It was 7th May 2025. India launched Operation Sindoor against terrorist infrastructure in Pakistan and Pakistan-occupied Jammu and Kashmir. What followed inside India was a crackdown on people reportedly supplying information, communication facilities and logistical support to Pakistan-linked operatives.
A year after Operation Sindoor was launched, on 8th May 2026, Punjab Police said in a statement that 457 Pakistan-linked spies or associates had been identified and arrested across 17 states and Union Territories. That number covers people with different roles, and trials are underway in these cases. While convictions have not yet been secured in a court of law, the figure indicates the scale of Pakistani attempts to build human networks inside India.
Those who came under investigation were influencers, students, health workers, contractors, shopkeepers, defence employees and unemployed youths. Some were reportedly offered money, some were groomed online by women using Hindu names, while others received visas, foreign trips or social media-related opportunities. Several were assigned tasks that appeared harmless until they developed into surveillance of military installations and troop movements.
According to investigators, Lahore-based travel operator Naushaba Masood was running a dual espionage and propaganda operation. Visa seekers were first asked to publish pro-Pakistan videos. Those who cooperated could be introduced to Pakistani Army and ISI officials. Reportedly, Masood targeted people specifically from the Hindu and Sikh communities.
In the Ghaziabad CCTV case, reports suggest that the police investigation revealed that Pakistan-linked handlers hired Hindu youths to install surveillance cameras because their presence would attract less suspicion. The cameras were reportedly placed near Delhi Cantonment and Sonipat railway station to livestream security-force movement. The National Investigation Agency (NIA) later took over the case. A seperate investigation report was filed against five juveniles.
These are not cases in which the religious identity of an accused is being guessed from a surname. They are accounts in which investigators explicitly described the targeting or deployment of Hindus as part of the operational method, which, in fact, is the smoking gun.
Pakistan-based handlers were not only looking for anyone willing to sell information. They were specifically looking to exploit Hindus by using their religious identity as camouflage. The same identity could later provide another benefit. Once such a module is exposed, the Hindu names at the Indian end can be highlighted while the Pakistani handlers, money trail and terror infrastructure controlling them are pushed into the background.
Jyoti Malhotra – From travel content to intelligence links
One of the earliest arrests made post-Operation Sindoor was that of Haryana-based travel influencer Jyoti Malhotra. She was arrested on 16th May 2025 and booked under the Official Secrets Act and Section 152 of the Bharatiya Nyaya Sanhita (BNS).
According to the investigators, she maintained contact with Pakistani officials and intelligence-linked persons after travelling to Pakistan. Police stated that she communicated with them through WhatsApp, Telegram and Snapchat. One reported contact was saved under a false Indian-looking name. Her public identity as a travel creator gave her an ordinary explanation for foreign trips, filming locations and building relationships across the border.
The case also fits into the network operated by Naushaba Masood. Investigators said Masood offered expedited visas and free travel to influencers. The initial return was not necessarily a military secret. It could be a favourable video about Pakistan. That content served propaganda goals while also testing whether the creator was cooperative and willing to follow instructions.
Malhotra’s bail was rejected by the Punjab and Haryana High Court on 7th March 2026. The court found sufficient prima facie material to deny bail but expressly clarified that its observations were not a final finding on guilt. On 5th June 2026, the Supreme Court declined to interfere with that decision and described the allegations as serious. She consequently remained in custody awaiting trial.
Her case demonstrates why an influencer is valuable to an intelligence operation. A creator can travel without appearing unusual. A camera is part of the job. Meetings with officials can be presented as content opportunities. The creator also has an audience through which propaganda can be circulated without appearing to originate from Pakistan.
From propaganda videos to espionage assignments
It has to be understood that the recruitment system need not always begin with a demand for classified information. It often starts with a small favour. Naushaba Masood’s network reportedly offered visas and travel assistance. Recruits were asked to upload pro-Pakistan videos. Those who complied could be given SIM cards, introduced to officials or assigned further work. Investigators described it as a calculated combination of intelligence collection and propaganda dissemination.
This model reduces resistance, and those who leak information often remain under the radar of investigative agencies. Publishing a tourism video does not feel like espionage. Sharing an OTP may be presented as a technical formality. Photographing a publicly visible building may not appear serious. The recruit is gradually made comfortable with secrecy, foreign contacts and payments.
Then, the assignments become part of what can be described as a well-orchestrated espionage network. Basically, the operatives first identify vulnerable individuals, develop friendly contact, ask for a small favour and provide payment or travel benefits. Once the recruit is comfortable enough, he or she is introduced to a Pakistani intelligence handler who would assign sensitive tasks and take control not only of the information the recruit is providing but also of the narrative for the future.
This progression is illustrated by the case of Sahdevsinh Gohil, who was a contractual health worker from Kutch. He was reportedly contacted by a Pakistani operative using the Hindu name “Aditi Bharadwaj”. According to Gujarat ATS, he supplied photographs and videos of BSF and Indian Navy facilities.
In January 2025, he reportedly obtained an Indian SIM using his Aadhaar and shared the OTP, which allowed the account to be operated from Pakistan. Investigators said he received a payment of Rs 40,000 for the task.
The use of the name “Aditi Bharadwaj” was itself part of the deception. A Pakistani operative did not approach the target under an obviously Pakistani identity. She adopted a name that would appear familiar and trustworthy to a Hindu Indian.
A similar method was reported in Rajasthan. Mangat Singh was arrested on 10th October 2025 after being honey-trapped by a Pakistani handler using the name “Isha Sharma”. Officials said emotional manipulation and financial inducements were used to obtain information about military activity around Alwar.
Pakistan’s handlers therefore use Hindu identity at both ends of the conversation. A fake Hindu woman is used to approach the target. Hindu recruits are used to perform tasks without attracting suspicion. Once exposed, those same recruits can be cited as evidence against Hindus collectively.
Ghaziabad module – Hindu youths were hired to avoid suspicion
The Uttar Pradesh investigation provides clearer evidence that religious identity had operational value. The first arrests included Suhail Malik, Praveel, Sana Iram alias Mehek, Raj Valmiki, Shiva Valmiki and Ritik Gangwar. Police stated that members of the group shared photographs, videos and locations of security-force establishments with foreign contacts. Later arrests included Ganesh Giri, Vivek Rai, Gagan Prajapati and Durgesh Nishad. Five juveniles were also detained.
Investigators recovered solar-powered, SIM-enabled CCTV cameras. One camera installed near Sonipat railway station reportedly remained active for 18 days. Another was linked to surveillance near Delhi Cantonment. The handlers intended to install dozens of cameras near sensitive sites. Recruits were paid small amounts for each photograph, video or installation.
Reports suggest that the Special Investigation Team (SIT) found that the cell had hired Hindu youths to carry out the installations so they could blend into normal activity and escape scrutiny. It was not simply that some accused happened to be Hindu. Their Hindu identity made them more useful.
A Muslim operative behaving suspiciously near a cantonment, railway route or security installation may attract attention. A local Hindu student, labourer, shopkeeper or technician installing a camera could be mistaken for someone performing an ordinary commercial task. The handler remains in Pakistan. The camera remains in India. The person exposed at the site has an Indian identity and no visible connection to a jihadist organisation.
More arrests were made including a woman named Meera Thakur who was married to a Muslim man involved in criminal activities. Notably, she was earlier arrested by the Special Cell of Delhi Police in an illegal arms and fake currency case, but later released on humanitarian grounds.
The NIA subsequently said the conspiracy involved solar-powered cameras at sensitive railway locations, Pakistan-based suspected terrorists’ access to live feeds, the procurement of Indian SIM cards and the transmission of photographs, videos and GPS coordinates. By May 2026, the agency said 21 accused had been arrested in the case.
Punjab’s solar-powered CCTV network
Punjab investigations revealed that the Ghaziabad operation was not an isolated experiment. Pakistan-linked handlers were repeatedly using inexpensive commercial cameras to obtain persistent surveillance without sending a trained operative across the border.
On 30th April 2026, Punjab Police announced the arrest of Sukhwinder Singh alias Sukha in one operation and Sona and Sandeep Singh alias Sonu in another. Police recovered China-made cameras with solar panels, SIM cards and 4G connectivity. The devices were installed near military-linked locations and configured to transmit live footage through mobile applications.
In the Kapurthala module, police said a shop near an Army cantonment was used to place a SIM-enabled camera on a pole. A Pakistan-based handler identified as “Fauji” paid Rs 35,000 for the installation. Police also linked Sandeep Singh to cross-border drug smuggling.
On 21st May 2026, Pathankot Police arrested Baljit Singh alias Bittu. He installed an internet-connected CCTV camera at a shop along NH-44 to monitor Army and paramilitary convoys travelling on the Pathankot-Jammu corridor. Police said the live feed was sent to Pakistan-based handlers. Singh reportedly received Rs 40,000 and instructions from a Dubai-based contact.
A day later, police arrested shopkeeper Ankit Sharma for facilitating the installation and concealing the camera and modem after becoming aware of police searches. Investigators said two other suspects were already lodged in jail in a narcotics case.
In June 2026, Ashok Singh and Akashdeep Singh were arrested over another solar-powered camera placed near the Bathinda-Sriganganagar highway. Police said that the camera had transmitted footage for around three months.
Such cameras do not need a wired electricity connection. They can operate in an isolated location. An embedded SIM sends the feed online. Once installed, the human recruit can walk away. Pakistani handlers can watch military movement continuously from across the border.
A camera costing a few thousand rupees can therefore replace a human spy who would otherwise need to remain near the target. The risk is transferred almost entirely to the local recruit.
A network built from ordinary people
Pakistan’s intelligence machinery does not need every recruit to possess classified files. It can assemble intelligence from ordinary observations. A contractor at an airbase knows when repair work is being carried out. A guest-house manager knows which scientists have arrived. A shopkeeper on a highway can observe military convoys. A health worker near the border can photograph new security infrastructure. A student can install a camera near a railway station. An influencer can travel, meet officials and publish content.
Individually, each piece of information may appear minor. When collected over weeks, it can reveal deployment patterns, convoy timings, construction activity, personnel movement and changes in readiness.
These cases also show that handlers search for different weaknesses, including money, romance, travel and visas, social recognition, personal distress, criminal exposure and blackmail.
The 15-year-old Pathankot boy arrested in January 2026 reportedly believed that his father had been murdered. Police said Pakistani accounts exploited his emotional vulnerability and persuaded him to send security-related information.
The recruitment chain is therefore not based only on ideological radicalisation. The ideology may come later. Pakistan first identifies the wound and then presents itself as the solution.
Key Pakistan-linked cases since Operation Sindoor
Jyoti Malhotra was arrested in Haryana on 16th May 2025. The travel influencer was accused of maintaining contact with Pakistani intelligence-linked persons and sharing sensitive information. Investigators said that travel access, official contacts and social-media cultivation were used to draw her into the network. Her bail was rejected by the Punjab and Haryana High Court and later by the Supreme Court. Her trial remains pending.
Sahdevsinh Gohil was arrested in Gujarat on 24th May 2025. The contractual health worker was accused of sending photographs and videos of BSF and Indian Navy facilities to a Pakistani operative using the name “Aditi Bharadwaj”. Gujarat ATS said that he received money and also provided access to an Indian SIM through an OTP. The case remains pending.
Abhishek Bhardwaj was arrested in Himachal Pradesh on 28th May 2025. Police said sensitive and objectionable material was recovered from the college dropout’s phone. He was booked under Section 152 of the Bharatiya Nyaya Sanhita over suspected links with Pakistani handlers. The precise method through which he was recruited has not been publicly established.
Mukesh Rajak and Rakesh Kumar Gupta were arrested in West Bengal in July 2025. Investigators said that they provided Indian SIM cards and OTPs used by Pakistani intelligence operatives to create WhatsApp accounts and honey-trap profiles. The men were accused of helping establish the Indian communication infrastructure needed by the foreign handlers. The investigation remains pending.
Mahendra Prasad was arrested in Rajasthan in August 2025. He worked as the manager of a DRDO guest house and supplied details about scientists, officers and defence-related activity. Investigators said he was in contact with a suspected Pakistani handler through social media. He was booked under the Official Secrets Act.
Mangat Singh was arrested in Rajasthan on 10th October 2025. The electrician lived near a military area in Alwar and was accused of sharing information about defence activity. Officials said a Pakistani handler using the name “Isha Sharma” honey-trapped him and used emotional manipulation along with financial inducements. He was arrested under the Official Secrets Act.
Prakash Singh alias Badal was arrested on 1st December 2025. Investigators accused him of sharing details about Army movements, roads, bridges, railway lines and military locations. He communicated through WhatsApp and received payments from Pakistani handlers. Officials also said that he supplied OTPs linked to Indian numbers. He was booked under the Official Secrets Act.
The Ghaziabad CCTV module was uncovered in Uttar Pradesh in March 2026. Those arrested included students, labourers and unemployed youths. Investigators said that the group installed cameras and supplied photographs, videos and live surveillance from areas near defence and railway locations. Small payments and online instructions were reportedly used to control the recruits. Investigators also said Hindu youths were selected for some tasks because they were less likely to attract suspicion. By May 2026, the NIA had reportedly arrested 21 people in connection with the wider conspiracy.
Sukhwinder Singh alias Sukha, Sona and Sandeep Singh alias Sonu were arrested in Punjab in April 2026. Police accused them of installing solar-powered and SIM-enabled cameras near military-linked locations. One module was reportedly controlled by a Pakistan-based handler called “Fauji”, who paid for the installation. Investigators also examined possible links with drug-smuggling networks.
Baljit Singh alias Bittu was arrested in Punjab on 21st May 2026. Police said that he installed an internet-connected camera along NH-44 to monitor Army and paramilitary convoys travelling towards Jammu. The live feed was reportedly accessible to Pakistan-based handlers. Investigators said he received Rs 40,000 and acted on instructions routed through a Dubai-based contact. Shopkeeper Ankit Sharma was arrested the following day for helping install the equipment and later concealing it. The wider network remains under investigation.
The propaganda operation was built into the recruitment system
The strongest evidence of propaganda intent does not come from speculation about what Pakistan may do in the future. Investigators described propaganda as part of the recruitment process itself.
Naushaba Masood’s recruits were asked to publish pro-Pakistan videos before being moved deeper into the network. Investigators explicitly described her system as a dual strategy combining intelligence collection with propaganda. Hindu and Sikh influencers were reportedly targeted because they offered greater credibility. Praise for Pakistan carries a different value when it comes from an Indian Hindu or Sikh creator rather than when it comes from a Pakistani government account.
This gives the handler three advantages. First, the recruit appears less suspicious while gathering information. Second, the recruit can generate apparently independent Indian propaganda. Third, if the network is exposed, Pakistan can point to the Indian Hindu face of the operation and obscure the foreign organisation that created it.
The propaganda value was visible after Prakash Singh’s arrest. A post in the r/indianmuslims community was titled “Not a Muslim”. Comments used formulations such as “Not all Hindus but always a Hindu” and described Hindus collectively as spies and terrorists. The Pakistani handlers disappeared from the communal framing. The identity of the Indian accused became the story.
This is precisely why the Hindu identity of recruits matters. Pakistan does not need to formally announce a “Hindu terror” operation. The optics develop automatically. A Pakistani-controlled network is transformed into evidence against Hindus.
A pre-existing intellectual and media framework is already available for this purpose. In a 2019 opinion article for Al Jazeera, Rana Ayyub accused the BJP of downplaying incidents of “Hindu terrorism”. Her earlier writing demonstrates that the terminology and political framework were already established long before these arrests.
Kasab’s kalawa – Pakistan had used the Hindu disguise before
The clearest historical precedent came during the 26/11 Mumbai terrorist attack. David Coleman Headley testified before a Mumbai court that he visited the Siddhivinayak temple and purchased red-and-yellow sacred threads. He said the ten terrorists could wear them as cover so people would believe they were Indians. Other accounts of his testimony record that he handed the threads to Lashkar-e-Taiba handler Sajid Mir.
Ajmal Kasab and the other terrorists were also given fake Indian college identity cards bearing Hindu names. Kasab’s card identified him as Sameer or Samir Choudhary, son of Dinesh Choudhary, associated with Arunodaya Degree College. Kasab’s confession recorded that the attackers were told the cards and sacred threads would deceive the police and help them complete the mission.
The operation therefore contained a manufactured Hindu trail that included Hindu names, fake Indian college identities, a kalawa, shaved or altered appearances, removal of identifying labels and a plan under which the terrorists were expected to die.
Former Mumbai Police Commissioner Rakesh Maria later wrote that had Kasab been killed, he would have been discovered as Samir Dinesh Chaudhari with a red thread on his wrist. He wrote that newspapers would have carried headlines about “Hindu terrorists” attacking Mumbai.
Special prosecutor Ujjwal Nikam later clarified that Maria had not categorically claimed that Lashkar’s declared objective was to manufacture the phrase “Hindu terror”. Nikam believed the fake cards were intended to conceal the attackers’ Pakistani nationality and mislead investigators.
That clarification does not erase the central fact. Pakistan-trained jihadists were deliberately made to resemble Hindu Indians. The disguise provided immediate operational cover. Had all ten died, the same disguise could have produced a false public conclusion about their identity. In fact, Congress leader Digvijay Singh’s promotion of the narrative that the RSS was behind the 26/11 attack, through the launch of the book titled “RSS ki Sazish 26/11”, is the clearest sign of what the intentions were and what would have happened if Kasab had not been caught alive.
Whether “Hindu terror” was the formal title of the operation is secondary. Pakistan created the evidence from which such a narrative could emerge. The post-Operation Sindoor cases follow the same underlying logic. Hindu identities help an operation blend into India. They also provide a false Indian face to an operation directed from Pakistan.
Abhinav Bharat and the construction of the “Hindu terror” narrative
The political expression “Hindu terror” gained prominence during investigations into the Malegaon, Samjhauta Express, Ajmer and Mecca Masjid blasts. The name Abhinav Bharat became central to several allegations involving right-wing activists.
The historical Abhinav Bharat was a revolutionary organisation associated with VD Savarkar and was disbanded after Independence. A different organisation using the same name emerged decades later and became part of the Malegaon investigation.
Former Home Ministry official RVS Mani has stated that the defunct name was deliberately revived in 2005-06 and used to bring right-wing individuals into a structure that could support the “Hindu terror” theory. A later review of his book Deception records his claim that the organisation was revived to provide a base for the narrative.
In The Myth of Hindu Terror, Mani says that the NIA’s investigations during 2009-10 overlooked the original lines of evidence in cases such as Samjhauta, Malegaon and Ajmer and replaced them with material supporting a Hindu-terror narrative. He also says that the agency was used politically to propagate the terms “Hindu terror” and “saffron terror”. These are the author’s claims based on his experience in the Home Ministry, not findings accepted by a court.
Mani separately questions the speed with which the 2008 Malegaon investigation moved towards Lt Col Shrikant Purohit and Hindu organisations. He says that the political establishment wanted terror incidents to be coloured “saffron”.
Pakistan benefits when that category is available. If Pakistani handlers recruit a Hindu youth, direct him to install a camera and pay him through an intermediary, the exposed operative is Hindu. Yet the plan, handler and beneficiary remain Pakistani. Once the Hindu name is extracted from the chain and presented without its controller, a Pakistan-backed operation can be repackaged as a Hindu security threat.
The pattern that emerges
The evidence since Operation Sindoor establishes four connected facts.
First, Pakistan-linked operatives are recruiting Indians for both espionage and propaganda. The Naushaba Masood investigation explicitly described those twin objectives.
Second, Hindus and Sikhs were specifically targeted in at least one influencer and visa network. This was not inferred from names. Investigators stated it directly.
Third, Hindu youths were selected in the Ghaziabad module because they would attract less suspicion while installing surveillance equipment.
Fourth, Pakistan and Lashkar-e-Taiba previously manufactured Hindu appearances and identities for the 26/11 terrorists. The kalawas and fake Hindu names are recorded in testimony, the chargesheet, Kasab’s confession and accounts of the trial.
Taken together, this is not a random collection of unrelated details. Hindu identity has repeatedly provided Pakistan-backed operations with camouflage, credibility and deniability.
The precise endgame may vary. One recruit is used to film a cantonment. Another activates an Indian SIM. Another publishes favourable videos. Another installs a solar-powered camera. The handler does not need every recruit to understand the larger operation. The common result is the same. Pakistan obtains information or influence while the person visible on Indian soil is an Indian Hindu or Sikh.
Pakistan recruits vulnerabilities, but identity multiplies their value
Money, honey traps and blackmail explain why a person may agree to work for a hostile intelligence service. They do not fully explain why particular profiles are valuable.
A Hindu influencer praising Pakistan has more propaganda value than a Pakistani official praising Pakistan. A Hindu youth installing a camera near a defence location draws less suspicion than an identifiable member of an Islamist module. A Hindu name on a dead terrorist’s identity card can misdirect an investigation. A Hindu accused, stripped of the context of his Pakistani handler, can later be held up as evidence of “Hindu terror”.
This is why the post-Operation Sindoor arrests cannot be dismissed as individual greed alone. The handlers are exploiting vulnerabilities, but they are also exploiting identity.
The operational method has evolved since 26/11. Fake identity cards and sacred threads have been replaced by influencers, Indian SIM cards, encrypted applications and solar-powered cameras. The purpose remains familiar: conceal the Pakistani hand behind an Indian face.
India’s counter-intelligence response must therefore look beyond conventional jihadist profiles. Hindu students, influencers, contractors, pilgrims and civilians living near defence installations are now targets for recruitment. Awareness campaigns must explain how friendly online contact, visa assistance, small payments and seemingly harmless requests can become the first stage of espionage.
Pakistan does not need to convert every recruit ideologically. It needs access, obedience and an Indian identity that can carry the blame when the operation is exposed.
The Hindu religious identity of a person involved in a Pakistani espionage network is not an incidental detail. It is part of the weapon that a hostile nation’s intelligence network is using against India.


