Terrorism is changing tactics, adapting to the times and technology. Pakistan’s ISI has shown remarkable flexibility in embracing technology to leverage what it calls providing a thousand cuts to India through a hybrid war spanning decades. Recent developments and arrests provide a peek into this dangerous mix of technology and terrorism. It is heartening to note that our internal and external intelligence agencies have also become quite adept at countering such threats, even though the initiative rests with the aggressor.
Introduction
For decades, Pakistan’s Inter-Services Intelligence has relied on trained handlers, covert operatives and cross-border networks to conduct espionage and support proxy operations against India. That model, however, appears to be evolving. A string of arrests across Delhi, Punjab, Haryana and other parts of India during 2025–26 has revealed a leaner, more deniable approach: recruitment through Instagram and other social-media platforms, payments ranging from a few thousand rupees to tens of thousands, and tasks as mundane as installing CCTV cameras, conducting reconnaissance or procuring and couriering SIM cards. From farmers and gig workers to MBA graduates and YouTubers, ISI’s new foot soldiers are ordinary Indians drawn in not by ideology, but by a few thousand rupees and a friendly message online.
This shift reflects an adaptation in the methods used by Pakistan-based handlers and ISI-linked networks. Rather than relying exclusively on the physical movement of trained operatives across the border, recent investigations show handlers using social media to identify, approach, and gradually task individuals inside India. In some cases, Indian SIM cards have been routed to Pakistan through Dubai and subsequently used by Pakistani intelligence operatives to communicate with and recruit Indians. The result is a diffuse, low-cost espionage architecture that is harder to detect because its initial activities resemble ordinary online interactions. Until a camera near a cantonment, reconnaissance of a security installation or a SIM card sent abroad reveals a very different purpose.
Understand the Recruitment Funnel
Recent investigations indicate that some Pakistan-based handlers operate through overseas intermediaries, particularly in Dubai and Qatar, using social media and digital communication to reduce direct traceability. Pakistan-based gangster Shehzad Bhatti, whom Indian agencies have described as an alleged ISI proxy, along with associates such as Hamad Memon, Ajmal Gujjar and Abid Jatt, illustrates aspects of this model — using social-media accounts to identify and cultivate recruits and allegedly directing activities through associates in India. Investigations have also documented the use of digital payment channels in some recruitment operations. Recruits may initially be kept unaware of the broader purpose of the assignments, with their involvement gradually expanding as they establish themselves as reliable assets.
Who gets targeted is equally telling. Many recruits identified in recent cases have been unemployed youth, casual workers or people facing financial difficulties — suggesting that vulnerability is often a significant point of entry. Recent investigations have involved people from a range of socioeconomic backgrounds, including garbage collectors, handloom workers, small traders, delivery workers and students. A smaller subset appears to have been drawn in through grievance narratives, including messaging around political, social or religious issues. In such cases, ideological or grievance-based motivations may overlap with financial incentives, rather than replacing them altogether. This is not merely a theoretical funnel — elements of this recruitment pattern are visible in a string of cases documented by Indian security agencies over the past two years.
Anatomy of a Recruitment: Documented Cases
Not every recruit fits the low-income profile, however. Social-media influencers such as Jyoti Malhotra, who ran the Travel With Jo channel, were allegedly cultivated through access, travel, and personal connections rather than direct financial inducements. Investigators said she came into contact with Ehsan-ur-Rahim alias Danish, a Pakistan High Commission official who was expelled by India in May 2025 and whom Indian sources identified as an alleged ISI operative. Jasbir Singh, another Punjabi YouTuber arrested in 2025, was also accused of maintaining contact with Pakistani intelligence-linked individuals, including the alleged handler Shakir alias Jutt Randhawa. At the more organised end sits the Shahzad Bhatti network, centred on a Pakistan-based gangster whom Indian agencies have described as linked to an ISI-backed terror network. Bhatti had around 2.5 lakh Instagram followers and more than 4.5 lakh on Facebook — roughly seven lakh combined — and investigators said he monitored likes and comments to identify potential recruits. Some were allegedly paid Rs 5,000–10,000 for putting up posters before being moved towards more dangerous assignments, including reconnaissance, explosives and grenade attacks. Indian agencies have also linked his network to attacks including the Sirsa Police station blast and the Ambala Police station attack. Taken together, these cases illustrate how individuals initially approached for seemingly minor online or logistical tasks can, according to investigators, be drawn into progressively more serious espionage and terror-related activity.
Institutional/law-enforcement response
Equally critical is faster, sustained coordination between Delhi Police, state Police forces, State Special Branch, the Local Intelligence Unit (LIU), the Intelligence Bureau, R&AW and the National Investigation Agency, since these networks tend to regenerate quickly once individual cells are dismantled. In catching these small-time ISI operators, state intelligence—especially the LIU, with its granular, ground-level presence—is particularly important, since these recruits operate far below the radar of central agencies until a task is already underway. To close this gap, intelligence agencies should actively cultivate lower-level informants embedded in vulnerable communities — gig workers, delivery networks, and financially distressed neighbourhoods — who can flag early signs of recruitment before a module becomes operational. If necessary, these grassroots-level intelligence personnel should receive stronger incentives, both financial and career-linked, to sustain these source networks over time. The value of this layered coordination was evident in the last week of May, when the Delhi Police Cell arrested nine Indians who were allegedly working for ISI. These young recruits from across the country — among them a garbage collector — underscore both the geographic spread of these modules and the socioeconomic profile of those being drawn in. Delhi Police Special Cell, working jointly with the Maharashtra Anti-Terrorism Squad, arrested two suspects in April 2026. Such joint operations, spanning multiple states in a single coordinated action, disrupt a network before it can rebuild under a new handler or shift base to a fresh state, as Bhatti’s outfit has repeatedly done.
Agencies must also strengthen their ability to trace SIM card and financial trails, which have emerged as important investigative leads in several recent cases. The Delhi case involving Sahil and Sameera, for instance, involved procuring eight Indian SIM cards and transferring them to Pakistan through Dubai. At the same time, other investigations have uncovered the use of digital payment channels in recruitment. Telecom and KYC enforcement therefore remain important safeguards, particularly against the fraudulent procurement and misuse of SIM cards. India has already tightened the regulatory framework around bulk SIM issuance and dealer verification. At the same time, recent Police investigations into so-called “ghost SIM” networks have shown how SIMs can still be obtained or activated through misuse of KYC and point-of-sale processes. The policy priority should therefore be stronger enforcement of existing KYC and telecom safeguards, rapid identification and deactivation of suspicious connections, and closer information-sharing between telecom operators, financial institutions and law-enforcement agencies. These measures could help intercept the communications infrastructure on which low-cost espionage and terror-support networks increasingly depend, rather than leaving investigators to reconstruct the trail only after an operation has taken place.
Platform and Technology Accountability
Handlers sustain loyalty through both financial and aspirational lures. Recruits are often promised eventual relocation to Dubai or other Gulf cities—a promise that rarely materialises but keeps them compliant through successive assignments. Once an individual is “raised” as an asset, their role expands beyond the original task: they also identify and recruit more young people from their own social and family circles, effectively turning each recruit into a self-replicating node in the network. This peer-to-peer expansion model makes the networks significantly harder to map and dismantle in full, since arresting one operative rarely exposes the full chain of people they were quietly bringing in behind them.
ISI’s selection process is itself methodical. Handlers first build flashy, sympathetic social media personas, positioning themselves as champions of the disgruntled and disaffected. They then closely study comments and engagement on these posts, using them to identify individuals expressing resentment against the establishment—the clearest signal of a receptive target. Security officials describe what follows as graded escalation: recruits who complete low-level tasks are gradually entrusted with more serious assignments, such as transporting arms and ammunition or facilitating handovers to hardened terrorists, with payment rising in step with the risk involved. Officials also note that youths from minority communities are disproportionately targeted through reels originating from their majority localities, with handlers using selectively edited or fabricated videos and audio clips to stir religious sentiment and deepen a sense of grievance.
Community and prevention-level measures
This entire approach reflects a deeper strategic shift. Earlier, Pakistan’s proxy networks relied on sending trained operatives across the border or arranging training for Indians abroad — a model fraught with logistical risk and traceability. Using vulnerable, home-grown recruits has proven cheaper and more deniable: if caught or killed, they represent no real loss to their handlers. This logic echoes General Zia-ul-Haq’s 1988 “Operation Topac,” widely described in Indian security literature as a strategy to “bleed India with a thousand cuts” by exploiting religious sentiment — reportedly designed so that if Indian recruits were caught, Pakistan and its proxies could claim these were persecuted Indian Muslims acting independently, with no Pakistani hand involved at all.
Legal and deterrence angle
A related concern raised by security officials is the pattern of well-funded legal defence mobilised for some of these small-time recruits and terror operatives. When lawyers charging substantial fees repeatedly contest such cases, it is worth asking who is funding this legal support, and what interest — ideological, financial, or otherwise — motivates the organisations underwriting it. This is not a call to restrict anyone’s right to legal defence, a constitutional guarantee, but a case for greater transparency around funding sources in cases with a demonstrated cross-border espionage or terror-financing angle, so legitimate defence is not indistinguishable from an extension of the network itself.
None of this, however, should come at the cost of fairness. Security agencies must act without bias, ensuring that only genuine offenders are booked, since the wrongful prosecution of an innocent citizen — however unintentional — breeds mistrust and can deepen communal or social fault lines that networks like these are, in part, designed to exploit. Integrity in investigation is not a constraint on effective counter-espionage; it sustains public cooperation. Agencies that are seen to act honestly, and only against those genuinely involved, retain the community trust that vigilance-based prevention ultimately depends on.






