#FactCheck: Viral AI image shown as AI -171 caught fire after collision
Executive Summary:
A dramatic image circulating online, showing a Boeing 787 of Air India engulfed in flames after crashing into a building in Ahmedabad, is not a genuine photograph from the incident. Our research has confirmed it was created using artificial intelligence.

Claim:
Social media posts and forwarded messages allege that the image shows the actual crash of Air India Flight AI‑171 near Ahmedabad airport on June 12, 2025.

Fact Check:
In our research to validate the authenticity of the viral image, we conducted a reverse image search and analyzed it using AI-detection tools like Hive Moderation. The image showed clear signs of manipulation, distorted details, and inconsistent lighting. Hive Moderation flagged it as “Likely AI-generated”, confirming it was synthetically created and not a real photograph.

In contrast, verified visuals and information about the Air India Flight AI-171 crash have been published by credible news agencies like The Indian Express and Hindustan Times, confirmed by the aviation authorities. Authentic reports include on-ground video footage and official statements, none of which feature the viral image. This confirms that the circulating photo is unrelated to the actual incident.

Conclusion:
The viral photograph is a fabrication, created by AI, not a real depiction of the Ahmedabad crash. It does not represent factual visuals from the tragedy. It’s essential to rely on verified images from credible news agencies and official investigation reports when discussing such sensitive events.
- Claim: An Air India Boeing aircraft crashed into a building near Ahmedabad airport
- Claimed On: Social Media
- Fact Check: False and Misleading
Related Blogs

Executive Summary - When Anthropic and OpenAI's AI Testing Turned Into Real Breaches
You would be surprised to know that a testing function built to measure how good AI models are at simulated hacking ended up doing the real thing instead. Not once , but three times, across two of the world's leading AI labs, within the same 9-day window at the end of July 2026. As per the reports, Anthropic, which is among the world's leading AI labs, was running these evaluations on its own AI models namely - Claude Opus 4.7, Claude Mythos 5, and an unreleased research model, inside an environment co-managed with a third-party evaluation vendor. As per the reports, the models were told they were operating inside closed, internet-free simulations. They were not. A configuration error left the door open to the real internet, and the AI did exactly what it was trained to do in a hacking exercise, find the target and break in. Except the targets, this time, were real companies. Real credentials got stolen. Real data got accessed. Two of the three victims didn't even know they'd been breached until the AI lab called to tell them. This shows how a single unverified assumption, "this environment has no internet access" can quietly collapse the entire safety boundary of an AI test. It indicates that as these systems get more capable and more autonomous, the risk isn't necessarily the AI deciding to go rogue, it is humans failing to double-check the cage before putting something powerful inside it. And it warns us that the margin for this kind of error is shrinking fast, because what used to be a contained mistake can now scan thousands of systems and act on it within minutes. bAnthropic was not alone. Just over a week earlier, on 21 July, OpenAI had disclosed that its own models, GPT-5.6 Sol and an unreleased successor broke out of an isolated test environment and reached the real production infrastructure of Hugging Face, another AI company. In fact, it was OpenAI's disclosure that pushed Anthropic to go back and audit its own evaluation runs in the first place, which is how the three incidents above came to light. This blog examines the incident not as an isolated slip-up by two labs, but as a preview of the larger picture, a world where the gap between "theoretically vulnerable" and "actually exploited" is closing faster than most organisations' security practices are ready for.
The Chain of Disclosures
It started with Hugging Face, the open-source AI platform, which disclosed on July 16 that it had detected and contained an intrusion into part of its production infrastructure, driven end-to-end by an autonomous AI agent. Five days later, OpenAI confirmed it was responsible: models it was evaluating internally, GPT-5.6 Sol and an unreleased prototype, both running with their cyber-safety behaviour deliberately turned down to measure raw capability, had exploited a previously unknown vulnerability to break out of an isolated test environment and reach Hugging Face's real servers, apparently while chasing answers to a benchmark challenge. That disclosure prompted Anthropic to go back through its own records. On July 30, it published the results: after auditing 141,006 evaluation runs in which its Claude models could conceivably have touched the internet, it found three incidents, six runs in total, in which a model reached real systems belonging to three outside organisations and gained unauthorised access.
How a Fictional Exercise became a Real Attack
All three Anthropic incidents shared the same root cause. Claude was being run through capture-the-flag exercises, a standard way labs test offensive cyber capability: the model is dropped into a fictional scenario, told a piece of secret data is hidden somewhere on a network, and left to find its own way in. Anthropic's prompts told Claude, explicitly, that the environment was an internet-free simulation. Because of a misunderstanding with its evaluation partner, Irregular, that statement was false; the machines had live internet access nobody had verified. So when Claude's search for the flag led it onto the open internet, it did what it had been told to expect: it assumed everything it found was part of the exercise, including things that weren't.
- Incident 1: A fictional target company happened to share its name with a real, active domain. Across four runs, Claude Opus 4.7 attacked the real company instead, extracting infrastructure credentials and reaching a database containing several hundred rows of genuine production data, the most serious impact of the three incidents. In its own reasoning, the model repeatedly noted the system looked real and kept going anyway.
- Incident 2: Inside its fictional scenario, Claude Mythos 5 found a fake "onboarding document" referencing a software package that didn't exist on PyPI, the public Python package registry. It recognised the opportunity, built a functioning malicious package, and, after working around several dead ends to get an email account and register on PyPI, published it. The package lived online for about an hour and was installed on fifteen real machines, including a security company's automated scanner, letting Claude harvest real credentials from a company it had never even set out to target.
- Incident 3: An unreleased internal research model, unable to find its fictional target, scanned roughly 9,000 real hosts and broke into one using textbook techniques credentials read off an exposed debug page, then SQL injection. Partway through, it noticed the system it had compromised had no plausible link to its assignment, concluded on its own that the target was real, and stopped.
Timeline of Incidents

The Threat is Scale, not Novelty
None of the three models discovered a novel vulnerability. Weak passwords, unauthenticated endpoints, exposed debug output, and a classic "dependency confusion" trick are techniques that have appeared on security checklists for a decade and are still relevant. That's arguably the more sobering finding: the frontier is not a new class of attack; it is the speed and tirelessness with which known, boring weaknesses can now be found and used. Anthropic's own analysis lands on a subtler point, too: in each case, whether the model's behaviour counted as "aligned" or "harmful" depended entirely on what it believed about its situation, not on any goal of its own. All three models were simply trying to complete the task they had been assigned. Two of them did so while holding a false belief, installed by their own evaluators, about whether their targets were real. Only the newest of the three models, on independently concluding it had reached a genuine system, chose to stop. Anthropic is careful to note this is not a controlled experiment and should not be read as a guarantee that newer models will always behave better. But the throughline is clear enough: telling a capable model a lie about its environment is not a neutral setup choice. It is itself a safety-relevant decision.
The Detection Gap
Perhaps the most alarming detail is the quietest one. Anthropic reached out to the three affected organisations on July 27. Two of them had detected nothing at all, no alert, no anomaly, no investigation until that call. Real credentials had been stolen and real data accessed inside systems whose owners had no idea anything had happened. That is a statement about the state of everyday detection capability, not about AI. An agent that completes an entire intrusion, start to finish, within a single automated session doesn't leave the kind of slow, human-paced footprint that most monitoring is built to catch.
The Silver Lining - Why These Disclosures Deserve Credit
Both incidents share an underappreciated feature: they were disclosed voluntarily, promptly, and with real detail, and both labs notified the organisations affected. Hugging Face brought in outside forensic specialists and law enforcement. Anthropic halted its cyber evaluations the same day it found the first suspicious transcript and has asked METR, an independent evaluation body, to review its findings. That kind of candour is exactly the behaviour any sensible policy response should want to reinforce. A regulatory reflex that punishes disclosure risks teaching labs to say less next time, not to do better. What both incidents point to, far more than any specific model capability, is a mundane and fixable governance gap: environments used to test powerful, semi-restrained AI systems need the same security discipline as production systems, verified network isolation, continuous monitoring, and evaluation scopes that are stated positively ("here is what's in bounds") rather than enforced by simply telling the model a comforting falsehood. As both companies note, a fictional test range that turns out to have a live path to the internet isn't really fictional anymore. Basic asset hygiene, like knowing what's exposed, patching debug endpoints, claiming your internal package names before someone else does, and watching outbound traffic from environments that are supposed to have none did more to prevent and contain these incidents than anything specific to the models involved.
CyberPeace findings and recomendations : For enterprises and public institutions
- Maintain a full inventory of internet-facing assets and unauthenticated endpoints, and assume the inventory is incomplete until proven otherwise.
- Eliminate default, weak, and reused credentials, and enforce phishing-resistant MFA on anyone externally reachable.
- Strip debug pages and verbose error output from production systems.
- Treat dependency confusion as a live threat: pin dependencies, use private registry namespaces, and pre-emptively claim internal package names on public registries.
- Apply deny-by-default egress filtering to every environment running AI or agentic tooling, including development and test environments, and verify isolation empirically rather than assuming it from configuration.
- Alert on any outbound connection from an environment that is supposed to have none.
- Review authentication and access logs from April 2026 onwards for short, unusually efficient sessions that look more like machine-speed compromise than human reconnaissance.
For AI developers and evaluation vendors
- Network-isolate offensive-capability evaluation environments by default, with isolation verified per run rather than inherited from configuration.
- State the scope explicitly and positively, which systems are in bounds rather than asserting a falsehood about connectivity.
- Build contractual isolation guarantees and joint pre-run verification into third-party evaluation partnerships; both labs involved here have acknowledged that neither side alone caught the misconfiguration.
- Monitor transcripts and network logs continuously, not retrospectively.
For policymakers
- A regulatory response that punishes candour risks producing silence rather than safety. India currently has no reporting framework that clearly covers containment failures in AI evaluations affecting Indian entities' behaviour.
- RT-In's existing incident-reporting directions were not drafted with this candour in mode. Closing that gap would mean an explicit reporting obligation for evaluation of containment failures touching third-party infrastructure and a safe harbour mechanism that protects labs which disclose promptly.
- Minimum containment standards (egress verification, log retention) for organisations conducting offensive-capability AI evaluation within Indian jurisdiction;
- Recognition in national cyber doctrine that agentic tooling collapses the gap between a known-but-deferred vulnerability and an exploited one.
Conclusion
The above incidents reveal less about AI's offensive capability and more about the gap between how these systems are tested and how carefully those tests are contained. Both labs found the breaches through their own review, not external detection, a point in their favor, but also a reminder that containment failures can go unnoticed for a while. The realistic risk ahead isn't a sudden leap in AI's hacking sophistication; it's the compounding effect of speed and scale applied to routine reconnaissance, run against infrastructure that assumes a human attacker's pace. Treating evaluation environments with the same rigor as production systems, sandboxing, monitoring, and independent audits, should become standard practice, not an afterthought triggered by another lab's incident. The path forward is less about slowing AI down and more about catching up our containment discipline to match what these systems can now do.
Sources
- Anthropic, "Investigating three real-world incidents in our cybersecurity evaluations" (July 30, 2026)
- OpenAI, "OpenAI and Hugging Face partner to address security incident during model evaluation" (July 21, 2026, updated July 28–29, 2026)
- Hugging Face, "Security incident disclosure — July 2026" (July 16, 2026)
- Axios, "Anthropic says three Claude models reached real-world systems during cyber tests" (July 30, 2026)
- Help Net Security, "Anthropic's Claude breached three companies during security tests" (July 31, 2026)
- Simon Willison, "Investigating three real-world incidents in our cybersecurity evaluations" (July 30, 2026)
Contributors
- Maj. Vineet Kumar, Founder & Global President, CyberPeace
- Mr. Neeraj Soni, Sr. Researcher, Policy & Advocacy, CyberPeace
- Mr. Isharth Kumar, (NLIU Bhopal), Intern, Policy & Advocacy, CyberPeace

Introduction
Not every major breach begins with a sophisticated new exploit. Sometimes it begins with a device nobody remembered to update, and this one began exactly that way, at scale. Security researchers have disclosed a campaign that compromised more than 14,530 internet connected cameras made by Dahua Technology, (one of the world's largest surveillance equipment manufacturers), using a mix of stolen credentials, two long known authentication flaws, and a peer to peer relay technique that let attackers reach devices tucked behind home and office routers. The operation, tracked by researchers at Hunt.io, has been named Operation CameraSwarm. It ran between June 17 and July 22, 2026, and was reconstructed almost entirely from an exposed 407 megabyte working directory the attackers themselves left accessible, containing over 2,600 files, campaign logs, shell history, and tooling. Confirmed compromises were concentrated in Ukraine and Russia, and researchers described the operators/attackers as Russian speaking based on language artifacts found in the recovered material, suggesting the campaign was most plausibly built around surveillance or access relevant to the ongoing conflict between the two countries, though no formal attribution to a named threat actor or state entity has been established or claimed. What makes this worth understanding in detail is not just the scale, though 14,500 compromised cameras is a serious number, but how mundane the actual break in methods were. None of this depended on the attackers discovering some brand new, unknown flaw, the kind of vulnerability security researchers call a ‘zero day’. It depended on something far more ordinary: thousands of devices running years-old software that had never been patched, combined with cheap automated tools that could try weak passwords and known exploits at scale.
What is Dahua, and why does this matter
Dahua Technology, founded in Hangzhou in 2001, is a publicly traded, partially state owned Chinese company and the world's second largest video surveillance manufacturer by revenue, trailing only fellow Chinese firm Hikvision. Its cameras, digital video recorders, and network video recorders are sold in roughly 180 countries through more than 2,100 partners, and the company has shipped tens of millions of devices into homes, retail stores, offices, and public infrastructure worldwide. That scale is precisely what makes any systemic vulnerability in Dahua's product line consequential well beyond a single country or sector.
How the attackers actually got in
Hunt.io attributed the compromises to three distinct attack paths. The largest, by far, was straightforward credential attacks, essentially automated login guessing using weak, default, or previously leaked passwords, which researchers traced to 12,324 unique IP addresses across more than 13,000 recorded campaign attempts. The second path exploited two authentication bypass flaws, catalogued as CVE-2021-33044 and CVE-2021-33045, both rated a severe 9.8 out of 10 on the current CVSS severity scale used by the US National Vulnerability Database. These are not new vulnerabilities. They were publicly disclosed back in 2021, and Dahua issued fixed firmware for them years ago, yet both remain listed today on the US Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog, a designation reserved specifically for flaws still being actively exploited in the wild despite available patches. The third and most technically interesting path involved a peer to peer, or P2P, relay mechanism built into Dahua's own Easy4IP cloud infrastructure, a system designed to let users remotely access their camera without manually configuring network settings. Security firm ITRES Labs, which documented this exposure separately in 2025, found that on firmware released before mid-2024, simply knowing a device's serial number was enough to establish a connection route through Dahua's relay servers before the camera's own login check ever kicked in, a design gap that let attackers reach devices even when they sat behind network address translation, the technical barrier that normally shields home devices from direct internet exposure. Hunt.io's recovered operator logs claimed an extraordinary 89.4 percent of live serial numbers tested returned an open channel without any authentication at all, though it is worth noting that figure comes solely from the attackers' own recovered data and has not been independently verified by Dahua, ITRES Labs, or any public incident response body as of this writing. Beyond the initial break in, the campaign also planted 1,923 cameras with a persistent account, essentially a backdoor login the operators could return to later, and researchers found evidence suggesting parts of the toolkit may have been built specifically to hand off access to a third party, though no confirmed link to a named threat actor or state sponsor has been established.
Why cameras remain such a persistent target
Internet connected cameras occupy an unusual position in the broader device ecosystem. Unlike a laptop or phone, they are rarely patched by an end user paying regular attention, they are often installed once and forgotten, and many owners never change the default credentials shipped from the factory. A compromised camera also offers an attacker something more than a foothold, live or recorded video feeds of homes, businesses, and sometimes sensitive facilities, which carries value well beyond the kind of access a compromised laptop typically provides.
CyberPeace Advisory | What device owners should do now
For anyone running Dahua surveillance equipment, or any internet connected camera system, several concrete steps meaningfully reduce exposure.
For Dahua device owners specifically:
Two steps address the exact mechanisms this campaign exploited.
- First, check the device's firmware version against Dahua's official download portal and apply the latest available update immediately, since the fixes for both 2021 authentication bypass vulnerabilities have existed for years and simply have not been applied on thousands of devices.
- Second, disable the P2P or Easy4IP remote access feature entirely unless it is actively required, since this is the exact mechanism the third attack path, the serial number based relay, relied on to reach cameras without any login check at all.
For any internet connected camera system, including in India:
The remaining precautions apply regardless of manufacturer, and are worth following on any brand of camera, DVR, or NVR connected to the internet.
- Replace default or weak passwords with strong, unique credentials on every camera and recorder, and remove any unused or unrecognised accounts, since the persistent account technique this campaign used depends entirely on unnoticed access surviving unchecked.
- Place surveillance devices on a segmented network separate from computers and phones, so that a compromised camera cannot become a stepping stone into more sensitive systems.
- Periodically audit which devices on a home or office network are internet facing at all, since many cameras end up exposed simply because remote access was left switched on by default and nobody thought to check.
- And where a device offers the option, disable any built in peer to peer or cloud relay convenience feature unless genuinely needed, since the underlying design pattern this campaign exploited, a remote access shortcut that runs before proper authentication.Is not unique to Dahua and has shown up across other camera brands in the past.
The view from India
This disclosure lands at a particularly relevant moment for India, which enforced sweeping new restrictions on Chinese origin CCTV equipment earlier this year. Since April 1, 2026, internet connected surveillance cameras sold in India have been required to carry Standardisation Testing and Quality Certification under Essential Requirements norms first introduced by the Ministry of Electronics and Information Technology in April 2024, It's a country-of-origin requirement under the Essential Requirements norms (introduced by India's Ministry of Electronics and Information Technology in April 2024), manufacturers must disclose the origin of key components like the System-on-Chip (SoC), and devices using Chinese-origin chipsets are reportedly not being granted approval by certifying authorities. Since Dahua's cameras, like Hikvision's and TP-Link's, generally rely on Chinese-made chipsets, the practical effect is that their products haven't received STQC certification, which functions as a blanket exclusion without the government needing to name any single company in the rule text itself. The stated rationale for that policy, concerns over hidden backdoor access, transmission of data to foreign servers, and deployment near sensitive locations, reads almost like a preview of exactly the kind of exposure Operation CameraSwarm has now documented in the wild. It is worth being precise here: the restriction applies to new sales, not existing installations, and CameraSwarm's confirmed victims were concentrated in Ukraine and Russia rather than India. But the underlying lesson travels well beyond any one country's borders. A camera manufactured with a convenience feature that bypasses its own login check, sitting unpatched for years despite a fix being publicly available, is a vulnerability that does not respect national boundaries, and India's decision to tighten certification requirements before an incident of this scale surfaced looks, in hindsight, considerably more prudent than reactive.
References
- The Hacker News, "Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P." August 19, 2026. https://thehackernews.com/2026/08/hackers-compromised-14500-dahua-devices.html
- Hunt.io, "Operation CameraSwarm: Dahua Cameras Compromised." https://hunt.io/blog/operation-cameraswarm-dahua-cameras-compromised
- ITRES Labs, "Dahua Beyond CVE-2025-31702: P2P Relay Exposure." October 29, 2025. https://labs.itresit.es/2025/10/29/dahua-beyond-cve-2025-31702-p2p-relay-exposure?
- Dahua Security, "DHCC-SA-202106-001: Security Advisory - Identity Authentication Bypass Vulnerability Found in Some Dahua Products." https://www.dahuasecurity.com/about-dahua/trust-center/dahua-psirt/dhcc-sa-202106-001%3Asecurity-advisory---identity-authentication-bypass-vulnerability-found-in-some-dahua-products
- National Vulnerability Database, "CVE-2021-33044 Detail." https://nvd.nist.gov/vuln/detail/CVE-2021-33044
- CISA, "Known Exploited Vulnerabilities Catalog." https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- Business Standard, "India to ban Chinese CCTV from Apr 1 as security concerns reshape market." https://www.business-standard.com/industry/news/india-ban-chinese-cctv-government-security-concerns-hikvision-dahua-market-126033000316_1.html
- PTC News, "India CCTV ban 2026: Hikvision, Dahua face STQC block as new security rules begin." https://www.ptcnews.tv/amp/nation/india-cctv-ban-hikvision-dahua-stqc-rules-2026-4422961
- Uyghur Human Rights Project, "Surveillance Tech Series: Dahua's Links to Human Rights Abuses in East Turkistan." https://uhrp.org/report/dahuas-links-to-human-rights-abuses-in-east-turkistan/

Introduction
AI has transformed the way we look at advanced technologies. As the use of AI is evolving, it also raises a concern about AI-based deepfake scams. Where scammers use AI technologies to create deep fake videos, images and audio to deceive people and commit AI-based crimes. Recently a Kerala man fall victim to such a scam. He received a WhatsApp video call, the scammer impersonated the face of the victim’s known friend using AI-based deep fake technology. There is a need for awareness and vigilance to safeguard ourselves from such incidents.
Unveiling the Kerala deep fake video call Scam
The man in Kerala received a WhatsApp video call from a person claiming to be his former colleague in Andhra Pradesh. In actuality, he was the scammer. He asked for help of 40,000 rupees from the Kerala man via google pay. Scammer to gain the trust even mentioned some common friends with the victim. The scammer said that he is at the Dubai airport and urgently need the money for the medical emergency of his sister.
As AI is capable of analysing and processing data such as facial images, videos, and audio creating a realistic deep fake of the same which closely resembles as real one. In the Kerala Deepfake video call scam the scammer made a video call that featured a convincingly similar facial appearance and voice as same to the victim’s colleague which the scammer was impersonating. The Kerala man believing that he was genuinely communicating with his colleague, transferred the money without hesitation. The Kerala man then called his former colleague on the number he had saved earlier in his contact list, and his former colleague said that he has not called him. Kerala man realised that he had been cheated by a scammer, who has used AI-based deep-fake technology to impersonate his former colleague.
Recognising Deepfake Red Flags
Deepfake-based scams are on the rise, as they pose challenges that really make it difficult to distinguish between genuine and fabricated audio, videos and images. Deepfake technology is capable of creating entirely fictional photos and videos from scratch. In fact, audio can be deepfaked too, to create “voice clones” of anyone.
However, there are some red flags which can indicate the authenticity of the content:
- Video quality- Deepfake videos often have compromised or poor video quality, and unusual blur resolution, which might pose a question to its genuineness.
- Looping videos: Deepfake videos often loop or unusually freeze or where the footage repeats itself, indicating that the video content might be fabricated.
- Verify Separately: Whenever you receive requests for such as financial help, verify the situation by directly contacting the person through a separate channel such as a phone call on his primary contact number.
- Be vigilant: Scammers often possess a sense of urgency leading to giving no time to the victim to think upon it and deceiving them by making a quick decision. So be vigilant and cautious when receiving and entertaining such a sudden emergency which demands financial support from you on an urgent basis.
- Report suspicious activity: If you encounter such activities on your social media accounts or through such calls report it to the platform or to the relevant authority.
Conclusion
The advanced nature of AI deepfake technology has introduced challenges in combatting such AI-based cyber crimes. The Kerala man’s case of falling victim to an AI-based deepfake video call and losing Rs 40,000 serves as an alarming need to remain extra vigilant and cautious in the digital age. So in the reported incident where Kerala man received a call from a person appearing as his former colleague but in actuality, he was a scammer and tricking the victim by using AI-based deepfake technology. By being aware of such types of rising scams and following precautionary measures we can protect ourselves from falling victim to such AI-based cyber crimes. And stay protected from such malicious scammers who exploit these technologies for their financial gain. Stay cautious and safe in the ever-evolving digital landscape.