#FactCheck-Fake Claim Links White House Dinner Shooting Suspect to ‘Indian Wife’; Viral Images Likely AI-Generated
Executive Summary
After reports identifying Cole Thomas Allen as the accused in the shooting incident at the White House Correspondents’ Association (WHCA) dinner, several Pakistani propaganda-linked social media accounts began circulating a new claim alleging that the suspect’s wife is an Indian woman named Priyanka Rao. Users shared a photo purportedly showing Cole Thomas Allen with Priyanka Rao, along with an alleged Indian passport in her name. One user posted the image with the caption: “31-year-old Cole Thomas Allen with his Indian wife Priyanka Rao. Why do they always have three names?”
However, research by the CyberPeace Research Wing found the claim to be fake. The viral passport and accompanying image appear to be AI-generated.
Claim:
Social media users claimed that Cole Thomas Allen, accused in the WHCA dinner shooting, is married to an Indian woman named Priyanka Rao.

Fact Check:
During the research, multiple inconsistencies were found in the viral passport image, strongly indicating it is fabricated. A close review of the document revealed several obvious errors commonly seen in AI-generated content. For instance, in the “Nationality” field, the name “Cole Thomas Allen” was written instead of a country name. Such a basic mistake would not appear in any genuine government-issued passport.
The Hindi text on the document was also highly inaccurate and unnatural. Examples included:
- “राष्ट्रीयता” misspelled as “राष्ट्रीयाय”
- “जन्मतिथि” replaced with meaningless text
- “जन्म स्थान” incorrectly written
- “Issue” mistranslated as unrelated wording
- “Date of Expiry” left untranslated in Hindi format
Further analysis using an AI detection tool indicated that the viral passport image had a 69 percent probability of being AI-generated.

Conclusion:
The claim that WHCA dinner shooting accused Cole Thomas Allen has an Indian wife named Priyanka Rao is fake. The viral passport and image being shared online are likely AI-generated and part of a misinformation campaign.
Related Blogs

Introduction
Data protection has been a critical aspect of advocacy and governance all across the world. Data fuels our cyber-ecosystem and strengthens the era of emerging technologies. All industries and sectors are now dependent upon the data of the user. The governments across the world have been deliberating internally to address the issue and legality of Data protection and privacy. The Indian government has witnessed various draft bills and policies focusing on Data protection over the years, and the contemporary bill is the Digital Personal Data Protection Bill, 2023, which was tabled at the Lok Sabha (Lower House of Parliament) on 03 August for discussions and parliamentary assent.
What is DPDP, 2023?
The goal of the complete and comprehensive Digital Personal Data Protection Bill of 2023 is to establish a framework for the protection of personal data in India. The measure acknowledges the significance of protecting personal data and seeks to strike a balance between the necessity to process personal data for legitimate purposes and the right of individuals to do so. The bill establishes a number of crucial expressions and ideas associated with the protection of personal data, including “data fiduciary,” “data principal,” and “sensitive personal data.” It also emphasises the duties of data fiduciaries, including the need to establish suitable security measures to preserve personal data and the need to secure data principals’ consent before processing their personal information. The measure also creates the Data Protection Board of India, which would implement its requirements and guarantee data fiduciaries’ compliance. The board will have the authority to look into grievances, give directives, and impose sanctions for non-compliance.
Key Features of the Bill
The bill tabled at the parliament has the following key features:
- The 2023 bill imposes reasonable obligations on data fiduciaries and data processors to safeguard digital personal data.
- Under the 2023 bill, a new Data Protection Board is established, which will ensure compliance, remedies and penalties.
- Under the new bill, the Board has been entrusted with the power equivalent to a civil court, such as the power to take cognisance in response to personal data breaches, investigate complaints, imposing penalties. Additionally, the Board can issue directions to ensure compliance with the act.
- The 2023 bill also secures more rights of Individuals and establishes a balance between user protection and growing innovations.
- The bill creates a transparent and accountable data governance framework by giving more rights to individuals.
- There is an Incorporation of Business-friendly provisions by removing criminal penalties for non-compliance and facilitating international data transfers.
- The new 2023 bill balances out fundamental privacy rights and puts reasonable limitations on those rights.
- The new data protection board will carefully examine the instance of non-compliance by imposing penalties on non-compiler.
- The bill does not provide any express clarity in regards to compensation to be granted to the Data Principal in case of a Data Breach.
- Under 2023 Deemed consent is there in its new form as ‘Legitimate Users’ pertaining to the conditions in regard to Sovernity and Intergrity of India.
- There is an introduction of the negative list, which restricts cross-data transfer.
Additionally, the measure makes special provisions for the processing of children’s personal data and acknowledges the significance of protecting children’s privacy. Additionally, it highlights the rights of the data subjects, including their right to access their personal information, their right to have wrong information corrected, and their right to be forgotten.
Drive4CyberPeace
A campaign was undertaken by CyberPeace to gain a critical understanding of what people understand about Data privacy and protection in India. The 4-month long campaign led to a pan-India interaction with netizens from different areas and backgrounds. The thoughts and opinions of the netizens were understood and collated in the form of a whitepaper which was, in turn, presented to Parliamentarians and government officials. The whitepaper laid the foundation of the recommendations submitted to the Ministry of Electronics and Information Technology as part of the stakeholder consultation.
Conclusion
Overall, the Digital Personal Data Protection Bill of 2023 is an important step towards safeguarding Indian citizens’ privacy and personal data. It creates a regulatory agency to guarantee compliance and enforcement and offers a thorough framework for data protection. The law includes special measures for the protection of sensitive personal data and the personal data of children and acknowledges the significance of striking a balance between the right to privacy and the necessity of data processing.

In Delhi there is a bank branch where a lot of money was stolen from people over the country. This bank branch is where all the money disappeared. The people who did this did not wear masks. Break in at midnight. They just used a passbook a rubber stamp and a form that nobody checked carefully. This is the truth that the people who investigate cybercrime keep finding. The way that cybercriminals get away with the money is not by using a computer it is by using a bank account. The police in Delhi who investigate cybercrime have found that a lot of accounts were opened at bank branches. These accounts were opened using identity documents that were borrowed bought or stolen. Then these accounts were rented out to groups of criminals. One bank branch keeps coming up in complaints. This is not bad luck it is a sign of a bigger problem with how banks check who is opening an account.
These fake accounts, which are called " accounts" are controlled by criminal groups, not the people whose names are on the accounts. These accounts are a part of the cybercrime problem in India. The mistakes that bank branches make which allow these accounts to be opened raise a lot of questions. These questions are about how banks check who is opening an account how they prevent money laundering and how they work with groups to stop cybercrime. The bank accounts are the way that cybercriminals in India get away with the money they steal from people. The cybercrime investigators keep finding bank accounts like the ones at the bank branch, in Delhi, where the money was stolen.
The Anatomy of a Mule Account Network
The pattern is now familiar to investigators. A fraud complaint on the National Cyber Crime Reporting Portal traces a victim's stolen money to a beneficiary account. When police pull the account-opening file, the person named on the KYC documents often denies ever visiting the branch or signing the forms; signature verification frequently shows a mismatch. In one recent Delhi case, a cooperative bank's deputy manager was arrested after a single account he had helped open surfaced in 159 separate cyber fraud complaints from across the country, with transactions worth nearly Rs 68 crore routed through it before detection. Similar investigations have uncovered supply gangs that procure dozens of accounts at a time using POS machines, stacks of ATM cards, and cheque books belonging to different people and rent them out to fraudsters as ready-made conduits for stolen money.
What makes a single branch or a small cluster of accounts significant is what it reveals about entry-point failure. Investigators do not describe these as sophisticated hacking operations; they describe them as verification failures as are accounts opened without the mandatory in-person checks, video KYC, or document authentication that RBI rules require. When 96, or 700, or 8.5 lakh mule accounts are traced back through a handful of branches and intermediaries, the story is not really about the fraudsters at the far end of the chain. It is about the choke point where honest oversight should have stopped the account from ever existing.
Where the KYC Framework Is Breaking Down
The RBI's Know Your Customer Master Direction requires banks to establish customer identity, verify a genuine business relationship, and apply risk-based due diligence before allowing an account to operate. In practice, investigators have repeatedly found accounts opened through complicit or negligent bank staff, business correspondents, and third-party agents who bypass these checks entirely. Analysts note that mule accounts systematically exploit gaps in customer onboarding, KYC verification, transaction monitoring, and dormant-account surveillance, with criminals using forged or stolen identity documents and layering funds across multiple accounts to escape detection. Economically vulnerable individuals who are daily-wage workers, students, the unemployed are frequently paid a small commission to hand over their documents or existing accounts, often without understanding that they could face criminal liability for transactions they never authorised.
This is compounded by a financial-inclusion paradox that regulators themselves acknowledge: India has expanded banking access faster than it has expanded financial and digital literacy, leaving a population that is easy to recruit knowingly or unknowingly into mule networks. The result is a KYC regime that looks robust on paper but is only as strong as its weakest branch-level implementation, and weak implementation has proved trivially easy for organised networks to locate and exploit at scale.
The Regulatory and Institutional Response
RBI: From Static Compliance to Active Detection
The Reserve Bank of India has moved beyond periodic KYC audits toward technology-driven detection. It has directed banks to tighten onboarding controls, strengthen transaction monitoring, and report suspicious activity more proactively, and it has proposed additional safeguards, including limits on aggregate credits into accounts where a satisfactory business relationship has not yet been established. Its most significant intervention is MuleHunter.ai, an AI and machine-learning system built to flag suspected mule accounts from transaction-behaviour patterns rather than static KYC data alone; the platform is already operational across roughly two dozen banks and is being expanded. The RBI Innovation Hub has also begun working directly with the Indian Cyber Crime Coordination Centre (I4C) to share fraud-risk intelligence and coordinate detection in near real time.
FIU-IND and the PMLA Framework
The Prevention of Money Laundering Act, 2002 (PMLA) is the backbone of India's AML architecture. It mandates KYC verification, Customer Due Diligence, record maintenance, and timely reporting of suspicious transactions to the Financial Intelligence Unit–India (FIU-IND). Banks are required to file Suspicious Transaction Reports (STRs) and Cash Transaction Reports with FIU-IND, which in turn analyses financial intelligence and shares it with law enforcement and regulators. On paper, this creates a feedback loop between banks, the RBI, and enforcement agencies; in practice, the sheer volume of mule-linked transactions are hundreds of thousands of accounts flagged nationally has strained the capacity of this reporting chain to generate timely, actionable freezes before funds are withdrawn or converted to cryptocurrency.
The IT Act, CERT-In, and Cyber Enforcement
The Information Technology Act, 2000, together with provisions of the Bharatiya Nyaya Sanhita, provides the criminal-law basis for prosecuting mule account operators, aggregators, and the fraudsters who direct them. CERT-In's role sits slightly upstream of the banking layer: it issues advisories on phishing, fake payment gateways, and compromised digital infrastructure that fraud syndicates use to recruit mule account holders and move money. The Ministry of Home Affairs' I4C coordinates the National Cyber Crime Reporting Portal and the 1930 helpline, which allow victims to report fraud and trigger a limited window for freezing beneficiary accounts. I4C has also issued direct public alerts against illegal payment gateways built on mule accounts, warning citizens not to rent or sell their bank credentials to intermediaries.
The Coordination Gap
None of these institutions is short of legal authority. The gap is operational: banks, the RBI, FIU-IND, state police cyber cells, the CBI, and I4C each hold a piece of the picture, but no single agency has a real-time, end-to-end view of an account from opening to fraud to freeze. A mule account can be flagged by one bank's internal monitoring, reported through a completely different victim's complaint in another state, and investigated by a third jurisdiction's cyber police with each step introducing delay. The Indian Banks' Association has publicly pushed for the RBI to be given clearer power to directly freeze accounts flagged as mule accounts, rather than requiring each bank to act unilaterally or wait for a police request, precisely because this fragmentation lets fraudsters withdraw or launder funds within hours of a transaction.
Policy Recommendations
1. Mandatory video-KYC and biometric re-verification for all new accounts opened through business correspondents and third-party agents, with personal liability for verifying bank officials found complicit.
2. A statutory, RBI-backed mechanism allowing banks to freeze accounts flagged by MuleHunter.ai-type systems or FIU-IND intelligence within hours, rather than only after a formal police complaint.
3. A unified, interoperable case database linking the National Cyber Crime Reporting Portal, FIU-IND's STR system, and state cyber cells, so that an account flagged once is visible to every agency instantly.
4. Stronger due-diligence audits of banking correspondents and cooperative banks, which recur disproportionately in mule account cases relative to their share of total accounts.
5. Public financial-literacy campaigns targeted at the economically vulnerable groups most often recruited as unwitting mule account holders, paired with clear legal guidance distinguishing victims from willing participants.
Conclusion
The branch-level mule account cases surfacing across Delhi and other cities are not isolated policing stories; they are a live audit of India's AML and KYC architecture. The RBI, FIU-IND, CERT-In, and law enforcement agencies each have credible tools and legal mandates like MuleHunter.ai, PMLA reporting, IT Act prosecutions, and I4C's coordination portal chief among them but fraud syndicates continue to outpace the system by exploiting the seams between institutions rather than any single point of failure. Closing that gap requires less new law and more operational integration: faster account freezes, verified accountability at the point of account opening, and a shared, real-time picture of mule networks across every agency involved. Until banks, regulators, and investigators can act as one system rather than several disconnected ones, every dismantled racket will simply be replaced by the next.
References
- https://aninews.in/news/national/general-news/delhi-police-arrests-bank-deputy-manager-in-83776792-crore-mule-account-case-linked-to-159-cyber-fraud-complaints20260610130737/
- https://the420.in/delhi-bank-manager-mule-account-cyber-fraud-case/
- https://www.business-standard.com/finance/news/what-are-mule-accounts-cybercrime-banking-layer-india-fraud-rbi-126062400855_1.html
- https://www.business-standard.com/india-news/centre-freezes-450-000-mule-bank-accounts-used-in-cyber-fraud-schemes-124111200320_1.html
- https://www.medianama.com/2025/04/223-iba-rbi-cyber-fraud-measures-freeze-bank-accounts-cybercrime/
- https://www.deccanherald.com/amp/story/india%2Fcentre-warns-of-illegal-payment-gateways-and-mule-accounts-3252723
- https://www.deccanherald.com/india/over-85-lakh-mule-accounts-in-700-bank-branches-used-by-cyber-criminals-cbi-3604229
- https://website.rbi.org.in/en/web/rbi/-/notifications/master-direction-know-your-customer-kyc-direction-2016-updated-as-on-may-04-2023-lt-span-gt-11566
- https://www.indiacode.nic.in/bitstream/123456789/15402/1/moneylaunderingact2002.pdf
- https://www.indiacode.nic.in/bitstream/123456789/13116/1/it_act_2000_updated.pdf
- https://www.mha.gov.in/en/division_of_mha/cyber-and-information-security-cis-division/Details-about-Indian-Cybercrime-Coordination-Centre-I4C-Scheme

The World Economic Forum reported that AI-generated misinformation and disinformation are the second most likely threat to present a material crisis on a global scale in 2024 at 53% (Sept. 2023). Artificial intelligence is automating the creation of fake news at a rate disproportionate to its fact-checking. It is spurring an explosion of web content mimicking factual articles that instead disseminate false information about grave themes such as elections, wars and natural disasters.
According to a report by the Centre for the Study of Democratic Institutions, a Canadian think tank, the most prevalent effect of Generative AI is the ability to flood the information ecosystem with misleading and factually-incorrect content. As reported by Democracy Reporting International during the 2024 elections of the European Union, Google's Gemini, OpenAI’s ChatGPT 3.5 and 4.0, and Microsoft’s AI interface ‘CoPilot’ were inaccurate one-third of the time when engaged for any queries regarding the election data. Therefore, a need for an innovative regulatory approach like regulatory sandboxes which can address these challenges while encouraging responsible AI innovation is desired.
What Is AI-driven Misinformation?
False or misleading information created, amplified, or spread using artificial intelligence technologies is AI-driven misinformation. Machine learning models are leveraged to automate and scale the creation of false and deceptive content. Some examples are deep fakes, AI-generated news articles, and bots that amplify false narratives on social media.
The biggest challenge is in the detection and management of AI-driven misinformation. It is difficult to distinguish AI-generated content from authentic content, especially as these technologies advance rapidly.
AI-driven misinformation can influence elections, public health, and social stability by spreading false or misleading information. While public adoption of the technology has undoubtedly been rapid, it is yet to achieve true acceptance and actually fulfill its potential in a positive manner because there is widespread cynicism about the technology - and rightly so. The general public sentiment about AI is laced with concern and doubt regarding the technology’s trustworthiness, mainly due to the absence of a regulatory framework maturing on par with the technological development.
Regulatory Sandboxes: An Overview
Regulatory sandboxes refer to regulatory tools that allow businesses to test and experiment with innovative products, services or businesses under the supervision of a regulator for a limited period. They engage by creating a controlled environment where regulators allow businesses to test new technologies or business models with relaxed regulations.
Regulatory sandboxes have been in use for many industries and the most recent example is their use in sectors like fintech, such as the UK’s Financial Conduct Authority sandbox. These models have been known to encourage innovation while allowing regulators to understand emerging risks. Lessons from the fintech sector show that the benefits of regulatory sandboxes include facilitating firm financing and market entry and increasing speed-to-market by reducing administrative and transaction costs. For regulators, testing in sandboxes informs policy-making and regulatory processes. Looking at the success in the fintech industry, regulatory sandboxes could be adapted to AI, particularly for overseeing technologies that have the potential to generate or spread misinformation.
The Role of Regulatory Sandboxes in Addressing AI Misinformation
Regulatory sandboxes can be used to test AI tools designed to identify or flag misinformation without the risks associated with immediate, wide-scale implementation. Stakeholders like AI developers, social media platforms, and regulators work in collaboration within the sandbox to refine the detection algorithms and evaluate their effectiveness as content moderation tools.
These sandboxes can help balance the need for innovation in AI and the necessity of protecting the public from harmful misinformation. They allow the creation of a flexible and adaptive framework capable of evolving with technological advancements and fostering transparency between AI developers and regulators. This would lead to more informed policymaking and building public trust in AI applications.
CyberPeace Policy Recommendations
Regulatory sandboxes offer a mechanism to predict solutions that will help to regulate the misinformation that AI tech creates. Some policy recommendations are as follows:
- Create guidelines for a global standard for including regulatory sandboxes that can be adapted locally and are useful in ensuring consistency in tackling AI-driven misinformation.
- Regulators can propose to offer incentives to companies that participate in sandboxes. This would encourage innovation in developing anti-misinformation tools, which could include tax breaks or grants.
- Awareness campaigns can help in educating the public about the risks of AI-driven misinformation and the role of regulatory sandboxes can help manage public expectations.
- Periodic and regular reviews and updates to the sandbox frameworks should be conducted to keep pace with advancements in AI technology and emerging forms of misinformation should be emphasized.
Conclusion and the Challenges for Regulatory Frameworks
Regulatory sandboxes offer a promising pathway to counter the challenges that AI-driven misinformation poses while fostering innovation. By providing a controlled environment for testing new AI tools, these sandboxes can help refine technologies aimed at detecting and mitigating false information. This approach ensures that AI development aligns with societal needs and regulatory standards, fostering greater trust and transparency. With the right support and ongoing adaptations, regulatory sandboxes can become vital in countering the spread of AI-generated misinformation, paving the way for a more secure and informed digital ecosystem.
References
- https://www.thehindu.com/sci-tech/technology/on-the-importance-of-regulatory-sandboxes-in-artificial-intelligence/article68176084.ece
- https://www.oecd.org/en/publications/regulatory-sandboxes-in-artificial-intelligence_8f80a0e6-en.html
- https://www.weforum.org/publications/global-risks-report-2024/
- https://democracy-reporting.org/en/office/global/publications/chatbot-audit#Conclusions