#FactCheck: Old EVM Protest Video Misleadingly Shared as Demonstration Against Chief Election Commissioner Gyanesh Kumar
Executive Summary
A video is being shared on social media with the claim that it shows a protest against Chief Election Commissioner Gyanesh Kumar in Delhi. A large number of people can be seen protesting in the video. CyberPeace Research found that the video is not related to any recent protest against Chief Election Commissioner Gyanesh Kumar. Our Research revealed that the video is from a protest against Electronic Voting Machines (EVMs) held at Jantar Mantar in Delhi on January 31, 2024.
Claim:
The video was shared on X with a caption claiming that, “Despite heavy rain, Gen-Z, the youth of the country, have once again taken to the streets of Delhi to protest against the dictatorship of the BJP government, raising slogans of ‘Remove EVMs and Remove the Chief Election Commissioner.’ Remove EVMs, save democracy; remove BJP, save the country; remove BJP, save the Constitution.”
https://x.com/yadavanoop08/status/2103713972256166204

Fact Check
To verify the viral video being shared with the claim that it shows a protest against Chief Election Commissioner Gyanesh Kumar in Delhi, we conducted a reverse image search using keyframes from the video. We found the same video uploaded on a Facebook account on January 31, 2024. The caption accompanying the video described it as a protest against Electronic Voting Machines (EVMs).
https://www.facebook.com/watch/?v=3672972219640920

During the same search, we also found the video uploaded on another Facebook account on January 31, 2024. The post described the video as showing a protest held at Jantar Mantar in Delhi.
https://www.facebook.com/watch/?v=397803899424353

We then checked Vaman Meshram’s Facebook account and found several photographs related to the protest held at Jantar Mantar on January 31, 2024. The visuals in these photographs match the scenes seen in the viral video.
https://www.facebook.com/photo/?fbid=954806319346006&set=pcb.954806489345989

Conclusion
The evidence gathered during our Research clearly establishes that the video being shared with the claim that it shows a protest against Chief Election Commissioner Gyanesh Kumar in Delhi is actually from a protest against Electronic Voting Machines (EVMs) held in 2024.
Related Blogs

Introduction
A digital forensic investigation can start with a question: what really happened? The tricky part is that the answer might be hidden in thousands of files, system logs, browser records, messages, application artefacts and timestamps. Traditional forensic practice gives a method to find, collect, check and report such evidence yet the amount of digital data keeps growing. NIST’s forensic guidance says that evidence must be kept safe its integrity checked and investigative steps written down so that results can be examined and repeated.[4] This is where Large Language Models (LLMs) draw interest. LLMs can. Summarise large amounts of text, spot connections between pieces of information and help an examiner move through evidence faster. However, an important question remains: can an LLM truly become an investigator or should it stay an assistant to one?
Understanding the basic idea: What is an LLM?
A Large Language Model is an AI system trained on collections of text so that it can learn language patterns and produce answers. In terms an LLM does not think like a human investigator. An LLM creates language from patterns it learned during training and from the details it receives. This makes an LLM handy for summarisation, classification, question answering and pulling information from text.
Where LLMs can actually help a forensic examiner

Finding relevant evidence faster
Consider a case involving a suspected phishing incident. A forensic examiner may have email headers, message bodies, attachments, browser history, DNS records and system logs. An LLM can help organize text-based evidence, spot repeated terms pull out indicators such as domains or IP addresses and cluster related events for review. Research on LLM-assisted forensics says that pattern recognition and early evidence analysis are promising use cases.[1][3]
Connecting the timeline
Investigations often rely on order: what happened first what followed and which artefacts back that order. An LLM can turn amounts of timestamped data into a clear timeline or point out records that seem related. The key point is that the LLM helps an examiner see relationships; it does not independently prove that one event caused another.
Making forensic reporting easier to understand
A good forensic report should be understandable to technical and non-technical readers. LLMs can help turn examiner notes or structured findings into clearer draft language, summaries or executive explanations. This is particularly useful when an investigation contains technical terms that need to be explained without losing their meaning. Research also identifies evidence presentation and reporting as a potential area for LLM assistance.[1]
A realistic example
Imagine an organisation reports that an employee account may have been compromised. The examiner collects the relevant disk image, authentication logs, browser history and email data using established procedures. After preservation and examination with validated tools, a controlled set of extracted text or structured artefacts could be given to an LLM. It might identify unusual login patterns, highlight a suspicious domain appearing in multiple sources, and draft questions for further examination.
The examiner then checks those observations against the original evidence and forensic tool outputs. If the model says a login occurred at 10:14, that timestamp must be verified in the source log. If it suggests that two events are linked, the relationship must be supported by evidence. The model can accelerate the search, but the evidence remains the foundation of the conclusion.
Why an LLM cannot simply replace the investigator

The biggest challenge is reliability. LLMs can produce fluent answers that sound convincing even when the answer is wrong. The 2026 systematic review of 33 peer-reviewed works on LLMs in digital forensics highlights hallucination, explainability, reproducibility and legal admissibility as major concerns.[1] In forensic work, an incorrect sentence is not just a minor inconvenience; it can change how a case is understood.
There is also a reproducibility problem. Traditional forensic practice depends on validated processes, integrity checks and documentation. NIST recommends verifying acquired data and recording actions and tools so work can be repeated.[4] LLM output can vary with the model, settings, context and system version. That makes raw model output unsuitable as forensic proof on its own.
Another concern is confidentiality. Evidence may contain personal information, credentials, private communications or sensitive organisational data. Sending it to an external AI service without proper controls can create a privacy and governance risk. NIST’s Generative AI Profile stresses managing risks across the AI lifecycle.[5]
What responsible LLM-assisted forensics could look like
A practical approach is to keep the examiner in control. The LLM should receive only the information needed for the task, preferably through a controlled environment with access restrictions and logging. Critical findings should always link back to the source artefact rather than being accepted because the model sounds confident.
A simple operational principle is: -

In practice, this means preserving and hashing evidence, using validated forensic tools for acquisition and examination, recording what data was supplied to the AI system, retaining relevant prompts and outputs in working notes, and independently verifying material claims. SWGDE guidance likewise emphasises protecting the integrity of evidence and documenting handling throughout the evidence lifecycle.[6]
A further possibility is a local or specialised forensic model. Research on “ForensicLLM” demonstrates this direction, including source attribution and retrieval-augmented approaches.[2] Such designs may provide a more controlled environment, but they still require testing and validation before operational use.
Conclusion
LLMs are unlikely to make the forensic examiner irrelevant. Their more realistic value is in helping the examiner deal with the scale and complexity of modern evidence. They can search, summarise, classify, correlate and help communicate findings, but these capabilities come with limitations that matter deeply in forensic work. A forensic conclusion must remain traceable to evidence, repeatable through a documented process and open to independent verification.[1][4]
The future of AI-assisted digital forensics is therefore less about replacing investigators and more about designing a disciplined partnership between human expertise and machine assistance. The strongest model is one in which AI speeds up the routine parts of an investigation while the examiner remains responsible for validation, interpretation and final conclusions. As research develops, the real question will not simply be whether an LLM is intelligent enough to analyse evidence, but whether the complete system around it is controlled, explainable and trustworthy enough for forensic use.
References / Endnotes
[1] Chernyshev, M., Baig, Z., Syed, N., Doss, R., & Shore, M. (2026). “Large language models in digital forensics: capabilities, challenges and future directions.” Forensic Science International: Digital Investigation, 56, 302043. https://doi.org/10.1016/j.fsidi.2025.302043
[2] “ForensicLLM: A local large language model for digital forensics.” Forensic Science International: Digital Investigation, 52, Supplement, 301872 (2025). https://doi.org/10.1016/j.fsidi.2025.301872
[3] Wickramasekara, A., Breitinger, F., & Scanlon, M. (2025). “Exploring the Potential of Large Language Models for Improving Digital Forensic Investigation Efficiency.” Forensic Science International: Digital Investigation, 52, 301859. https://doi.org/10.1016/j.fsidi.2024.301859
[4] Kent, K., Chevalier, S., Grance, T., & Dang, H. (2006). Guide to Integrating Forensic Techniques into Incident Response, NIST Special Publication 800-86. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.SP.800-86
[5] Autio, C., Schwartz, R., Dunietz, J., Jain, S., Stanley, M., Tabassi, E., Hall, P., & Roberts, K. (2024). Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile, NIST AI 600-1. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.AI.600-1
[6] Scientific Working Group on Digital Evidence (SWGDE). Best Practices for Digital Evidence Collection, 18-F-002-2.0. https://www.swgde.org/documents/published-complete-listing/18-f-002-2-0/

Introduction
Established in the US, one of the world’s largest cab networks came into existence in 2010 and, since its inception, has expanded all over the globe with operations in 10,000 cities across 71 countries. It made a remarkable start in India in 2017 and, since then, has seen a rise in the customers and drivers for the company. India is among the largest markets for Uber, with 600,000 monthly drivers and 8.5 million monthly riders.
GeM
Government e-Marketplace (GeM) is a one-stop portal to facilitate online procurement of common-use Goods & Services required by various Government Departments / Organizations / PSUs. GeM aims to enhance transparency, efficiency and speed in public procurement. It provides the tools of e-bidding, reverses e-auction and demand aggregation to facilitate government users achieve the best value for their money. Government e-Marketplace owes its genesis to the recommendations of two Groups of Secretaries to the Prime Minister in January 2016. They recommended setting up a dedicated e-market for different goods & services procured or sold by Government/PSUs besides reforming DGS&D. Subsequently, the Finance Minister, in his Budget speech for FY 2016-17, announced setting up of a technology-driven platform to facilitate procurement of goods and services by various Ministries and agencies of the Government. The portal was launched on 9th August 2016 by the Commerce & Industry Minister.
Uber-GeM collaboration
The cab network giant has registered on the portal of the Government E-marketplace and has declared that it will offer its services to Government officials from Ministries and PSUs. The project is currently in its pilot phase and shall be executed systematically to cover all the ministries and PSUs in the nation. The officials can book cabs at a fixed price with no cancellation or surge fees on the rides. The authorised officials will be able to book a cab from the portal and select from the list of drivers available. It will be a cashless/cardless ride for the officials; additional vehicle categories for government riders have been added, namely, GeM Yatraa Hatch and GeM Yatraa Sedan, and there will be hourly rentals for multiple-stops, allowing the government officials to enjoy the flexible and easily accessible network of cabs in major cities.
Advantages
Such collaboration between Government institutions and corporates will go a long way to secure a stable equilibrium in the market. Uber, a US-based company, enjoys a vast user base in India and has created new job avenues. The advantages of the collaboration between GeM and Uber are as follows-
Easy accessibility
This will undoubtedly provide ease in accessibility in terms of being in a new place, and language barriers will no longer exist with such options for Government officials.
Increased jobs for drivers
With more cabs being engaged with ministries and PSUs, it is pertinent that the requirement for drivers will grow, thus increasing the employability rate in India and allowing the user to have an uninterrupted experience.
Ease of travel and commuting
This move will provide flexibility, thus leading to more ease in travel in cases of emergencies or places inaccessible by trains or other modes of transport.
Rise in travel and tourism
Coupled with the other factors, the opportunities for the users to visit different places will be an added advantage which will help boost the tourism industry, thus creating a balance in the market.
Sustainable Government corporate relationship

Such collaborations between the government and corporates will be substantial, signifying the ease of doing business in India. They will also act as a beacon of example for compliance with opportunities for the other companies and stakeholders.
Opportunities for collaboration with ingenious start-ups
With such major corporate joining hands with the government, the indigenous start-ups will have various opportunities to engage with companies and recreate similar businesses rooted in India, thus transforming the economy.
Conclusion
Transportation and communication play a vital role in our lives, thus, such collaboration will go a long way in creating a better and more uniform user experience in the country. This also goes a long way to showcase that the Governmental platforms also offer services of a global standard. Such portals exist in South Korea, Singapore, the US and Europe. The network of cabs can only be sustained using the locals as drivers, hence these collaborations are win-win for all as the market dynamics are improving, employability will increase, and improved user experience will be seen.

Introduction
In the sprawling online world, trusted relationships are frequently taken advantage of by cybercriminals seeking to penetrate guarded systems. The Watering Hole Attack is one advanced method, which focuses on a user’s ecosystem by compromising the genuine sites they often use. This attack method is different from phishing or direct attacks as it quietly exploits the everyday browsing of the target to serve malicious content. The quiet and exact nature of watering hole attacks makes them prevalent amongst Advanced Persistent Threat (APT) groups, especially in conjunction with state-sponsored cyber-espionage operations.
What Qualifies as a Watering Hole Attack?
A Watering Hole Attack targets and infects a trusted website. The targeted website is one that is used by a particular organization or community, such as a specific industry sector. This type of cyberattack is analogous to the method of attack used by animals and predators waiting by the water’s edge for prey to drink. Attackers prey on their targets by injecting malicious code, such as an exploit kit or malware loader, into websites that are popular with their victims. These victims are then infected when they visit said websites unknowingly. This opens as a gateway for attackers to infiltrate corporate systems, harvest credentials, and pivot across internal networks.
How Watering Hole Attacks Unfold
The attack lifecycle usually progresses as follows:
- Reconnaissance - Attackers gather intelligence on the websites frequented by the target audience, including specialized communities, partner websites, or local news sites.
- Website Exploitation - Through the use of outdated CMS software and insecure plugins, attackers gain access to the target website and insert malicious code such as JS or iframe redirections.
- Delivery and Exploitation - The visitor’s browser executes the malicious code injected into the page. The code might include a redirection payload which sends the user to an exploit kit that checks the user’s browser, plugins, operating system, and other components for vulnerabilities.
- Infection and Persistence - The infected system malware such as RATs, keyloggers, or backdoors. These enable lateral and long-term movements within the organisation for espionage.
- Command and Control (C2) - For further instructions, additional payload delivery, and stolen data retrieval, infected devices connect to servers managed by the attackers.
Key Features of Watering Hole Attacks
- Indirect Approach: Instead of going after the main target, attackers focus on sites that the main target trusts.
- Supply-Chain-Like Impact: An infected industry portal can affect many companies at the same time.
- Low Profile: It is difficult to identify since the traffic comes from real websites.
- Advanced Customization: Exploit kits are known to specialize in making custom payloads for specific browsers or OS versions to increase the chance of success.
Why Are These Attacks Dangerous?
Worming hole attacks shift the battlefield to new grounds in cyber warfare on the web. They eliminate the need for firewalls, email shields, and other security measures because they operate on the traffic to and from real, trusted websites. When the attacks work as intended, the following consequences can be expected:
- Stealing Credentials: Including privileged accounts and VPN credentials.
- Espionage: Theft of intellectual property, defense blueprints, or government confidential information.
- Supply Chain Attacks: Resulting in a series of infections among related companies.
- Zero-Day Exploits: Including automated attacks using zero-day exploits for full damage.
Incidents of Primary Concern
The implications of watering hole attacks have been felt in the real world for quite some time. An example from 2019 reveals this, where a known VoIP firm’s site was compromised and used to spread data-stealing malware to its users. Likewise, in 2014, the Operation Snowman campaign—which seems to have a state-backed origin—attempted to infect users of a U.S. veterans’ portal in order to gain access to visitors from government, defense, and related fields. Rounding up the list, in 2021, cybercriminals attacked regional publications focusing on energy, using the publications to spread malware to company officials and engineers working on critical infrastructure, as well as to steal data from their systems. These attacks show the widespread and dangerous impact of watering hole attacks in the world of cybersecurity.
Detection Issues
Due to the following reasons, traditional approaches to security fail to detect watering hole attacks:
- Use of Authentic Websites: Attacks involving trusted and popular domains evade detection via blacklisting.
- Encrypted Traffic: Delivering payloads over HTTPS conceals malicious scripts from being inspected at the network level.
- Fileless Methods: Using in-memory execution is a modern campaign technique, and detection based on signatures is futile.
Mitigation Strategies
To effectively neutralize the threat of watering hole attacks, an organization should implement a defense-in-depth strategy that incorporates the following elements:
- Patch Management and Hardening -
- Conduct routine updates on operating systems, web browsers, and extensions to eliminate exploit opportunities.
- Either remove or reduce the use of high-risk elements such as Flash and Java, if feasible.
- Network Segmentation - Minimize lateral movement by isolating critical systems from the general user network.
- Behavioral Analytics - Implement Endpoint Detection and Response (EDR) tools to oversee unusual behaviors on processes—for example, script execution or dubious outgoing connections.
- DNS Filtering and Web Isolation - Implement DNS-layer security to deny access to known malicious domains and use browser isolation for dangerous sites.
- Threat Intelligence Integration - Track watering hole threats and campaigns for indicators of compromise (IoCs) on advisories and threat feeds.
- Multi-Layer Email and Web Security - Use web gateways integrated with dynamic content scanning, heuristic analysis, and sandboxing.
- Zero Trust Architecture - Apply least privilege access, require device attestation, and continuous authentication for accessing sensitive resources.
Incident Response Best Practices
- Forensic Analysis: Check affected endpoints for any mechanisms set up for persistence and communication with C2 servers.
- Log Review: Look through proxy, DNS, and firewall logs to detect suspicious traffic.
- Threat Hunting: Search your environment for known Indicators of Compromise (IoCs) related to recent watering hole attacks.
- User Awareness Training: Help employees understand the dangers related to visiting external industry websites and promote safe browsing practices.
The Immediate Need for Action
The adoption of cloud computing and remote working models has significantly increased the attack surface for watering hole attacks. Trust and healthcare sectors are increasingly targeted by nation-state groups and cybercrime gangs using this technique. Not taking action may lead to data leaks, legal fines, and break-ins through the supply chain, which damage the trustworthiness and operational capacity of the enterprise.
Conclusion
Watering hole attacks demonstrate how phishing attacks evolve from a broad attack to a very specific, trust-based attack. Protecting against these advanced attacks requires the zero-trust mindset, adaptive defenses, and continuous monitoring, which is multicentral security. Advanced response measures, proactive threat intelligence, and detection technologies integration enable organizations to turn this silent threat from a lurking predator to a manageable risk.
References
- https://www.fortinet.com/resources/cyberglossary/watering-hole-attack
- https://en.wikipedia.org/wiki/Watering_hole_attack
- https://www.proofpoint.com/us/threat-reference/watering-hole
- https://www.techtarget.com/searchsecurity/definition/watering-hole-attack