During Operation Sindoor in May 2025, something happened that received less attention than the missile strikes but may prove more consequential in the long term. Within hours of India's retaliatory action, a coordinated surge of social media posts from accounts linked to China and Pakistan flooded Twitter, Instagram, and Facebook with a single framing: India is the new Israel. The posts drew parallels between Indian action against a sovereign terrorist attack and Israeli occupation of Gaza. They used identical hashtags, identical language, identical timing. This was not organic outrage. It was an influence operation. An ORF survey conducted during the crisis found that only 32 percent of Indians could reliably identify a deepfake. The remaining 68 percent were the target audience.
The operation did not require a single soldier to cross the border. It did not require access to classified systems. It did not require hacking a government database. It required understanding how Instagram's algorithm amplifies emotionally charged content, and then feeding it precisely the content it is designed to promote.
This is the national security threat India has not legislated against.
On August 5, the Indian government summoned Meta's global leadership to New Delhi. For two days, MeitY officials and Union Minister Ashwini Vaishnaw questioned them on algorithmic bias and content manipulation. On August 8, the government ordered Meta to revamp its algorithms. The confrontation was necessary. It was also insufficient.
Meta operates three platforms in India: WhatsApp with 837 million daily users, Instagram with 501 million, Facebook with 403 million. The Reuters Digital News Report 2026 found that 42 percent of Indians aged 18 to 24 get their news primarily from Instagram. Not from newspapers, not from television, not from government briefings. From a feed curated by an algorithm designed in Menlo Park, California, optimised for engagement, not for national security or public order.
The algorithm does not distinguish between a wedding video and a communal provocation. It measures both by one metric: did the user stay longer? If a video inciting mob violence generates higher engagement than a government fact-check, the algorithm promotes the incitement and buries the correction. This is not a design flaw. It is the design.
China understood this before India did. The Chinese Communist Party's doctrine of "Three Warfares," public opinion warfare, psychological warfare, and legal warfare, treats social media manipulation as a domain of conflict equivalent to air, land, sea, and cyber. During the Doklam standoff in 2017, Chinese state media and coordinated accounts issued threats including "free Sikkim" and called India's then-External Affairs Minister "a liar." In June 2020, Twitter removed 23,750 accounts from a Chinese network with 150,000 amplifier accounts propagating CCP-aligned narratives. Facebook and Instagram disclosed similar large-scale coordinated operations. A USI monograph published in 2026 documented China's cognitive warfare strategy against India as a systematic, peacetime operation aimed at exploiting India's "open information environment, linguistic diversity, and civil-military fault lines."
Pakistan has adopted the same playbook with Chinese assistance. During Operation Sindoor, Pakistani accounts used Chinese AI tools to generate deepfake videos, fabricated damage assessments, and false casualty figures. Carnegie Mellon University's IDeaS Centre documented Pakistani influence operations targeting India through coordinated troll networks, spam accounts, and bot amplification. The operations were not sophisticated in isolation. They were effective because they exploited the same algorithmic logic that Meta uses to sell advertising: emotional content generates engagement, engagement generates distribution, distribution generates belief.
The dynamic is not confined to foreign adversaries. This year's youth-led "Cockroach" movement (CJP) — the GenZ protest that erupted over the examination-paper leaks and demanded the education minister's resignation — mobilised hundreds of thousands not through party machinery or newspapers but through Instagram reels and coordinated hashtags, cresting into a march on Parliament before much of the political class had registered it. Whatever one's view of its demands, it proved the same mechanics this piece describes: emotionally charged content, algorithmically amplified, converting a grievance into a mass movement at a speed no traditional institution could match. The feed a hostile state can weaponise against India is the same feed that can move a domestic crowd overnight — which is precisely why sovereignty over that layer cannot remain optional.
India has secured sovereignty in every critical infrastructure domain except this one. UPI freed India from Visa and Mastercard's payment rails. Aadhaar gave India a sovereign identity system independent of any foreign database. NavIC provides satellite navigation without dependence on American GPS. BrahMos, Tejas, and INS Vikrant demonstrate indigenous defence capability. In each case, the strategic insight was the same: dependence on foreign infrastructure in a critical domain is a vulnerability that adversaries will eventually exploit.
Information infrastructure is the last domain where India remains entirely dependent on foreign platforms. The digital public square where 500 million Indians form opinions about their government, their military, their borders, and their neighbours is owned by an American corporation, governed by American corporate policy, and optimised by an algorithm that no Indian institution has audited, regulated, or even fully understood.
Every Indian attempt to build a sovereign social media alternative has failed. Koo shut down. No Indian platform can compete with Meta's network effects. The structural dependency is now so deep that the government's only option was to summon Meta's executives and ask them to fix their algorithm. India did not regulate. It requested.
Three interventions would begin to convert this vulnerability into sovereignty.
First, mandate algorithmic transparency by statute. Every recommendation algorithm serving more than 10 crore Indian users must submit its content ranking logic to a designated Indian regulator for security audit. The EU's Digital Services Act requires this. India, with five times the user base and active adversary exploitation documented during a military operation, has no equivalent. The Digital India Act has been in draft since 2023.
Second, establish an Information Warfare Command, equivalent in institutional authority to the existing Cyber Command, with a specific mandate to monitor, attribute, and counter foreign influence operations on social media platforms operating in India. The cognitive warfare dimension of Sindoor proved that the next conflict will be fought on Instagram before it is fought on the border.
Third, invest in indigenous content recommendation infrastructure. India proved with UPI that public digital infrastructure can outperform private foreign monopolies. A sovereign recommendation layer, designed to prioritise verified news sources and suppress coordinated inauthentic behaviour during declared security emergencies, is an engineering challenge India has the capacity to meet.
India does not have a social media problem. India has a sovereignty problem that lives on social media. The adversary has understood the algorithm. The question is whether India will legislate before the next operation exploits it.

