JupiteX Get the app
Defence & Security7 Oct 2026 · about 7 min

Op Firewall: ‘Joshita from Mumbai’, ‘Anvi from Delhi’ and the Pakistani spy trap

The brief

The alleged espionage network was a coordinated system for approaching defence personnel and seeking sensitive naval information. Investigators said it combined fake social-media identities, WhatsApp communication, honeytrap attempts, monetary inducements, Indian SIM cards, OTPs, and cryptocurrency-linked payments. It matters because the operation allegedly targeted information about naval assets and facilities, not merely personal details. Operation Firewall-2026 began as a probe into suspected links between individuals in India and Pakistani intelligence operatives. The Andhra Pradesh Counter Intelligence Cell coordinated with police forces across 10 states and Union Territories. Two alleged female PIO identities, Joshita Pall and Anvi Mehta, were central to the investigation. They allegedly contacted naval personnel through false professional profiles and moved conversations to WhatsApp. Police identified 18 suspects, including 13 naval personnel. The investigation therefore examined both the direct approaches and the support network that allegedly enabled accounts, phone numbers, payments, and further targeting. The article describes allegations, not final court findings.

01

What is the alleged espionage network, and what was Operation Firewall-2026 investigating?

The alleged espionage network was a coordinated system for approaching defence personnel and seeking sensitive naval information. Investigators said it combined fake social-media identities, WhatsApp communication, honeytrap attempts, monetary inducements, Indian SIM cards, OTPs, and cryptocurrency-linked payments. It matters because the operation allegedly targeted information about naval assets and facilities, not merely personal details.

Operation Firewall-2026 began as a probe into suspected links between individuals in India and Pakistani intelligence operatives. The Andhra Pradesh Counter Intelligence Cell coordinated with police forces across 10 states and Union Territories. Two alleged female PIO identities, Joshita Pall and Anvi Mehta, were central to the investigation. They allegedly contacted naval personnel through false professional profiles and moved conversations to WhatsApp.

Police identified 18 suspects, including 13 naval personnel. The investigation therefore examined both the direct approaches and the support network that allegedly enabled accounts, phone numbers, payments, and further targeting. The article describes allegations, not final court findings.

02

How large was the alleged network, and how many of the 18 identified suspects were naval personnel?

The investigation identified 18 suspects in the alleged espionage case. Police said 13 of them were naval personnel. That figure shows that the case involved both alleged targets or participants within the naval system and a wider network supporting communications and payments. The article does not provide a complete breakdown of the remaining five suspects.

The alleged network extended across multiple states and Union Territories. Andhra Pradesh’s Counter Intelligence Cell coordinated with police forces in 10 states and Union Territories under Operation Firewall-2026. Investigators also examined people who allegedly supplied Indian mobile numbers, obtained SIM cards under Indian names, shared WhatsApp activation OTPs, or helped route cryptocurrency-linked payments.

The scale is therefore described in two ways: 18 identified suspects and a geographically broad investigation. However, the article does not state that all support-network members were included in the 18. These figures remain allegations reported during an ongoing investigation, rather than final judicial findings.

03

How did the alleged identities of Joshita Pall and Anvi Mehta try to build trust with naval personnel and obtain information?

The alleged identities tried to make their approaches appear personal and credible. Police said female PIO profiles contacted defence personnel through Facebook and Instagram, then built familiarity and trust. The conversations were reportedly moved to WhatsApp, where messages, voice calls, video calls, misleading promises, sexually explicit content, and monetary inducements were allegedly used.

Joshita Pall purportedly presented herself as a ship-building company employee in Mumbai. She allegedly asked about ship and submarine movements, numbers, photographs, and commanding officers. Anvi Mehta allegedly posed as a psychologist based in Delhi. She reportedly used voice and video calls, attempted to honeytrap naval personnel, and sought photographs of ships and sensitive establishments.

The alleged method relied on gradual escalation. A harmless-looking online introduction could become a private chat, then a request for information or a video demonstration. The article says these identities and communications formed part of the alleged modus operandi. It does not establish that every contacted person shared information.

04

What kinds of naval information and images were allegedly sought from the targets?

The alleged information requests covered operational details and visual material about naval assets. Police said targets were asked about the movement and number of ships and submarines. Requests also reportedly included photographs and videos of naval vessels, sensitive establishments, and commanding officers. Such information can reveal more than a single image when combined with timing, location, and personnel details.

The article gives a specific example involving Joshita Pall, who allegedly claimed to work for a ship-building company in Mumbai. She reportedly sought ship and submarine movements, numbers, photographs, and commanders’ details. Anvi Mehta allegedly sought photographs of naval ships and sensitive establishments. During video calls, she allegedly tried to persuade personnel to display restricted or sensitive areas.

Visakhapatnam featured prominently because it hosts the Eastern Naval Command, Naval Dockyard, Hindustan Shipyard Ltd, and Visakhapatnam Port. The article reports alleged requests and attempts, not proof that all requested material was obtained or disclosed.

05

How were Indian SIM cards and WhatsApp activation OTPs allegedly used to support the operation?

The alleged support mechanism used Indian phone infrastructure to make communications possible and potentially less conspicuous. Investigators said SIM cards were obtained in India under Indian names. Indian mobile numbers and WhatsApp activation OTPs were then allegedly used to support accounts connected with the operation. The OTP is the temporary code WhatsApp sends to verify a phone number.

According to the police material cited in the article, Indian personnel were allegedly offered monetary incentives through cryptocurrency or other intermediaries to share OTPs. Those codes were reportedly used to activate WhatsApp accounts in Pakistan. The accounts could then contact further targets, attempt honeytraps, and seek sensitive defence information.

This arrangement allegedly separated the people supplying phone access from those conducting the approaches. It also created a support layer beyond the fake identities seen by naval personnel. The article describes the use as an alleged mechanism uncovered by investigators; it does not establish how many accounts were activated or how much information was obtained.

06

What consequences could follow if sensitive information about ships, submarines, or naval facilities were exposed?

Sensitive information about ships, submarines, or naval facilities can create serious security risks. When movement details, photographs, videos, or commanders’ identities are combined, they may reveal patterns, locations, routines, capabilities, or vulnerable points. Information about restricted areas could also help an adversary understand how a facility is organised. These are general national-security consequences, not specific damage reported in the article.

For example, a ship photograph may seem harmless alone. Added movement timing, submarine numbers, or details of a command facility could make it more useful for surveillance or planning. Personal information about officers could also support further targeting, impersonation, or coercion. The alleged operation sought several kinds of information through chats and video calls, which could allow separate details to be assembled.

The article does not say that a particular attack, operational failure, or confirmed compromise resulted. It reports alleged attempts to collect information. The case shows why personnel must protect classified material, report suspicious approaches, and avoid showing restricted areas during calls.

07

Why can fake online identities, trusted messaging apps, and cryptocurrency payments make modern espionage difficult to detect and trace?

Modern espionage can be difficult to detect when ordinary online behaviour is used as cover. A fake profile can imitate a professional or personal identity and begin with harmless conversation. A trusted messaging app then moves the interaction into a private channel. Gradual requests may seem less suspicious than one direct demand. The article describes this progression from social-media contact to WhatsApp messages, calls, and video calls.

The alleged case illustrates the combination. Joshita purportedly posed as a ship-building employee, while Anvi allegedly posed as a psychologist. Payments were reportedly offered through cryptocurrency or intermediaries, and Indian phone numbers and OTPs allegedly supported accounts activated in Pakistan. Each layer could separate the target from the real organiser.

These methods do not make detection impossible. Account records, device information, payment trails, SIM registration, and communication patterns can help investigators connect activity. Still, fake identities, encrypted or private chats, intermediaries, and cross-border infrastructure can slow attribution. The article shows why digital awareness and rapid reporting matter in defence environments.

This brief was written by AI from the original reporting and checked by other models. Names, figures and quotes come from the source; read it for full context.

Read more in the JupiteX app

Pulse is free. New stories every 4 hours, each one broken into the questions that explain it.

Or read more news on the web