Uttar Pradesh has emerged as a major focus in an expanding investigation into alleged Pakistan-linked digital radicalisation and sleeper-cell recruitment networks, with security agencies uncovering a sophisticated online operation targeting Indian youth through social media platforms.
According to investigators, the network was allegedly operated by Pakistan-based gangster Shahzad Bhatti along with handlers suspected to have links with Inter-Services Intelligence. Officials say the operation relied heavily on Instagram, YouTube and encrypted messaging apps to identify and influence vulnerable young people across northern India.
The case gained national attention after coordinated raids were carried out across multiple states, including Uttar Pradesh, Delhi, Haryana, Punjab, Rajasthan and Madhya Pradesh. Around 300 suspects were reportedly detained for questioning and digital scrutiny as agencies attempted to map the wider network.
Investigators believe the alleged module represents a new “hybrid threat” model where online radicalisation, organised crime, espionage and anti-national activities are blended into decentralised civilian networks that are difficult to detect.
Security officials said Shahzad Bhatti allegedly projected an image of wealth and luxury through carefully crafted social media content featuring expensive cars, foreign trips, luxury villas and cash. Agencies suspect the content was designed to attract impressionable youth seeking status, identity and financial opportunities before gradually exposing them to extremist narratives and covert operational tasks.
Authorities believe Uttar Pradesh has become especially vulnerable because of its large youth population, growing smartphone penetration and widespread social media usage.
In recent developments, the Uttar Pradesh Anti-Terrorism Squad arrested two young men identified as Hizbullah Ali Khan alias Tushar Chauhan from Meerut and Sameer Khan from Delhi’s Seemapuri. Investigators allege the duo was in the early stages of online indoctrination and had been communicating with handlers linked to the network.
Officials said the suspects were not hardened operatives but vulnerable recruits undergoing systematic digital grooming. Their alleged handlers reportedly used social media platforms to first establish trust before introducing extremist content and operational guidance.
Rajeev Krishna said recent cases indicate an evolving threat pattern in which foreign handlers use social media, financial incentives and local civilian networks to recruit young individuals into illegal and anti-national activities.
Security agencies are also investigating multiple linked cases across western Uttar Pradesh. In Ghaziabad, officials dismantled an alleged espionage network involving 21 arrests, including a woman accused of sharing sensitive information and videos with Pakistan-based handlers in exchange for money.
In another case from Bijnor, investigators uncovered a module allegedly involved in posting firearm videos online, damaging railway signalling infrastructure and planning disruptive activities aimed at spreading panic.
Officials warned that railway systems and public infrastructure are increasingly being viewed as soft targets because even limited sabotage can create widespread disruption and fear.
Security agencies are now analysing digital footprints, encrypted communication records and financial transactions to determine the full extent of the alleged network operating across Uttar Pradesh and neighbouring states.
The investigation continues as agencies intensify efforts to prevent online radicalisation and dismantle sleeper-cell structures allegedly operating through social media platforms.


























