ISI-linked underworld modules may be smokescreen for major J&K attack, agencies warn
Synopsis
Key Takeaways
Indian security agencies have dismantled several terror-linked modules over recent months that were allegedly being run by underworld networks at the direction of Pakistan's Inter-Services Intelligence (ISI), with investigators now warning that these cells may have been deliberately designed as a smokescreen to divert attention from a far larger strike planned in Jammu and Kashmir. The names of underworld figures Dawood Ibrahim, Shahzad Bhatti, and Ajmal Gujjar have surfaced during interrogations following the arrest of multiple youths recruited through social media platforms.
The Smokescreen Theory
While early-stage investigations pointed to attack plans targeting Delhi and Mumbai, intelligence agencies have since revised their assessment. A senior Intelligence Bureau (IB) official said the broader objective appeared to be engineering a major strike in Jammu and Kashmir, with certain modules potentially created solely to confuse and overstretch security agencies.
'It is a fact that the underworld has set up multiple modules in the country. Some of these networks may have been intended only to create confusion and divert attention away from a possible attack in Jammu and Kashmir,' the official said.
Recruitment Pattern and Modus Operandi
The underworld-linked networks focused specifically on recruiting mobile phone mechanics, individuals with strong computer skills, and CCTV technicians — a profile markedly different from conventional terror recruitment. The pattern first came to light when police uncovered a module operating out of Faridabad, whose members had installed solar-powered CCTV systems at sensitive and high-footfall locations.
Investigators probing the Faridabad cell found that its members had planned to install surveillance systems at railway stations along the Delhi-Jammu corridor to monitor military movements. Members of the group had also reportedly travelled to Pulwama and allegedly passed sensitive information to handlers based in Pakistan.
Officials noted a deliberate shift in the recruitment strategy: all recruits were Indian nationals, and religion was not a factor in their selection. Handlers also avoided recruiting residents from Jammu and Kashmir itself, reportedly to reduce the risk of early exposure. 'Recruiting local residents from Jammu and Kashmir would have immediately attracted suspicion and increased the chances of the network being exposed,' officials said.
Pulwama and Pahalgam Blueprint
According to investigators, the ISI allegedly sought to replicate the scale and impact of the Pulwama and Pahalgam attacks while using Indian operatives as primary executors — a structural departure from earlier cross-border infiltration models. Intelligence inputs suggest the ISI was attempting to engineer an attack of comparable magnitude while minimising the visible Pakistan footprint.
This comes amid heightened security across Jammu and Kashmir following the Pahalgam attack and Operation Sindoor, during which Indian armed forces reportedly targeted and destroyed major terror infrastructure linked to Lashkar-e-Tayiba and Jaish-e-Mohammad. Officials said security arrangements in the region remain at their highest levels.
Pakistan's Strategic Context
Intelligence officials pointed to Pakistan's domestic pressures as a driver of continued proxy activity. Pakistan, they noted, is keen to keep the Kashmir issue internationally alive at a time when it faces serious internal challenges, including unrest in Balochistan, Khyber Pakhtunkhwa, and Pakistan-occupied Kashmir.
Officials said the ISI continues efforts to revive or seed home-grown terror networks in Jammu and Kashmir, though such operations are currently being conducted in a deliberately low-profile manner. Agencies have been cautioned to remain alert to the emergence of further modules linked to figures such as Bhatti and Dawood, with the assessment that some cells are designed as decoys while others are tasked with executing a strike.
What Security Agencies Are Watching
The intelligence community's working hypothesis — that multiple simultaneous modules serve both operational and deception functions — marks a significant evolution in threat assessment. Analysts note this is consistent with ISI tradecraft of layering genuine cells with dummy networks to exhaust investigative bandwidth. With Operation Sindoor having disrupted established terror infrastructure, agencies believe Pakistan may be doubling down on proxy networks using civilian cover. Further arrests and module busts are expected as investigations widen.