What first appeared to be a series of threatening emails sent to government institutions has now led investigators across three states and into an alleged network with links to Bangladesh.
Two men have been arrested in Bihar and Jharkhand in connection with bomb threats sent to the Gujarat Legislative Assembly, Chief Minister’s Office, schools, colleges, courts and other institutions.
The investigation by the Cyber Center of Excellence began after a threatening email reached Gujarat authorities on September 10. A technical analysis of the message eventually took investigators to Bhagalpur in Bihar and then to Deoghar in Jharkhand.
Threat email triggered investigation
At around 7:09 am on September 10, Gujarat’s Legislative and Parliamentary Affairs Department received an email from an account identified as jondmoragn52627@gmail.com.
The message allegedly threatened bomb attacks at the Gujarat Assembly and the Chief Minister’s Office. It also contained threats against Prime Minister Narendra Modi, Union Home Minister Amit Shah and countries supporting India during the ongoing BRICS Summit.
With the threat involving key government institutions, investigators began examining the email’s digital trail to find where it had originated.
Digital trail leads police to Bihar
The technical investigation indicated that the email account was being operated from Bhagalpur, Bihar.
Police then arrested Roshan Kumar Bhumihar (Rai) in Bhagalpur. During questioning, he allegedly told investigators that the email account had been given to him by Gulshan Kumar Singh, who lives in Deoghar, Jharkhand.
Following the lead, police teams moved to Deoghar and arrested Gulshan Kumar.
Investigators have allegedly identified Gulshan as the main person behind the network.
Police find more than 5 lakh email IDs
The investigation took a larger turn after police recovered a list containing 5,13,847 unique email IDs and passwords.
According to investigators, Gulshan had been creating and selling email accounts and passwords since 2022. The accounts were allegedly supplied to other people, including Roshan, who was then asked to use them for sending threatening messages.
Police are now checking how these accounts were created and whether they were used in other cases involving threats or cybercrime.
Investigators also suspect that some of the accounts were created using methods aimed at getting around normal authentication checks.
Probe finds alleged Bangladesh connection
Police say the investigation has also revealed an alleged Bangladesh link.
According to investigators, Gulshan was in direct contact with people in Bangladesh and allegedly received instructions from them. He is also accused of sharing the list of email accounts with associates there.
The network allegedly received financial support from Bangladesh, with investigators also examining the use of cryptocurrency wallets for transactions.
Police are now working to identify the people in Bangladesh who may have been providing instructions or financial support.
Investigation continues across three states
The operation involved teams working across Gujarat, Bihar and Jharkhand.
The Cyber Center of Excellence received assistance from the Gandhinagar Police, as well as police teams in Bhagalpur and Deoghar.
The two arrests are only the beginning of the investigation. Police are now trying to establish whether the large number of email accounts was used for other threats or cybercrimes and whether more people were involved in the alleged network. The investigation remains underway.
Also Read: H-4 Work Permit Row: US Court Gives Relief To 7 Spouses, But Others Still Wait








