JupiteX Get the app
Defence & Security7 Oct 2026 · about 6 min

‘Op Dolphin’s Nose’ in 2019 and now ‘Op Firewall’: How India is busting Pakistani spy rings

The brief

Operation Firewall-2026 was the code name for coordinated counterintelligence raids conducted on October 1. Its purpose was to uncover a suspected Pakistani espionage network operating in India. Investigators focused on how targets were recruited and whether sensitive naval information had been transferred. The network allegedly used fake online identities, WhatsApp accounts and financial incentives. Two suspected Pakistani operatives, Joshita Pall and Anvi Mehta, reportedly approached Navy personnel through Facebook and Instagram. Their alleged requests involved ships, submarines, commanders and restricted naval sites. The investigation identified 18 suspects. Two people were arrested, while 13 Navy personnel were questioned without formal arrest as investigators sought stronger evidence. The case also examines Indian SIM cards, shared WhatsApp activation codes and money allegedly routed through cryptocurrency or intermediaries.

01

What was Operation Firewall, and what espionage network was it intended to uncover?

Operation Firewall-2026 was the code name for coordinated counterintelligence raids conducted on October 1. Its purpose was to uncover a suspected Pakistani espionage network operating in India. Investigators focused on how targets were recruited and whether sensitive naval information had been transferred.

The network allegedly used fake online identities, WhatsApp accounts and financial incentives. Two suspected Pakistani operatives, Joshita Pall and Anvi Mehta, reportedly approached Navy personnel through Facebook and Instagram. Their alleged requests involved ships, submarines, commanders and restricted naval sites.

The investigation identified 18 suspects. Two people were arrested, while 13 Navy personnel were questioned without formal arrest as investigators sought stronger evidence. The case also examines Indian SIM cards, shared WhatsApp activation codes and money allegedly routed through cryptocurrency or intermediaries.

02

How large was the suspected network, and how widely did the investigation spread across India?

The suspected network was broad, but the article distinguishes between people identified, arrested and questioned. Counterintelligence authorities identified 18 suspects in total. Two were arrested: Navy sailor Pradeep Mukherjee and Navy contractual driver Annam Sai Varaprasad. Thirteen Navy personnel were questioned but had not been formally arrested.

The investigation spread far beyond Visakhapatnam. About a dozen counterintelligence teams worked across Andhra Pradesh, Kerala, Maharashtra, Karnataka, Gujarat, Goa, Delhi, Tamil Nadu, Chhattisgarh and Bihar. They coordinated with state anti-terrorism squads, naval officials and local police.

This geographic reach suggests investigators were tracing a network rather than examining one isolated contact. Authorities were also studying social-media accounts, Indian SIM cards, WhatsApp activation codes and financial channels. The article does not establish that every identified suspect shared classified information.

03

How did the alleged Pakistani operatives use fake social-media identities, honey traps, money and WhatsApp to recruit targets?

The alleged Pakistani operatives used ordinary social platforms as an entry point. Joshita Pall reportedly posed as a ship-building company employee in Mumbai. Anvi Mehta allegedly claimed to be a Delhi-based psychologist. These identities helped them appear relevant or trustworthy to Navy personnel.

After making contact on Facebook or Instagram, they allegedly moved conversations to WhatsApp. Messages, voice calls, video calls, sexually explicit material and promises of money were used to pressure or entice targets. Pall reportedly sought naval details, while Mehta allegedly tried to expose sensitive areas during video calls. Some Indians were also allegedly paid for WhatsApp activation OTPs.

Those OTPs could activate accounts in Pakistan, allowing further contact with potential targets. Investigators are examining whether cryptocurrency traders or intermediaries moved money from Pakistan. The article describes allegations under investigation, not proven conduct by every person questioned.

04

What kinds of information about Visakhapatnam’s Eastern Naval Command were the suspects allegedly asked to provide?

The requested material could reveal how the Eastern Naval Command operates. According to the police statement, the alleged information included the number and movement of naval ships and submarines. Investigators also cited photographs and videos of naval assets and sensitive establishments.

The alleged requests went beyond equipment. Joshita Pall reportedly sought photographs and details of Commanding Officers, offering money in return. Anvi Mehta allegedly used voice and video calls to seek ship photographs and persuade personnel to display restricted or sensitive locations on camera.

Such information can help a foreign intelligence service build a picture of naval readiness, routines and leadership. The article does not say that all requested information was successfully delivered, or that every suspect provided it. Authorities were still questioning personnel and collecting evidence about what was actually shared.

05

What could happen to India’s naval security if information about ships, submarines, commanders and restricted facilities were shared with a foreign intelligence service?

Information about ships, submarines and commanders is valuable because it can reveal patterns, priorities and personnel. Even separate photographs or movement details may become more dangerous when combined. A foreign intelligence service could use them to map naval activity and identify important people or facilities.

For example, repeated reports about vessel movements might show schedules or operational routines. Images of restricted establishments could reveal layouts, access points or security practices. Commander details could support further impersonation, targeting or recruitment. These are potential risks; the article does not confirm that a successful operational compromise occurred.

India’s naval security therefore depends on stopping leaks early and checking what information has actually left protected systems or conversations. The current investigation is questioning 13 Navy personnel and reviewing digital and financial links. Its findings could show whether the alleged network caused a real breach or mainly attempted one.

06

How was the 2026 operation similar to and different from Operation Dolphin’s Nose, the espionage case exposed in 2019?

Operation Firewall resembles Operation Dolphin’s Nose because both cases involved alleged espionage around the Eastern Naval Command in Visakhapatnam. In both instances, Andhra Pradesh’s Counter Intelligence Cell investigated networks suspected of obtaining sensitive defence information. The repeated focus shows why the command remains a major counterintelligence concern.

The reported scale and details differ. In the 2026 case, authorities identified 18 suspects, arrested two people and questioned 13 Navy personnel. Investigators describe fake social-media identities, honey traps, OTP sharing and cryptocurrency-linked payments. In 2019, the CIC reportedly arrested 15 people, including seven Indian Navy sailors and a Mumbai-based hawala operator.

The supplied article ends while introducing the 2019 arrests, so it does not provide fuller details about that earlier network. It therefore supports a careful comparison, not a complete one. The clearest difference is that the 2026 investigation was spread across 10 states and Union Territories.

07

What is counterintelligence, and how does it protect military organizations from foreign agents using social media, financial networks and stolen phone credentials?

Counterintelligence means protecting a country’s security organizations from foreign intelligence activity. It involves finding spies, identifying recruitment methods, limiting information leaks and gathering evidence for action. In military settings, it also means teaching personnel to recognize manipulation and report unusual approaches.

In this case, investigators examined social-media accounts, fake identities and communications moved to WhatsApp. They also traced Indian SIM cards, shared activation OTPs and alleged payments through cryptocurrency or intermediaries. These steps connect the human, digital and financial parts of an espionage network. Police, naval officials and state agencies worked together.

Effective counterintelligence must continue after arrests. Authorities need to determine what information was accessed, whether credentials were reused and which contacts remain active. They must also strengthen account security, protect sensitive locations and reduce the success of honey traps. The article shows an ongoing investigation, not a final assessment of the network’s damage.

This brief was written by AI from the original reporting and checked by other models. Names, figures and quotes come from the source; read it for full context.

Read more in the JupiteX app

Pulse is free. New stories every 4 hours, each one broken into the questions that explain it.

Or read more news on the web