ISI-linked underworld modules may be smokescreen for major J&K attack, agencies warn

Share:
Audio Loading voice…
ISI-linked underworld modules may be smokescreen for major J&K attack, agencies warn

Synopsis

Indian security agencies have busted multiple ISI-linked underworld cells — and now believe some were decoys. The real target, according to intelligence officials, may be a Pulwama or Pahalgam-scale strike in Jammu and Kashmir, executed entirely through Indian nationals to obscure Pakistan's hand.

Key Takeaways

Indian agencies have dismantled several ISI-linked underworld modules over recent months, with Dawood Ibrahim , Shahzad Bhatti , and Ajmal Gujjar named in investigations.
A senior Intelligence Bureau official warned that some modules may have been set up solely as a smokescreen to divert attention from a planned strike in Jammu and Kashmir .
The Faridabad module had installed solar-powered CCTV systems at sensitive locations and planned surveillance of the Delhi-Jammu rail corridor to monitor military movements.
All recruits were Indian nationals ; religion was not a selection criterion — a deliberate departure from conventional ISI recruitment patterns.
The ISI allegedly sought to replicate the Pulwama and Pahalgam attacks using Indian operatives, avoiding a visible Pakistan footprint.
Security across Jammu and Kashmir remains at its highest level following the Pahalgam attack and Operation Sindoor .

Indian security agencies have dismantled several terror-linked modules over recent months that were allegedly being run by underworld networks at the direction of Pakistan's Inter-Services Intelligence (ISI), with investigators now warning that these cells may have been deliberately designed as a smokescreen to divert attention from a far larger strike planned in Jammu and Kashmir. The names of underworld figures Dawood Ibrahim, Shahzad Bhatti, and Ajmal Gujjar have surfaced during interrogations following the arrest of multiple youths recruited through social media platforms.

The Smokescreen Theory

While early-stage investigations pointed to attack plans targeting Delhi and Mumbai, intelligence agencies have since revised their assessment. A senior Intelligence Bureau (IB) official said the broader objective appeared to be engineering a major strike in Jammu and Kashmir, with certain modules potentially created solely to confuse and overstretch security agencies.

'It is a fact that the underworld has set up multiple modules in the country. Some of these networks may have been intended only to create confusion and divert attention away from a possible attack in Jammu and Kashmir,' the official said.

Recruitment Pattern and Modus Operandi

The underworld-linked networks focused specifically on recruiting mobile phone mechanics, individuals with strong computer skills, and CCTV technicians — a profile markedly different from conventional terror recruitment. The pattern first came to light when police uncovered a module operating out of Faridabad, whose members had installed solar-powered CCTV systems at sensitive and high-footfall locations.

Investigators probing the Faridabad cell found that its members had planned to install surveillance systems at railway stations along the Delhi-Jammu corridor to monitor military movements. Members of the group had also reportedly travelled to Pulwama and allegedly passed sensitive information to handlers based in Pakistan.

Officials noted a deliberate shift in the recruitment strategy: all recruits were Indian nationals, and religion was not a factor in their selection. Handlers also avoided recruiting residents from Jammu and Kashmir itself, reportedly to reduce the risk of early exposure. 'Recruiting local residents from Jammu and Kashmir would have immediately attracted suspicion and increased the chances of the network being exposed,' officials said.

Pulwama and Pahalgam Blueprint

According to investigators, the ISI allegedly sought to replicate the scale and impact of the Pulwama and Pahalgam attacks while using Indian operatives as primary executors — a structural departure from earlier cross-border infiltration models. Intelligence inputs suggest the ISI was attempting to engineer an attack of comparable magnitude while minimising the visible Pakistan footprint.

This comes amid heightened security across Jammu and Kashmir following the Pahalgam attack and Operation Sindoor, during which Indian armed forces reportedly targeted and destroyed major terror infrastructure linked to Lashkar-e-Tayiba and Jaish-e-Mohammad. Officials said security arrangements in the region remain at their highest levels.

Pakistan's Strategic Context

Intelligence officials pointed to Pakistan's domestic pressures as a driver of continued proxy activity. Pakistan, they noted, is keen to keep the Kashmir issue internationally alive at a time when it faces serious internal challenges, including unrest in Balochistan, Khyber Pakhtunkhwa, and Pakistan-occupied Kashmir.

Officials said the ISI continues efforts to revive or seed home-grown terror networks in Jammu and Kashmir, though such operations are currently being conducted in a deliberately low-profile manner. Agencies have been cautioned to remain alert to the emergence of further modules linked to figures such as Bhatti and Dawood, with the assessment that some cells are designed as decoys while others are tasked with executing a strike.

What Security Agencies Are Watching

The intelligence community's working hypothesis — that multiple simultaneous modules serve both operational and deception functions — marks a significant evolution in threat assessment. Analysts note this is consistent with ISI tradecraft of layering genuine cells with dummy networks to exhaust investigative bandwidth. With Operation Sindoor having disrupted established terror infrastructure, agencies believe Pakistan may be doubling down on proxy networks using civilian cover. Further arrests and module busts are expected as investigations widen.

Point of View

If accurate, signals a sophisticated evolution in ISI proxy strategy — one that exploits India's investigative bandwidth by flooding the zone with decoy cells. The deliberate exclusion of Kashmiri recruits and the use of civilian-skilled Indian nationals suggest handlers have studied past exposure patterns and adapted. What is underreported is the CCTV surveillance angle: installing monitoring infrastructure along the Delhi-Jammu corridor is not a distraction tactic — it is classic pre-attack intelligence gathering. The convergence of Operation Sindoor's disruption of established terror infrastructure with this new civilian-cover recruitment model suggests Pakistan is recalibrating, not retreating. Agencies must resist the temptation to declare victory on the busted modules and stay alert to the cells still undetected.
NationPress
5 Aug 2026

Frequently Asked Questions

What are the ISI-linked underworld modules that Indian agencies have busted?
Indian security agencies have dismantled several terror cells allegedly run by underworld networks — including figures linked to Dawood Ibrahim, Shahzad Bhatti, and Ajmal Gujjar — at the direction of Pakistan's ISI. The modules recruited Indian nationals through social media and were tasked with surveillance and attack planning.
Why do agencies believe these modules are a smokescreen for a J&K attack?
A senior Intelligence Bureau official said some modules appear designed to confuse and overstretch security agencies rather than execute attacks themselves. Investigators found that the Faridabad cell had conducted surveillance along the Delhi-Jammu corridor and that members had travelled to Pulwama, pointing to a larger Jammu and Kashmir-focused conspiracy.
How is this ISI recruitment model different from past patterns?
Unlike earlier networks, all recruits were Indian nationals and religion was not a factor in selection. The ISI also deliberately avoided recruiting residents of Jammu and Kashmir to reduce early exposure risk — a significant departure from conventional cross-border infiltration methods.
What was the Faridabad module doing?
The Faridabad module had installed solar-powered CCTV systems at sensitive and crowded locations and had planned to set up surveillance at railway stations along the Delhi-Jammu route to monitor military movements. Members reportedly travelled to Pulwama and passed sensitive information to Pakistan-based handlers.
What is the security situation in Jammu and Kashmir currently?
Security arrangements in Jammu and Kashmir remain at their highest levels following the Pahalgam attack and Operation Sindoor, during which Indian armed forces reportedly destroyed major terror infrastructure linked to Lashkar-e-Tayiba and Jaish-e-Mohammad. Intelligence officials say the ISI is continuing low-profile efforts to seed home-grown networks in the region.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest Yesterday
  2. 1 month ago
  3. 2 months ago
  4. 2 months ago
  5. 2 months ago
  6. 3 months ago
  7. 3 months ago
  8. 8 months ago
Google Prefer NP
On Google