The story so far:
A team of officers and personnel from Andhra Pradesh’s Counter Intelligence Cell (CIC), working with Naval Intelligence and Anti-Terrorist Squads (ATS) across 10 States, has busted a major Pakistan-sponsored espionage network allegedly focused on gathering field intelligence on the Indian Navy, with the Eastern Naval Command (ENC) as a particular target. The investigation and subsequent crackdown were carried out under the code name Operation Firewall-2026.
The operation led to the identification of 18 key suspects, including 13 naval personnel spread across 10 States — Andhra Pradesh, Kerala, Maharashtra, Karnataka, Goa, Delhi, Gujarat, Tamil Nadu, Bihar and Chhattisgarh.

Two people have so far been arrested: Pradeep Mukherjee, an ENC-posted sailor who was arrested on October 3 while undergoing training at INS Agrani in Coimbatore, and Annam Sai Vara Prasad, a civilian contract driver engaged for naval officers at the Visakhapatnam naval base.
What is this espionage racket?
As in several cross-border espionage operations, Pakistan Intelligence Operatives (PIOs) allegedly created fake profiles of women on social media to honey-trap servicemen and defence contractors.
Trained women operatives using pseudonyms — including “Joshita Pall,” who claimed to work for a shipbuilding firm in Mumbai, and “Anvi Mehta,” who purported to be a Delhi-based psychologist — allegedly made initial contact through Facebook before moving the conversations to WhatsApp.
According to investigators, the operatives approached defence personnel through fake social media profiles and, after establishing familiarity and trust, gradually shifted to text messages, voice calls and video calls.

The strategy involved fabricated professional identities, promises of relationships or other inducements, sexually explicit content and monetary incentives, including payments through cryptocurrency. The ultimate objective, investigators allege, was to persuade personnel to share sensitive defence information.
The information sought reportedly included the movement and numbers of naval ships and submarines, photographs and videos of naval assets and sensitive installations, and the identities and movements of commanding officers. Operatives also allegedly tried to persuade personnel to show sensitive areas of naval bases, ships and submarines during video calls.
It remains unclear whether sexually explicit material was subsequently used for blackmail or coercion to obtain sensitive information.
Investigators also uncovered a support network that allegedly used Indian SIM cards registered in local names and shared one-time passwords (OTPs) with foreign handlers. Indian intermediaries were reportedly offered monetary incentives, either through cryptocurrency or local contacts, to provide OTPs needed to activate WhatsApp accounts. These accounts were then allegedly operated from Pakistan to approach additional targets.
What was Operation Dolphin’s Nose?
This is not the first espionage case of its kind to target the Eastern Naval Command.
In December 2019, Operation Dolphin’s Nose exposed a major cross-border spying network targeting the ENC. The case revealed a PIO network that allegedly used digital honey-traps, hawala funding channels and local conduits to recruit junior naval personnel.
The case was first cracked and investigated by the AP CIC before being handed over to the National Investigation Agency (NIA). Around 15 people, including seven naval personnel, were arrested, establishing links to Pakistan’s Inter-Services Intelligence (ISI). The NIA has since secured convictions against several of the accused.
The modus operandi and the intelligence sought were strikingly similar: information on ship and submarine movements, dockyard layouts and base logistics.
The accused were booked under stringent provisions, including the Unlawful Activities (Prevention) Act (UAPA), Section 3 of the Official Secrets Act (OSA) and Section 120B of the Indian Penal Code (IPC), relating to criminal conspiracy.
Why focus on Visakhapatnam, and how do intelligence inputs matter?
Visakhapatnam is home to one of India’s largest naval bases and serves as the home port for the Arihant-class nuclear ballistic missile submarines (SSBNs), which come under the Strategic Forces Command (SFC). The sensitive Ship Building Centre (SBC), where these submarines are constructed, is also located here.
For PIOs, the objective is to obtain field-level intelligence — from ship and submarine deployments and the movements of officers to seemingly routine details such as the quantity of rations loaded onto a vessel.

“Apart from other forms of intelligence gathering, field-level intelligence remains one of the oldest and most reliable methods, and honey-trapping is the oldest trick in the book. It happened earlier, and it will continue to happen,” said a former intelligence officer.
Knowing the movements of a ship or naval platform in advance can make it considerably easier for an adversary to position intelligence-gathering assets. Such platforms can collect critical information, including radar and acoustic signatures and transmission patterns, helping an adversary track and identify naval assets.
“PIOs engage targets in lengthy conversations — sometimes mundane, sometimes sexually explicit — to fish out relevant details and piece together the larger picture,” he said.

History has repeatedly demonstrated the value of field intelligence.
During the 1971 war with Pakistan, an intercepted signal seeking a specialised grade of submarine lubricant in Chittagong provided a crucial field-intelligence indicator that helped confirm the presence of PNS Ghazi in the Bay of Bengal.
Similarly, Pakistan’s procurement of large quantities of specialised extreme-cold-weather gear and snow boots from European markets was a classic field-intelligence indicator. It became a major intelligence success before the 1984 Siachen operation, and the same kind of indicator was missed before the 1999 Kargil War.

“Hence, field-level intelligence matters immensely to any nation,” the officer said.
How did the agencies crack the case?
The AP CIC, central intelligence agencies and Naval Intelligence had been tracking digital footprints and network activity for some time. Anomalous activity — including domestic OTP-generation requests associated with foreign digital signatures and suspicious social-media interactions involving defence personnel — raised red flags.
The suspects were subsequently placed under covert physical and digital surveillance before the security agencies moved in.
The CIC deployed 12 specialised counter-intelligence teams across 10 States. Working alongside local ATS units and naval officials, the teams carried out coordinated raids at multiple locations.
Digital forensic audits were then conducted on mobile phones, hard drives and other communication devices seized from naval bases and residential premises. Investigators undertook detailed forensic recovery of deleted chats, transmitted files and other digital traces.
What are the rules for armed forces personnel on social media?
The Indian Armed Forces, including the Navy, maintain strict cybersecurity protocols and specific rules governing the use of smartphones and social media.
The Indian Navy has imposed restrictions, including a blanket ban on several social media platforms and messaging applications.

There are also strict rules governing the carrying and use of smartphones in sensitive operational areas. Official information, operational schedules, patrol details and military documentation are not to be discussed or transmitted through commercial instant-messaging platforms.
(Inputs from Rajulapudi Srinivas)
Published – October 07, 2026 11:40 am IST


