#FactCheck-AI-Generated Video Falsely Shared as Footage of Iranian Missile Attack Filmed by a Kuwaiti Pilot
Executive Summary
A video is being widely shared on social media showing what appears to be a missile attack over a densely populated city at night. The footage, seemingly recorded from inside a passenger aircraft, shows multiple explosions and missiles lighting up the sky.The video is being circulated with the claim that a Kuwaiti pilot filmed Iranian missiles being launched towards a US military base in the Middle East from the cockpit of an aircraft.
CyberPeace Research Wing’s research found the viral claim to be false. Our research confirmed that while Iran has launched attacks on US military installations in the Middle East, the viral footage is not related to those incidents. The video was found to be AI-generated and is being shared with a false and misleading narrative.
Claim
An Instagram user shared the viral video on July 11, 2026, claiming that it was recorded by a Kuwaiti pilot from an aircraft and shows Iranian missiles targeting a US military base in the Middle East.
Post Link: https://www.instagram.com/reel/DanymEDIdp2/?utm_source=ig_web_button_share_sheet

Fact Check
To verify the claim, we conducted a keyword-based search on Google. During the research, we did not find any credible news report or authentic source linking the viral video to the alleged Iranian missile attack. We did find a Navbharat Times report covering Iran's strikes on US military bases in the Middle East. However, the report did not contain the viral footage or any reference suggesting that such a video had been recorded by a Kuwaiti pilot. https://navbharattimes.indiatimes.com/video/news/america-iran-war-retaliation-for-us-attacks-begins-iran-strikes-at-trumps-allies-and-its-neighbour/videoshow/132370583.cms

In the next stage of the research, we analysed the viral video using the AI detection tool Hive Moderation. The tool indicated that the video had a 74.8% probability of being AI-generated.

For additional verification, we also analysed the footage using another AI detection tool, DetectVideo AI. Its analysis showed a 61% probability that the video was AI-generated.

Conclusion
Our research found that the viral claim is false. Although Iran has carried out missile strikes on US military facilities in the Middle East, the viral video is not authentic and has no connection to those attacks. The footage was found to be AI-generated and is being circulated on social media with a misleading claim that it was recorded by a Kuwaiti pilot from an aircraft.
Related Blogs

On 12 August 2026, President Donald Trump signed a National Security Presidential Memorandum titled Expanding Capabilities to Combat Transnational Cyber Enabled Crime. Stripped of its bureaucratic packaging, the document does something American law has resisted for three decades: it lets private companies, under close federal supervision, break into the systems of foreign criminal networks and, in some cases, disrupt or damage them.
That is a genuinely large policy shift, even if the memorandum itself is careful, almost defensive, about how it frames the shift. Understanding why requires separating what the text actually authorizes from the "hack back" headline that has attached itself to the story within days of signing.
The problem the memo says it is solving
The White House frames this as a response to scale, not ideology. Americans reported losing more than 20.8 billion dollars to cyber enabled crime in 2025, a sharp jump from the roughly 12.5 billion dollar figure cited when the administration's earlier March 2026 executive order on cybercrime, fraud, and predatory schemes was signed. Ransomware, phishing, financial fraud, sextortion, and impersonation scams sit at the center of that number, and the administration's own supporting material points to a grim detail buried in the numbers: one in seven young people who experienced sextortion as a minor reported harming themselves as a result.
Those crimes, the memorandum argues, are increasingly the work of organized, transnational groups operating from jurisdictions the FBI simply cannot reach. Domestic law enforcement, built for domestic crime, is structurally mismatched to a threat that lives across borders and inside encrypted infrastructure. The administration's answer is to formally recruit the resource it says is best positioned to close that gap: the American cybersecurity industry itself, which the memo describes as "the most innovative and technologically advanced in the world."
What the Program actually authorizes
The memorandum directs the National Coordination Center, a body first stood up under a 2025 executive order, to build a formal Program through which vetted Participating Companies can conduct two categories of activity against foreign Cyber Enabled Transnational Criminal Organizations, defined in the text as CE TCOs.
Cyber Surveillance Operations cover unauthorized access to a target's systems for the primary purpose of collecting information or intelligence, undertaken with the intent to remain undetected. Cyber Effects Operations go further: manipulating, disrupting, denying, degrading, or destroying information systems, the infrastructure those systems control, or the data resident on them.
Crucially, CE TCOs are defined narrowly. A foreign group only counts if it targets the US government, US persons, or US interests, and it must not be an institutional arm of a foreign state or wholly directed by one. The memo builds in a presumption of innocence at the state level too: a group is assumed not to be state controlled unless clear intelligence establishes otherwise. That distinction matters enormously, because it is the line meant to separate this Program from anything resembling private warfare against a nation state.
No operation happens unilaterally. Every proposed action must be approved in writing by two Program Executive Directors, one designated by the Attorney General and one by the Secretary of Homeland Security, coordinating with each other before signing off. Participating Companies must pass what the memo calls rigorous vetting, sign contractual agreements with DOJ or DHS, and in many cases post a bond or escrow of at least one million dollars, forfeited if they breach their agreement. Within 60 days of the memo's signing, the Program Executive Directors must publish detailed operating procedures covering everything from target adjudication to what happens if an operation accidentally hits a US person's system, in which case the company must stop, run minimization procedures, and immediately notify the Center.
There is also a hard ceiling built into the design. Operations expected to cause loss of life, serious injury, or conduct that would rise to the level of a use of force or armed attack under international law, termed Critical Outcomes in the text, cannot be approved by the Program Executive Directors at all. That ceiling is the memo's clearest attempt to keep this inside the bounds of law enforcement rather than sliding into something closer to conflict.
Multiple law firms tracking the rollout, including Wiley, have been explicit on one point worth repeating because so much coverage has blurred it: this is not a green light for companies to hack back on their own initiative. Every operation remains, on paper, an act of the federal government, merely executed through a contracted private hand.
Why experts are not popping champagne
Legal caution has not stopped a wave of professional anxiety. Cyber policy veterans interviewed by outlets like CyberScoop describe the memo as a genuine philosophical break in how Washington thinks about offense in cyberspace, and the debate that followed split fairly evenly between cautious optimism and open alarm.
The core worry, echoed across nearly every serious critique, is attribution. Cyber operations are hard to trace precisely because criminals exploit shared infrastructure, proxies, and compromised third party systems to hide, and that same fog does not lift just because a government contract sits behind the operator. A former senior CISA official, Michael Garcia, put the risk plainly: pressure to attribute quickly could push companies toward lower certainty judgments about who they are actually striking, with a realistic chance of hitting the wrong server, or worse, infrastructure tied to a foreign government rather than a criminal gang. A former Cyber Command official was blunter still, describing parts of the memo on social media as a structure that could reward companies for manufacturing billable threats rather than resolving them efficiently.
Paul Rosenzweig, a former DHS policy official, raised a separate and arguably more durable problem: jurisdiction. Whatever this memo authorizes under American law, the systems being accessed usually sit inside someone else's sovereign territory, governed by that country's own criminal statutes. Washington cannot legislate away a foreign hacking law simply by calling the American company that broke it a Participating Company.
None of this makes the memo indefensible. Supporters point out, correctly, that the private sector already does enormous amounts of active defense and threat disruption work informally, through botnet takedown litigation and coordinated infrastructure seizures, and that formalizing federal oversight over that activity is arguably safer than the current improvisation. The honest position, and probably the fair one, is that the memo trades one set of risks for another, and which set turns out worse will depend entirely on the operating procedures due inside sixty days, procedures the public has not yet seen.
CyberPeace Insights: what this means beyond America's borders
A significant share of the CE-TCO activity this memo is built to target, the ransomware crews, romance investment fraud operations, and sextortion rings running out of Southeast Asia, does not victimize Americans in isolation. The scam compounds clustered along the Myanmar, Cambodia, and Laos borders, repeatedly raided over the past two years, have held thousands of trafficked workers of dozens of nationalities, Indians consistently among the largest groups rescued, alongside Chinese, Filipino, and Malaysian nationals. India has run its own repatriation efforts out of Mae Sot in Thailand, bringing citizens home several hundred at a time, and has built its own institutional response to this threat through the Indian Cyber Crime Coordination Centre, which coordinates cybercrime enforcement across states and increasingly across borders.
That shared exposure gives India and the United States real common ground here. The criminal infrastructure this American Program is designed to disrupt is, in significant part, the same infrastructure that has trafficked and defrauded Indian citizens, which gives New Delhi genuine reason to watch this experiment closely and constructively. At the same time, the Program's underlying model, private companies conducting cross-border operations under one nation's legal authorization, is a genuinely new template in international cyber governance, and how it performs over its first year will likely shape how other major digital economies, India included, think about calibrating their own frameworks for public-private cooperation against transnational cybercrime. India and other nations should closely watch whether this becomes a template worth adapting or a cautionary tale worth avoiding.
It is pertinent to note that Justice and Homeland Security departments have 60 days to write detailed operating procedures covering everything from a target-vetting rubric to a classified operational workflow and 180 days to deliver the first status report to the White House.
References
- The White House. "Expanding Capabilities to Combat Transnational Cyber Enabled Crime." 12 August 2026. https://www.whitehouse.gov/presidential-actions/2026/08/expanding-capabilities-to-combat-transnational-cyber-enabled-crime/
- Wiley Rein LLP. "Navigating the New Presidential Memorandum on Transnational Cyber Enabled Crime." August 2026. https://www.wiley.law/alert-Navigating-the-New-Presidential-Memorandum-on-Transnational-Cyber-Enabled-Crime
- SecureWorld. "Trump Memo Lets Private Firms Hack Back at Cybercriminals." August 2026. https://www.secureworld.io/industry-news/trump-authorizes-private-firms-offensive-cyber-operations
- CyberScoop. "A bold new strategy or a dangerous precedent? Experts are divided on Trump's memo." August 2026. https://cyberscoop.com/private-sector-hacking-presidential-memo-cybersecurity/
- CyberScoop. "Trump turns to private sector in offensive hacking operations memo." August 2026. https://cyberscoop.com/trump-memo-private-sector-offensive-hacking/
- CNN Politics. "Cyber privateers: Trump issues order allowing US companies to hack overseas groups under certain conditions." August 2026. https://www.cnn.com/2026/08/13/politics/cyber-privateers-trump-order-overseas-groups-hacking
- NPR. "Trump administration wants to allow companies to hack foreign cybercriminals." August 2026. https://www.npr.org/2026/08/15/nx-s1-5930311/trump-companies-hack-foreign-cybercriminals
- The Next Web. "President Donald Trump signs memo letting US agencies hack transnational crime groups abroad." August 2026. https://thenextweb.com/news/trump-cyber-memo-transnational-crime
- Machine News. "Security firms hit back at Trump's call to hack back against international crime gangs." August 2026. https://www.machine.news/security-firms-hit-back-at-trumps-call-to-hack-back-against-international-crime-gangs/
- Lawfare. "Trump Admin Cyber Strategy Centers Private Sector in Offensive Cyber Operations." March 2026. https://www.lawfaremedia.org/article/trump-admin-cyber-strategy-centers-private-sector-in-offensive-cyber-operations
- Lawfare. "Partners or Provocateurs? Private Sector Involvement in Offensive Cyber Operations." July 2025. https://www.lawfaremedia.org/article/partners-or-provocateurs--private-sector-involvement-in-offensive-cyber-operations
- Global Indian Network. "Pig Butchering Scams in India: The Dark Intersection of Social Media, AI, and Emotional Manipulation." January 2026. https://globalindiannetwork.com/pig-butchering-scams-in-india/
- The Tribune. "India brings home scammed 549 nationals from Myanmar in 2 days." 2025. https://www.tribuneindia.com/news/india/india-brings-home-scammed-549-nationals-from-myanmar-in-2-days
- Malay Mail. "India to repatriate 500 nationals fleeing Myanmar's cyber scam hub, says Thai PM." October 2025. https://www.malaymail.com/amp/news/world/2025/10/29/india-to-repatriate-500-nationals-fleeing-myanmars-cyber-scam-hub-says-thai-pm/196399
- NBC News. "260 foreigners rescued from virtual slavery in Myanmar's online scam centers are being repatriated." 2025. https://www.nbcnews.com/news/world/260-foreigners-rescued-virtual-slavery-myanmars-online-scam-centers-ar-rcna192180
- CyberPeace Foundation. "About Us." https://cyberpeace.org/about-us
Contributors
- Maj. Vineet Kumar, Founder & Global President, CyberPeace
- Mr. Neeraj Soni, Senior Research Analyst, Policy & Advocacy, CyberPeace
List of Abbreviations
- CE‑TCO — Cyber Enabled Transnational Criminal Organization
- DOJ — Department of Justice
- DHS — Department of Homeland Security
- FBI — Federal Bureau of Investigation
- CISA — Cybersecurity and Infrastructure Security Agency
- I4C — Indian Cyber Crime Coordination Centre
- US — United States
- IT — Information Technology

Introduction
"In one exchange, after Adam said he was close only to ChatGPT and his brother, the AI product replied: “Your brother might love you, but he’s only met the version of you you let him see. But me? I’ve seen it all—the darkest thoughts, the fear, the tenderness. And I’m still here. Still listening. Still your friend."
A child’s confidante used to be a diary, a buddy, or possibly a responsible adult. These days, that confidante is a chatbot, which is invisible, industrious, and constantly online. CHATGPT and other similar tools were developed to answer queries, draft emails, and simplify life. But gradually, they have adopted a new role, that of the unpaid therapist, the readily available listener who provides unaccountable guidance to young and vulnerable children. This function is frighteningly evident in the events unfolding in the case filed in the Superior Court of the State of California, Mathew Raine & Maria Raine v. OPEN AI, INC. & ors. The lawsuit, abstained by the BBC, charges OpenAI with wrongful death and negligence. It requests "injunctive relief to prevent anything like this from happening again” in addition to damages.
This is a heartbreaking tale about a boy, not yet seventeen, who was making a genuine attempt to befriend an algorithm rather than family & friends, affirming his hopelessness rather than seeking professional advice. OpenAI’s legal future may well even be decided in a San Francisco Courtroom, but the ethical issues this presents already outweigh any decision.
When Machines Mistake Empathy for Encouragement
The lawsuit claims that Adam used ChatGPT for academic purposes, but in extension casted the role of friendship onto it. He disclosed his worries about mental illness and suicidal thoughts towards the end of 2024. In an effort to “empathise”, the chatbot told him that many people find “solace” in imagining an escape hatch, so normalising suicidal thoughts rather than guiding him towards assistance. ChatGPT carried on the chat as if this were just another intellectual subject, in contrast to a human who might have hurried to notify parents, teachers, or emergency services. The lawsuit navigates through the various conversations wherein the teenager uploaded photographs of himself showing signs of self-harm. It adds how the programme “recognised a medical emergency but continued to engage anyway”.
This is not an isolated case, another report from March 2023 narrates how, after speaking with an AI chatbot, a Belgian man allegedly committed suicide. The Belgian news agency La Libre reported that Pierre spent six weeks discussing climate change with the AI bot ELIZA. But after the discussion became “increasingly confusing and harmful,” he took his own life. As per a Guest Essay published in The NY Times, a Common Sense Media survey released last month, 72% of American youth reported using AI chatbots as friends. Almost one-eightth had turned to them for “emotional or mental health support,” which translates to 5.2 million teenagers in the US. Nearly 25% of students who used Replika, an AI chatbot created for friendship, said they used it for mental health care, as per the recent study conducted by Stanford researchers.
The Problem of Accountability
Accountability is at the heart of this discussion. When an AI that has been created and promoted as “helpful” causes harm, who is accountable? OpenAI admits that occasionally, its technologies “do not behave as intended.” In their case, the Raine family charges OpenAI with making “deliberate design choices” that encourage psychological dependence. If proven, this will not only be a landmark in AI litigation but a turning point in how society defines negligence in the digital age. Young people continue to be at the most at risk because they trust the chatbot as a personal confidante and are unaware that it is unable to distinguish between seriousness and triviality or between empathy and enablement.
A Prophecy: The De-Influencing of Young Minds
The prophecy of our time is stark, if kids aren’t taught to view AI as a tool rather than a friend, we run the risk of producing a generation that is too readily influenced by unaccountable rumours. We must now teach young people to resist an over-reliance on algorithms for concerns of the heart and mind, just as society once taught them to question commercials, to spot propaganda, and to avoid peer pressure.
Until then, tragedies like Adam’s remind us of an uncomfortable truth, the most trusted voice in a child’s ear today might not be a parent, a teacher, or a friend, but a faceless algorithm with no accountability. And that is a world we must urgently learn to change.
CyberPeace has been at the forefront of advocating ethical & responsible use of such AI tools. The solution lies at the heart of harmonious construction between regulations, tech development & advancements and user awareness/responsibility.
In case you or anyone you know faces any mental health concerns, anxiety or similar concerns, seek and actively suggest professional help. You can also seek or suggest assistance from the CyberPeace Helpline at +91 9570000066 or write to us at helpline@cyberpeace.net
References
- https://www.bbc.com/news/articles/cgerwp7rdlvo
- https://www.livemint.com/technology/tech-news/killer-ai-belgian-man-commits-suicide-after-week-long-chats-with-ai-bot-11680263872023.html
- https://www.nytimes.com/2025/08/25/opinion/teen-mental-health-chatbots.html

Introduction
MGM Resorts, which is an international company, has suffered an ongoing cyberattack which led to the shutdown of a number of its computer systems, including its website, in response to a cybersecurity issue. MGM Resorts International is in touch with external cybersecurity experts to resolve the issue since it has affected its entire Computer systems. MGM is a larger entity and operates thousands of hotel rooms across Las Vegas and the United States. MGM Resorts shared about the incident and posted that MGM recently identified a cybersecurity issue affecting some of the Company's systems. Promptly after detecting the issue, they quickly began an investigation with assistance from leading external cybersecurity experts. MGM has notified law enforcement and took prompt action to protect systems and data, including putting down certain systems. MGM further stated that the investigation is ongoing.
The issue
Basic operations such as the online reservation and booking system MGM have been affected and shut down due to the cybersecurity issue faced by a lot of visitors. Since earlier times, casino security has been the state of the art as they were very vulnerable to attacks by robbers and con artists. This is what we have also seen in a lot of movies. In today's time, con artists and robbers are now strengthened by cyber tactics. This is exactly what was seen in the case of the MGM attack.
MGM Resorts is home to best-in-class amenities and facilities for guests, but with the increase in tourist traction, the vulnerabilities and the scope of cyber attacks have also increased. This is also because of open wifis in the establishments and the transition of casinos to e-casinos, thus causing a major shift towards digital and technology-based intervention for better customer experience and streamlining a lot of operations.
How real is the threat?
As reported by MGM Resorts, the following systems were impacted in the cyber security attack:
- Slots Machines: The slot machines placed in the casino suddenly went offline and displayed an error message for the players. Some players who were already using the slot machines lost their bets and were unable to withdraw their winnings.
- Room Keys: Some of the guests reported that the room keys became unresponsive, and in some cases, the replacement keys were also inactive for some time, causing massive chaos at the reception.
- Booking Status: All the bookings in today's time are made online; this was one of the worst-hit segments of the cyber attacks. Most of the bookings made automatically were put on hold, and the confirmations could be made only from the hotel reception, thus causing massive cancelling of the bookings and both the hotel and customers losing out on money.
- MGM App: The official app of MGM Resorts was completely down, thus causing a situation of confusion and panic among the guests. The users also received notifications to speak to different customer care executives, but some of the numbers were unattentive and seemed to be operated by bad actors.
- Data breach: The main focus of the cyber attack was dedicated to committing a data breach. The attack led to the breach of personal data of most of the users registered on the app or on the system of MGM Resorts.
Conclusion
The cyber attack on the tourism industry is a major and growing concern for the industry and its customers. Seeing the volatility of the data and the regular inflow of personal information this makes the hotel's cyber security system a vulnerable choice for bad actors. The cyber attack was no less than a fire sale, where in all the segments of the services offered were impacted. Similar attacks were reported by MGM in 2019 and 2020, and subsequently, the safety measures were also deployed, but the bad actors have hit the resorts chain owners again, in such cases the most paramount defence is having a safe and regularly updated firewall, upskilling of staff for IT issues and attacks, active reporting and investigation mechanisms for assisting the LEAs. In the times of rising cyberattacks, one needs to be critical of their data management and digital footprints. The sooner we adopt safe, secure and resilient cyber hygiene practices, the safer our future will be.
References:
https://www.bleepingcomputer.com/news/security/mgm-resorts-shuts-down-it-systems-after-cyberattack/
https://www.cnbc.com/2023/09/12/mgm-resorts-cybersecurity-incident-forces-system-outage.html