#FactCheck - Viral Video Misrepresented as Reaction to Pakistan’s Defeat in T20 World Cup
Research Wing
Innovation and Research
PUBLISHED ON
Feb 17, 2026
10
Executive Summary
A video is being widely shared on social media with the claim that Baloch people celebrated by dancing after Pakistan’s crushing defeat to India in the T20 World Cup. However, research by the CyberPeace found the claim to be misleading. The video is actually from a Lohri celebration held on January 23 at Government College University in Lahore, and is unrelated to any cricket match. India defeated Pakistan by 61 runs in the T20 World Cup 2026 match held in Colombo last Sunday. India scored 175 runs for the loss of seven wickets in 20 overs, while Pakistan were bowled out for 114 runs in 18 overs.
Claim
The 30-second video was shared on X with the caption, “Baloch people celebrate India’s victory.” The footage shows a group of men dressed in traditional attire dancing around a fire, while a large crowd gathers around and applauds.
To verify the authenticity of the viral claim, key frames from the video were extracted and subjected to reverse image search. The search led to an Instagram post uploaded on January 26, 2026, by an account associated with Government College University Lahore. The caption described the performance as a Balochistan cultural dance held at the university’s amphitheatre.
Further research also uncovered another video of the same event, recorded from a different angle and uploaded on January 24, 2026, on Instagram. The caption again confirmed that the event took place at Government College University Lahore.
The evidence confirms that the viral video does not show Baloch people celebrating Pakistan’s defeat in the T20 World Cup. Instead, it depicts a cultural dance performance during a Lohri celebration at Government College University Lahore, and has been shared with a misleading claim.
A video circulating on social media is being linked to the ongoing tensions in West Asia involving the United States, Israel, and Iran. The clip shows an aircraft crashing into a residential area, with users claiming that a Dubai-bound plane carrying Israeli soldiers crashed near Tel Aviv airport, killing everyone on board. However, an research by the CyberPeace has found the claim to be false. The viral video is AI-generated, and no such incident has taken place in Israel.
Claim
An Instagram user “bebakawaaztv” shared the video on April 7, 2026, claiming that a Dubai aircraft carrying Israeli soldiers crashed near Tel Aviv airport in a residential area, allegedly after being hit by debris from an Iranian hypersonic missile.
To verify the claim, we closely examined the viral video. Several visual inconsistencies indicated that it was not real. The aircraft appears to be flying unusually low over a residential area—something that is highly improbable under normal aviation conditions. Its landing gear seems to touch rooftops without causing any visible damage. Additionally, the wings of the aircraft pass through structures like poles without any collision impact, which is physically impossible. These anomalies strongly suggested that the video was artificially created.
We further analyzed the video using the AI detection tool HIVE Moderation, which indicated a 99% probability that the content is AI-generated.
Another analysis using Sightengine also flagged the video as likely AI-generated.
Conclusion
The viral claim is false and misleading. There is no credible evidence or verified report confirming that any Dubai aircraft carrying Israeli soldiers crashed near Tel Aviv airport. No such incident has been reported by any reliable international or local media outlets. The video in question is digitally fabricated using AI technology, and the visual inconsistencies within the clip clearly indicate manipulation. Such content is often designed to exploit ongoing geopolitical tensions and spread misinformation at scale
A video is going viral on social media showing a woman performing a pre-wedding ritual called “Roka” for a couple at a metro station. Many users are sharing the clip believing it to be a real incident. CyberPeace found in its research that the viral claim is false. The video is actually scripted.
Claim:
An Instagram user posted the video on February 7, 2026, with the caption, “A mother performed her son’s Roka with his girlfriend at a metro station.”
To verify the claim, we conducted a reverse image search using Google Lens on screenshots from the viral video. We found the same video was first uploaded on February 5, 2026, by an Instagram account named “chalte_phirte098.” The profile belongs to digital content creator Aarav Mavi, who regularly posts relationship and breakup-related videos.
Although the viral clip does not include any disclaimer stating that it is scripted, an older video posted by the creator on December 16, 2025, clarifies that his content is based on real-life stories shared by people but is filmed using professional actors. Several similar staged videos are also available on his profile on Instagram.
Conclusion:
Our research clearly shows that the viral video claiming to show a pre-wedding Roka ceremony at a metro station is not real. It was created by a content creator for entertainment purposes. Therefore, the claim circulating on social media is misleading.
Welcome to the third edition of our blog on digital forensics series. In our previous blogwe discussed the difference between copying, cloning, and imaging in the context of Digital Forensics, and found out why imaging is a better process. Today we will discuss the process of evidence collection in Digital Forensics. The whole process starts with making sure the evidence collection team has all necessary tools required for the task.
Investigating Tools and Equipment:
Below are some mentioned tools that the team should carry with them for a successful evidence collection:
Anti-static bags
Faraday bags
Toolkit having screwdrivers(nonmagnetic), scissors, pins, cutters, forceps, clips etc.
Rubber gloves
Incident response toolkit (Software)
Converter/Adapter: USB, SATA, IDE, SCSI
Imaging software
Volatile data collection tools (FTK Imager, Magnet Forensics RAM Capture)
Pens, permanent markers
Storage containers
Batteries
Video cameras
Note/sketch pads
Blank storage media
Write-Blocker device
Labels
Crime scene security tapes
Camera
What sources of Data are necessary for Digital Evidence?
Hard-Drive (Desktop, Laptop, External, Server)
Flash Drive
SD Cards
Floppy Disks
Optical Media (CD, DVD)
CCTV/DVR
Internal Storage of Mobile Device
GPS (Mobile/Car)
Call Site Track (Towers)
RAM
Evidence Collection
The investigators encounter two primary types of evidence during the course of gathering evidence: non-electronic and electronic evidence.
The following approaches could be used to gather non-electronic evidence:
In the course of looking into electronic crimes, recovering non-electronic evidence can be extremely important. Be cautious to make sure that this kind of evidence is retrieved and kept safe. Items that may be relevant to a later review of electronic evidence include passwords, papers or printouts, calendars, literature, hardware and software manuals, text or graphical computer printouts, and photos. These items should be secured and kept for further examination.
They are frequently found close to the computer or other related hardware. Locating, securing, and preserving all evidence is required by departmental procedures.
Three scenarios arise for the collection of digital evidence from computers:
Situation 1: The desktop is visible, and the monitor is on.
Take a picture of the screen and note the data that is visible.
Utilize tools for memory capturing to gather volatile data.
Look for virtual disks. If so, gather mounted data's logical copies.
Give each port and connection a label.
Take a picture of them.
Turn off network access to stop remote access.
Cut off the power or turn it off.
Locate and disconnect the hard drive by opening the CPU chassis.
Take all evidence and place it in anti-magnetic (Faraday) bags.
Deliver the evidence to the forensic lab.
Keep the chain of custody intact.
Situation 2: The monitor is turned on, but it either has a blank screen (sleep mode) or an image for the screensaver.
Make a small mouse movement (without pressing buttons). The work product should appear on the screen, or it should ask for a password.
If moving the mouse does not result in a change to the screen, stop using the mouse and stop all keystrokes.
Take a picture of the screen and note the data that is visible.
Use memory capturing tools to gather volatile data (always use a write blocker to prevent manipulation during data collection).
Proceed further in accordance with Situation 1.
Situation 3: The Monitor Is Off
Write down the "off" status.
After turning on the monitor, check to see if its status matches that of situations 1 or 2 above, and then take the appropriate action.
Using a phone modem, cable, confirm that you are connected to the outside world. Try to find the phone number if there is a connection to the phone.
To protect evidence, take out the floppy disks that might be there, package each disk separately, and label the evidence. Put in a blank floppy disk or a seizure disk, if one is available. Avoid touching the CD drive or taking out CDs.
Cover the power connector and every drive slot with tape.
Note the serial number, make, and model.
Take a picture of the computer's connections and make a diagram with the relevant cables.
To enable precise reassembly at a later date, label all connectors and cable ends, including connections to peripheral devices. Put "unused" on any connection ports that are not in use. Recognize docking stations for laptop computers in an attempt to locate additional storage media.
All evidence should be seized and placed in anti-magnetic (Faraday) bags.
All evidence should be seized and placed in anti-magnetic (Faraday) bags.
Put a tag or label on every bag.
Deliver the evidence to the forensic lab.
Keep the chain of custody intact.
Following the effective gathering of data, the following steps in the process are crucial: data packaging, data transportation, and data storage.
The following are the steps involved in data packaging, transportation, and storage:
Packaging:
Label every computer system that is gathered so that it can be put back together exactly as it was found
When gathering evidence at a scene of crime,
Before packing, make sure that every piece of evidence has been appropriately labeled and documented.
Latent or trace evidence requires particular attention, and steps should be taken to preserve it.
Use paper or antistatic plastic bags for packing magnetic media to prevent static electricity. Do not use materials like regular plastic bags (instead use faraday bags) that can cause static electricity.
Be careful not to bend, fold, computer media like tapes, or CD-ROM.
Make sure that the labels on every container used to store evidence are correct.
Transporting
Make sure devices are not packed in containers and are safely fastened inside the car to avoid shock and excessive vibrations. Computers could be positioned on the floor of the car,and monitors could be mounted on the seat with the screen down .
When transporting evidence—
Any electronic evidence should be kept away from magnetic sources. Radiation transmitters, speaker magnets, and heated seats are a few examples of items that can contaminate electronic evidence.
Avoid leaving electronic evidence in your car for longer than necessary. Electronic devices can be harmed by extremes in temperature, humidity.
Maintain the integrity of the chain of custody while transporting any evidence.
Storing
Evidence should be kept safe and away from extremes in humidity and temperature. Keep it away from dust, moisture, magnetic devices, and other dangerous impurities. Be advised that extended storage may cause important evidence—like dates, times, and system configurations—to disappear. Because batteries have a finite lifespan, data loss may occur if they malfunction. Whenever the battery operated device needs immediate attention, it should be informed to the relevant authority (eg., the chief of laboratory, the forensic examiner, and the custodian of the evidence).
CONCLUSION:
Thus, securing the crime scene to packaging, transportation and storage of data are the important steps in the process of collecting digital evidence in forensic investigations. Keeping the authenticity during the process along with their provenance is critical during this phase. It is also important to ensure the admissibility of evidence in legal proceedings. This systematic approach is essential for effectively investigating and prosecuting digital crimes.
Become a part of our vision to make the digital world safe for all!
Numerous avenues exist for individuals to unite with us and our collaborators in fostering global cyber security
Awareness
Stay Informed: Elevate Your Awareness with Our Latest Events and News Articles Promoting Cyber Peace and Security.
Your institution or organization can partner with us in any one of our initiatives or policy research activities and complement the region-specific resources and talent we need.