that may escalate geopolitical tensions.
- Claim: Mass uprising in Balochistan as citizens reject Pakistan and honor India.
- Claimed On: Social Media
- Fact Check: False and Misleading
Related Blogs

Somewhere in a compliance meeting right now, someone is saying "we have eighteen months, we're fine." That sentence is doing the same thing a snooze button does at 6 a.m.: technically buying time, while quietly making the actual wake up call worse. India's data protection law just started its countdown, and the 18 months everyone keeps citing is not a grace period to procrastinate through. It is closer to a runway before takeoff. Runways exist for one purpose: building up speed until the plane has no choice but to leave the ground. Standing still on one is not a strategy.
What actually got notified, and when
On 13 November 2025, the Ministry of Electronics and Information Technology notified the Digital Personal Data Protection Rules, 2025, giving operational shape to the Digital Personal Data Protection Act that Parliament had passed back in August 2023. Alongside the Rules themselves, MeitY issued a separate Enforcement Notification setting out exactly when different provisions kick in, and a further notification establishing the Data Protection Board of India, headquartered in the National Capital Region with four members. The final Rules followed a genuinely deliberative process, MeitY had floated draft Rules in January 2025 for public consultation and received 6,915 individual inputs from startups, industry bodies, civil society groups, and citizens before finalising the version now in force. The headline structural decision, and the one causing the most confusion in boardrooms, is that the Rules do not commence all at once. They commence in three distinct phases spread across eighteen months, and different obligations become legally binding at each stage.
The phased timeline, laid out plainly

That third date, 13 May 2027, is the one that matters most for the vast majority of organisations, since it is where the bulk of actual operational obligations, the parts that touch product design, customer facing notices, and breach response, become enforceable. Legal commentary tracking the rollout has been consistent that this is described as a hard deadline with no grace period expected once it arrives, since the Data Protection Board is already operational and can begin receiving complaints well before Phase 3 obligations formally take effect.
Why "later" is a genuinely expensive plan
The financial stakes attached to Phase 3 non-compliance are not modest. The Schedule to the DPDP Act sets fixed penalty ceilings rather than turnover linked fines, which sounds gentler than Europe's GDPR model until you look at the actual numbers. Failure to implement reasonable security safeguards that results in a data breach can draw a penalty of up to 250 crore rupees per instance, the single highest tier in the Schedule. Failing to notify the Board or affected individuals after a breach occurs can draw up to 200 crore rupees, as can non-compliance with the Act's specific protections for children's data. Because these are assessed per instance rather than as a single capped exposure, a single incident that trips more than one obligation, say, inadequate safeguards that also delay breach notification, can compound into penalty exposure running into hundreds of crores from one event. All penalties collected go to the Consolidated Fund of India rather than to affected individuals directly, meaning the deterrent is aimed squarely at organisational behaviour, not compensation.
The part everyone keeps underestimating: this is not just a legal department problem
Perhaps the most consequential shift buried inside the DPDP framework is who actually has to own it. Reading the Rules as a checklist for the legal or privacy team alone misses how far the obligations actually reach. Building a compliant consent lifecycle touches product design. Security safeguards touch cybersecurity and IT infrastructure directly. Retention and deletion logic touches data governance and engineering. Third party risk review touches procurement. Breach preparedness touches internal audit and incident response. And increasingly, as organisations deploy AI systems that process personal data, AI governance enters the picture too, since a model trained or fine tuned on personal data inherits the same DPDP obligations as any other processing activity.
That cross functional reality is where most readiness programmes currently fall short. Treating DPDP compliance as a documentation exercise, updating a privacy policy PDF and calling it done, produces the appearance of compliance without the operational substance a Data Protection Board investigation would actually test. A breach response plan that exists only on paper and has never been rehearsed will not hold up against the 72 hour data principal notification window the Rules impose once Phase 3 lands. A consent mechanism bolted onto a website without corresponding backend logic to honour withdrawal requests will not satisfy an actual audit.
What a serious readiness posture looks like right now
Organisations that are ahead of this curve are already treating the eighteen month window as three overlapping workstreams rather than one deadline to hit at the end.
- The first is discovery: mapping what personal data exists, where it flows, who owns each system that touches it, and why it is collected in the first place, since compliance is structurally impossible without first knowing what you are protecting. This stage typically surfaces uncomfortable findings, shadow data sets nobody formally owns, vendor integrations nobody fully mapped, legacy systems still holding data well past any reasonable retention justification.
- The second is build: standing up the actual mechanisms, consent flows that can genuinely honour a withdrawal request end to end, rights request handling that does not depend on a single overworked employee checking an inbox, retention and deletion logic wired into the systems themselves rather than described only in a policy document, and security controls proportionate to the sensitivity of what is being protected.
- The third is proof: generating the internal evidence, audit trails, documented decisions, tested response procedures, that demonstrates governance was real rather than retrofitted after the fact. A Data Protection Board investigation, when it eventually happens, will not be satisfied by a well written policy; it will look for evidence that the policy was actually operational.
The actual question worth asking
The right question was never "when does DPDP become enforceable." Phase 1 already answered that; the law is live, and the Data Protection Board already exists and can act. The better question, the one worth taking into any leadership review between now and May 2027, is simpler and considerably less comfortable: will the organisation actually be ready when each phase's obligations become operational, or will readiness be assembled in a scramble once the deadline stops being theoretical. 18 months sounds long right up until the week it does not, and by the time Phase 3 lands, "we'll get to it" will no longer be a sentence any organisation gets to finish.
References
- Ministry of Electronics and Information Technology, Digital Personal Data Protection Rules, 2025, notified 13 November 2025. Press Information Bureau, "Digital Personal Data Protection Rules, 2025 Notified," 14 November 2025. https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc20251117695301.pdf
- Shardul Amarchand Mangaldas & Co, "Enforcement of the DPDP Act and notification of the DPDP rules." https://www.amsshardul.com/insight/enforcement-of-the-dpdp-act-and-notification-of-the-dpdp-rules/
- S&R Associates, "India's Digital Personal Data Protection Regime Takes Effect." https://www.snrlaw.in/indias-digital-personal-data-protection-regime-takes-effect/
- Khurana & Khurana, "MeitY Notifies Rules Operationalising The DPDP Framework." https://www.khuranaandkhurana.com/update-meity-notifies-rules-operationalising-the-dpdp-framework-in-india
- Exchange4media, "DPDP Act 2025: Penalties for violations can reach Rs 250 crore." https://www.exchange4media.com/digital-news/dpdp-act-2025-penalties-for-confirmed-violations-can-reach-rs-250-crore-149360.html
- Seclore, "DPDP Rules 2025: India's Complete Compliance Guide." https://www.seclore.com/fundamentals/dpdp-rules-2025-compliance-guide/

Introduction
Devices and interconnectivity are the pipelines which drive the data into cyberspace, and in turn, the users consume this data to perform different tasks in the digital age. The security of devices and networks is essential as they are the first defenders of cyberspace. Bad actors often target systems and networks with malware and ransomware, these attacks are differently motivated, but all wreak havoc upon the system and can impact individuals and organisations alike. Mobile users worldwide prefer iOS or Android, but both operating systems are vulnerable to cyberattacks these days. Some of these attacks go undetected for a long time.
Op Triangulation
As reported by Kaspersky, While monitoring the network traffic of their own corporate Wi-Fi network dedicated to mobile devices using the Kaspersky Unified Monitoring and Analysis Platform (KUMA), Kaspersky noticed suspicious activity that originated from several iOS-based phones. Since it is impossible to inspect modern iOS devices from the inside, they created offline backups of the devices in question, inspected them using the Mobile Verification Toolkit’s mvt-ios and discovered traces of compromise. This is known as Operation Triangulation and has been in action since 2019 and got detected in 2023.
The Malware
A portion of the filesystem, including some of the user data and service databases, is included in mobile device backups. The files, directories, and database entries’ timestamps make it possible to reconstruct the events that happened to the device roughly. The “timeline.csv” file created by the mvt-ios software contains a sorted timeline of events that is comparable to the super-timeline utilised by traditional digital forensic tools. Pinpointing particular artefacts that show the compromise using this timeframe. This made it possible to advance the research and reassemble the broad infection sequence:
Through the iMessage service, a message with an attachment containing an exploit is delivered to the target iOS device.
The message initiates a vulnerability that results in code execution without any user input.
The exploit’s code downloads multiple additional stages, including additional exploits for privilege escalation, from the C&C server.
After successful exploitation, a fully functional APT platform is downloaded as the final payload from the C&C server.
The first message and the attachment’s exploit are removed

The lack of persistence support in the harmful toolset is most likely a result of OS restrictions. Multiple devices’ timeframes suggest that after rebooting, they might get infected again. The earliest signs of infection that we found date to 2019. The most recent version of the devices that have been successfully attacked as of the time of writing in June 2023 is iOS 15.7.
The final payload analysis is still ongoing. The programme executes with root rights, implements a set of commands for gathering user and system data, and can run any code downloaded as plugin modules from the C&C server.
Malicious Domains
Using the forensic artefacts, it was possible to identify the domain name set used by the exploits and further malicious stages. They can be used to check the DNS logs for historical information and to identify the devices currently running the malware:
addatamarket[.]net
backuprabbit[.]com
businessvideonews[.]com
cloudsponcer[.]com
datamarketplace[.]net
mobilegamerstats[.]com
snoweeanalytics[.]com
tagclick-cdn[.]com
topographyupdates[.]com
unlimitedteacup[.]com
virtuallaughing[.]com
web-trackers[.]com
growthtransport[.]com
anstv[.]netAns7tv[.]net
Safeguards for iOS users
Despite its world-class safety and privacy architecture, iOS is vulnerable to a few attacks; the following steps can be undertaken to safeguard iOS users –
Keeping Device updated
Security patches
Disabling iMessage would prevent Zero clicks exploits or the Triangulation attacks
Paying zero attention to unwanted, unsolicited messages
The user should make sure that any application they are downloading or installing; it should be from a trusted source ( This Zero click attack does not occur by any other means, It exploits / it targets software vulnerabilities in operating systems networks and applications)
Being cautious with the messaging app and emails
Implement device restrictions (management features like parental control and restrictions over using necessary applications)

Conclusion
Operation Triangulation is one of the recent operations combating cyber attacks, but such operations are launched nearly daily. This is also due to a rapid rise in internet and technology penetration across the world. Cyberattacks have taken a new face as they have evolved with the new and emerging technology. The influence of the Darknet has allowed many hackers to remain on the black hat side due to easy accessibility to illegal tools and material over the dark net, which facilitates such crimes.

Overview:
In today’s digital landscape, safeguarding personal data and communications is more crucial than ever. WhatsApp, as one of the world’s leading messaging platforms, consistently enhances its security features to protect user interactions, offering a seamless and private messaging experience
App Lock: Secure Access with Biometric Authentication
To fortify security at the device level, WhatsApp offers an app lock feature, enabling users to protect their app with biometric authentication such as fingerprint or Face ID. This feature ensures that only authorized users can access the app, adding an additional layer of protection to private conversations.
How to Enable App Lock:
- Open WhatsApp and navigate to Settings.
- Select Privacy.
- Scroll down and tap App Lock.
- Activate Fingerprint Lock or Face ID and follow the on-screen instructions.

Chat Lock: Restrict Access to Private Conversations
WhatsApp allows users to lock specific chats, moving them to a secured folder that requires biometric authentication or a passcode for access. This feature is ideal for safeguarding sensitive conversations from unauthorized viewing.
How to Lock a Chat:
- Open WhatsApp and select the chat to be locked.
- Tap on the three dots (Android) or More Options (iPhone).
- Select Lock Chat
- Enable the lock using Fingerprint or Face ID.

Privacy Checkup: Strengthening Security Preferences
The privacy checkup tool assists users in reviewing and customizing essential security settings. It provides guidance on adjusting visibility preferences, call security, and blocked contacts, ensuring a personalized and secure communication experience.
How to Run Privacy Checkup:
- Open WhatsApp and navigate to Settings.
- Tap Privacy.
- Select Privacy Checkup and follow the prompts to adjust settings.

Automatic Blocking of Unknown Accounts and Messages
To combat spam and potential security threats, WhatsApp automatically restricts unknown accounts that send excessive messages. Users can also manually block or report suspicious contacts to further enhance security.
How to Manage Blocking of Unknown Accounts:
- Open WhatsApp and go to Settings.
- Select Privacy.
- Tap to Advanced
- Enable Block unknown account messages

IP Address Protection in Calls
To prevent tracking and enhance privacy, WhatsApp provides an option to hide IP addresses during calls. When enabled, calls are routed through WhatsApp’s servers, preventing location exposure via direct connections.
How to Enable IP Address Protection in Calls:
- Open WhatsApp and go to Settings.
- Select Privacy, then tap Advanced.
- Enable Protect IP Address in Calls.

Disappearing Messages: Auto-Deleting Conversations
Disappearing messages help maintain confidentiality by automatically deleting sent messages after a predefined period—24 hours, 7 days, or 90 days. This feature is particularly beneficial for reducing digital footprints.
How to Enable Disappearing Messages:
- Open the chat and tap the Chat Name.
- Select Disappearing Messages.
- Choose the preferred duration before messages disappear.

View Once: One-Time Access to Media Files
The ‘View Once’ feature ensures that shared photos and videos can only be viewed a single time before being automatically deleted, reducing the risk of unauthorized storage or redistribution.
How to Send View Once Media:
- Open a chat and tap the attachment icon.
- Choose Camera or Gallery to select media.
- Tap the ‘1’ icon before sending the media file.

Group Privacy Controls: Manage Who Can Add You
WhatsApp provides users with the ability to control group invitations, preventing unwanted additions by unknown individuals. Users can restrict group invitations to ‘Everyone,’ ‘My Contacts,’ or ‘My Contacts Except…’ for enhanced privacy.
How to Adjust Group Privacy Settings:
- Open WhatsApp and go to Settings.
- Select Privacy and tap Groups.
- Choose from the available options: Everyone, My Contacts, or My Contacts Except

Conclusion
WhatsApp continuously enhances its security features to protect user privacy and ensure safe communication. With tools like App Lock, Chat Lock, Privacy Checkup, IP Address Protection, and Disappearing Messages, users can safeguard their data and interactions. Features like View Once and Group Privacy Controls further enhance confidentiality. By enabling these settings, users can maintain a secure and private messaging experience, effectively reducing risks associated with unauthorized access, tracking, and digital footprints. Stay updated and leverage these features for enhanced security.