Gujarat bomb threat: Two arrested in Bihar, Jharkhand; Bangladesh-backed network exposed

Share:
Audio Loading voice…
Gujarat bomb threat: Two arrested in Bihar, Jharkhand; Bangladesh-backed network exposed

Synopsis

A bomb threat e-mail targeting Prime Minister Modi, Home Minister Shah, the Gujarat Secretariat and BRICS partner nations has cracked open an alleged multi-state cyber network with Bangladesh financing and crypto payments — and a recovered database of over 5 lakh e-mail credentials suggests the threat operation was built for scale, not just a one-off hoax.

Key Takeaways

Gujarat Police arrested Roshan Kumar Rajendra Kumar Bhumihar from Bhagalpur, Bihar and alleged main accused Gulshan Kumar Kaushal Singh from Deoghar, Jharkhand on 14 September 2026 .
The bomb threat e-mail was received at 9:47 am on 10 September by Gujarat's Legal and Parliamentary Affairs Department , targeting the CM's office, the state legislature, PM Narendra Modi , Home Minister Amit Shah , and BRICS partner nations.
Investigators recovered a database of 5,13,847 unique e-mail IDs and passwords allegedly intended for further threats and cybercrimes.
The network allegedly received financial support from co-accused in Bangladesh , with crypto wallets used for transactions.
The joint operation spanned three states , co-ordinated by the Cyber Centre of Excellence (CCoE) with police from Gandhinagar , Bhagalpur , and Deoghar .
Public advised to call cybercrime helpline 1930 on receiving any threatening e-mails and not to forward or delete them.

Gujarat Police have arrested two men from Bihar and Jharkhand in connection with a multi-state cyber network allegedly responsible for sending bomb threat e-mails targeting the Gujarat Chief Minister's office, the Gujarat Legislative Assembly, Prime Minister Narendra Modi, Union Home Minister Amit Shah, and nations that backed India at the recent BRICS Summit. The arrests, announced on Monday, 14 September 2026, followed a rapid digital investigation by the Cyber Centre of Excellence (CCoE) into a threatening e-mail received on 10 September.

The Threat and How It Was Traced

The threat e-mail arrived at 9:47 am on 10 September on the official e-mail ID of Gujarat's Legal and Parliamentary Affairs Department. It explicitly threatened to blow up the Gujarat Secretariat, the state legislature, and the offices of the country's top two constitutional functionaries. The message was sent from the address jondmoragn52627@gmail.com.

A technical team from the CCoE analysed the e-mail's digital trail and traced it to Bhagalpur, Bihar, leading to the arrest of Roshan Kumar Rajendra Kumar Bhumihar. During interrogation, he allegedly identified Gulshan Kumar Kaushal Singh of Deoghar, Jharkhand as the person who had provided the e-mail ID. A coordinated operation involving technical surveillance and field teams subsequently led to Singh's arrest, according to police.

Bangladesh Connection and Crypto Trail

The investigation has reportedly unearthed an alleged cross-border dimension: the accused were allegedly receiving financial support from co-accused individuals based in Bangladesh, and the recovered e-mail credential database had also been shared with contacts there. Investigators have further found that crypto wallets were allegedly used to facilitate financial transactions within the network, according to the CCoE.

Notably, the accused reportedly used sophisticated methods to create e-mail accounts and bypass standard authentication processes — suggesting a level of technical capability beyond typical opportunistic threat actors.

A Database of Over 5 Lakh Credentials

Among the most alarming finds was a list of 5,13,847 unique e-mail IDs and passwords recovered from the accused. Police suspect this database was intended for use in sending further threatening e-mails to government offices, schools, colleges, and courts, as well as for broader cyber crimes and other illegal activities. The scale of the credential cache points to a potentially wide-ranging operation that extended well beyond the Gujarat threat.

The Joint Operation

The operation was carried out simultaneously across three states, with the CCoE receiving assistance from Gandhinagar Police in Gujarat, Bhagalpur Police in Bihar, and Deoghar Police in Jharkhand. Investigation into the full scope of the e-mail IDs, their intended use, and possible links to other threatening messages or cybercrimes is ongoing, officials said.

Public Advisory

Police have advised members of the public who receive threatening e-mails not to panic and to immediately contact local police or call the 1930 cybercrime helpline. Authorities have also urged people not to delete, forward, or circulate threatening e-mails, screenshots, or unverified information on social media, and not to engage with the sender under any circumstances.

With a Bangladesh-linked network, a half-million-strong credential database, and crypto-denominated payments in the picture, investigators say the full contours of the operation are yet to emerge.

Point of View

Cryptocurrency and cross-border handlers are being combined to target India's constitutional apparatus. A database of over 5 lakh compromised credentials recovered from two individuals in Tier-2 cities signals industrial-scale preparation, not improvised mischief. The Bangladesh angle demands diplomatic attention alongside policing. And the targeting of BRICS partner nations in the threat message, however theatrical, adds a geopolitical layer that intelligence agencies cannot treat as incidental.
NationPress
14 Sept 2026

Frequently Asked Questions

Who were arrested in the Gujarat bomb threat e-mail case?
Two men were arrested: Roshan Kumar Rajendra Kumar Bhumihar from Bhagalpur, Bihar, and alleged main accused Gulshan Kumar Kaushal Singh from Deoghar, Jharkhand. The arrests were made following a digital investigation by Gujarat's Cyber Centre of Excellence (CCoE) into a bomb threat e-mail sent on 10 September 2026.
What did the bomb threat e-mail say and who were the targets?
The threatening e-mail, received by Gujarat's Legal and Parliamentary Affairs Department at 9:47 am on 10 September, threatened to blow up the Gujarat Chief Minister's office, the Gujarat Legislative Assembly, the offices of Prime Minister Narendra Modi and Home Minister Amit Shah, and nations that supported India at the recent BRICS Summit.
What is the Bangladesh connection in this case?
Investigators have found that the accused were allegedly receiving financial support from co-accused individuals based in Bangladesh. The recovered database of over 5 lakh e-mail credentials was also reportedly shared with contacts in Bangladesh, and crypto wallets were allegedly used to move funds across the network.
What was recovered from the accused and why is it significant?
Police recovered a list of 5,13,847 unique e-mail IDs and passwords from the accused. According to authorities, the database was allegedly intended for sending further threat e-mails to government offices, schools, colleges, and courts, as well as for broader cybercrime activity — indicating the network was built for large-scale operations.
What should the public do if they receive a threatening e-mail?
Gujarat Police have advised recipients of threatening e-mails not to panic and to immediately contact local police or dial the cybercrime helpline at 1930. Authorities also caution against deleting, forwarding or circulating such e-mails or unverified information on social media, and advise against communicating with the sender.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 1 month ago
  2. 2 months ago
  3. 3 months ago
  4. 3 months ago
  5. 4 months ago
  6. 6 months ago
  7. 1 year ago
  8. 1 year ago
Google Prefer NP
On Google