#FactCheck: AI-Generated Photo Shared to Claim Boycott of Hindu Sammelan
Executive Summary:
A photo circulating on social media shows a stage with the words “Hindu Sammelan” (Hindu Conference) written in large letters. In front of the stage, rows of chairs appear largely empty, with only a few people seated while most seats remain vacant.
Users sharing the image claim that the event, held under the banner of a “Hindu Sammelan,” was in fact a “Brahmin Sammelan,” and that indigenous communities chose to stay away, resulting in poor attendance.
It is noteworthy that, on the occasion of the centenary year of the Rashtriya Swayamsevak Sangh (RSS), various “Hindu Sammelan” events are being organized across the country. The viral image is being linked to this broader context.
However, research conducted by the CyberPeace found the viral claim to be false. Our research revealed that the image being shared on social media is not authentic but AI-generated and is being circulated with a misleading narrative.
Claim
On February 21, 2026, a Facebook user shared the viral image. The original and archived links are provided below
- https://www.facebook.com/photo?fbid=935049042540479&set=gm.2425972001215469&idorvanity=465387370607285
- https://ghostarchive.org/archive/sxC6d

Fact Check:
A keyword search on Google confirmed that several “Hindu Sammelan” events have indeed been organized across the country as part of the RSS centenary year. For instance, media reports have covered such events in different cities, including Nagpur.

However, upon closely examining the viral image, we observed certain visual inconsistencies and unnatural elements that raised suspicion of AI generation. We first analyzed the image using the AI detection tool Hive Moderation, which indicated a 79.3 percent probability that the image was AI-generated.

To further verify, we scanned the image using another AI detection platform, Sightengine. The results showed a 97 percent likelihood that the image was AI-generated.

Conclusion
Our research confirms that the image circulating on social media is not genuine. It has been artificially created using AI technology and is being shared with a misleading claim.
Related Blogs

On 12 August 2026, President Donald Trump signed a National Security Presidential Memorandum titled Expanding Capabilities to Combat Transnational Cyber Enabled Crime. Stripped of its bureaucratic packaging, the document does something American law has resisted for three decades: it lets private companies, under close federal supervision, break into the systems of foreign criminal networks and, in some cases, disrupt or damage them.
That is a genuinely large policy shift, even if the memorandum itself is careful, almost defensive, about how it frames the shift. Understanding why requires separating what the text actually authorizes from the "hack back" headline that has attached itself to the story within days of signing.
The problem the memo says it is solving
The White House frames this as a response to scale, not ideology. Americans reported losing more than 20.8 billion dollars to cyber enabled crime in 2025, a sharp jump from the roughly 12.5 billion dollar figure cited when the administration's earlier March 2026 executive order on cybercrime, fraud, and predatory schemes was signed. Ransomware, phishing, financial fraud, sextortion, and impersonation scams sit at the center of that number, and the administration's own supporting material points to a grim detail buried in the numbers: one in seven young people who experienced sextortion as a minor reported harming themselves as a result.
Those crimes, the memorandum argues, are increasingly the work of organized, transnational groups operating from jurisdictions the FBI simply cannot reach. Domestic law enforcement, built for domestic crime, is structurally mismatched to a threat that lives across borders and inside encrypted infrastructure. The administration's answer is to formally recruit the resource it says is best positioned to close that gap: the American cybersecurity industry itself, which the memo describes as "the most innovative and technologically advanced in the world."
What the Program actually authorizes
The memorandum directs the National Coordination Center, a body first stood up under a 2025 executive order, to build a formal Program through which vetted Participating Companies can conduct two categories of activity against foreign Cyber Enabled Transnational Criminal Organizations, defined in the text as CE TCOs.
Cyber Surveillance Operations cover unauthorized access to a target's systems for the primary purpose of collecting information or intelligence, undertaken with the intent to remain undetected. Cyber Effects Operations go further: manipulating, disrupting, denying, degrading, or destroying information systems, the infrastructure those systems control, or the data resident on them.
Crucially, CE TCOs are defined narrowly. A foreign group only counts if it targets the US government, US persons, or US interests, and it must not be an institutional arm of a foreign state or wholly directed by one. The memo builds in a presumption of innocence at the state level too: a group is assumed not to be state controlled unless clear intelligence establishes otherwise. That distinction matters enormously, because it is the line meant to separate this Program from anything resembling private warfare against a nation state.
No operation happens unilaterally. Every proposed action must be approved in writing by two Program Executive Directors, one designated by the Attorney General and one by the Secretary of Homeland Security, coordinating with each other before signing off. Participating Companies must pass what the memo calls rigorous vetting, sign contractual agreements with DOJ or DHS, and in many cases post a bond or escrow of at least one million dollars, forfeited if they breach their agreement. Within 60 days of the memo's signing, the Program Executive Directors must publish detailed operating procedures covering everything from target adjudication to what happens if an operation accidentally hits a US person's system, in which case the company must stop, run minimization procedures, and immediately notify the Center.
There is also a hard ceiling built into the design. Operations expected to cause loss of life, serious injury, or conduct that would rise to the level of a use of force or armed attack under international law, termed Critical Outcomes in the text, cannot be approved by the Program Executive Directors at all. That ceiling is the memo's clearest attempt to keep this inside the bounds of law enforcement rather than sliding into something closer to conflict.
Multiple law firms tracking the rollout, including Wiley, have been explicit on one point worth repeating because so much coverage has blurred it: this is not a green light for companies to hack back on their own initiative. Every operation remains, on paper, an act of the federal government, merely executed through a contracted private hand.
Why experts are not popping champagne
Legal caution has not stopped a wave of professional anxiety. Cyber policy veterans interviewed by outlets like CyberScoop describe the memo as a genuine philosophical break in how Washington thinks about offense in cyberspace, and the debate that followed split fairly evenly between cautious optimism and open alarm.
The core worry, echoed across nearly every serious critique, is attribution. Cyber operations are hard to trace precisely because criminals exploit shared infrastructure, proxies, and compromised third party systems to hide, and that same fog does not lift just because a government contract sits behind the operator. A former senior CISA official, Michael Garcia, put the risk plainly: pressure to attribute quickly could push companies toward lower certainty judgments about who they are actually striking, with a realistic chance of hitting the wrong server, or worse, infrastructure tied to a foreign government rather than a criminal gang. A former Cyber Command official was blunter still, describing parts of the memo on social media as a structure that could reward companies for manufacturing billable threats rather than resolving them efficiently.
Paul Rosenzweig, a former DHS policy official, raised a separate and arguably more durable problem: jurisdiction. Whatever this memo authorizes under American law, the systems being accessed usually sit inside someone else's sovereign territory, governed by that country's own criminal statutes. Washington cannot legislate away a foreign hacking law simply by calling the American company that broke it a Participating Company.
None of this makes the memo indefensible. Supporters point out, correctly, that the private sector already does enormous amounts of active defense and threat disruption work informally, through botnet takedown litigation and coordinated infrastructure seizures, and that formalizing federal oversight over that activity is arguably safer than the current improvisation. The honest position, and probably the fair one, is that the memo trades one set of risks for another, and which set turns out worse will depend entirely on the operating procedures due inside sixty days, procedures the public has not yet seen.
CyberPeace Insights: what this means beyond America's borders
A significant share of the CE-TCO activity this memo is built to target, the ransomware crews, romance investment fraud operations, and sextortion rings running out of Southeast Asia, does not victimize Americans in isolation. The scam compounds clustered along the Myanmar, Cambodia, and Laos borders, repeatedly raided over the past two years, have held thousands of trafficked workers of dozens of nationalities, Indians consistently among the largest groups rescued, alongside Chinese, Filipino, and Malaysian nationals. India has run its own repatriation efforts out of Mae Sot in Thailand, bringing citizens home several hundred at a time, and has built its own institutional response to this threat through the Indian Cyber Crime Coordination Centre, which coordinates cybercrime enforcement across states and increasingly across borders.
That shared exposure gives India and the United States real common ground here. The criminal infrastructure this American Program is designed to disrupt is, in significant part, the same infrastructure that has trafficked and defrauded Indian citizens, which gives New Delhi genuine reason to watch this experiment closely and constructively. At the same time, the Program's underlying model, private companies conducting cross-border operations under one nation's legal authorization, is a genuinely new template in international cyber governance, and how it performs over its first year will likely shape how other major digital economies, India included, think about calibrating their own frameworks for public-private cooperation against transnational cybercrime. India and other nations should closely watch whether this becomes a template worth adapting or a cautionary tale worth avoiding.
It is pertinent to note that Justice and Homeland Security departments have 60 days to write detailed operating procedures covering everything from a target-vetting rubric to a classified operational workflow and 180 days to deliver the first status report to the White House.
References
- The White House. "Expanding Capabilities to Combat Transnational Cyber Enabled Crime." 12 August 2026. https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/
- Wiley Rein LLP. "Navigating the New Presidential Memorandum on Transnational Cyber Enabled Crime." August 2026. https://www.wiley.law/alert-Navigating-the-New-Presidential-Memorandum-on-Transnational-Cyber-Enabled-Crime
- SecureWorld. "Trump Memo Lets Private Firms Hack Back at Cybercriminals." August 2026. https://www.secureworld.io/industry-news/trump-authorizes-private-firms-offensive-cyber-operations
- CyberScoop. "A bold new strategy or a dangerous precedent? Experts are divided on Trump's memo." August 2026. https://cyberscoop.com/private-sector-hacking-presidential-memo-cybersecurity/
- CyberScoop. "Trump turns to private sector in offensive hacking operations memo." August 2026. https://cyberscoop.com/trump-memo-private-sector-offensive-hacking/
- CNN Politics. "Cyber privateers: Trump issues order allowing US companies to hack overseas groups under certain conditions." August 2026. https://www.cnn.com/2026/08/13/politics/cyber-privateers-trump-order-overseas-groups-hacking
- NPR. "Trump administration wants to allow companies to hack foreign cybercriminals." August 2026. https://www.npr.org/2026/08/15/nx-s1-5930311/trump-companies-hack-foreign-cybercriminals
- The Next Web. "President Donald Trump signs memo letting US agencies hack transnational crime groups abroad." August 2026. https://thenextweb.com/news/trump-cyber-memo-transnational-crime
- Machine News. "Security firms hit back at Trump's call to hack back against international crime gangs." August 2026. https://www.machine.news/security-firms-hit-back-at-trumps-call-to-hack-back-against-international-crime-gangs/
- Lawfare. "Trump Admin Cyber Strategy Centers Private Sector in Offensive Cyber Operations." March 2026. https://www.lawfaremedia.org/article/trump-admin-cyber-strategy-centers-private-sector-in-offensive-cyber-operations
- Lawfare. "Partners or Provocateurs? Private Sector Involvement in Offensive Cyber Operations." July 2025. https://www.lawfaremedia.org/article/partners-or-provocateurs--private-sector-involvement-in-offensive-cyber-operations
- Global Indian Network. "Pig Butchering Scams in India: The Dark Intersection of Social Media, AI, and Emotional Manipulation." January 2026. https://globalindiannetwork.com/pig-butchering-scams-in-india/
- The Tribune. "India brings home scammed 549 nationals from Myanmar in 2 days." 2025. https://www.tribuneindia.com/news/india/india-brings-home-scammed-549-nationals-from-myanmar-in-2-days
- Malay Mail. "India to repatriate 500 nationals fleeing Myanmar's cyber scam hub, says Thai PM." October 2025. https://www.malaymail.com/amp/news/world/2025/10/29/india-to-repatriate-500-nationals-fleeing-myanmars-cyber-scam-hub-says-thai-pm/196399
- NBC News. "260 foreigners rescued from virtual slavery in Myanmar's online scam centers are being repatriated." 2025. https://www.nbcnews.com/news/world/260-foreigners-rescued-virtual-slavery-myanmars-online-scam-centers-ar-rcna192180
- CyberPeace Foundation. "About Us." https://cyberpeace.org/about-us
Contributors
- Maj. Vineet Kumar, Founder & Global President, CyberPeace
- Mr. Neeraj Soni, Senior Research Analyst, Policy & Advocacy, CyberPeace
List of Abbreviations
- CE‑TCO — Cyber Enabled Transnational Criminal Organization
- DOJ — Department of Justice
- DHS — Department of Homeland Security
- FBI — Federal Bureau of Investigation
- CISA — Cybersecurity and Infrastructure Security Agency
- I4C — Indian Cyber Crime Coordination Centre
- US — United States
- IT — Information Technology

Executive Summary:
A video circulating on Social media has claimed that Iran has launched a missile strike destroying Ben Gurion Airport in Tel Aviv. With rising tensions in geopolitics, the video quickly became popular. However, our research has detailed inspections through digital verification tools and visual analysis showed that the video is AI-generated. No incident or damage ever occurred.

Claim:
A viral video circulating on social media platforms claims to show Tel Aviv’s Ben Gurion Airport destroyed following an Iranian missile strike. The video is being shared with captions suggesting it is the last recorded visuals from the attack, with some users asserting it as evidence of escalating conflict between Iran and Israel.

Fact Check:
After looking into the video that purported to show the destruction of Tel Aviv's Ben Gurion Airport in an Iranian missile strike, we researched the topic whether the claim is accurate or not. The video depicts a damaged airport terminal, with debris and fires, but a visual analysis determined that there were a number of suspicious characteristics: asymmetrical layout, artificial-looking smoke patterns, and the absence of activity or humans—those are all typical indications of AI generation. Our research traced the origins of the video to an Instagram post, with a date of May 27, 2025, made by what seems to be a user who frequently shares AI-generated images.


In order to verify our conclusions, we used Hive Moderation, an AI content detection tool, which produced a result of an 80% probability that the video is altered, and this level of probability strongly supports the idea that the footage is not real. Additionally, reports from popular organizations like India Today and Reuters supported these results. All findings resulting from our research established that the video is synthetic and unrelated to any event occurring at Ben Gurion Airport, and therefore debunked a false narrative propagated on social media.

To confirm, we also compared the visuals with a real aerial image of Tel Aviv’s Ben Gurion Airport available on aviation stock sites.



Fig: Google Maps image of Tel Aviv’s Ben Gurion Airport
The visuals from the viral video are not real locations or scenes of Aviv’s Ben Gurion Airport's true location and configuration therefore it is fake and misleading.
Conclusion:
After thorough research it is concluded that the viral video is fake and it is not an actual missile strike at Ben Gurion Airport. The video is made with AI, and posted by a content creator of synthetic content well before any conflict update. There is no official confirmation or credible news coverage to substantiate the claim, with a high probability of AI-detection, and it has been proven to be digitally manipulated. Therefore, the claim is untrue and misleading.
- Claim: A video shows Iran's missile strike destroying Tel Aviv’s Ben Gurion Airport.
- Claimed On: Social Media
- Fact Check: False and Misleading

Executive Summary
Amid renewed military tensions between Iran and Israel in West Asia, a video is widely circulating on social media showing a multi-storey building being struck, followed by a massive explosion and fire. Several users are sharing this clip with the claim that it shows a recent Iranian attack on Tel Aviv, Israel. However, CyberPeace Research Wing research found that the claim is misleading. The viral video has no connection to the current Iran–Israel conflict. It is actually from a Russian drone strike in Ukraine that took place in September 2025, and is now being falsely linked to the ongoing tensions in West Asia.
Claim
An Instagram user shared the viral video with the caption:“Iran–Israel tensions at peak, reports of retaliatory action towards Tel Aviv… New wave of Iranian response towards Tel Aviv amid escalating tensions between Iran and Israel. The situation in the region continues to intensify as both sides accuse each other, while the international community closely monitors developments. The Middle East situation is rapidly evolving and updates are emerging. It is important to rely only on official information and credible sources.”
https://www.instagram.com/shan_of_voice/reel/DZWRp8vqiM8
https://archive.ph/s26qV

Fact Check
To verify the authenticity of the video, we extracted keyframes and conducted a Google Lens reverse image search. The same footage was found in a report published by The Guardian on 16 September 2025.
According to the report, the video shows a Russian drone strike on a building in Kharkiv, Ukraine, in which three men and one woman were injured.

Further verification through keyword search led us to the same footage on the official YouTube channel of Associated Press, published on 17 September 2025.
https://www.youtube.com/watch?v=cAke3aAhPxs

The Associated Press also confirmed that the video shows a Russian drone strike on a building in Kharkiv, Ukraine.
Conclusion
Our research found that the viral video has no connection to the ongoing Iran–Israel tensions or any attack on Tel Aviv. The footage is from a Russian drone strike in Kharkiv, Ukraine (September 2025), and is being misleadingly shared in the context of the West Asia conflict.