Science & Technology

From Handlers to Hackers: India’s New Threat Matrix

Two Incidents, Two Different Security Layers

The Nalagarh police-station blast in Himachal Pradesh and the Delhi espionage case involving an alleged Pakistan-linked network appear to be separate investigations. Yet together, they reveal how contemporary cross-border threats can operate through multiple layers—foreign handlers, vulnerable local recruits, digital platforms, criminal networks and seemingly ordinary logistical resources. Both cases remain under investigation, and allegations against the accused will ultimately have to withstand judicial scrutiny.

Nalagarh: Turning Vulnerability into Violent Recruitment

The January 1 IED explosion near Nalagarh police station initially appeared to be an isolated security incident. The device was placed near the outer wall of a room used by the investigating officer. Subsequent investigation, however, pointed towards an alleged wider conspiracy extending into Punjab and involving foreign-based handlers.

On August 13, the National Investigation Agency arrested Mahavir Kumar alias Kaka, Ajay Mehra and Manpreet Singh alias Mani in connection with the case. Earlier investigations alleged that Mahavir and Manpreet carried out the attack under instructions from foreign-based operatives identified as Gopi Nawanshahria, Jassi Kulam and Sushant Chopra, whom Punjab Police have linked to the banned Babbar Khalsa International. A Glock pistol and four live cartridges were reportedly recovered from two suspects.

The case highlights an increasingly concerning recruitment model: exploiting economically vulnerable and drug-dependent young people as disposable operatives. Such a structure can separate overseas planners from local attackers, making intelligence gathering and attribution considerably more difficult.

Delhi: When Digital Tools Become Espionage Infrastructure

The Delhi Police Special Cell investigation illustrates another dimension of the threat. Police arrested Mohammad Sahil, 25, and his wife Sameera, 21, alleging that they had maintained contact with Pakistan-based intelligence operatives through social media since 2024.

Investigators allege that the couple procured eight Indian SIM cards and sent them through Dubai to Pakistan between 2024 and 2025 for around ₹30,000. The numbers were allegedly used to activate WhatsApp accounts from Pakistan, enter Indian groups and seek sensitive defence-related information.

Police further allege that Sahil was tasked with reconnaissance of cantonments, developing local contacts and obtaining information concerning Army personnel facing court-martial proceedings.

The case demonstrates how inexpensive, easily available tools can become strategic assets. SIM cards, social-media accounts and encrypted messaging can potentially provide foreign handlers with Indian digital identities and facilitate compartmentalised recruitment or information gathering.

From Conventional Terrorism to Hybrid Networks

India’s cross-border terrorism challenge has historically centred on Pakistan-based organisations such as Lashkar-e-Taiba and Jaish-e-Mohammed, with the 2008 Mumbai attacks remaining the defining example of externally directed mass-casualty terrorism.

The emerging pattern is more complicated. Terror networks can intersect with narcotics, organised crime, drones, encrypted communications and foreign-based handlers, creating decentralised structures that are harder to detect. Recent NIA searches across Punjab and Haryana linked to Pakistan-based terrorist Shahzad Bhatti have further highlighted concerns over gangster-terror networks.

Security Must Follow the Network

The Nalagarh and Delhi investigations underline that modern counter-terrorism cannot stop at borders or weapons seizures. Authorities must simultaneously track money, narcotics, digital communications, SIM procurement, courier routes, recruitment and local vulnerabilities.

At the same time, effective security requires precision. Drug dependence, economic hardship, online contact or community connections cannot themselves become evidence of terrorism. India’s strongest defence will be integrated intelligence, targeted policing, due process and social intervention—disrupting the network without alienating the society it seeks to protect.

 

 

(With agency inputs)