#FactCheck-Protest Video from Nagrota Falsely Linked to Opposition Against Indian Army
Executive Summary
A video is being widely circulated on social media by Pakistani propaganda-linked users, showing a group of people protesting on a road. It is being claimed that protesters in Jammu & Kashmir stopped Indian Army personnel from entering Nagrota, indicating growing public opposition against the forces. Research by CyberPeace Research Wing found that the claim is misleading. The viral video is unrelated to any protest against the Indian Army.
Claim
A user posted the video on X, claiming: “The days of Indian military occupation are numbered; people of Jammu & Kashmir have risen against India. Protesters stopped the Indian Army from entering Nagrota.”
- https://x.com/Stealthfalconer/status/2050301106623045758?s=20

Fact Check
During the research, the CyberPeace Research Wing team found no evidence of any such incident where civilians blocked or opposed the Indian Army in Nagrota. Further probe led to a post by an X user “Defence News Of INDIA,” which contained the full version of the viral video. The accompanying information clarified that the protest took place in Dansal’s Badsu Panchayat area of Nagrota and was led by BJP MLA Devayani Rana.

The protest was organized against the Public Health Engineering (PHE) Department over severe water shortage issues in the region. Locals, along with the MLA, staged a sit-in to highlight the lack of water supply.
We also found multiple media reports, including from KBC News – Kashmir and Jammu Links News, confirming that Devayani Rana led a road blockade protest in her constituency over water scarcity and accused the Jal Shakti Department of negligence and administrative failure. Additionally, videos of the same protest were available on social media platforms, including live streams shared from Devayani Rana’s official pages.

Conclusion
Our research confirms that the viral claim is false and misleading. The video does not show any protest against the Indian Army. It is actually from a demonstration led by Devayani Rana and local residents over water shortage issues in Nagrota.
Related Blogs
%20(1).webp)
Disclaimer:
The information is based on claims made by threat actors and does not imply confirmation of the breach, by CyberPeace. CyberPeace includes this detail solely to provide factual transparency and does not condone any unlawful activities. This information is shared only for research purposes and to spread awareness. CyberPeace encourages individuals and organizations to adopt proactive cybersecurity measures to protect against potential threats.
🚨 Data Breach Alert ⚠️:
Recently The Research Wing of CyberPeace and Autobot Infosec have come across a claim on a threat actor’s dark web website alleging a data breach involving 637k+ records from Federal Bank. According to the threat actor’s claim, the data allegedly includes sensitive details such as-
- 🧑Customer Name
- 🆔Customer ID
- 🏠 Customer Address
- 🎂 Date of Birth
- 🔢 Age
- 🚻 Gender
- 📞Mobile Number
- 🪪 PAN Number
- 🚘 Driving License Number
- 🛂 Passport Number
- 🔑 UID Number
- 🗳️ Voter ID Information
The alleged data was initially discovered on a dark web website, where the threat actors allegedly claimed to be offering the breached information for sale. Following their announcement of the breach, a portion of the data was reportedly published on December 27, 2024. A few days later, the full dataset was allegedly released on the same forum.
About the Threat Actor Group:
Bashe, a ransomware group that emerged in 2024, is claimed to have evolved from the LockBit ransomware group, previously operating under the names APT73 and Eraleig. The group employs data encryption combined with extortion tactics, threatening to release sensitive information if ransom demands are unmet. Their operations primarily target critical industries, including technology, healthcare, and finance, demonstrating a strategic focus on high-value sectors.

Breakdown of the Alleged Post by the Threat Actor:
- Target: Allegedly involves Customer’s Data of Federal Bank.
- Data Volume: Claimed breach includes 637,894 records.
- Data Fields: Threat actor claims the data contains sensitive information, including Customer name, Customer ID, Date of Birth, PAN Number, Age, Gender, Father Name, Spouse Name, Driving Licence, Passport Number, UID Number, Voter ID, District, Zip Code, Home Address, Mailing Address, State etc.
Analysis:
The analysis of the alleged data breach highlights the states purportedly most impacted, along with insights into the affected age groups, gender distribution, and other key insights associated with the compromised data. This evaluation aims to provide a clearer understanding of the claimed breach's scope and its potential demographic and geographic impact.
Top States Impacted:
As per the alleged breached data, Tamil Nadu has the highest number of affected customers, accounting for a significant 34.49% of the total breach. Karnataka follows closely with 26.89%, indicating a substantial number of individuals affected in the state. In contrast states such as Uttar Pradesh, Haryana, Delhi, and Rajasthan report minimal impact, with each state having less than 1% of affected customers. Gujarat records 3.70% of the breach, with a sharp drop in affected numbers from other states, highlighting a significant disparity in the extent of the breach across regions.

Impacted Age Range Statistics:
The alleged data breach has predominantly impacted customers in the 31-40 years age group, which constitutes the largest segment at 35.80% of the affected individuals. Following this, the 21-30 years age group also shows significant impact, comprising 27.72% of those affected. The 41-50 years age group accounts for 20.55% of the impacted population, while individuals aged 50 and above represent 12.68%. In contrast, the 0-20 years age group is the least affected, with only 3.24% of customers falling into this category.

Gender Wise Statistics:
The alleged data breach has predominantly impacted male customers, who constitute the majority at 74.05% of the affected individuals. Female customers account for 23.18%, while a smaller segment, categorized as "Others," constitutes 2.77%.

The alleged dataset from the threat actors indicated that a significant portion of customers' personal identification data was compromised. This includes sensitive information such as driving licenses, passport numbers, UID numbers, voter IDs, and PAN numbers.
Significance of the Allegations:
Though the claims have not been independently verified at our end it underscores the rising risks of cyberattacks and data breaches, especially in the financial and banking sectors. If true, the exposure of such sensitive information could lead to financial fraud, identity theft, and severe reputational damage for individuals and organizations alike.
CyberPeace Advisory:
CyberPeace emphasizes the importance of vigilance and proactive measures to address cybersecurity risks:
- Monitor Your Accounts: Keep a close eye on financial and email accounts for any suspicious activity.
- Update Passwords: Change your passwords immediately and enable Multi Factor Authentication(MFA) wherever possible.
- Beware of Phishing Attacks: Threat actors may exploit the leaked data to craft targeted phishing scams. Do not click on unsolicited links or share sensitive details over email or phone.
- For Organizations: Strengthen data protection mechanisms, regularly audit security infrastructure, and respond swiftly to emerging threats.
- Report: For more assistance or to report cyber incidents, visit https://cybercrime.gov.in or contact our helpline team at helpline@cyberpeace.net.
We advise affected parties and the broader public to stay alert and take necessary precautions. CyberPeace remains committed to raising awareness about cybersecurity threats and advocating for better protection mechanisms. We urge all stakeholders to investigate the claims and ensure appropriate steps are taken to protect the impacted data, if the breach is confirmed. Our Research Wing is actively observing the situation and we aim to collaborate with the stakeholders and relevant agencies to mitigate the impact.
Stay Vigilant! Stay CyberPeaceful.

Introduction
For most of us, UPI is part of daily routine: scan a QR code for chai, send money to family, split a bill, or pay a shopkeeper in seconds. That convenience is exactly why a message saying “UPI charges are coming” can cause confusion. Scammers can use that uncertainty through fake calls, WhatsApp messages, payment links, or edited screenshots. This blog keeps the topic simple: what MDR means, which UPI payments remain free, how scammers misuse the word “fee”, and what a reader should do when a payment request does not look right.
News in Focus: Why the “UPI Charge” Headline Needs Context

On 15 September 2026, the Ministry of Finance clarified the revised UPI framework. From 15 October 2026, a 0.4% MDR will apply to specified P2M transactions above ₹2,000, subject to the published conditions and caps. P2P transfers remain free, payments to merchants up to ₹2,000 remain free, and the government states that MDR is an ecosystem charge, not a customer fee. Banks are to ensure it is not passed on to customers. [1]
So, What Does This Mean for an Everyday User?

The important distinction is between a legitimate MDR rule and a scammer’s request for money. A message saying “pay ₹99 to release your UPI transaction” is not made genuine by mentioning NPCI, a bank, a government notice, or a news report.
A Related Cyber-Fraud Headline: Do Not Mix Two Different Issues

The supplied newspaper clipping discusses a separate cyber-fraud issue involving suspicious transactions and bank accounts linked to cybercrime. It is useful context, but it should not be read as proof that ordinary UPI users must pay a special “verification” or “release” fee. Separating the two issues helps prevent panic and misinformation.
Where Scammers Use the Confusion
“Pay a small fee to receive money”
A simple red flag is the demand for an upfront fee: “Your refund is ready, pay a processing fee first.” NPCI warns that scanning a QR code and entering a UPI PIN is for making a payment, not for receiving money or cashback. [2]
Fake payment success screens
Another common trick targets merchants: a fraudster shows a convincing “Payment Successful” screenshot and collects goods before the seller checks the account. In August 2026, Delhi Police reported a case involving allegedly fake or manipulated Paytm/UPI screenshots, followed by an attempt to gain access to victims’ mobile phones. [3] In September, police in Jharsuguda and Basti reported similar fake-confirmation cases; the Basti case involved a fabricated SBI YONO screenshot. [4][5]
“Your UPI is blocked because of new charges”
Scammers also borrow the language of genuine policy announcements. The caller creates urgency, claims your account is restricted, and asks you to install an app, share an OTP, approve a collect request, or transfer a small amount “for verification”. A real headline does not make an unexpected payment request genuine.
The Five-Second UPI Safety Check
Puse Before You Pay
WHO is asking? WHAT exactly are they asking you to do? WHERE did the payment request appear? WHEN did the request arrive? WHY would you need to pay to receive money? Verify the transaction in your own bank or UPI app. Merchants should not rely on a screenshot shown by a customer. Customers should not treat a QR code, collect request, or incoming message as proof that they are “receiving” money. Read the final authorisation screen before entering the UPI PIN. NPCI says users should never share the PIN and that bank customer support will not ask for it. [6]
If You Think You Have Been Scammed

- Stop engaging with the suspected caller, account, or chat. Do not send another payment to “fix” the first one.
- Contact your bank or the relevant payment app using an official support channel and report the transaction.
- For financial cyber fraud in India, call 1930 as soon as possible and report the incident through the National Cyber Crime Reporting Portal. The official portal identifies 1930 as the helpline for immediate reporting of financial cyber fraud. [7]
- Keep the transaction ID, screenshots, phone numbers, messages, and dates. Do not delete useful evidence.
Conclusion
The safest way to understand the UPI charge discussion is to slow the headline down. Yes, a revised MDR framework has been announced for certain merchant transactions above ₹2,000 from 15 October 2026. But that does not make a P2P transfer subject to a “release fee”, and it does not make an unsolicited ₹49, ₹99, or ₹199 demand legitimate. Check the transaction type, confirm where the charge sits, verify the payment in your own app or bank account, and never disclose your UPI PIN. Digital safety is not about fearing every payment; it is about recognising when someone asks you to leave the normal payment process.
Remember
UPI convenience should never require blind trust. Verify the sender, verify the screen, verify the transaction.
References
[1] Press Information Bureau, Ministry of Finance, “UPI Continues to Remain Free for Peer to Peer Transactions and 96% of Merchant Transactions,” 15 September 2026. https://www.pib.gov.in/PressReleseDetailm.aspx?PRID=2310586
[2] National Payments Corporation of India (NPCI), “Fraud Awareness,” current guidance on fake cashback links, QR codes and UPI PIN safety. https://www.npci.org.in/fraud-awareness
[3] Hindustan Times / PTI, “Delhi Police arrest man in ₹30.81 lakh cyber fraud involving fake UPI payments,” 26 August 2026. https://www.hindustantimes.com/cities/delhi-news/delhi-police-arrest-man-in-rs-30-81-lakh-cyber-fraud-involving-fake-upi-payments-101787734051785.html
[4] The Times of India, “Two held for fake UPI payment fraud in Jharsuguda,” 11 September 2026. https://timesofindia.indiatimes.com/city/bhubaneswar/two-held-for-fake-upi-payment-fraud-in-jharsuguda/articleshow/134072823.cms
[5] The Times of India, “Basti: 2 held for fake UPI payment scam,” 13 September 2026. https://timesofindia.indiatimes.com/articleshow/134154561.cms
[6] NPCI, “UPI - Frequently Asked Questions,” UPI PIN and transaction-confirmation guidance. https://www.npci.org.in/what-we-do/upi/faqs
[7] Government of India, National Cyber Crime Reporting Portal, financial cyber fraud reporting guidance and helpline 1930. https://www.cybercrime.gov.in/
[8] Moneycontrol, “Don't trust the screenshot: How to spot a fake UPI payment,” 6 August 2026. https://www.moneycontrol.com/news/business/personal-finance/don-t-trust-the-screenshot-how-to-spot-a-fake-upi-payment-13996275.html
Image note: Both visuals were supplied by the requester. Figure 1 was cross-checked against the Ministry of Finance/PIB clarification cited in Reference [1].

Executive Summary:
A viral video showing flames and thick smoke from large fuel tanks has been shared widely on social media. Many claimed it showed a recent Russian missile attack on a fuel depot in Ukraine. However, our research found that the video is not related to the Russia-Ukraine conflict. It actually shows a fire that happened at Al Hamriyah Port in Sharjah, United Arab Emirates, on May 31, 2025. The confusion was likely caused by a lack of context and misleading captions.

Claim:
The circulating claim suggests that Russia deliberately bombed Ukraine's fuel reserves and the viral video shows evidence of the bombing. The posts claim the fuel depot was destroyed purposefully during military operations, implying an increase in violence. This narrative is intended to generate feelings and reinforce fears related to war.

Fact Check:
After doing a reverse image search of the key frames of the viral video, we found that the video is actually from Al Hamriyah Port, UAE, not from the Russia-Ukraine conflict. During further research we found the same visuals were also published by regional news outlets in the UAE, including Gulf News and Khaleej Times, which reported on a massive fire at Al Hamriyah Port on 31 May 2025.
As per the news report, a fire broke out at a fuel storage facility in Al Hamriyah Port, UAE. Fortunately, no casualties were reported. Fire Management Services responded promptly and successfully brought the situation under control.


Conclusion:
The belief that the viral video is evidence of a Russian strike in Ukraine is misleading and incorrect. The video is actually of a fire at a commercial port in the UAE. When you share misleading footage like that, you distort reality and incite fear based on lies. It is simply a reminder that not all viral media is what it appears to be, and every viewer should take the time to check and verify the content source and context before accepting or reposting. In this instance, the original claim is untrue and misleading.
- Claim: Fresh attack in Ukraine! Russian military strikes again!
- Claimed On: Social Media
- Fact Check: False and Misleading