News · Defence & Security
How did a Pakistan-linked spy network target Navy’s Eastern Command, and how was it cracked? | Explained
Investigators say the Pakistan-linked network tried to collect field intelligence on the Indian Navy. Its alleged targets included ship and submarine movements, photographs and videos of naval assets, sensitive installations, and the identities and movements of commanding officers. Such information can expose how naval forces operate and where important assets are located. The Eastern Naval Command was especially attractive because it is based around Visakhapatnam, one of India’s largest naval hubs. The city is home to the Arihant-class nuclear ballistic missile submarines and the sensitive Ship Building Centre, where those submarines are constructed. Personnel were also allegedly asked to show restricted areas during video calls. The case highlights why routine-looking information can matter. Investigators allege that operatives used fake relationships, explicit content and payments to build trust and encourage disclosures. The investigation, named Operation Firewall-2026, identified 18 key suspects and led to two arrests so far.
Based on reporting by The Hindu
What was the Pakistan-linked espionage network accused of doing, and why was the Eastern Naval Command targeted?
Investigators say the Pakistan-linked network tried to collect field intelligence on the Indian Navy. Its alleged targets included ship and submarine movements, photographs and videos of naval assets, sensitive installations, and the identities and movements of commanding officers. Such information can expose how naval forces operate and where important assets are located.
The Eastern Naval Command was especially attractive because it is based around Visakhapatnam, one of India’s largest naval hubs. The city is home to the Arihant-class nuclear ballistic missile submarines and the sensitive Ship Building Centre, where those submarines are constructed. Personnel were also allegedly asked to show restricted areas during video calls.
The case highlights why routine-looking information can matter. Investigators allege that operatives used fake relationships, explicit content and payments to build trust and encourage disclosures. The investigation, named Operation Firewall-2026, identified 18 key suspects and led to two arrests so far.
How large was the alleged network, and how widely was it spread across India?
Operation Firewall-2026 uncovered an alleged espionage network with 18 key suspects. Thirteen were naval personnel. The group was not confined to one base or one region, showing the broad reach of the suspected recruitment effort.
The suspects were spread across Andhra Pradesh, Kerala, Maharashtra, Karnataka, Goa, Delhi, Gujarat, Tamil Nadu, Bihar and Chhattisgarh. The investigation involved the Andhra Pradesh Counter Intelligence Cell, Naval Intelligence and Anti-Terrorist Squads from these States. Their coordination was central to examining leads across different locations.
Only two arrests had been reported in the article. Pradeep Mukherjee, an ENC-posted sailor, was arrested on October 3 while training at INS Agrani in Coimbatore. Annam Sai Vara Prasad, a civilian contract driver for naval officers, was also arrested. The remaining suspects had been identified, but the article does not state that all were arrested or charged.
How did the operatives use fake online identities, honey-trapping, cryptocurrency and Indian SIM cards to obtain naval information?
The alleged operatives began with fabricated online identities. Profiles such as Joshita Pall and Anvi Mehta claimed professional backgrounds in shipbuilding and psychology. They reportedly contacted defence personnel on Facebook, then shifted conversations to WhatsApp after building familiarity and trust.
The honey-trap combined emotional pressure and inducements. Operatives allegedly promised relationships, shared sexually explicit material, and offered money, including cryptocurrency. They sought information about naval ships, submarines, installations and officers. They also allegedly tried to persuade targets to display sensitive areas during video calls. The article says it remains unclear whether explicit material was later used for blackmail.
Investigators also found an alleged SIM-card support network. Indian intermediaries reportedly registered SIM cards in local names and shared one-time passwords with foreign handlers. Those handlers allegedly used the OTPs to activate WhatsApp accounts from Pakistan, creating more channels for approaching Indian targets.
How did the Andhra Pradesh Counter Intelligence Cell, Naval Intelligence and State ATS teams uncover and disrupt the network?
The investigation was a multi-agency effort rather than a single-unit operation. Andhra Pradesh’s Counter Intelligence Cell worked with Naval Intelligence and Anti-Terrorist Squads in 10 States. Their cooperation helped connect suspicious contacts, personnel and support activities across widely separated locations.
The operation identified 18 key suspects, including 13 naval personnel. Investigators linked the alleged network to fake social-media profiles, WhatsApp communications, cryptocurrency incentives and Indian SIM cards activated using shared OTPs. These clues showed both the direct approach to targets and the support system behind it.
The disruption included at least two arrests. Pradeep Mukherjee, an ENC-posted sailor, was arrested on October 3 during training at INS Agrani in Coimbatore. Civilian contract driver Annam Sai Vara Prasad was also arrested. The article does not describe every investigative step, but it shows that intelligence coordination converted a cross-State inquiry into a wider crackdown.
What could happen if an adversary learned the movements, signatures or communication patterns of Indian ships and submarines?
The article stresses that knowing a ship or naval platform’s movements in advance can make it considerably easier for an adversary to track and understand military activity. Information about deployments, routes, timings and commanders can therefore have value even when it appears ordinary.
For example, repeated details about a submarine’s movements, a ship’s loading routine or an officer’s schedule could reveal patterns. Photographs and videos might expose equipment, base layouts or restricted areas. Communication habits can also help an adversary connect people, places and operations. The article specifically says investigators sought such field-level information.
The danger is cumulative. One small disclosure may seem harmless, but several details can build a clearer picture of naval capabilities and routines. That is why the alleged network targeted personnel and contractors, not only senior officials. The investigation shows that protecting operational information requires attention to casual conversations, online contacts and seemingly minor requests.
How was this operation similar to the 2019 Operation Dolphin’s Nose, and what did that earlier case reveal about Pakistan-linked spying?
The two operations showed striking similarities. Both targeted the Eastern Naval Command and allegedly sought information on ship and submarine movements, dockyard layouts and base logistics. Both also used digital honey-traps and local intermediaries to reach naval personnel.
Operation Dolphin’s Nose was exposed in December 2019. Investigators found a Pakistan Intelligence Operative network that allegedly used fake online relationships, hawala funding channels and local conduits to recruit junior naval personnel. Around 15 people, including seven naval personnel, were arrested. The case established links to Pakistan’s Inter-Services Intelligence, or ISI.
The earlier case was first cracked by the Andhra Pradesh Counter Intelligence Cell and later handed to the National Investigation Agency. The NIA subsequently secured convictions against several accused people. The recurring methods suggest that field intelligence remains a continuing security concern, although the article does not establish that every person or channel in the newer case is connected to the 2019 network.
What is field intelligence, and why can seemingly minor details—such as supplies, routines or movements—reveal the location and capabilities of military forces?
Field intelligence means information gathered from real-world activity rather than only from formal documents or technical systems. In this case, it includes ship and submarine movements, officer locations, base routines, photographs, videos and logistics. A former intelligence officer described it as an old and reliable method of intelligence gathering.
A detail such as the quantity of rations loaded onto a vessel may appear harmless. Combined with timing, personnel movements or port activity, it could indicate a vessel’s likely deployment or duration at sea. Similar clues from photos, conversations and video calls may reveal layouts, equipment or access points. The article says the suspected network sought precisely these kinds of details.
The importance lies in combination. Individual facts can form a useful pattern when collected over time. That is why operatives allegedly approached both naval personnel and a civilian contract driver. The case shows that security depends not only on protecting classified files, but also on controlling routine information shared online or in conversation.
Key Facts:
📌 The network allegedly targeted naval movements, assets, installations and commanders.
📌 Visakhapatnam hosts Arihant-class submarines and the Ship Building Centre.
📌 Operation Firewall-2026 identified 18 key suspects and produced two arrests.
📌 Investigators identified 18 key suspects.
📌 Thirteen suspects were naval personnel.
📌 The alleged network spanned 10 States across India.
📌 Fake profiles moved conversations from Facebook to WhatsApp.