Last Updated:
A nine-month operation culminated in a multi-state crackdown that exposed how a Pakistani gangster used social media and vulnerable Indian youth to build a low-cost terror network
Shahzad Bhatti, a Pakistani gangster from Bahawalnagar in Punjab province, has reinvented himself online as a digital influencer and alleged proxy of the ISI.
Atulchandra Kulkarni, IPS (Retd.), former Special DGP of the National Investigation Agency (NIA), writes exclusively for News18 on how Indian security agencies spent nine months tracking and dismantling the Shahzad Bhatti Network, a Pakistan-based terror-gangster syndicate accused of using social media, organised crime and vulnerable Indian youth to build a dispersed network of violence and espionage across the country. In this exclusive account, Kulkarni examines how the agencies pieced together the network’s operations, recruitment model, criminal-terror links and cross-border connections, and what the crackdown reveals about the changing nature of Pakistan-backed terrorism in India.
In a sweeping pre-Independence Day crackdown, Indian security agencies detained 253 people across 14 states and arrested more than 200 operatives linked to the Pakistan-based Shahzad Bhatti Network (SBN), foiling the plans for subversive attacks across the country, around August 15. The August 12 operation, conducted through coordinated intelligence-sharing between central agencies and state police, exposed a disturbing model of cross-border terrorism: one in which Pakistani handlers recruit Indian youth through social media, pay them for seemingly minor criminal tasks and gradually draw them into reconnaissance, weapons trafficking and targeted terror/violence.
The operation was the culmination of nearly nine months of coordinated work that began in November 2025, with intelligence being collated and disseminated among multiple state police forces through the Multi-Agency Centre (MAC). The scale of the crackdown shows why Indian agencies regard the network as much more than another gangster outfit. About 100 First Information Reports (FIRS) ie formal criminal cases have been registered against the SBN, with more than 200 people arrested under stringent legal provisions, including those under the Unlawful Activities (Prevention) Act, the Bharatiya Nyaya Sanhita (Indian Penal Code), the Arms Act, the Narcotic Drugs and Psychotropic Substances Act and the Explosive Substances Act.
The network, which Indian authorities describe as backed by Pakistan’s Inter Services Intelligence (ISI), is associated with grenade, Improvised Explosive Devices (IED) and petrol-bomb attacks, targeted killings, espionage and the movement of weapons and narcotics into India. The seizures during the crackdown included scores of IEDs, grenades bearing Pakistan Ordnance Factory markings, pistols, live ammunition and CCTV equipment intended for surveillance.
Lethal Operation
At the centre of this sprawling operation is Shahzad Bhatti, a Pakistani gangster from Bahawalnagar in Punjab province who has reinvented himself online as a digital influencer and alleged proxy of the ISI. Also spelled ‘Shehzad Bhatti’, he is known by his moniker—”Don of Punjab”—in Pakistani criminal circles. On social media, he presents a very different persona as a digital influencer and reel creator, with an online reach reportedly running into hundreds of thousands.
Bhatti has multiple criminal cases in Pakistan and cannot safely return there, according to officials, explaining his reported movements between Pakistan, the Gulf and Europe, including Dubai and Portugal. Intelligence inputs describe him as a Pakistan-based underworld gangster who allegedly operates as an associate, proxy or operative of the ISI.
Rather than sending trained militants across the border, Bhatti and his associates have built an online distributed network of vulnerable Indian recruits who can be hired, tasked and discarded remotely.
What makes Bhatti’s model distinctive, according to Indian investigators, is that he does not rely on traditional underground militant cells. Instead, he built an open, social-media-driven recruitment machine—reportedly amassing roughly 0.25 million (250,000) on Instagram and over 0.45 million (450,000) on Facebook—a following more typical of an online influencer than a terror handler. He used this reach to identify and contact young men across India, offering money, and in some cases promises of help settling abroad, in exchange for small tasks that escalated over time: from putting up posters, to reconnaissance, to smuggling, to violence.
Intelligence inputs describe Bhatti’s associates operating multiple social-media accounts, sometimes distinguished by numerical suffixes, and aggressively reaching out to potential recruits. The network uses Instagram, WhatsApp, Telegram, Signal, Snapchat, YouTube and other encrypted platforms to identify people who appear susceptible to money, status, gangster culture or the promise of adventure.
The pool is said to include unemployed young men, petty criminals, people with substance dependencies and others in financial distress, particularly those aged between 18 and 25. Yet intriguingly, recruitment is not necessarily confined to a particular religion, region or ideological constituency. Social-media profiles, criminal associations and word-of-mouth contacts can be enough.
A recruit might initially be offered a thousand rupees to put up posters carrying the name “Tehreek-e-Taliban Hindustan”, an entity that investigators describe as a fabricated front rather than an established independent organisation. Recruits were typically paid as little as Rs 5,000 for such tasks, with payments escalating to as much as Rs 3 lakh for targeting and killing police/security personnel.
From there, assignments can become progressively more serious: taking photographs of a police station, transferring money, transporting material, conducting reconnaissance or facilitating the movement of weapons. Investigators describe this as a “proof of work” model. The recruit is paid for a relatively minor task, creating trust and demonstrating reliability before the next assignment arrives. The financial rewards rise with the danger.
The recruit does not necessarily need to understand the entire conspiracy. He does not need to know the handler’s identity, the ultimate target or the location of the weapons. He needs only to complete the task in front of him.
That compartmentalisation makes the network resemble a gig economy for violence.
There is an important reason to resist describing every recruit as a terrorist in the conventional sense. Many of the people caught in these investigations appear to have entered the network without any noticeable deep ideological commitment.
One recruit was a biryani seller. Another was a ginger vendor. Another was a money lender. Investigators have also named recruits, including Sonu Meena, Sachin, Sohail, Md Rihan, Arif and Md Kaif.
A traditional terrorist organisation invests heavily in ideological indoctrination and training. Bhatti’s model, as described by Indian agencies, can dispense with much of that investment. It can recruit someone who is already attracted to guns, gangsters or easy money and give him a job.
The recruit may believe he is helping a gangster. He may think he is committing an ordinary crime. He may not understand that the target has been selected for political, religious or security reasons aimed at jeopardising the national security of India. By the time he recognises the larger purpose, he may already be implicated.
That makes the network simultaneously more dangerous and more difficult to detect.
What The Network Was Allegedly Planning
According to Indian officials, the network’s objective was to sustain a persistent, low-intensity campaign of violence and destabilisation rather than a single largescale attack. The objective of SBN is not necessarily to mount a spectacular attack but to make violence cheap and repeatable by keeping up a low-intensity campaign inside India by outsourcing individual acts to people who may never meet one another or even understand the organisation they are serving.
Reported and alleged elements of the plan included reconnaissance of sensitive sites. Local recruits were paid to scout police stations, defence installations and religious sites, and to install hidden surveillance cameras to feed intelligence back to handlers.
The network was also associated with grenade, IED and petrol-bomb attacks, including a grenade attack on the Gurdaspur City Police Station and other border-district police posts in Punjab, using explosives allegedly supplied through Bhatti’s smuggling channels.
Targeted killings were another element—of police personnel and other individuals, including attacks tied to religious or political grievances, such as the Jalandhar influencer’s house and the home of a leader of BhartiyaJanata Party (BJP), the ruling political party in New Delhi for over a decade.
Arms and narcotics trafficking formed another part of the alleged operation, with weapons and heroin (“chitta”) being smuggled from Pakistan through Punjab into Delhi-NCR to fund operations and arm recruits.
Online radicalisation and recruitment, using Instagram, Facebook, WhatsApp, Telegram and other encrypted platforms to identify, groom and pay vulnerable young men, often without requiring any real ideological commitment, completed the model.
Security officials describe this as a deliberate strategy: rather than infiltrating trained militants, Bhatti’s network sought to weaponise ordinary, financially vulnerable Indian youth as low-cost, easily replaceable “foot soldiers”, making the network harder to fully dismantle even after individual cells are broken up.
What makes the Bhatti network so lethal is that it merges Pakistan-backed terrorism with organised crime, narcotics trafficking and the social-media economy by preying on young, financially vulnerable youths, often with a criminal record. The recruit is sometimes barely aware that the seemingly petty job he has agreed to perform is part of a cross-border terror operation.
Bhatti’s power is his ability to turn the internet into a recruiting market.
Investigators describe a “dead-drop” delivery system for smuggled narcotics and weapons to avoid detection, and that Bhatti operated jointly with an aide identified as Ajmal Gujar, running arms, ammunition and narcotics smuggling from Pakistan through Punjab into Delhi-NCR for further distribution.
Bhatti and his associates have used dead-drop arrangements, could be through drone droppings as well, for weapons and narcotics, with consignments moving from Pakistan through Punjab and onward towards Delhi-NCR. The same infrastructure can serve multiple purposes: drugs can finance criminal operations, weapons can arm recruits, and the criminal network can provide cover for terror activity.
Money can travel through hawala, cash, UPI, digital wallets, USDT and cryptocurrencies, according to the intelligence assessment, creating multiple channels for financing and making the trail harder to follow.
Though Bhatti is also alleged to be a rival of jailed Indian gangster Lawrence Bishnoi, separate leaked videos purportedly showed contact between Bishnoi and Bhatti, prompting a Gujarat government probe. His associates have included Abid Jatt, Ajmal Gujar, Rana Hunain, Suhail Baloch and others, and have been involved in recruitment, tasking, finding and cross-border arms trafficking, according to intelligence assessments. Associates such as Abid Jatt alias Abid Chhal, Ajmal Gujar, Munna Zingada, Hammad Memon, Rana Hunain and Yawar Khan have also been identified in intelligence inputs as part of the wider ecosystem around Bhatti.
The Network’s Criminal Trail
The criminal cases associated with SBN illustrate the range of its alleged activities. In February 2026, two Punjab Police personnel were shot dead at a police post in Gurdaspur near the Pakistan border by unidentified assailants. In May, the group calling itself Tehreek-e-Taliban Hindustan claimed responsibility for the killing of Assistant Sub-Inspector Joga Singh and publicly declared security personnel and members of the Rashtriya Swayamsevak Sangh (RSS) to be the targets.
In March 2025, investigators believed SBN-linked elements were involved in a grenade attack on the residence of BJP leader Manoranjan Kalia in Jalandhar. Another case involved Rozer Sandhu, a Punjab-based social-media influencer whose house was allegedly attacked with a grenade after Bhatti accused him of disrespecting Islam online. Punjab Police arrested nine people in that case, including the alleged principal accused, Hardik Kamboj of Haryana.
Two petrol bombs were also hurled at an RSS office in Nivaranpur in Ranchi, the capital of Jharkhand, on June 16, 2026.
Separately, a 20-year-old man named Krish Rai was arrested in Rajasthan for allegedly filming police stations in Hanumangarh and Raisinghnagar (which are close to the international border with Pakistan) and sending the footage and coordinates to a person claiming to be Bhatti.
Delhi Police’s Special Cell has separately investigated a Bhatti-linked terror-gangster module under FIR No. 126/2026, arresting, among others, Vijay alias Shooter Rajaram Baja of Pune, Sajid Mehboob Shaikh alias Arbaz, Hujaifa Farukh Ahmed Hashmi and Taukir Rizwall Ahmad, residents of Kurla in Mumbai.
Other investigations show the network’s reliance on reconnaissance. The Uttar Pradesh ATS has alleged that Daniel Ashraf Ansari received reconnaissance assignments involving sensitive locations. In Ghaziabad, police uncovered an online-radicalisation module involving geo-tagged photographs of military and strategic locations.
The network has also been linked, through associate Zeeshan Akhtar, a Jalandhar-based criminal, with a history of organised crime, murder and robbery, to the 2024 Mumbai murder of political leader and ex-Member of Legislative Assembly (MLA) Baba Siddique. Akhtar has been accused of providing logistical support and information to the shooters and subsequently fleeing India with assistance from Bhatti.
The alleged involvement of Zeeshan Akhtar adds another dimension to the network’s crime-terror nexus.
In India, Bhatti faces at least 15 registered cases in Punjab alone, including cases involving the targeting of police personnel in the border districts of Gurdaspur and Amritsar Rural. By mid-2026, Indian authorities had begun referring officially to the Shahzad Bhatti Network as a Pakistan-based, ISI-backed terror syndicate.
Geographical Footprint
By the time of the major multi-agency crackdown in August 2026, authorities said the network’s reach extended across 14 Indian states and Union Territories: Uttar Pradesh, Haryana, Delhi, Punjab, Rajasthan, Maharashtra, Uttarakhand, Karnataka, Gujarat, Bihar, Telangana, Himachal Pradesh, Jammu & Kashmir, and Kerala.
The network’s geographical footprint is striking. Additional cases have surfaced around the India-Bangladesh border in West Bengal. The map matters because it suggests that the network is not simply exploiting Punjab’s proximity to Pakistan. It is attempting to build a distributed Indian supply of manpower.
The scale of the subsequent crackdown illustrates why the authorities regard it as more than another gangster feud. More than 90 FIRS have been registered in cases attributed to or associated with SBN, with more than 200 people arrested under provisions, including the UAPA, BNS, Arms Act, NDPS Act and Explosive Substances Act. Punjab and Haryana were also searched separately by the National Investigation Agency, which has opened several cases connected to Bhatti.
Indian agencies began coordinating against the network for nearly nine months from November 2025, with intelligence being collated and disseminated among multiple state police forces and through the Multi-Agency Centre.
The threat became particularly acute ahead of Independence Day.
On August 12, authorities mounted coordinated operations across 14 states and Union Territories. A total of 253 individuals were detained: 62 in Uttar Pradesh, 52 in Haryana, 51 in Delhi, 44 in Punjab, 15 in Rajasthan, eight in Maharashtra, five in Uttarakhand, three each in Karnataka and Gujarat, and two each in Telangana, Himachal Pradesh, Jammu and Kashmir, Bihar and Kerala. FIRs were also registered against suspected SBN associates in Delhi and Karnataka.
The operation was the culmination of the intelligence-sharing system developed over the preceding nine months. More than 100 Instagram handles shared with various state police forces and linked to SBN have also been blocked. Cyber patrolling further revealed that Pakistan-based members of SBN were shifting to new social-media accounts, although a decline in Indian followers of SBN has also been noticed.
The crackdown therefore did more than remove individual operatives. It disrupted the digital infrastructure through which the network sought to replenish itself.
That is significant because the SBN model is potentially more resilient than a conventional cell structure. Arrest one operative and another can be recruited online. Block one account and another can appear. Break one logistical route and another can be improvised.
Serious Warning
For Maharashtra, the warning is especially serious because the state figures prominently in the network’s wider geographical spread and in cases involving Mumbai and Pune-based suspects.
The concern expressed by investigators is that an SBN-linked incident could be attempted through a person who would not ordinarily attract the attention of a counter-terrorism unit. A petty criminal, a young man with a fascination for gangsters, or someone with a history of violence may look like a routine policing problem until a seemingly minor assignment suddenly acquires strategic significance.
That creates a narrow window for intervention.
The appropriate response therefore cannot rest solely on conventional counterterrorism surveillance. Local policing, cyber intelligence, crime branches and specialised counter-terrorism agencies have to connect information that would otherwise remain in separate silos.
The lesson of SBN is precisely that the first indication of a terror plot may look like a minor crime.
That is why Indian agencies are urging greater scrutiny of known violent offenders and underworld elements, closer coordination between local police and specialised agencies, stronger cyber monitoring and security audits around sensitive installations and critical infrastructure.
The challenge is to identify meaningful indicators without turning a vast and noisy digital population into a pool of suspects.
A Low-Cost War
Bhatti’s network is emblematic of the changing nature of Pakistan’s confrontation with India. The traditional image of a proxy war involves a militant trained across the border, supplied with weapons and infiltrated into India. The newer model can be far more fragmented.
Instead of relying exclusively on trained ideological cadres, Bhatti’s network uses social media and encrypted platforms to identity people who appear susceptible to money, status, gangster culture or the promise of adventure.
The network does not necessarily require a large standing army of militants. It requires a steady supply of people willing to do small things for money. This is what makes the model potentially more resilient than a conventional cell structure.
The Indian state’s response will consequently have to extend beyond arresting handlers and recovering explosives. It will have to disrupt the economic and social machinery that allows criminal networks to convert vulnerability into violence: narcotics, illegal finance, weapons trafficking, online influence and the culture of gangster celebrity that gives such networks an aspirational sheen.
The case of Shahzad Bhatti points to a potentially consequential evolution in asymmetric warfare: the outsourcing of terrorism to the criminal margins of society, managed from abroad but executed by people recruited inside India.
But the crackdown this month also demonstrates the capacity of Indian intelligence and policing agencies to identify, map and disrupt it before a diffuse network of petty criminals and vulnerable youths can be turned into a larger instrument of violence.
The Dawood Connection
The underworld-terrorist nexus is not new to India. From the 1970s onwards, the underworld in Mumbai gained strength through smuggling of contraband, and in the 1980s, inter-gang rivalry spilled onto the streets of Mumbai. The situation only worsened in the next decade with the Dawood Ibrahim syndicate emerging strongest by decimating rival gangs and spreading its criminal tentacles across the globe. While Dawood flew out to Dubai at the end of the decade, he continued to maintain his stranglehold on various sectors of Mumbai’s economy, including the construction and film industries in particular and the business world in general.
In the 1990s, the syndicate forged links with Pakistan’s ISI and assisted in the training of Indian youths in PoK. Most infamously, the Dawood syndicate assisted in the ‘Shekhadi landings’—the illegal smuggling of nearly 3,000 kg of RDX supplied by ISI, weapons, and ammunition onto the Raigad coast of Maharashtra in early February 1993, which was used to execute the Mumbai serial blasts that year, which killed 257 people while injuring 1,400 more.
By this time, Dawood had shifted to Pakistan and it was his key associates Tiger Memon, Yakub Memon, Abu Salem and others who had carried out the ghastly blasts, which exposed the ISI-underworld nexus for the first time.
Cut to 2026. One of Dawood’s cronies – Munna Zhingada (real name: Syed Mudassar Hussain) has been identified along with several others as part of the SBN. Munna is a Mumbai-born gangster and former top hitman of the Dawood gang who operates from Karachi, Pakistan, as a key operative for the ISI.
He gained notoriety in 2000, almost 10 years after joining the gang, when he was sent to Bangkok as part of a hit squad to kill Chhota Rajan, Dawood’s former aide-turned-rival. Munna was arrested there and became the centre of a tug-of-war between India and Pakistan with both providing citizenship proofs. Pakistan claimed him to be one Mohd Saleem, a Pakistani national. This was accepted by the Thai courts in 2019 which handed Munna to Pakistan.
The SBN is even more sinister than it appears in its current form as Munna’s role is to act as a bridge between the ISI and criminal networks as well as the Indian underworld. As was revealed in investigations, Munna uses social media and encrypted apps to recruit vulnerable youths in Mumbai and other Indian cities for espionage and terror plots.
September 09, 2026, 12:10 IST
Read More







