MEBRO

DISINFO DESK

International

10 Indian Leaders Deepfaked: Inside Pakistan's AI Disinformation Blitz

A pro-Pakistan X account fabricated AI videos of PM Modi, India's Army Chief, and eight other officials to frame India as an Israeli ally in the Iran war. Forensic analysis of the @InsiderWB deepfake campaign targeting Indian leaders in March 2026.

FALSE

FILED SEP 6, 2026 · UPDATED SEP 6, 2026 · 28 SOURCES

The Sinking That Started Everything

To understand why this deepfake campaign hit as hard as it did, you need to start four days before the first fake video appeared. On March 4, 2026, USS Charlotte — a US Navy attack submarine — fired two Mark 48 torpedoes at the Iranian frigate IRIS Dena approximately 19 nautical miles off Galle, Sri Lanka. Sri Lankan search-and-rescue pulled 32 survivors from the water; independent reporting on the death toll varies, with one count putting it at 87 killed from a crew reported between 130 and 180. It was the first US submarine combat action since World War II. [3][27]

What made the sinking particularly explosive for India: the IRIS Dena had spent February 15–25, 2026 at Visakhapatnam as a participant in India's International Fleet Review 2026 and the Milan naval exercises — the Indian Navy had publicly welcomed the ship on February 17. Indian naval crews had hosted the Iranian officers. India possessed detailed knowledge of the ship's transit route from those exercises. When the submarine found IRIS Dena in open ocean, Pakistan-linked accounts immediately began circulating a narrative: India had leaked the ship's position to the US and Israel. [27]

India's government had publicly declared neutrality in the Iran-US-Israel conflict. That neutrality was now the target. A neutral India maintains diplomatic influence on all sides and cannot be painted as hostile to Muslim nations. Destroying that neutrality — fabricating statements in which Indian officials explicitly sided with Israel — was the operation's core strategic objective. [12]

Every video claiming Indian officials supported Israel against Iran, shared intelligence on IRIS Dena, or pledged alignment with Israel is confirmed AI-fabricated. India maintained official neutrality throughout. The PIB, MEA, India's Deepfakes Analysis Unit, BOOM, Alt News, FACTLY, and The Quint all independently confirmed fabrication across the campaign's videos. No credible source corroborates any of the claims made in these deepfakes.

@InsiderWB: The Primary Delivery Vehicle

@InsiderWB is a pro-Pakistan X account with a distinctive operational profile: a small, tightly curated following of predominantly Pakistan-based journalists and political leaders, and a pattern of posting at high frequency specifically during India-related geopolitical crises. It has been active since the May 2025 India-Pakistan conflict, where it began sharing doctored media. Following a legal demand served to X Inc. under India's Information Technology Act, the account is now withheld in India. [1]

The March 12–13 surge — BOOM documented at least 10 deepfakes from the account in this window — was not @InsiderWB's first operation in the Iran war period. By that point, deepfakes of Rajnath Singh (March 3) and the Army Chief (March 9) had already circulated for days. The surge broadened the target set to include PM Modi, Maj. Gen. CS Mann, Squadron Leader Ankita, and others. [1]

Two specific amplifier accounts documented by Alt News — @GPX_Press and @GeopolPt — reshared the Dwivedi deepfake on March 9, 2026, the same day PIB issued its formal debunk, drawing more than 43,500 and 32,000 views respectively before the fact-check reached the same audience. [18]

The propagation chain followed a documented pattern: @InsiderWB posts on X → Pakistani propaganda network amplifies → WhatsApp carries videos into Indian communities → international pickup. Turkish newspaper Yeni Safak cited the Dwivedi deepfake as authentic, claiming "India admitted to sharing the location of an Iranian ship with Israel" — a claim PIB publicly and directly rejected, extending the disinformation into the Turkish-language media ecosystem and beyond South Asia. [13][28]

The Army Chief Deepfake: A Forensic Breakdown

The Army Chief deepfake was the campaign's most consequential fabrication. It was technically sophisticated in a specific way: only the audio was synthetic. The video itself was genuine — a 21-minute Firstpost interview from the Raisina Dialogue 2026, published March 7, 2026, in which General Upendra Dwivedi discussed Operation Sindoor, Pakistan, and the future of warfare. A segment was extracted, the authentic video retained, and the audio track replaced with AI-synthesized speech. [4]

The fabricated audio, as reported by Deccan Herald and independently corroborated in Alt News's translation of the clip: "...as Israeli['s] strategic allies, it was our duty to inform Israel of their exact location as part of our newer strategic deal." [5][4]

This technique exploits how casual viewers process video authority: genuine face + genuine setting = trusted content. The fabricators understood that a clip of a known Army Chief, in a recognizable interview context, carrying fabricated audio would be processed by most viewers as authentic. Most people do not listen for spectral artifacts in voice synthesis.

The Hiya Deepfake Voice Detector returns an authenticity score from 0–100, where 100 = fully authentic human voice and 0 = completely AI-synthesized. The Dwivedi deepfake returned 1/100 — effectively the floor of the scale, indicating maximum confidence of AI generation with minimal residual authentic voice characteristics. BOOM documented this result. The tool uses spectral analysis of voice frequency patterns to distinguish neural voice synthesis artifacts from natural human phonetic variation. [2]

Independently, Hive Moderation — a separate system analyzing visual and audio stream consistency — returned a 99.9% AI-generated probability, per Alt News's analysis. FACTLY additionally observed visible lip-sync mismatches in the video, providing a non-AI human-perceptible verification marker. The convergence of Hiya at 1/100, Hive at 99.9%, and visible lip-sync failures across independent methodologies constitutes unusually strong forensic consensus. [4] [7]

The Army Chief deepfake went viral within hours of its March 9 posting. PIB issued its formal debunking the same day — but by then, the clip had already reached international audiences. India's Deepfakes Analysis Unit (a civil-society AI forensics body run by the Misinformation Combat Alliance, distinct from PIB) separately confirmed the entire audio track was synthetic. The Indian Embassy in Oman issued a public advisory directed at Gulf Indian diaspora communities, using PIB's verbatim language: "Beware! This is an AI-generated deepfake video shared to mislead the public." [14] [21]

The Full Target Roster: At Least 10 Officials

Cross-referencing BOOM's reporting with independent fact-checks from Alt News, FACTLY, WION, Free Press Journal, and TFIPost identifies at least 10 individual targets across the March 2026 campaign: Army Chief Gen. Upendra Dwivedi, Defence Minister Rajnath Singh, MEA spokesperson Randhir Jaiswal, External Affairs Minister S. Jaishankar, Navy Chief Adm. Dinesh Tripathi, PM Narendra Modi, Maj. Gen. CS Mann, Squadron Leader Ankita, Joint Secretary (I&B) C Senthil Rajan, and journalist Palki Sharma. The roster spans the Indian military command structure, senior cabinet ministers, the MEA spokesperson, a joint secretary from the Ministry of Information and Broadcasting, and a prominent journalist. [1][2][4][8][9][15][17]

Evidence Deep-Dive: Production Techniques and the Institutional Response

The campaign employed at least two distinct production techniques, documented separately by WION and FACTLY:

Technique 1 — Audio replacement over genuine footage: The primary method across most deepfakes. Authentic video from recognizable, newsworthy contexts (Raisina Dialogue, parliamentary briefings, official press conferences) was retained while the audio track was replaced with AI-synthesized speech. This exploits the fact that credibility signals in video are dominated by visual recognition of faces and settings — most viewers do not analytically interrogate audio.

Technique 2 — Fabricated news-outlet branding: At least one video in the broader campaign was produced with a fabricated WION news logo embedded in the frame — an attempt to lend AI-fabricated content the visual authority of an established international news broadcast. WION's own reporting documented this technique on a separate deepfake in the campaign. [15]

The Rajnath Singh deepfake and the Sindhi Samaj Sammelan: The authentic Rajnath Singh speech at the Sindhi Samaj Sammelan (November 2025) contained zero geopolitical content. His confirmed authentic statement concerned cultural heritage: "Today, the land of Sindh may not be a part of India, but civilisationally, Sindh will always be a part of India." The disinformation operation excised this cultural address entirely and replaced the audio with fabricated war rhetoric — exploiting the visual authority of a formal government event. The gap between the authentic and fabricated content is total. [20] [8]

Multiple independent debunks in days: The Dwivedi deepfake alone was independently investigated and debunked by PIB, BOOM, Alt News, FACTLY, and The Quint within days of the video's first circulation — an unusual density of near-simultaneous independent verification that reflects the operation's assessed threat level.

The 31 Hacked Accounts: A Parallel Operation

Separate from @InsiderWB's operation — but part of the same pro-Pakistan information warfare surge — X's safety team on March 6, 2026 exposed a distinct operation: a single Pakistan-based operator had simultaneously renamed 31 hacked X accounts on February 27, 2026 to variants of "Iran War Monitor" and began distributing AI-generated war footage.

The operational details documented by Tribune India: [11] [23]

X Product Head Nikita Bier stated: "All were hacked and the usernames were changed on February 27 to 'Iran War Monitor' or some derivative." X stated it had improved detection speed and reduced incentive structures for spreading misleading content. [23]

The scale difference between the two operations is instructive: @InsiderWB operated as a single, persistent, purpose-built account with a track record of targeted India-specific disinformation dating to 2025. The 31-account network was a tactical burst operation, high-volume but quickly detected and terminated. Together they demonstrate a two-tier Pakistan information warfare architecture: slow-burn dedicated accounts for sustained targeted influence, and rapid-burst hacked networks for amplification during crisis windows.

India's Four-Layer Institutional Response

India's response to the March 2026 campaign was an unusually comprehensive one, with four distinct institutional layers activating simultaneously:

Layer 1 — PIB Fact Check Unit India's designated rapid-response debunking body, operating under the Press Information Bureau. Contact: factcheck@pib.gov.in / WhatsApp +91 8799711259. PIB has debunked over 2,400 false items in four years, with more than 800 in the past year alone. [9] PIB issued formal debunks for every major deepfake in this campaign, each accompanied by the verified authentic context (original speech, original date, actual content).

Layer 2 — Ministry of External Affairs (Direct Institutional Statement) In an unusual move, the MEA — whose spokesperson Randhir Jaiswal was directly impersonated — issued its own direct debunk via its official X account, bypassing PIB's normal channel. The verbatim statement: "Deepfake Video Alert! This is an AI generated video intended to spread disinformation! Please stay alert against such fake videos and content on social media." This is significant because it represents one of the few cases where the targeted institution itself (not just PIB) publicly labeled the fabrication. [19]

Layer 3 — India's Deepfakes Analysis Unit A civil-society AI forensics body run by the Misinformation Combat Alliance, distinct from PIB. The Deepfakes Analysis Unit confirmed the entire audio tracks as synthetic on both the Dwivedi and Tripathi deepfakes. WION cited its findings directly. [22] [15]

Layer 4 — IT Act Enforcement and Account Withholding India's Information Technology Act was invoked to compel X to withhold @InsiderWB for Indian users. Under Section 66D of the IT Act (2000, as amended 2008), "cheating by personation using computer resource" carries up to 3 years imprisonment and fines up to ₹1 lakh. [6] Under Section 66F (cyber terrorism), acts intended to threaten India's sovereignty, security, or unity can attract life imprisonment. [26] Separately, India's IT Rules were amended in February 2026, effective February 20, requiring intermediaries to act within 3 hours of a court order or a reasoned government-agency takedown notice — down from the earlier 36-hour window, with a tighter 2-hour deadline specifically for deepfake and non-consensual sexual content. [25]

The convergence of these four response layers — civil society fact-checkers (PIB), the targeted ministry itself (MEA), a dedicated AI forensics body (DAU/MCA), and legal enforcement (IT Act) — operating simultaneously represents a qualitatively different response posture than India's earlier piecemeal debunking efforts.

Pakistan's Strategic Objectives and the Escalation Trajectory

Based on ORF analysis [12] and the Bulletin of the Atomic Scientists [16], the strategic objectives of the March 2026 operation can be deconstructed across three dimensions:

Objective 1 — International Isolation of India. By getting Turkey's Yeni Safak to cite the Dwivedi deepfake as authentic, the campaign momentarily achieved international credibility for the false narrative that India was complicit in the IRIS Dena sinking. This was intended to turn Muslim-majority countries against India and force India out of its neutral diplomatic position. The Indian Embassy in Oman's emergency advisory confirmed the campaign reached Gulf Indian diaspora communities — a population India monitors for diplomatic sensitivity. [14]

Objective 2 — Degradation of Indian Government Credibility. Fabricating statements by the Army Chief, Defence Minister, EAM, and MEA Spokesperson simultaneously suggests the goal was not merely to spread one lie but to create a pervasive atmosphere of distrust in Indian official communications — where citizens cannot trust whether a video of any senior official is real. PIB issued formal debunks for each video, but the asymmetry is structural: fabricating a deepfake takes minutes; institutional debunking takes hours; restoring lost trust takes far longer.

Objective 3 — Domestic Communal Tension Exploitation. India has a large Muslim population. Fabricated videos of Indian officials pledging support to Israel — a state conducting military operations against Iran — were calibrated to inflame Hindu-Muslim communal tensions within India. The strategic logic: a domestically destabilized India is less capable of projecting confident diplomatic neutrality. ORF documents that ISPR, closely aligned with the ISI, "trains cyber volunteers, funds propaganda content, and engages diaspora media in the Persian Gulf and the United Kingdom" — part of a broader effort ORF says has previously targeted Indian Muslims to "exacerbate internal divisions." [12]

The Escalation Trajectory: ORF's analysis traces Pakistan's information operations from coordinated hashtag campaigns — including #IndianFalseFlag content that spread within 16 hours of the April 2025 Pahalgam attack — through to the fully synthetic audiovisual impersonation of sitting government officials seen in March 2026. [12]

That trajectory, in under twelve months, represents a documented capability step-change in Pakistan's information-warfare apparatus.

The Nuclear Dimension: When Deepfakes Become a Security Crisis

The Bulletin of the Atomic Scientists' January 2026 analysis of the May 2025 India-Pakistan crisis identifies a systemic risk that elevates campaigns like this one beyond standard disinformation: both India and Pakistan are nuclear-armed states with established doctrines that include rapid conventional escalation. [16] [24]

Deepfake technology has lowered the cost of constructing plausible false evidence for any state with modest AI infrastructure. The India-Pakistan situation is particularly dangerous because disinformation that falsely attributes hostile military coordination to one state — as these deepfakes did — can trigger real military responses based on false intelligence. The speed of viral propagation (the Dwivedi deepfake's amplifiers alone drew tens of thousands of views within hours) means false narratives can circulate faster than institutional fact-checking.

The Bulletin found that existing bilateral channels between India and Pakistan — including the military hotline — are "used for communication only at the peak of crises" and play a limited role in preventing miscalculation, and it recommends establishing dedicated rapid-response fact-checking mechanisms and more proactive, coordinated crisis messaging between the two states. [24]

India's current four-layer response (PIB + MEA + DAU + IT Act) is robust domestically. What it struggles to address is international propagation: Turkish newspaper Yeni Safak's citation of the Dwivedi deepfake as authentic required no coordination from India to retract. By the time a Turkish editor receives a PIB debunk from New Delhi, the story has already been read, reshared, and built upon across Turkish-language social media. The limits of existing bilateral and multilateral channels for rapid cross-border disinformation correction represent an unresolved structural vulnerability this campaign has exposed.

Conclusion: What This Campaign Tells Us About AI Disinformation at Scale

The @InsiderWB campaign of March 2026 is not primarily a story about ten deepfakes. It is a story about the systematic exploitation of three simultaneous vulnerabilities: an unexplained geopolitical event that created an explanatory vacuum (IRIS Dena's sinking), a deliberate target (India's declared neutrality), and a lowered technical barrier (AI voice synthesis that can now produce a convincing Army Chief in minutes).

The campaign succeeded partially even where fact-checkers succeeded completely. PIB debunked the Dwivedi deepfake on March 9. Alt News published its Hive Moderation results. FACTLY documented the lip-sync mismatches. The Quint WebQoof issued an independent denial. And yet Yeni Safak still published the false narrative as real. The Indian Embassy in Oman was still issuing advisories days later. The disinformation reached parts of its target audience faster than the corrections did.

The documented escalation from Pakistan's April 2025 hashtag operations — coordinated #IndianFalseFlag campaigns that spread within 16 hours of the Pahalgam attack — to fully synthetic audiovisual impersonation of sitting government officials in March 2026 is the data point that should drive India-Pakistan crisis communication policy. The Bulletin of the Atomic Scientists' analysis found that the bilateral channels which do exist remain limited and reactive rather than built for real-time crisis-period fact-checking between two nuclear-armed neighbors in one of the world's most volatile regions. [16]

Until that gap is closed, the operational tempo advantage belongs to whoever can synthesize a convincing general faster than institutions can issue a press release.

SOURCES · 28

  1. [1]US–Iran Crisis: Deepfakes Of Indian Leaders Supporting Israel Surface — boomlive.in

    72/100 · boomlive.in

  2. [2]Video Of COAS Admitting That India Leaked IRIS Dena's Location Is A Deepfake — boomlive.in

    72/100 · boomlive.in

  3. [3]New Details: How U.S. Navy Sub USS Charlotte Sank Iranian Frigate IRIS Dena With Two MK-48 Torpedoes — armyrecognition.com

    72/100 · armyrecognition.com

  4. [4]Viral clip of Army Chief Upendra Dwivedi 'admitting' India gave away Iranian ship's location is a deepfake — altnews.in

    72/100 · altnews.in

  5. [5]PIB Fact Check: AI deepfake video falsely shows Gen Dwivedi Speaking on Iran ship — deccanherald.com

    72/100 · deccanherald.com

  6. [6]Section 66D IT Act: Punishment for Online Cheating by Personation — apnilaw.com

    72/100 · apnilaw.com

  7. [7]This video of Army Chief General Upendra Dwivedi allegedly admitting India shared the location of IRIS Dena is a deepfake — factly.in

    72/100 · factly.in

  8. [8]This viral video of Defence Minister Rajnath Singh claiming India supported Israel is a deepfake — factly.in

    72/100 · factly.in

  9. [9]Govt Exposes Pakistan-Linked Deepfake Propaganda Targeting Jaishankar Amid West Asia Tensions — tfipost.com

    72/100 · tfipost.com

  10. [10]Fact Check: Deepfake Video Falsely Shows MEA Spokesperson Randhir Jaiswal Warning Iran Amid War With US-Israel — freepressjournal.in

    72/100 · freepressjournal.in

  11. [11]How Pakistan man used 31 hacked X accounts to spread fake AI generated Iran-US war misinformation — tribuneindia.com

    72/100 · tribuneindia.com

  12. [12]Pakistan's Information Warfare: Strategic Implications and India's Response — orfonline.org

    72/100 · orfonline.org

  13. [13]Fact-Check: Did Army Chief Admit That India Shared Iranian Ship's Location With Israel? No! — thequint.com

    72/100 · thequint.com

  14. [14]Indian Embassy in Oman warns public against AI-generated deepfake video of Army Chief — thearabianstories.com

    72/100 · thearabianstories.com

  15. [15]Infowarfare: Pakistan uses AI deep fakes of Indian military leaders to spread misinformation — wionews.com

    72/100 · wionews.com

  16. [16]Disinformation and deepfakes: Improving crisis communications in India and Pakistan — thebulletin.org (Bulletin of the Atomic Scientists)

    72/100 · thebulletin.org

  17. [17]BOOM: Expanded full target roster — C Senthil Rajan & Sqn. Ldr. Ankita confirmed — boomlive.in

    72/100 · boomlive.in

  18. [18]Alt News: @GPX_Press & @GeopolPt amplification — 43,500+ and 32,000+ views before fact-check — altnews.in

    72/100 · altnews.in

  19. [19]Free Press Journal: MEA official X alert — "Deepfake Video Alert! This is an AI generated video intended to spread disinformation" — freepressjournal.in

    72/100 · freepressjournal.in

  20. [20]FACTLY: Rajnath Singh authentic Sindhi Samaj Sammelan quote vs. fabricated war rhetoric — factly.in

    72/100 · factly.in

  21. [21]Embassy of India, Oman: "Beware! This is an AI-generated deepfake video shared to mislead the public" — thearabianstories.com

    72/100 · thearabianstories.com

  22. [22]WION: India's Deepfakes Analysis Unit confirmed synthetic audio on Adm. Tripathi video — wionews.com

    72/100 · wionews.com

  23. [23]Tribune India: Nikita Bier (X) quote on the 31-account hacked network — tribuneindia.com

    72/100 · tribuneindia.com

  24. [24]Bulletin of the Atomic Scientists: limited bilateral India-Pakistan crisis communication channels; deepfake escalation risk — thebulletin.org

    72/100 · thebulletin.org

  25. [25]Centre Notifies IT Rules Amendment: 3-Hour Takedown Deadline for AI Content — visionias.in

    72/100 · visionias.in

  26. [26]Punishment under Section 66F of the IT Act: Cyber Terrorism and Life Imprisonment Explained — apnilaw.com

    72/100 · apnilaw.com

  27. [27]Iranian warship was returning from naval exercises hosted by India when hit by US torpedo — timesofisrael.com

    72/100 · timesofisrael.com

  28. [28]Govt Dismisses Turkish Newspaper's Report Claiming India Shared Iranian Ship's Location With Israel — ianslive.in

    72/100 · ianslive.in

MEBRO · DISINFO DESK · mebro.app

Investigative report — not a user-submitted fact-check.

AI-built, source-verified. Every claim here was checked against the sources cited above before publishing — but don't just trust us: follow any citation to its source and confirm it yourself. That's the whole point.