Representative image NEW DELHI: Investigations into the blast near Delhi’s Red Fort on November 10 last year have revealed how a “white-collar” terror module relied on a sophisticated network of “ghost” SIM cards and encrypted messaging apps to stay in touch with Pakistani handlers.The accused, many of them highly educated doctors, used illegally obtained or fraudulently issued SIM cards and multiple mobile devices to evade surveillance. The findings of this probe subsequently became the basis for a sweeping directive issued by the Department of Telecommunications (DoT) on November 28, mandating that app-based communication services such as WhatsApp, Telegram and Signal must remain continuously linked to an active physical SIM card installed in the device.A “ghost” SIM card is a mobile connection that is illegally issued or fraudulently activated without being linked to the actual user, security officials said. Such SIMs are typically obtained using forged or misused identity documents, including Aadhaar details of unsuspecting civilians, or through bulk activations that bypass verification norms. Investigators say these numbers allow criminals and terror operatives to communicate and use encrypted messaging applications while remaining largely untraceable, posing a significant challenge to telecom surveillance and law enforcement agencies.The ‘dual-phone’ playbookOfficials said the probe uncovered a tactical “dual-phone” protocol followed by the module. Each accused carried two to three mobile phones. One “clean” handset, registered in their own name, was used for routine personal and professional communication to avoid suspicion. The second, described as a “terror phone”, was used exclusively for encrypted communication with handlers in Pakistan through WhatsApp and Telegram, officials said.The SIM cards used in these secondary devices were issued in the names of unsuspecting civilians whose Aadhaar details had been misused, the officials told news agency PTI. In a parallel development, Jammu and Kashmir Police also uncovered a separate racket in which SIM cards were issued using fake Aadhaar cards.Among those arrested were Muzammil Ganaie and Adeel Rather, while Dr Umar-un-Nabi, another key accused, was killed while driving an explosives-laden vehicle near the Red Fort, officials said. The Pakistani handlers were identified by the codenames ‘Ukasa’, ‘Faizan’ and ‘Hashmi’.A disturbing trendInvestigators said security agencies noted a disturbing trend in which these compromised SIMs remained active on messaging platforms even when the devices were being operated from Pakistan-occupied Jammu & Kashmir (PoJK) or Pakistan. By exploiting app features that allow continued access without a physical SIM inside the device, handlers were able to remotely guide the module.Officials said the operatives were directed to learn improvised explosive device (IED) assembly through online videos and plan “hinterland” attacks, even though some of the recruits initially wanted to join conflict zones in Syria or Afghanistan.How does the government plan to tackle this?To plug these vulnerabilities, the Centre invoked the Telecommunications Act, 2023, along with the Telecom Cyber Security Rules, to “safeguard the integrity of the telecom ecosystem”. Under the new framework, all Telecommunication Identifier User Entities (TIUEs) have been given 90 days to ensure their applications function only when an active SIM card is present in the device.The order also directs telecom operators to automatically log users out of platforms such as WhatsApp, Telegram and Signal if no active SIM is detected. Messaging and social media platforms, including Snapchat, Sharechat and Jiochat, have been asked to submit compliance reports to the DoT.“This feature of using apps without a SIM is posing a challenge to telecom cyber security as it is being misused from outside the country to commit cyber frauds and terror activities,” the DoT had said while explaining the rationale behind the move.The directive is being fast-tracked in the Jammu and Kashmir telecom circle. While officials acknowledge that deactivating all expired or fraudulent SIMs will take time, the move is being viewed as a significant blow to the digital infrastructure used by terror networks to radicalise and manage “white-collar” operatives.Failure to comply with the new norms will attract stringent action under the Telecom Cyber Security Rules and other applicable laws, officials said.The white-collar terror moduleThe “white-collar” terror module began to unravel on the intervening night of October 18-19, 2025, when posters of the banned Jaish-e-Mohammad (JeM) appeared on walls outside Srinagar city, warning of attacks on police and security forces in the Valley.Treating the development as a serious threat, Senior Superintendent of Police, Srinagar, GV Sundeep Chakravarthy constituted multiple teams to carry out an in-depth investigation. Based on the statements of the arrested accused, the probe led police to Al Falah University in Haryana’s Faridabad, where two doctors, Ganaie, a resident of Koil in south Kashmir’s Pulwama, and Shaheen Sayeed from Lucknow, were arrested.A large cache of arms and ammunition, including 2,900 kg of ammonium nitrate, potassium nitrate and sulphur, was seized during the operation, officials said.The car explosion near the Red Fort, which claimed 15 lives, is being investigated by the National Investigation Agency (NIA).About the AuthorTOI News DeskThe TOI News Desk comprises a dedicated and tireless team of journalists who operate around the clock to deliver the most current and comprehensive news and updates to the readers of The Times of India worldwide. With an unwavering commitment to excellence in journalism, our team is at the forefront of gathering, verifying, and presenting breaking news, in-depth analysis, and insightful reports on a wide range of topics. The TOI News Desk is your trusted source for staying informed and connected to the ever-evolving global landscape, ensuring that our readers are equipped with the latest developments that matter most.”Read MoreEnd of ArticleFollow Us On Social MediaVideosIndian Army Raises Bhairav Special Force With Over One Lakh Drone Operatives For Modern WarfareCM Revanth Reddy’s Remarks In Telangana Assembly Sparks Row, BRS Slams ‘Filthy Language’‘If Trump Can Capture Maduro, Why Can’t Modi Bring Back 26/11 Mastermind From Pakistan’: Owaisi‘Avoid All Non-Essential Travel To Venezuela’: India Issues Advisory For Citizens After US Strikes”No Control Over Minority Violence In Bangladesh…”: Former Indian Envoy Slams Yunus Govt“Infamous For His Tour With Anti-National Propaganda”: BJP Rips Rahul Gandhi Over Vietnam VisitInqilab Moncho To March Nationwide Seeking Justice For Sharif Osman Hadi14 Naxals Neutralized In Sukma And Bijapur As Security Forces Launch Anti-Maoist OperationHimachal College Horror: Student Dies After Alleging Sexual Harassment, RaggingIndia Reveals First Vande Bharat Sleeper Offering Faster Overnight Travel On Kolkata-Guwahati Line123Photostories6 places where the world’s deadliest snakes are found7 fascinating creatures with blue-coloured bloodJay Bhanushali and Mahhi Vij: Tracing the former couple’s journey from love to amicable separationVaishno Devi Yatra 2025–26: RFID card rules, smart lockers, helpline numbers and helicopter fare revisionRelief for Pune commuters: Double-decker flyover at SPPU Chowk nears completion; Metro Line-3 trial beginsThe right daily walking distance to improve fitness, according to researchMorning or evening, when is the right time to consume magnesium supplementBeautiful and unique baby girl names that are perfect for your firstbornNine Planets and What To Donate To Appease The Planets5 signs that over-exposure to social media is causing attention problems in teens123Hot PicksUS strikes VenezuelaVande Bharat Sleeper TrainPublic holidays January 2026Gold rate todayDelcy RodríguezVivek RamaswamyBank Holidays JanuaryTop TrendingSan Francisco 49ersBrittany MahomesNoah Lyles and Junelle Bromfield Net WorthWayne Gretzky Daughter Net WorthSidney Crosby LifestyleLeBron James vs Stephen Curry Net WorthTom BradyLeBron James WifeCam ThomasCharlie Kirk

Representative image NEW DELHI: Investigations into the blast near Delhi’s Red Fort on November 10 last year have revealed how a “white-collar” terror module relied on a sophisticated network of “ghost” SIM cards and encrypted messaging apps to stay in touch with Pakistani handlers.The accused, many of them highly educated doctors, used illegally obtained or fraudulently issued SIM cards and multiple mobile devices to evade surveillance. The findings of this probe subsequently became the basis for a sweeping directive issued by the Department of Telecommunications (DoT) on November 28, mandating that app-based communication services such as WhatsApp, Telegram and Signal must remain continuously linked to an active physical SIM card installed in the device.A “ghost” SIM card is a mobile connection that is illegally issued or fraudulently activated without being linked to the actual user, security officials said. Such SIMs are typically obtained using forged or misused identity documents, including Aadhaar details of unsuspecting civilians, or through bulk activations that bypass verification norms. Investigators say these numbers allow criminals and terror operatives to communicate and use encrypted messaging applications while remaining largely untraceable, posing a significant challenge to telecom surveillance and law enforcement agencies.The ‘dual-phone’ playbookOfficials said the probe uncovered a tactical “dual-phone” protocol followed by the module. Each accused carried two to three mobile phones. One “clean” handset, registered in their own name, was used for routine personal and professional communication to avoid suspicion. The second, described as a “terror phone”, was used exclusively for encrypted communication with handlers in Pakistan through WhatsApp and Telegram, officials said.The SIM cards used in these secondary devices were issued in the names of unsuspecting civilians whose Aadhaar details had been misused, the officials told news agency PTI. In a parallel development, Jammu and Kashmir Police also uncovered a separate racket in which SIM cards were issued using fake Aadhaar cards.Among those arrested were Muzammil Ganaie and Adeel Rather, while Dr Umar-un-Nabi, another key accused, was killed while driving an explosives-laden vehicle near the Red Fort, officials said. The Pakistani handlers were identified by the codenames ‘Ukasa’, ‘Faizan’ and ‘Hashmi’.A disturbing trendInvestigators said security agencies noted a disturbing trend in which these compromised SIMs remained active on messaging platforms even when the devices were being operated from Pakistan-occupied Jammu & Kashmir (PoJK) or Pakistan. By exploiting app features that allow continued access without a physical SIM inside the device, handlers were able to remotely guide the module.Officials said the operatives were directed to learn improvised explosive device (IED) assembly through online videos and plan “hinterland” attacks, even though some of the recruits initially wanted to join conflict zones in Syria or Afghanistan.How does the government plan to tackle this?To plug these vulnerabilities, the Centre invoked the Telecommunications Act, 2023, along with the Telecom Cyber Security Rules, to “safeguard the integrity of the telecom ecosystem”. Under the new framework, all Telecommunication Identifier User Entities (TIUEs) have been given 90 days to ensure their applications function only when an active SIM card is present in the device.The order also directs telecom operators to automatically log users out of platforms such as WhatsApp, Telegram and Signal if no active SIM is detected. Messaging and social media platforms, including Snapchat, Sharechat and Jiochat, have been asked to submit compliance reports to the DoT.“This feature of using apps without a SIM is posing a challenge to telecom cyber security as it is being misused from outside the country to commit cyber frauds and terror activities,” the DoT had said while explaining the rationale behind the move.The directive is being fast-tracked in the Jammu and Kashmir telecom circle. While officials acknowledge that deactivating all expired or fraudulent SIMs will take time, the move is being viewed as a significant blow to the digital infrastructure used by terror networks to radicalise and manage “white-collar” operatives.Failure to comply with the new norms will attract stringent action under the Telecom Cyber Security Rules and other applicable laws, officials said.The white-collar terror moduleThe “white-collar” terror module began to unravel on the intervening night of October 18-19, 2025, when posters of the banned Jaish-e-Mohammad (JeM) appeared on walls outside Srinagar city, warning of attacks on police and security forces in the Valley.Treating the development as a serious threat, Senior Superintendent of Police, Srinagar, GV Sundeep Chakravarthy constituted multiple teams to carry out an in-depth investigation. Based on the statements of the arrested accused, the probe led police to Al Falah University in Haryana’s Faridabad, where two doctors, Ganaie, a resident of Koil in south Kashmir’s Pulwama, and Shaheen Sayeed from Lucknow, were arrested.A large cache of arms and ammunition, including 2,900 kg of ammonium nitrate, potassium nitrate and sulphur, was seized during the operation, officials said.The car explosion near the Red Fort, which claimed 15 lives, is being investigated by the National Investigation Agency (NIA).About the AuthorTOI News DeskThe TOI News Desk comprises a dedicated and tireless team of journalists who operate around the clock to deliver the most current and comprehensive news and updates to the readers of The Times of India worldwide. With an unwavering commitment to excellence in journalism, our team is at the forefront of gathering, verifying, and presenting breaking news, in-depth analysis, and insightful reports on a wide range of topics. The TOI News Desk is your trusted source for staying informed and connected to the ever-evolving global landscape, ensuring that our readers are equipped with the latest developments that matter most.”Read MoreEnd of ArticleFollow Us On Social MediaVideosIndian Army Raises Bhairav Special Force With Over One Lakh Drone Operatives For Modern WarfareCM Revanth Reddy’s Remarks In Telangana Assembly Sparks Row, BRS Slams ‘Filthy Language’‘If Trump Can Capture Maduro, Why Can’t Modi Bring Back 26/11 Mastermind From Pakistan’: Owaisi‘Avoid All Non-Essential Travel To Venezuela’: India Issues Advisory For Citizens After US Strikes”No Control Over Minority Violence In Bangladesh…”: Former Indian Envoy Slams Yunus Govt“Infamous For His Tour With Anti-National Propaganda”: BJP Rips Rahul Gandhi Over Vietnam VisitInqilab Moncho To March Nationwide Seeking Justice For Sharif Osman Hadi14 Naxals Neutralized In Sukma And Bijapur As Security Forces Launch Anti-Maoist OperationHimachal College Horror: Student Dies After Alleging Sexual Harassment, RaggingIndia Reveals First Vande Bharat Sleeper Offering Faster Overnight Travel On Kolkata-Guwahati Line123Photostories6 places where the world’s deadliest snakes are found7 fascinating creatures with blue-coloured bloodJay Bhanushali and Mahhi Vij: Tracing the former couple’s journey from love to amicable separationVaishno Devi Yatra 2025–26: RFID card rules, smart lockers, helpline numbers and helicopter fare revisionRelief for Pune commuters: Double-decker flyover at SPPU Chowk nears completion; Metro Line-3 trial beginsThe right daily walking distance to improve fitness, according to researchMorning or evening, when is the right time to consume magnesium supplementBeautiful and unique baby girl names that are perfect for your firstbornNine Planets and What To Donate To Appease The Planets5 signs that over-exposure to social media is causing attention problems in teens123Hot PicksUS strikes VenezuelaVande Bharat Sleeper TrainPublic holidays January 2026Gold rate todayDelcy RodríguezVivek RamaswamyBank Holidays JanuaryTop TrendingSan Francisco 49ersBrittany MahomesNoah Lyles and Junelle Bromfield Net WorthWayne Gretzky Daughter Net WorthSidney Crosby LifestyleLeBron James vs Stephen Curry Net WorthTom BradyLeBron James WifeCam ThomasCharlie Kirk


Red Fort blast: Probe unveils how terrorists spoke to Pakistani handlers - What's a 'ghost' SIM card?

NEW DELHI: Investigations into the blast near Delhi’s Red Fort on November 10 last year have revealed how a “white-collar” terror module relied on a sophisticated network of “ghost” SIM cards and encrypted messaging apps to stay in touch with Pakistani handlers.The accused, many of them highly educated doctors, used illegally obtained or fraudulently issued SIM cards and multiple mobile devices to evade surveillance. The findings of this probe subsequently became the basis for a sweeping directive issued by the Department of Telecommunications (DoT) on November 28, mandating that app-based communication services such as WhatsApp, Telegram and Signal must remain continuously linked to an active physical SIM card installed in the device.A “ghost” SIM card is a mobile connection that is illegally issued or fraudulently activated without being linked to the actual user, security officials said. Such SIMs are typically obtained using forged or misused identity documents, including Aadhaar details of unsuspecting civilians, or through bulk activations that bypass verification norms. Investigators say these numbers allow criminals and terror operatives to communicate and use encrypted messaging applications while remaining largely untraceable, posing a significant challenge to telecom surveillance and law enforcement agencies.The ‘dual-phone’ playbookOfficials said the probe uncovered a tactical “dual-phone” protocol followed by the module. Each accused carried two to three mobile phones. One “clean” handset, registered in their own name, was used for routine personal and professional communication to avoid suspicion. The second, described as a “terror phone”, was used exclusively for encrypted communication with handlers in Pakistan through WhatsApp and Telegram, officials said.The SIM cards used in these secondary devices were issued in the names of unsuspecting civilians whose Aadhaar details had been misused, the officials told news agency PTI. In a parallel development, Jammu and Kashmir Police also uncovered a separate racket in which SIM cards were issued using fake Aadhaar cards.Among those arrested were Muzammil Ganaie and Adeel Rather, while Dr Umar-un-Nabi, another key accused, was killed while driving an explosives-laden vehicle near the Red Fort, officials said. The Pakistani handlers were identified by the codenames ‘Ukasa’, ‘Faizan’ and ‘Hashmi’.A disturbing trendInvestigators said security agencies noted a disturbing trend in which these compromised SIMs remained active on messaging platforms even when the devices were being operated from Pakistan-occupied Jammu & Kashmir (PoJK) or Pakistan. By exploiting app features that allow continued access without a physical SIM inside the device, handlers were able to remotely guide the module.Officials said the operatives were directed to learn improvised explosive device (IED) assembly through online videos and plan “hinterland” attacks, even though some of the recruits initially wanted to join conflict zones in Syria or Afghanistan.How does the government plan to tackle this?To plug these vulnerabilities, the Centre invoked the Telecommunications Act, 2023, along with the Telecom Cyber Security Rules, to “safeguard the integrity of the telecom ecosystem”. Under the new framework, all Telecommunication Identifier User Entities (TIUEs) have been given 90 days to ensure their applications function only when an active SIM card is present in the device.The order also directs telecom operators to automatically log users out of platforms such as WhatsApp, Telegram and Signal if no active SIM is detected. Messaging and social media platforms, including Snapchat, Sharechat and Jiochat, have been asked to submit compliance reports to the DoT.“This feature of using apps without a SIM is posing a challenge to telecom cyber security as it is being misused from outside the country to commit cyber frauds and terror activities,” the DoT had said while explaining the rationale behind the move.The directive is being fast-tracked in the Jammu and Kashmir telecom circle. While officials acknowledge that deactivating all expired or fraudulent SIMs will take time, the move is being viewed as a significant blow to the digital infrastructure used by terror networks to radicalise and manage “white-collar” operatives.Failure to comply with the new norms will attract stringent action under the Telecom Cyber Security Rules and other applicable laws, officials said.The white-collar terror moduleThe “white-collar” terror module began to unravel on the intervening night of October 18-19, 2025, when posters of the banned Jaish-e-Mohammad (JeM) appeared on walls outside Srinagar city, warning of attacks on police and security forces in the Valley.Treating the development as a serious threat, Senior Superintendent of Police, Srinagar, GV Sundeep Chakravarthy constituted multiple teams to carry out an in-depth investigation. Based on the statements of the arrested accused, the probe led police to Al Falah University in Haryana’s Faridabad, where two doctors, Ganaie, a resident of Koil in south Kashmir’s Pulwama, and Shaheen Sayeed from Lucknow, were arrested.A large cache of arms and ammunition, including 2,900 kg of ammonium nitrate, potassium nitrate and sulphur, was seized during the operation, officials said.The car explosion near the Red Fort, which claimed 15 lives, is being investigated by the National Investigation Agency (NIA).



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *