scorecardresearch
Add as a preferred source on Google
Wednesday, October 7, 2026

Support our Journalism

Depth, context and analysis

Subscribe
HomeDefenceTwist in Vizag spy racket case: Pakistani women operatives, social media avatars,...

Twist in Vizag spy racket case: Pakistani women operatives, social media avatars, honey-trapped navymen

Busting espionage ring targeting Eastern Naval Command leads investigators into honeytrap web across social media platforms; Navy personnel snared by Pakistani woman operatives.

Follow Us :
Text Size:

Hyderabad: The only artificial part of it was the human role-playing. Busting an espionage ring targeting Eastern Naval Command at Visakhapatnam has led investigators further into a deadly, carefully constructed honeytrap operation that targeted Indian Navy personnel through social media.

Operation Fire Wall 2026, the coordinated operation of an Andhra Pradesh Counter-Intelligence (CI) unit, Navy Intelligence, and Anti-Terrorism Squad (ATS) that said on Tuesday it had busted an espionage ring targeting the Eastern Naval Command, has revealed a large network of Pakistani Intelligence Operatives (PIOs) who compromised and turned 13 Navy personnel and five others.

In a document available with ThePrint, the alarming breach details how the CI team, aided by other Indian intelligence and law enforcement agencies, unmasked a ring of female Pakistani Intelligence Operatives (PIOs) who weaponised deep-cover digital identities to systematically honeytrap and compromise Indian naval personnel, including officers.

Operating under aliases like ‘Joshita Pall’ and ‘Anvi Mehta’, two of the PIOs posed as a Mumbai-based employee of a shipbuilding firm and a Delhi-based psychologist, respectively. To the initially unsuspecting Navy personnel scrolling through their social media feeds, Pall and Mehta posed as ordinary professional women, the official document released by the Andhra Counter-Intelligence team reveals. For months, the two women, aided by other PIOs, befriended several officers with social media avatars designed to captivate.

Behind the digital contact, a meticulously coordinated espionage dragnet played out, the report explains. The objective of the operation, it details, was to target defence personnel and collect high-value intelligence on India’s maritime assets with a seemingly deceptive digital footprint.

The big switch

‘Joshita Pall’ and ‘Anvi Mehta’ initiated contact with Navy personnel through mainstream social media platforms such as Facebook and Instagram. “Once a baseline of trust and psychological rapport was established, the handlers seamlessly shifted their targets over to WhatsApp,” the document explains.

It was on WhatsApp that the casual text conversations morphed into voice and video calls designed to completely compromise the targeted personnel, the details obtained say.

‘Joshita Pall’, who posed as a shipbuilding executive, is understood to have actively solicited classified details regarding the exact volume and deployment schedules of Indian Navy ships and submarines. Worse still, the compromised personnel are known to have shared personal profiles and photographs of their commanding officers.

‘Anvi Mehta’, on the other hand, played at a different level, leveraging a sympathetic psychologist image to manipulate sailors, inducing them to turn their cameras around and stream live footage of restricted naval establishments, hulls, and sensitive interior installations.


Also Read: Partners in crime—how a Delhi couple ‘tracked armymen facing court martial and spied for ISI’


Encrypted spaces

Once the visual and data leaks were obtained, the investigators uncovered a more insidious layer to the espionage network: the weaponisation of identity through technical compromise, the note explains.

Once the PIOs established compliance, they led the Indian personnel into sharing their personal WhatsApp OTPs (One-Time Passwords) by promising lucrative monetary kickbacks. The stolen OTPs were immediately routed back to handlers in Pakistan, who used them to “activate and hijack” Indian WhatsApp accounts natively.

Once compromised, the PIOs in Pakistan used Indian numbers to weaponise other unsuspecting officers in a deadly replication of their first infiltration.

‘Operation Firewall 2026’ goes on to disclose the financial infrastructure underpinning the decentralised payment apparatus designed to evade the Enforcement Directorate’s net that tracks money-laundering. Simply put, once a target provided actionable intelligence or an OTP to an account, money was dispersed through complex cryptocurrency networks. Shadow third-party intermediaries operated these money trails directly from Pakistan, the note says.

This digital paper trail has now provided investigators with an unassailable financial link directly connecting the PIO network to the compromised Indian defence personnel, who now face severe legal consequences under applicable national security and anti-espionage laws.

As ThePrint reported on Tuesday, 18 people, including 13 personnel from 10 Indian states, have been arrested. Charges were framed under the Bharatiya Nyaya Sanhita, the Official Secrets Act, and the Unlawful Activities Prevention Act.

The CI unit initially suspected the involvement of just two persons- Visakhapatnam-based Navy officer Pradeep Mukherjee and a civilian driver, A. Sai Varaprasad, contracted by the Navy – but their investigation has revealed a larger module of 18 people compromised by PIOs. Mukherjee and Prasad have been remanded to judicial custody till 14 October, and are presently at the District Jail, Vijayawada.

Even though the first set of arrests was made on 2 and 4 October in Coimbatore and Vizag, the investigation concerning suspected transmission of information relating to defence establishments in Visakhapatnam and other parts of the country through encrypted communication channels was confirmed internally only in September.

Acting on credible information, the Counter Intelligence Cell in Andhra Pradesh registered Crime No. 01/2026 at the Counter Intelligence Police Station, Vijayawada, on 2 September.

At the time of publishing this story, the alleged conspiracy continues to be investigated.

“The investigation is sensitive and ongoing. Further details will be disclosed at an appropriate stage, keeping in view the requirements of the investigation and national security,” an official statement issued by the Andhra Pradesh Police on Tuesday said.

(Edited by Nardeep Singh Dahiya)


Also Read: Op Sindoor & the ‘spy’ next door: The fate of 9 espionage cases, 1 year on


 

Subscribe to our channels on YouTube, Telegram & WhatsApp

Nine Years, Made Possible by Readers

In 2017, Shekhar Gupta started ThePrint with a simple belief: Indian readers want journalism that asks why and what next, not just what. And that enough of them would be willing to pay for good journalism.

Nine years on, that belief has held.

And, in these nine years, we’ve stayed true to our mission. We’ve been asking the follow-up questions, going beyond the headlines and explaining what’s actually happening. We’ve travelled across the country to bring you in-depth, visually-compelling stories from the ground.

It’s been nine years of readers choosing to make this possible. If you’d like to be one of them:

Support ThePrint

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Most Popular