#FactCheck: Old Ukraine Blast Video Falsely Shared as Iran Strike on Israeli Nuclear Site
Executive Summary
A video showing a massive fire and explosion is going viral on social media. The clip shows a large plume of smoke followed by a sudden blast. It is being shared with the claim that it depicts Iran attacking a nuclear reactor in Israel amid the ongoing Iran-Israel conflict. However, research by CyberPeace found that the claim is misleading. The viral video is actually from 2017 and shows a massive explosion at an ammunition depot in Ukraine.
Claim:
On social media platform X (formerly Twitter), a user shared the video on March 21, 2026, with the caption:“Israel’s nuclear reactor was targeted with Fateh and Khyber missiles. Well done Iran! The whole world is with you.”

Fact Check:
To verify the viral claim, we extracted keyframes from the video and conducted a reverse image search. During this process, we found the same video uploaded on March 23, 2017, on a YouTube channel named “null.” According to the upload, the video shows a massive explosion at an ammunition depot in Balakliya, Ukraine. Using these clues, we performed a keyword search and found a report published on March 24, 2017, by Global News.

According to the report, a major fire and explosion broke out at a large military ammunition depot in Balakliya, located in Ukraine’s Kharkiv region. The incident resulted in one death, while nearly 20,000 people from surrounding areas were evacuated to safer locations.
Conclusion:
The claim that the video shows Iran attacking a nuclear reactor in Israel is misleading. The viral footage is actually from 2017 and depicts an explosion at an ammunition depot in Ukraine.
Related Blogs

CERT-In, India's national cybersecurity agency, operates under mounting pressure. Cyberattacks in the country have doubled from 1.4 million in FY2022 to 2.9 million in FY2026, even as the window between a vulnerability's discovery and its exploitation continues to narrow. Rather than wait for access to the most advanced AI security tools, some of which face export restrictions, the agency has spent recent months building its own solution.
CERT-In has developed a new sandbox platform built with open-source AI, designed to identify cybersecurity gaps in public-sector systems. The sandbox functions as an isolated testing environment, allowing teams to safely evaluate software and applications without exposing the broader system to risk. Officials have framed this as a foundation rather than a substitute. MeitY Secretary S Krishnan described the platform as a step toward building a secure environment for eventual access to international AI models — suggesting the current approach is understood as an interim measure, not a permanent alternative to global tools.
This effort sits within a broader policy push: encouraging domestic AI development and tightening oversight of AI use in finance and online content. Taken together, these moves suggest a deliberate strategy of capacity-building through incremental, self-reliant steps, rather than a story about capability gaps or resource shortfalls.
A Crisis Measured in Millions
It helps to look at why this matters so much right now. A joint study by the Data Security Council of India and BCG found that recorded cyberattacks in the country roughly doubled in four years, from about 1.4 million in FY22 to 2.9 million in FY26. What's more worrying is how little time defenders now have to react to the average time it takes attackers to exploit a newly found vulnerability dropped from 745 days in FY22 to just 44 days in FY26, largely because attackers are using AI themselves to scout targets and build exploits faster. Banking, financial services, healthcare, telecom and government portals bear the brunt of this, with ransomware-as-a-service groups and state-linked actors increasingly slipping in through vendor portals and supply-chain weak points.
Turning Existing AI Into a Working Defence
CERT-In's Sandbox in Action
Instead of treating the lack of any one frontier model as a dealbreaker, CERT-In simply built its own closed trial platform officials have taken to calling it a "war room" where open-source and other AI models are set loose on software code to find vulnerabilities and shape secure workflows for India's top public sector companies, including in financial services. At a press conference, Meity secretary S. Krishnan pointed out that these substitute models already match roughly 60 to 70 per cent of the performance of the most advanced security-focused systems out there globally. That's a fairly substantial chunk of the capability, and it's coming from tools India can actually access today. The testing has stretched to core digital infrastructure like Aadhaar and government login systems, while some of the country's biggest tech firms are already using currently available AI models to patch widely used enterprise software, banking platforms included. The logic is simple enough: build the muscle now with whatever's on hand, so the enterprise environment is already in better shape by the time more capable tools eventually arrive.
Investing in Sovereign Capability
Arguably the more important move here is a longer-term one , India's bet on building its own frontier-grade security AI. The Centre has reportedly asked domestic AI developers Sarvam AI and BharatGen to build advanced cybersecurity capabilities of their own, hosted on the government's isolated computer infrastructure and eventually put to work protecting critical infrastructure. There's no public timeline yet for when these indigenous models will be ready, but the intent behind the move isn't hard to read: cut India's reliance on any single foreign provider for defending the systems that underpin banking, identity and public administration, while keeping sensitive testing and deployment on Indian soil. Officials have also signalled a preference for on-premises deployment of high-capability AI tools where the stakes are highest, rather than leaning entirely on overseas cloud infrastructure. It's a choice that points toward building lasting, self-reliant capacity rather than making a one-off purchase.
A Tightening Regulatory Net
RBI's Model Risk Guardrails
None of this is happening in a vacuum. On 24 June 2026, the Reserve Bank of India released draft guidance on model risk management that, for the first time, brings AI and machine learning systems used by banks, NBFCs and other regulated entities under a single, board-level governance framework. The draft asks institutions to keep a full inventory of every model they use, rank each one by risk, and build in human override and "kill-switch" mechanisms so a malfunctioning AI system can be shut down immediately. It also makes one thing very clear: banks can't shrug off accountability just because the technology came from a vendor.
MeitY's Deepfake and Synthetic-Content Rules
Around the same time, the Ministry of Electronics and Information Technology notified amendments to the IT Rules that formally define "synthetically generated information," require deepfakes and AI-altered media to carry clear, persistent labels and embedded provenance metadata, and cut the takedown window for unlawful synthetic content down to just three hours. Taken together, the RBI and MeitY rules form the regulatory backbone that CERT-In's technical sandbox is meant to plug into giving India a more coordinated response to both the defensive and the deceptive sides of AI.
One Chain of Command
Officials have gone out of their way to stress that all these moving parts aren't creating confusion in India's cybersecurity reporting structure. CERT-In director general Sanjay Bahl has said the National Security Council Secretariat remains the overarching body, with CERT-In as the top cyber reporting and investigations organisation across sectors, and that sectoral regulators like the RBI and SEBI still report into this one structure rather than running their own parallel systems.
Conclusion
Look at CERT-In's sandbox, the push for sovereign AI, and the tightening regulatory net together, and a clearer picture forms. This isn't really a story about a piece of technology India doesn't have. It's a story about capability being built, deliberately and in the open. The country is using the AI tools available right now to close real security gaps, backing homegrown alternatives for the long haul, and pairing both with governance rules that keep banks, platforms and public infrastructure honest. If there's a lesson in all this, it's that real resilience against a fast-moving cyberthreat landscape rarely arrives all at once. It gets built the way most lasting capability does piece by piece, mostly at home, without waiting for any single outside breakthrough to show up first.
References
- https://inc42.com/buzz/centre-asks-sarvam-ai-bharatgen-to-develop-mythos-like-cyber-ai-models/
- https://inc42.com/buzz/centre-asks-sarvam-ai-bharatgen-to-develop-mythos-like-cyber-ai-models/
- https://www.newkerala.com/news/a/govt-prioritises-access-anthropics-mythos-ai-model-strengthen-475.htm
- https://blog.qualys.com/product-tech/2026/06/24/cert-in-ai-vulnerability-blueprint-machine-speed-risk-operations
- https://www.business-standard.com/technology/tech-news/mythos-threat-govt-tech-firms-test-their-softwares-for-vulnerabilities-126052700386_1.html
- https://inc42.com/buzz/centre-asks-sarvam-ai-bharatgen-to-develop-mythos-like-cyber-ai-models/
- https://www.finextra.com/blogposting/32142/rbis-model-risk-management-guidance-2026--summary
- https://www.medianama.com/2026/06/223-rbi-ai-guidelines-2026-banks-kill-switch/
- https://www.freshfields.com/en/our-thinking/blogs/technology-quotient/india-targets-deepfakes-and-ai-generated-content-key-changes-under-meitys-2026-102mjwn

Introduction
Digital Arrests are a form of scam that involves the digital restraint of individuals. These restraints can vary from restricting access to the account(s), and digital platforms, to implementing measures to prevent further digital activities or being restrained on video calling or being monitored through video calling. Typically, these scams target vulnerable individuals who are unfamiliar with digital fraud tactics, making them more susceptible to manipulation. These scams often target the victims on allegations of drug trafficking, money laundering, falsified documents, etc. These are serious crimes and these scammers scare the victim into thinking that either their identities were used to commit these crimes or they have committed these crimes. Recently there has been an uptick in the digital fraud scams in India highlighting the growing concerns.
The Legality of Digital Arrests in India
There is no legal provision for law enforcement to conduct ‘arrests’ via video calls or online monitoring. If you receive such calls, it is a clear scam. In fact, recently enacted new criminal laws do not provide for any provision for law enforcement agencies conducting a digital arrest. The law only provides for service of the summons and the proceedings in an electronic mode.
The Bhartiya Nagrik Suraksha Sanhita (BNSS), 2023 provides for the summons to be served electronically under section 63. The section defines the form of summons. It states that every summons served electronically shall be encrypted and bear the image of the seal of the Court or digital signature. Further, according to section 532 of the BNSS, the trial and proceedings may be held in electronic mode, by use of electronic communication or by the use of audio-video electronic means.
Modus Operandi
Under digital arrest scams, the scammer makes a connection via video calls (WhatsApp calls, skype, etc) with the victim over their alleged involvement in crimes (financial, drug trafficking, etc) in bogus charges. The victims are intimidated that the arrest will take place soon and till the time the arresting officers do not reach the victim they are to remain on the call and be under digital surveillance and not contact anyone during the ongoing investigation.
During this period, the scammers start collecting information from the victim to confirm their identity and create an atmosphere in which multiple senior officials are on the victim’s case and they are investigating the case thoroughly. By this time, the victim, scared out of their wits, sits through this arrest and it is then that the scammers posing as law enforcement officials make comments that they can avoid arrest by paying a certain amount of the fines to the accounts that they specify. This monitoring/ surveillance continues till the time the victim makes the transfers to the accounts provided by the scammers. These are the common manipulation tactics used by scammers in digital arrest fraud.
Recent Cyber Arrest Cases
- Recently a 35-year-old NBCC official was duped of Rs 55 lakh in a 'digital arrest' scam. Posing as customs officials, fraudsters claimed her details were linked to intercepted illegal items and a pending arrest. They kept her on video calls, convincing her to transfer Rs 55 lakh to avoid money laundering charges. After the transfer, the scammers vanished. A police investigation traced the funds to a fake company, leading to the arrest of suspects.
- Another recent case involved a neurologist who was duped Rs 2.81 crores in a ‘digital arrest’ scam. Fraudsters claimed her phone number and Aadhaar was linked to accounts transferring funds to an Individual. Under pressure, she was convinced to undergo “verification” and made multiple transactions over two days. The scammers threatened legal consequences for money laundering if she didn’t comply. Now a police investigation is ongoing, and her immense financial loss highlights the severity of this cybercrime.
- One another case took place where the victim was duped of Rs 7.67 crores in a prolonged ‘digital arrest’ scam over three months. Fraudsters posing as TRAI officials claimed complaints against her phone number and threatened to suspend it, alleging illegal use of another number linked to her Aadhaar. Pressured and manipulated through video calls, the victim was coerced into transferring large sums, even taking an Rs 80 lakh loan. The case is under investigation as authorities pursue the cybercriminals behind the massive fraud.
Best Practices
- Do not panic when you get any calls where sudden unexpected news is shared with you. Scammers thrive on the panic that they create.
- Do not share personal details such as Aadhaar number, PAN number etc with unknown or suspect entities. Be cautious of your personal and financial information such as credit card numbers, OTPs, or any other passwords with anyone.
- If individuals contact, claiming to be government officials, always verify their identities by contacting the entity through the proper channels.
- Report and block any fraudulent communications that are received and mark them as Spam. This would further inform other users if they see the caller ID being marked as fraud or spam.
- If you have been defrauded then report about the same to the authorities so that action can be taken and authorities can arrest the fraudsters.
- Do not transfer any money as part of ‘fines’ or ‘dues’ to the accounts that these calls or messages link to.
- In case of any threat, issue or discrepancy, file a complaint at cybercrime.gov.in or helpline number 1930. You can also seek assistance from the CyberPeace helpline at +91 9570000066.
References:
- https://www.cyberpeace.org/resources/blogs/digital-arrest-fraud
- https://www.business-standard.com/india-news/what-is-digital-house-arrest-find-out-how-to-avoid-this-new-scam-124052400799_1.html
- https://www.the420.in/ias-ips-officers-major-generals-doctors-and-professors-fall-victim-to-digital-arrest-losing-crores-stay-alert-read-5-real-cases-inside/
- https://indianexpress.com/article/cities/delhi/senior-nbcc-official-duped-in-case-of-digital-arrest-3-arrested-delhi-police-9588418/#:~:text=Of%20the%20duped%20amount%2C%20Rs,a%20Delhi%20police%20officer%20said (case study 1)
- https://timesofindia.indiatimes.com/city/lucknow/lucknow-sgpgims-professor-duped-of-rs-2-81-crore-in-digital-arrest-scam/articleshow/112521530.cms (case study 2)
- https://timesofindia.indiatimes.com/city/jaipur/bits-prof-duped-of-7-67cr-cops-want-cbi-probe-in-case/articleshow/109514200.cms (case study 3)

Executive Summary:
A video is being widely circulated on social media in connection with the relief and rescue operations following the devastating floods in Nepal. The video shows security personnel rescuing a girl trapped under debris and later giving her soup. The video is being shared with the claim that security personnel rescued a girl who had been buried under mud three days after the disaster in Timure village of Nepal’s Rasuwa district. A research by CyberPeace Research Wing found the viral claim to be false. Our research revealed that the viral video does not depict a real incident but is AI-generated.
Claim:
A user on social media platform X (formerly Twitter) shared the viral video with the caption: “Nepal: It was nothing short of a miracle to witness this. After three days, death had to retreat and life emerged victorious. A six-year-old girl, who had been buried under the disaster debris for three days, was rescued by Nepal’s security forces. The incident took place in Timure village of Nepal’s Rasuwa district. Six-year-old Manisha was pulled out alive after being buried under debris caused by floods and landslides.”
https://x.com/AjitSinghRathi/status/2094306889001742826?s=20

Fact Check:
A close examination of the viral video revealed several inconsistencies, raising suspicions that the video was AI-generated. We then scanned the viral video using the AI detection tool Hive Moderation. According to the results, there is a 77 per cent likelihood that the viral video is AI-generated.

As part of our research, we scanned the video using the AI detection tool Wasitai. According to the results, the viral video is AI-generated.

Conclusion:
Our research found the viral claim to be false. Our findings revealed that the viral video does not depict a real incident but is AI-generated.