Gujarat Police Bust Interstate Bomb Threat Network; Two Arrested in Bihar and Jharkhand

Gujarat Police Bust Interstate Bomb Threat Network; Two Arrested in Bihar and Jharkhand

Gujarat Police have dismantled an alleged interstate cybercrime network suspected of sending bomb threat emails to government offices, educational institutions and courts, leading to the arrest of two men from Bihar and Jharkhand.

The arrests followed a detailed investigation into a threatening email received by the Gujarat government’s Legislative and Parliamentary Affairs Department on September 10. According to investigators, the email threatened attacks on several high-profile government establishments and individuals, prompting a technical investigation by the Cyber Centre of Excellence.

Police identified the suspected origin of the email in Bhagalpur, Bihar, and subsequently arrested Roshan Kumar Rai from the district. A second accused, Gulshan Kumar Singh, was later arrested in Deoghar, Jharkhand. Investigators suspect Singh played a key role in supplying email credentials that were allegedly used to distribute threatening messages and facilitate other cyber-related activities.

Investigation Begins After Gujarat Secretariat Threat

The investigation was launched after authorities received a bomb threat email on September 10. The message allegedly threatened the Gujarat Secretariat, the Chief Minister’s Office and the state Legislative Assembly. It also referred to the Prime Minister, the Union Home Minister and countries that had supported India during the recently concluded BRICS summit in New Delhi.

Given the nature of the message and the institutions named in it, investigators began examining the email’s digital trail. Technical analysis and digital evidence reportedly helped police trace the activity to Bhagalpur in Bihar.

Following the investigation, police arrested Roshan Kumar Rai, who is accused of sending the threatening email. During questioning, investigators allegedly obtained information about the source of the email credentials, which led them to Gulshan Kumar Singh in Deoghar, Jharkhand.

More Than 5 Lakh Email IDs and Passwords Recovered

One of the major findings in the investigation was the alleged recovery of a database containing 5,13,847 unique email IDs and passwords.

According to police, the credentials were allegedly used for sending threatening emails to government offices, schools, colleges and courts. Investigators are also examining whether the accounts were used for other forms of cybercrime.

The large number of email credentials has expanded the scope of the investigation beyond the individual bomb threat sent to Gujarat authorities. Police are now examining how the accounts were obtained or created, who had access to them and whether the same infrastructure was used to send threats to institutions in other parts of the country.Bomb Threat To PM, HM, Gujarat CMO, BRICS Partners: Two Held,  Bangladesh-Backed Network Unearthed By Police | Nation

Suspected Bangladesh Connection Under Investigation

Investigators have also identified a suspected cross-border financial link. According to Gujarat Police, the accused allegedly received financial support from associates based in Bangladesh.

Police are examining claims that the email credential database was shared with associates in Bangladesh. Investigators have also found indications that cryptocurrency wallets were used for financial transactions connected to the network.

Authorities are now working to identify the individuals allegedly operating from Bangladesh and determine the nature and extent of their involvement. The investigation is also expected to establish whether the cross-border connection was limited to financial transactions or involved the planning and distribution of threatening messages.

Coordinated Operation Across Multiple Locations

The arrests were carried out through coordinated action involving Gujarat Police and police teams in Bihar and Jharkhand.

After the technical investigation identified Bhagalpur as the alleged source of the Gujarat threat email, police teams moved to locate the suspected sender. The subsequent investigation led officers to Deoghar, where the second accused was arrested.

The interstate nature of the operation highlights the role of digital evidence in tracing cybercrime networks operating across state boundaries. Investigators are continuing to analyse electronic evidence and the large collection of email credentials seized during the probe.

Probe Continues Into Wider Cybercrime Activities

Police are now investigating whether the two arrested men were involved in additional bomb threat cases or other cybercrimes.

The database containing more than five lakh email IDs and passwords is considered an important part of the investigation because authorities are examining whether the credentials were systematically used to target multiple institutions.

Investigators are also looking into the alleged financial arrangements, cryptocurrency transactions and communications with suspected associates outside India. The objective is to determine the complete structure of the network, identify additional participants and establish the extent to which the infrastructure was used for threatening communications.

The investigation remains ongoing, and authorities are conducting further technical analysis of the digital evidence collected during the operation.

Authorities Examine Digital Trail

The case demonstrates how bomb threats delivered through email can require investigations extending well beyond the location of the institution receiving the message. In this case, the alleged sender was traced to Bihar, while another suspected participant was located in Jharkhand and investigators identified a possible cross-border connection.

With the identities of additional individuals yet to be established, police are continuing to examine the digital and financial trail associated with the network.