#FactCheck -AI-Manipulated Video Falsely Claims ₹50 Crore Deal Involving Bhupen Bora
Executive Summary
A purported news clip circulating on social media claims that the Bharatiya Janata Party (BJP) purchased Bhupen Bora, a leader of the Indian National Congress, for ₹50 crore as part of a political deal in Assam. The viral clip further alleges that the transaction took place under the leadership of Assam Chief Minister Himanta Biswa Sarma and included an agreement to induct several Congress leaders into the BJP.
However, research by CyberPeace found the viral claim to be false and revealed that the original news video had been manipulated using AI and shared with misleading claims.
Claim
On February 18, 2026, a user shared the viral video on Facebook, claiming that the Assam BJP had bought a Congress leader who had lost the last three elections for ₹50 crore, and that the alleged deal led by Himanta Biswa Sarma had drawn public criticism.

Fact Check:
To verify the authenticity of the claim, we extracted key frames from the viral video and conducted a reverse image search using Google Lens. During the research, we found the original version of the video published on the website of Aaj Tak on February 16, 2026. In the original report, the anchor is only seen reporting on Bhupen Bora’s resignation from the party. The report does not mention any alleged financial transaction or political deal, contrary to the claims made in the viral clip.

In the next stage of the research, the viral video was analysed using the AI detection tool AURGIN AI, which identified the video as AI-generated.

Conclusion
Our research found that users had manipulated the original news broadcast using AI and shared it with misleading claims. The viral clip does not show any real financial deal between Bhupen Bora and the Assam Chief Minister.
Related Blogs

Introduction
The misinformation crisis has evolved from being merely an abstract risk to a clear-cut and measurable danger to individuals, families, institutions and the whole information ecosystem. The recent death hoax with the famous actor Dharmendra is a perfect illustration of how the monster of falsehoods rises, conquers the world and does damage before the mechanisms of correction have a chance to operate. The first week of November 2025 saw the first wave of reports from different social media accounts and even some online news outlets that claimed Dharmendra had died at the age of 89. The news travelled like wildfire, causing confusion, grief and emotional suffering in large circles of fans, one could say the whole world. But then, the family came to the scene with the loudest, clearest, and most conclusive denial of them all. This case is not a one-time event. It is part of a cycle of misinformation that goes through the stages from one unverified claim to the next due to the emotional value, the virality of platforms, and the accelerating online engagement.
How One Wrong Post Can Create Worry and Fear
This kind of false news spreads fast on social media because people share emotional posts without checking the source, and automated accounts often repeat the same claim which makes it look true. Such hoaxes create fear, sadness and stress for fans, and they place sudden pressure on the family who must deal with public worry at a time when they need calm and privacy. The message shared by Hema Malini who is the wife of the actor shows how hurtful and careless misinformation can be, and it reminds everyone that even one false post can create real emotional damage for many people.

Why This Hoax Spread So Quickly
- Sensationalism Drives Engagement: Rumours regarding the passing of a public figure, particularly someone who is universally loved, cause an immediate outburst of feelings. Such news is practically taken for granted by the online public, who are very likely to share it, most of the time without checking its authenticity, which, in turn, leads to viral spread.
- Very Fast Weaving-in on social media: Social media networks are very much made for swift sharing. Long before the official sources were able to either confirm or dismiss the matter, posts, reels, and messages ripped through the networks.
- Digital Users Not Verifying Source: A large part of the audience depends on screenshots, forwards, and unverified posts for keeping up with the news. This opens a very nice environment for the spreading of hoaxes.
- Weak Verification Protocols: Although there have been measures to inform the public about misinformation, most news companies still give priority to the speed of reporting rather than its correctness, though not all the time, especially for the more entertaining and attractive topics like the health or death of famous people.
- Algorithmic Amplification Risks: The engagement is mainly driven by algorithms that bring to the surface the posts that evoke strong emotions. In a way, it is very unfair because the false or sensational claims are getting in front at the same time as the corrective updates, hence, the public is getting misled. In the absence of algorithmic safeguards, misinformation is on the rise and becoming stronger.
Best Practices For Users:
- Make sure to verify before sharing, especially if the topic is about health or death.
- Get updates by following official accounts rather than through sharing of viral forwards.
- Be aware of the emotional manipulation tactics used in misleading information.
Conclusion
The rumour surrounding Dharmendra's death is yet another example that misinformation, whether promptly corrected or not, can still inflict distress, cause loss of trust and damage to reputation. It also emphasises the need for stronger information governance, responsible digital journalism, and platform intervention mechanisms as a matter of urgency. This incident, from clicks to consequences, points to a basic truth: misinformation in the digital age is quicker to spread than facts, and the responsibility of putting a stop to it falls on all the stakeholders’ platforms, media, and users.
References
- https://timesofindia.indiatimes.com/entertainment/hindi/bollywood/news/esha-deol-and-hema-malini-dismiss-dharmendras-fake-death-news-relieved-fans-pray-for-actors-speedy-recovery-aap-jld-se-jld-apne-ghar-aye/articleshow/125242843.cms
- https://www.altnews.in/media-misreport-bollywood-actor-dharmendra-hasnt-passed-away-yet/
- https://economictimes.indiatimes.com/news/india/dharmendra-death-news-bollywoods-veeru-and-he-man-passes-away-at-89/articleshow/125238900.cms

Introduction
The increase in consumer demands has resulted in a sharp increase in digital financing in India. As a result, the reputation of the digital lending sector has been impacted, as bad actors increasingly deploy illicit lending platforms such as fraudulent loans and trading apps. As millions of Indians download fast loan applications to help them meet their financial ends, the fraudulent apps result in cyber crimes including financial fraud. Consumers need to be vigilant of dubious trading or loan applications as bad actors frequently use illegitimate apps to trick victims by advertising limited-period offers and applying pressure.
Recently the Indian Cyber Crime Coordination Centre (I4C) led handel CyberDost has issued a cybercrime alert against the ‘CashExpand-U’ finance assistant app, which has been now removed from the Google Play Store. The app was found to be associated with hostile foreign entities, and the app had made it easier to raise small loans. However, such loan apps are seldom credible and may compromise financial information.
Raising cases of Fraudulent Loan Apps
The finance minister had stated that the government is constantly engaged with the Reserve Bank of India and other regulators and stakeholders to control fraudulent loan apps. In FY23, there were 1,062 complaints against such apps, the Finance Minister shared during a Lok Sabha session. Google removed almost 134 fake apps from the Play Store in a single week in September 2023 after multiple complaints were registered against such apps. The Reserve Bank of India (RBI) had also issued regulatory guidelines on digital lending in April 2023 to bring transparency in the digital loan space.
CyberPeace Policy Wing Advisory for Users
- Be cautious of App Permissions
Fake lending apps collect data by fraudulently taking numerous app permissions from consumers and misusing them later. The users must effectively manage their app permissions to avoid denying any extra permissions such as access to contacts, location, and photos. This is because fraudulent digital lenders access users' personal data to extort additional money even after loan repayment.
- Practice Due Diligence
Consumers must exercise care & caution before applying for a loan from digital lending platforms. Before applying for a loan or downloading any such apps, consumers must conduct due diligence by verifying the app's name, rating, reviews, physical address, and contact information. Always double-verify the paperwork before signing any agreement or contract. Always apply for loans from RBI-approved and compliant banking and financial services providers.
- Download from Official Sources
To avoid downloading counterfeit apps, only download lending apps from official stores like Google Play Store or Apple App Store, and avoid downloading apps from web links sent via SMS, email, or social media, even if shared by your known persons.
- Be sceptical of too-good-to-be-true offerings
Be cautious of deals that seem too good to be true, like hassle-free easy loans as they can be fraudulent. If an offer seems too good to be true, it might be a red flag. Hence always conduct your own research to verify the lender and avoid making hasty decisions.
- Reporting Mechanism
In case of facing a scam by such fraudulent apps, victims can file a complaint with the ‘National Cyber Crime Reporting Portal’ or Cyber Crime Helpline ‘1930’, or they can also contact us at CyberPeace Helpline +919570000066 and helpline@cyberpeace.net to get assistance in reporting their cases.
Final Words
Illegitimate loan/trading apps have been raising concerns by defrauding innocent consumers who seek financial assistance. The Center has recently warned against the CashExpand-U app, which has been now removed from the Google Play Store. Users are advised to exercise due care and caution while downloading loan apps and applying for loans to prevent any potential scams. keep up to date with news from concerned authorities about common scams and fraudulent practices in the lending space and stay safe in the online world.
References:
- https://www.livemint.com/news/beware-govt-issues-cybercrime-alert-against-loan-app-cashexpand-u-finance-assistant-11720338996430.html
- https://timesofindia.indiatimes.com/technology/tech-news/government-has-issued-an-important-warning-for-this-loan-app/articleshow/111541577.cms

Executive Summary:
One of the most complex threats that have appeared in the space of network security is focused on the packet rate attacks that tend to challenge traditional approaches to DDoS threats’ involvement. In this year, the British based biggest Internet cloud provider of Europe, OVHcloud was attacked by a record and unprecedented DDoS attack reaching the rate of 840 million packets per second. Targets over 1 Tbps have been observed more regularly starting from 2023, and becoming nearly a daily occurrence in 2024. The maximum attack on May 25, 2024, got to 2.5 Tbps, this points to a direction to even larger and more complex attacks of up to 5 Tbps. Many of these attacks target critical equipment such as Mikrotik models within the core network environment; detection and subsequent containment of these threats prove a test for cloud security measures.
Modus Operandi of a Packet Rate Attack:
A type of cyberattack where an attacker sends with a large volume of packets in a short period of time aimed at a network device is known as packet rate attack, or packet flood attack or network flood attack under volumetric DDoS attack. As opposed to the deliberately narrow bandwidth attacks, these raids target the computation time linked with package processing.
Key technical characteristics include:
- Packet Size: Usually compact, and in many cases is less than 100 bytes
- Protocol: Named UDP, although it can also involve TCP SYN or other protocol flood attacks
- Rate: Exceeding 100 million packets per second (Mpps), with recent attacks exceeding 840 Mpps
- Source IP Diversity: Usually originating from a small number of sources and with a large number of requests per IP, which testifies about the usage of amplification principles
- Attack on the Network Stack : To understand the impact, let's examine how these attacks affect different layers of the network stack:
1. Layer 3 (Network Layer):
- Each packet requires routing table lookups and hence routers and L3 switches have the problem of high CPU usage.
- These mechanisms can often be saturated so that network communication will be negatively impacted by the attacker.
2. Layer 4 (Transport Layer):
- Other stateful devices (e.g. firewalls, load balancers) have problems with tables of connections
- TCP SYN floods can also utilize all connection slots so that no incoming genuine connection can be made.
3. Layer 7 (Application Layer):
- Web servers and application firewalls may be triggered to deliver a better response in a large number of requests
- Session management systems can become saturated, and hence, the performance of future iterations will be a little lower than expected in terms of their perceived quality by the end-user.
Technical Analysis of Attack Vectors
Recent studies have identified several key vectors exploited in high-volume packet rate attacks:
1.MikroTik RouterOS Exploitation:
- Vulnerability: CVE-2023-4967
- Impact: Allows remote attackers to generate massive packet floods
- Technical detail: Exploits a flaw in the FastTrack implementation
2.DNS Amplification:
- Amplification factor: Up to 54x
- Technique: Exploits open DNS resolvers to generate large responses to small queries
- Challenge: Difficult to distinguish from legitimate DNS traffic
3.NTP Reflection:
- Command: monlist
- Amplification factor: Up to 556.9x
- Mitigation: Requires NTP server updates and network-level filtering
Mitigation Strategies: A Technical Perspective
1. Combating packet rate attacks requires a multi-layered approach:
- Hardware-based Mitigation:
- Implementation: FPGA-based packet processing
- Advantage: Can handle millions of packets per second with minimal latency
- Challenge: High cost and specialized programming requirements
2.Anycast Network Distribution:
- Technique: Distributing traffic across multiple global nodes
- Benefit: Dilutes attack traffic, preventing single-point failures
- Consideration: Requires careful BGP routing configuration
3.Stateless Packet Filtering:
- Method: Applying filtering rules without maintaining connection state
- Advantage: Lower computational overhead compared to stateful inspection
- Trade-off: Less granular control over traffic
4.Machine Learning-based Detection:
- Approach: Using ML models to identify attack patterns in real-time
- Key metrics: Packet size distribution, inter-arrival times, protocol anomalies
- Challenge: Requires continuous model training to adapt to new attack patterns
Performance Metrics and Benchmarking
When evaluating DDoS mitigation solutions for packet rate attacks, consider these key performance indicators:
- Flows per second (fps) or packet per second (pps) capability
- Dispersion and the latency that comes with it is inherent to mitigation systems.
- The false positive rate in the case of the attack detection
- Exposure time before beginning of mitigation from the moment of attack
Way Forward
The packet rate attacks are constantly evolving where the credible defenses have not stayed the same. The next step entails extension to edge computing and 5G networks for distributing mitigation closer to the attack origins. Further, AI-based proactive tools of analysis for prediction of such threats will help to strengthen the protection of critical infrastructure against them in advance.
In order to stay one step ahead in this, it is necessary to constantly conduct research, advance new technologies, and work together with other cybersecurity professionals. There is always a need to develop secure defenses that safeguard these networks.
Reference:
https://blog.ovhcloud.com/the-rise-of-packet-rate-attacks-when-core-routers-turn-evil/
https://cybersecuritynews.com/record-breaking-ddos-attack-840-mpps/
https://www.cloudflare.com/learning/ddos/famous-ddos-attacks/