For the first time, Indian security agencies have included Pakistan-based alleged ISI handler Shahzad Bhatti in a threat-assessment advisory, with agencies warning that his network could attempt low-intensity
attacks or disruptive activities in Delhi and its peripheral areas around the BRICS Summit 2026, according to security sources.
According to the sources, agencies are particularly assessing the possibility of Bhatti’s network using local operatives to conduct reconnaissance, procure weapons and identify vulnerable or sensitive locations. Police personnel could also be among the potential targets, the sources said.
The advisory has called for heightened surveillance of suspicious movements, possible online recruitment activity, attempts at arms procurement and reconnaissance of sensitive installations and locations.
Security agencies are also examining the possibility of targeted firing, grenade attacks or other disruptive activities, with investigators keeping a close watch on suspected local conduits who could potentially be activated by the Pakistan-based network.
The latest assessment comes only weeks after Indian security agencies jointly carried out a major multi-state crackdown against what authorities have described as the ISI-backed Shahzad Bhatti Network (SBN).
Officials are therefore maintaining a close watch on individuals suspected of facilitating reconnaissance, recruitment, logistics and weapons procurement, particularly in and around the national capital.
With the BRICS Summit 2026 expected to bring heightened security requirements in Delhi, agencies are treating any attempted low-level attack or disruption as a potential tactic aimed at creating panic, diverting security resources or testing the response of law enforcement agencies.
Major Multi-State Crackdown
According to the Ministry of Home Affairs (MHA), security agencies carried out a coordinated operation against the network ahead of Independence Day, detaining 253 people across 14 states and disrupting what the government described as a terror syndicate.
The operation was conducted on August 12 through coordinated intelligence-sharing with state police forces. The MHA said the operation resulted in 253 detentions across Uttar Pradesh, Haryana, Delhi, Punjab, Rajasthan, Maharashtra, Uttarakhand, Karnataka, Gujarat, Bihar, Telangana, Himachal Pradesh, Jammu and Kashmir, and Kerala.
The MHA said the action was undertaken to counter disruptions allegedly being planned around Independence Day and formed part of the government’s stated “zero tolerance” policy towards cross-border terrorism.
The Home Ministry said security forces recovered IEDs, grenades bearing Pakistan Ordnance Factory markings, pistols, live cartridges and CCTV cameras allegedly used for espionage during the operations.
According to the MHA, more than 80 FIRs and over 200 arrests have cumulatively been recorded against the network under provisions including the Unlawful Activities (Prevention) Act, Bharatiya Nyaya Sanhita, Arms Act, NDPS Act and Explosive Substances Act.
Network Allegedly Used Local Conduits
The MHA has described the Shahzad Bhatti Network as a Pakistan-based, ISI-backed terror syndicate linked to grenade, IED and petrol-bomb attacks, as well as targeted killings in India.
Authorities have also alleged that members of the network paid local conduits to conduct reconnaissance of police, defence and religious sites and to install CCTV cameras for surveillance and espionage.
The latest threat assessment indicates that, despite the recent crackdown, agencies remain concerned about the possibility of residual operatives or sympathisers attempting to revive parts of the network.
















