Gujarat police have arrested two individuals in Bihar and Jharkhand for sending bomb threats, uncovering an interstate cyber syndicate linked to Bangladesh. The investigation revealed the group possessed over 513,000 compromised email credentials used to threaten state institutions and international summit partners.
Authorities in Gujarat have dismantled an interstate cyber syndicate following a series of bomb threats that targeted the state legislative assembly, the Chief Minister’s office, and international partners involved in the BRICS summit. The Cyber Center of Excellence led the operation, tracing a threatening email sent on September 10 to a digital trail that ended in Bhagalpur, Bihar.
Police have arrested two primary suspects in connection with the threats. The investigation identified Roshan Kumar Bhumihar of Bhagalpur as the individual who sent the emails, while Gulshan Kumar Singh of Deoghar, Jharkhand, was identified as the main operator of the network. According to law enforcement, Singh had been actively trading stolen email credentials since 2022.
The investigation has highlighted the involvement of external actors, with police confirming that the syndicate received financial and operational guidance from associates based in Bangladesh. Financial backing for the group’s activities was reportedly routed through cryptocurrency transactions, a method used to complicate tracking by authorities.
One of the most significant findings in the probe is the recovery of 513,847 unique email IDs and passwords. Investigators suspect these compromised credentials were used to automate threat campaigns targeting schools, courts, and government infrastructure across the country. Law enforcement agencies are now working to determine the full extent of this data breach and whether the syndicate has used these credentials for other cyber-criminal activities beyond the recent bomb threats.
The case underscores the increasing security challenges posed by digital syndicates operating across borders. As the investigation continues, authorities are focused on identifying the international handlers behind the financial support and determining how the group bypassed security protocols to access such a large volume of sensitive account information. Further updates are expected as police work to trace the full network of the syndicate.
