#FactCheck-AI-Generated Video Falsely Shared as Footage of Iranian Missile Attack Filmed by a Kuwaiti Pilot
Executive Summary
A video is being widely shared on social media showing what appears to be a missile attack over a densely populated city at night. The footage, seemingly recorded from inside a passenger aircraft, shows multiple explosions and missiles lighting up the sky.The video is being circulated with the claim that a Kuwaiti pilot filmed Iranian missiles being launched towards a US military base in the Middle East from the cockpit of an aircraft.
CyberPeace Research Wing’s research found the viral claim to be false. Our research confirmed that while Iran has launched attacks on US military installations in the Middle East, the viral footage is not related to those incidents. The video was found to be AI-generated and is being shared with a false and misleading narrative.
Claim
An Instagram user shared the viral video on July 11, 2026, claiming that it was recorded by a Kuwaiti pilot from an aircraft and shows Iranian missiles targeting a US military base in the Middle East.
Post Link: https://www.instagram.com/reel/DanymEDIdp2/?utm_source=ig_web_button_share_sheet

Fact Check
To verify the claim, we conducted a keyword-based search on Google. During the research, we did not find any credible news report or authentic source linking the viral video to the alleged Iranian missile attack. We did find a Navbharat Times report covering Iran's strikes on US military bases in the Middle East. However, the report did not contain the viral footage or any reference suggesting that such a video had been recorded by a Kuwaiti pilot. https://navbharattimes.indiatimes.com/video/news/america-iran-war-retaliation-for-us-attacks-begins-iran-strikes-at-trumps-allies-and-its-neighbour/videoshow/132370583.cms

In the next stage of the research, we analysed the viral video using the AI detection tool Hive Moderation. The tool indicated that the video had a 74.8% probability of being AI-generated.

For additional verification, we also analysed the footage using another AI detection tool, DetectVideo AI. Its analysis showed a 61% probability that the video was AI-generated.

Conclusion
Our research found that the viral claim is false. Although Iran has carried out missile strikes on US military facilities in the Middle East, the viral video is not authentic and has no connection to those attacks. The footage was found to be AI-generated and is being circulated on social media with a misleading claim that it was recorded by a Kuwaiti pilot from an aircraft.
Related Blogs

Introduction
With mobile phones at the centre of our working and personal lives, the SIM card, which was once just a plain chip that links phones with networks, has turned into a vital component of our online identity, SIM cloning has become a sneaky but powerful cyber-attack, where attackers are able to subvert multi-factor authentication (MFA), intercept sensitive messages, and empty bank accounts, frequently without the victim's immediate awareness. As threat actors are becoming more sophisticated, knowing the process, effects, and prevention of SIM cloning is essential for security professionals, telecom operators, and individuals alike.
Understanding SIM Cloning
SIM cloning is the act of making an exact copy of a victim's original SIM card. After cloning, the attacker's phone acts like the victim's, receiving calls, messages, and OTPs. This allows for a variety of cybercrimes, ranging from unauthorised financial transactions to social media account hijacking. The attacker virtually impersonates the victim, often leading to disastrous outcomes.
The cloning can be executed through various means:
● Phishing or Social Engineering: The attack compels the victim or a mobile carrier into divulging personal information or requesting a replacement SIM.
● SIM Swap Requests: Attackers use fake IDs or stolen credentials to make telecom providers port the victim's number to a new SIM.
● SS7 Protocol Exploitation: Certain sophisticated attacks target weaknesses in the Signalling System No. 7 (SS7) protocol employed by cellular networks to communicate.
● Hardware based SIM Cloning: Although uncommon, experienced attackers will clone SIMs through the use of specialized hardware and malware that steals authentication keys.
The Real-World Consequences
The harm inflicted by SIM cloning is systemic as well as personal. The victims are deprived of their phones and online accounts, realising the breach only when improper dealings or login attempts have occurred. The FBI reported over $50 million loss in 2023 from crimes associated with SIM, most of which involved cryptocurrency account and high net-worth persons.
Closer to home, Indian entrepreneurs, journalists, and fintech users have reported losing access to their numbers, only to have their WhatsApp, UPI, and banking apps taken over. In a few instances, the attackers even contacted contacts, posing as the victim to scam others.
Why the Threat Is Growing
Dependence on SMS-based OTPs is still a core vulnerability. Even as there are attempts to move towards app-based two-factor authentication (2FA), most banking, government, and e-commerce websites continue to employ SMS as their main authentication method. This reliance provides an entry point for attackers who can replicate a SIM and obtain OTPs without detection.
Vulnerabilities in telecom infrastructure are also a part of the issue. Insider attacks at telecom operators, where malicious employees handle fraud SIM swap requests, also keep cropping up. On top of that, most users are not even aware of what exactly SIM cloning is or how to identify it, leaving attackers with a head start.
Very often, the victims are only aware that their SIM has been cloned when they lose mobile service or notice unusual activity on their accounts. Red flags include loss of signal, failure to send or receive messages, and inability to receive OTPs. Alerts on password changes or unusual login attempts must never be taken lightly, particularly if this is coupled with loss of mobile service.
How Users Can Protect Themselves
● Use A Strong SIM Pin: This protects your SIM from access by unauthorized users should your phone be lost or stolen.
● Secure Personal Information: Don't post sensitive personal information online that can have a place in social engineering.
● Notify your Carrier of Suspicious Activity: If your phone suddenly has lost service or is behaving strangely, contact your mobile operator immediately.
● Register for Telecom Alerts: Many providers offer alerts to SIM swap or porting requests that are useful to preliminarily detect a possible takeover.
● Verify SIM card status using Sanchar Saathi: Visit [https://sancharsaathi.gov.in](https://sancharsaathi.gov.in) to check how many mobile numbers are issued using your ID. This government portal allows you to identify unauthorized or unknown SIM cards, helping prevent SIM swapping fraud. You can also request to block suspicious numbers linked to your identity.
Conclusion
SIM cloning is not a retrograde nod to vintage cybercrime; it's an effective method of exploitation, especially where there's a strong presence of SMS-based authentication. The attack vector is simple, but the damage it causes can be profound, both financial and reputational. With telecommunication networks forming the backbone of digital identity, users, regulators, and telecom service providers have to move in tandem. For the users, awareness is the best protection. For Telecoms, security must be a baseline requirement, not a value-add option. It's time to redefine mobile security, before your identity is in anyone else's hands.
References
● https://www.trai.gov.in/faqcategory/mobile-number-portability
● https://www.cert-in.org.in/PDF/Digital_Threat_Report_2024.pdf
● https://www.ic3.gov/PSA/2022/PSA220208/
● https://www.hdfcbank.com/personal/useful-links/security/beware-of-fraud/sim-swap
● https://security-gen.com/SecurityGen-Article-Cloning-SimCard.pdf
● https://www.p1sec.com/blog/understanding-ss7-attacks-vulnerabilities-impacts-and-protection-measures

Perth, Western Australia — For most of the past year, the name TeamPCP has circulated quietly within cybersecurity circles as shorthand for a particular kind of dread: not the dread of a phishing email or a suspicious link, but the dread of software you already trusted turning against you. This week, that quiet circulation became public record. The Australian Federal Police, working alongside the FBI and the Western Australia Police Force, arrested and charged two Western Australian men, aged 21 and 23, with a combined 14 offences over their alleged role in the group.
The arrests themselves are notable. The story behind them is more so.
A Campaign Built on Borrowed Trust
TeamPCP's alleged method was not to break down the front door. It was to compromise the door itself, the trusted mechanisms by which developers pull code into their own projects every day. The group has been linked to widespread supply-chain attacks that targeted open-source software and developer platforms to steal credentials, authentication secrets, and source code, with high-profile incidents affecting projects including Trivy, LiteLLM, Telnyx, SAP, and TanStack, alongside breaches at organisations such as the European Commission, Mistral AI, OpenAI, and GitHub. Reporting has also linked the campaign to ecosystems including GitHub Actions, Docker Hub, npm, PyPI and OpenVSX, the invisible plumbing through which most modern software is assembled.
The scale, as alleged by investigators, is difficult to overstate. Authorities say the malicious code potentially compromised over a thousand organisations worldwide, enabling the theft of roughly half a million credentials and the exfiltration of at least 300GB of data, figures that should be understood as allegations under active investigation rather than an independently verified victim count. The AFP itself has said the compromise of a small number of trusted software components had a significant global impact, with remediation costs estimated in the hundreds of millions of dollars.
Why This Attack Was So Hard to See Coming
The mechanics matter. Rather than tricking a user into clicking something malicious, the alleged operation worked by compromising the credentials developers use to publish legitimate software updates, then pushing tampered versions out through the same trusted distribution pipelines millions of applications rely on automatically. There is no obviously suspicious file, no rogue website, only a routine update, arriving exactly where it was expected.
Investigators also describe a cascading structure to the intrusions: credentials harvested from one compromised project reportedly opened the door to the next, turning isolated breaches into a chain reaction across the open-source ecosystem. TeamPCP has been described as running one of the most consequential campaigns of software supply-chain attacks investigators have tracked, and the group's reach extended notably into the AI stack — LiteLLM, one of the projects reportedly compromised, is an open-source gateway widely used to connect applications to large language model providers, meaning the attack's blast radius extended into the very infrastructure powering today's AI boom.
The Investigation and the Charges
The two men were charged following a joint investigation by the AFP and WAPF, working in parallel with the FBI, into what authorities describe as a sophisticated cybercrime syndicate accused of creating malicious open-source software to defraud thousands of global businesses. The charges span identity theft, unauthorised data modification, and money laundering, with maximum penalties ranging from three to twenty years' imprisonment. Search warrants were executed in Perth on 26 August 2026, and investigators seized electronic devices for forensic analysis after raids at properties in Cottesloe, Hamilton Hill, and Mandurah. FBI Cyber Division Assistant Director Brett Leatherman noted the significance of the international cooperation involved in the case, while investigators have not ruled out further arrests.
The Real Story: A Governance Problem, Not Just a Crime Story
It would be easy to file this under "hackers caught" and move on. But the more consequential story is structural. Modern organisations do not merely secure their own infrastructure, they inherit risk from every library, package, CI/CD pipeline, repository, vendor and developer tool they depend on, often without ever auditing that dependency chain directly. Guidance from the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on securing open-source software has increasingly emphasised managing these dependencies through software bills of materials (SBOMs), precisely because so few organisations can otherwise answer a basic question: what, exactly, is running inside our systems?
TeamPCP's alleged campaign is a case study in why that question can no longer be optional. If an organisation's security posture is only as strong as the thousands of components it silently trusts, then supply-chain security is not a developer problem to be quietly patched — it is a governance issue, deserving board-level attention, vendor accountability frameworks, and mandatory disclosure practices.
CyberPeace's Take
At CyberPeace, we've been watching campaigns like TeamPCP's less as isolated incidents and more as a pattern that keeps repeating with higher stakes each time. What stands out to our team isn't the sophistication of the code, open-source poisoning is, frankly, not a new technique, it's the sophistication of patience. Compromising a maintainer's publishing credentials and simply waiting for the next scheduled release to carry the payload downstream is a strategy built for an ecosystem that still largely operates on implicit trust rather than continuous verification. That gap between how fast software moves and how slowly trust is actually checked is precisely where operations like this thrive.
We'd also push back gently on treating this as a "developer hygiene" story. Most engineering teams pulling in a package from npm or PyPI are not, and should not be expected to be, forensically auditing every dependency update by hand, that isn't scalable, and it was never a realistic line of defence. The actual fix has to sit further upstream: provenance verification baked into CI/CD pipelines, signed commits and releases treated as non-negotiable rather than optional, and SBOMs that are actually queried during incident response rather than generated once and filed away.
Our broader concern, honestly, is about incentive alignment. Open-source maintainers are frequently unpaid or under-resourced volunteers holding publishing keys to software depended on by billion-dollar enterprises. Until organisations that consume open-source software at scale start meaningfully funding its security, not just its development, this pattern isn't going away. It will simply find its next entry point.
References
- Australian Federal Police. Two WA men charged following AFP-FBI-WAPF disruption of alleged global cybercrime syndicate. afp.gov.au
- Bleeping Computer. Australia arrests alleged TeamPCP hackers behind supply-chain attacks. bleepingcomputer.com
- CyberScoop. Two alleged TeamPCP members arrested and charged after months of software supply-chain chaos. cyberscoop.com
- Cyber Daily. Busted! Alleged Aussie hackers linked to TeamPCP arrested in joint AFP-FBI-WAPF operation. cyberdaily.au
- Help Net Security. Two alleged TeamPCP hackers arrested over global supply chain attacks. helpnetsecurity.com
- Krebs on Security. Two Alleged 'TeamPCP' Hackers Arrested in Australia. krebsonsecurity.com
- TechCrunch. Australian police arrest two over TeamPCP hacks targeting Mercor, OpenAI, and others. techcrunch.com
- The Hacker News. Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks. thehackernews.com

Introduction
In recent years, India has seen tremendous growth in its space industry. The satellite infrastructure of India now provides key services to a variety of sectors, including communication, navigation, broadcasting, disaster management and national security operations. Satellite communications globally will connect remote communities, aid in the delivery of Digital Governance and support India's strategic military capabilities. Given the expanding space ecosystem in India with the involvement of the public sector, private sector and research institutions, the security of satellite communications is becoming increasingly important.
At the same time, as satellite communication technologies become more pervasive, the risk of cyber threats targeting space systems increases. Cyberattacks against satellites, ground terminals or communication networks may critically impact, disrupt, damage, and/or destroy essential services, and expose sensitive information. To mitigate these risks, CERT-In (Computer Emergency Response Team), in collaboration with the SatCom Industry Association of India released a Cyber Security Framework and Guidelines for Space Platforms/Systems, including Satellite Communication, in 2026. This framework aims to establish and enhance cybersecurity measures throughout India's space ecosystem, while guiding how to better prepare for and respond to the growing volume of cyber threat activity targeting Space Systems.
Overview of the CERT-In Space Cybersecurity Framework
CERT-In introduced a dedicated cybersecurity framework for space systems in February 2026. Developed in collaboration with industry stakeholders, the framework provides guidelines to strengthen the security of satellite communication infrastructure across India. Although the guidelines are advisory in nature, they are designed to promote best practices and encourage organisations to adopt robust cybersecurity measures.
The framework targets a wide range of stakeholders involved in satellite communication operations. These include government agencies, satellite operators, ground station operators, equipment manufacturers, technology vendors, and emerging space startups. By outlining cybersecurity principles, technical controls, and governance mechanisms, the framework aims to create a coordinated approach to protecting space assets.
Another key objective of the guidelines is to foster collaboration between the public and private sectors. As India’s space industry expands and private participation increases, maintaining a secure and resilient ecosystem becomes essential. The framework, therefore, emphasises risk management, incident reporting, and continuous monitoring to strengthen the overall cybersecurity posture of the space sector.
Key Components of Satellite Communication Systems
Satellite communication systems are made up of multiple interconnected devices that can be used to deliver communication services. The cybersecurity framework groups these elements into three categories: the space segment, the ground segment, and the user segment.
The space segment is everything related to the satellite itself, including the satellite's onboard systems. This includes the satellite's communication payload, telemetry systems, antennas, power systems, and software that controls its operation. Because satellites operate in remote parts of space with very little opportunity for maintenance, securing these systems is critical in order to guard against unauthorized access to or control of these systems.
The ground segment comprises the terrestrial infrastructure responsible for controlling the satellite's operations. It consists of satellite mission control centres, ground stations, network gateways and data processing facilities. The ground stations send commands to the satellites and receive telemetry data from the satellites, which makes the ground station a very important physical interface point between the satellite asset located in outer space and a terrestrial network.
The user segment contains any device terminal being used by either an individual or an organisation that is accessing a satellite service. Examples of user devices are satellite phones, VSAT terminals, modems, and IoT devices connected to satellite networks. Since these devices connect directly to the communication networks, vulnerabilities in user equipment could also represent a significant threat to the cybersecurity of satellite communications.
Major Cyber Threats to Space Infrastructure
The space systems that support the delivery of satellite communications are being increasingly targeted with multiple types of cyber threats. A major category includes cyber-attacks on communication links between satellites and ground stations. Cyber criminals can attempt to jam the satellite’s communication link, intercept communication signals, or re-transmit previously sent communication signals in order to disrupt the operation of the affected satellites.
Attacks on the systems that control the satellite are serious threats to satellite operations. Cybercriminals and hostile actors can perform command injection attacks where commands are sent to a satellite, and the satellite responds through some undesired action. If cybercriminals are able to gain access to the telemetry or command channels, they can potentially disrupt the operation of the satellite or alter the telemetry data being received from the satellite.
The ground infrastructure that supports satellite communications is still a major target for cybercriminals. Mission control networks and data centres are susceptible to malware, ransomware, phishing, and insider threats. Attackers will frequently target ground stations because they provide a connection point to terrestrial networks and can exploit vulnerabilities from the ground station’s IT systems into the satellite control systems. The combination of these threats illustrates the need for an overall security strategy that encompasses all parts of the satellite communications ecosystem.
Key Security Principles and Measures
A comprehensive overview of multiple principles designed to increase the security of satellite communications is provided in the CERT-In Framework on Cybersecurity for Satellite Communications. The first of these principles, security by design, refers to ensuring that all cybersecurity controls associated with a system are implemented at the time of the system's initial design and development, not afterwards; therefore, security controls should be incorporated throughout the entire lifecycle of a satellite system.
The second principle, which is known as Defense-in-Depth, consists of implementing many different layers or tiers of security controls to protect a system against cyber threats or attacks. An example of the different categories of security controls includes physical security, network security, and access control, among others. By combining security controls across multiple categories, an organisation may be able to reduce the chance that one single vulnerability will result in the loss of the entire system.
The third principle in the Framework, Zero Trust Architecture (ZTA): Users and/or devices located within a network should not be able to rely on implicit trust. Therefore, every request for access to the network will be verified and continuously monitored for potential threats.
The previous two principles stated that secure satellite communications should be conducted using strong encryption and authentication methods, as well as secure communications methods, and that an enterprise monitoring system would be put into place to help detect anomalies or suspicious behaviour.
Conclusion
India is taking an important step toward protecting its expanding space ecosystem by creating a cybersecurity framework to safeguard cyberspace systems from cyber threats. The CERT-In guidelines offer a structured means of reducing the likelihood of cyber threats impacting satellite communication infrastructure through secure system design, continuous monitoring of systems and creating consistent partnerships among organisations. As well as providing evidence that both government and private sector organisations share a collective responsibility for the protection of space assets, both sectors participate in a collaborative effort.
India will need to implement rigorous cybersecurity measures as it expands its space infrastructure in order to ensure the continued availability of critical space infrastructure and ultimately develop its existing commercial satellite business operations with the highest level of safety and security.
References
- https://www.cert-in.org.in/s2cMainServlet?pageid=GUIDLNVIEW02&refcode=CISG-2026-01
- https://www.pib.gov.in/PressReleasePage.aspx?PRID=2233122®=3&lang=1