Gujarat bomb threat: Two arrested in Bihar, Jharkhand; Bangladesh-backed network exposed
Synopsis
Key Takeaways
Gujarat Police have arrested two men from Bihar and Jharkhand in connection with a multi-state cyber network allegedly responsible for sending bomb threat e-mails targeting the Gujarat Chief Minister's office, the Gujarat Legislative Assembly, Prime Minister Narendra Modi, Union Home Minister Amit Shah, and nations that backed India at the recent BRICS Summit. The arrests, announced on Monday, 14 September 2026, followed a rapid digital investigation by the Cyber Centre of Excellence (CCoE) into a threatening e-mail received on 10 September.
The Threat and How It Was Traced
The threat e-mail arrived at 9:47 am on 10 September on the official e-mail ID of Gujarat's Legal and Parliamentary Affairs Department. It explicitly threatened to blow up the Gujarat Secretariat, the state legislature, and the offices of the country's top two constitutional functionaries. The message was sent from the address jondmoragn52627@gmail.com.
A technical team from the CCoE analysed the e-mail's digital trail and traced it to Bhagalpur, Bihar, leading to the arrest of Roshan Kumar Rajendra Kumar Bhumihar. During interrogation, he allegedly identified Gulshan Kumar Kaushal Singh of Deoghar, Jharkhand as the person who had provided the e-mail ID. A coordinated operation involving technical surveillance and field teams subsequently led to Singh's arrest, according to police.
Bangladesh Connection and Crypto Trail
The investigation has reportedly unearthed an alleged cross-border dimension: the accused were allegedly receiving financial support from co-accused individuals based in Bangladesh, and the recovered e-mail credential database had also been shared with contacts there. Investigators have further found that crypto wallets were allegedly used to facilitate financial transactions within the network, according to the CCoE.
Notably, the accused reportedly used sophisticated methods to create e-mail accounts and bypass standard authentication processes — suggesting a level of technical capability beyond typical opportunistic threat actors.
A Database of Over 5 Lakh Credentials
Among the most alarming finds was a list of 5,13,847 unique e-mail IDs and passwords recovered from the accused. Police suspect this database was intended for use in sending further threatening e-mails to government offices, schools, colleges, and courts, as well as for broader cyber crimes and other illegal activities. The scale of the credential cache points to a potentially wide-ranging operation that extended well beyond the Gujarat threat.
The Joint Operation
The operation was carried out simultaneously across three states, with the CCoE receiving assistance from Gandhinagar Police in Gujarat, Bhagalpur Police in Bihar, and Deoghar Police in Jharkhand. Investigation into the full scope of the e-mail IDs, their intended use, and possible links to other threatening messages or cybercrimes is ongoing, officials said.
Public Advisory
Police have advised members of the public who receive threatening e-mails not to panic and to immediately contact local police or call the 1930 cybercrime helpline. Authorities have also urged people not to delete, forward, or circulate threatening e-mails, screenshots, or unverified information on social media, and not to engage with the sender under any circumstances.
With a Bangladesh-linked network, a half-million-strong credential database, and crypto-denominated payments in the picture, investigators say the full contours of the operation are yet to emerge.