Background on the Pahalgam Incident
The April 2025 terror attack in Pahalgam, located in Jammu and Kashmir, resulted in the deaths of 26 tourists at a popular valley spot. The incident drew widespread condemnation and prompted a detailed investigation by India's National Investigation Agency (NIA), the premier central counter-terrorism body.
Role of the National Investigation Agency in the Probe
The NIA took over the investigation following the attack, focusing on cross-border linkages and the conspiracy behind the planning. Chargesheets filed by the agency have provided key insights into how the operation was orchestrated from outside India.
Key Findings on Pakistan-Based Control
According to the NIA chargesheet, the entire plot was planned and directed from Pakistan. A Lashkar-e-Taiba (LeT) operative identified as Saifullah, also known as Sajid Jatt or 'Langda', operated from Lahore and issued instructions to the attackers on the ground.
Detailed Planning Timeline Revealed
The chargesheet outlines specific steps in the preparation phase. On April 15 and 16, 2025, three terrorists identified as Faisal Jatt alias Suleiman, Habib Tahir alias Chhotu, and Hamza Afghani were dispatched to conduct reconnaissance in the Baisaran valley and surrounding areas of Pahalgam. Their task involved assessing security arrangements and tourist movements.
On the day of the attack, Saifullah maintained constant communication from Lahore, providing real-time updates including coordinates, location data, movement instructions, hideout details, and escape routes.
Photo by Ankur Khandelwal on Unsplash
Evidence of Cross-Border Logistics
Recovered mobile phones from the terrorists killed in subsequent operations were traced to purchases in Pakistan. One phone was acquired online and shipped to an address in Lahore's Quaid-e-Azam Industrial Estate, while another was bought in Karachi's Shahra locality. Local residents Parvez and Bashir Ahmed were identified as having assisted the Pakistani terrorists during the execution.
The False Flag Narrative and Its Exposure
Immediately after the attack, The Resistance Front (TRF), described as a proxy of LeT, claimed responsibility via a Telegram channel named 'Kashmir Fight'. As international pressure mounted, including a UN Security Council condemnation, the group backtracked, alleging the channel had been hacked. NIA technical analysis traced the channel's origin to Battagram in Pakistan's Khyber Pakhtunkhwa province, with another related channel operating from Rawalpindi.
Possible International Connections Under Scrutiny
A subsequent NIA chargesheet in June 2026 flagged the need for further examination of potential links between the Pakistan-based groups involved and other designated outfits, including Hamas. Officials noted increasing interactions between Hamas and Pakistan-based entities such as LeT and Jaish-e-Mohammed in recent months.
Operational Response and Broader Implications
The revelations contributed to India's 'Operation Sindoor', which targeted terror infrastructure across the border. The probe underscores the challenges of cross-border terrorism and the importance of robust intelligence sharing and technical surveillance in countering such threats.
Photo by alireza nazari on Unsplash
Stakeholder Perspectives and Ongoing Investigations
Security agencies continue to monitor the activities of wanted individuals like Saifullah, who remains at large in Pakistan. The NIA has highlighted the use of proxies and digital platforms to spread misinformation following attacks. International cooperation remains key to addressing the evolving threat landscape.
Future Outlook for Counter-Terrorism Efforts
The detailed timeline from the NIA probe offers valuable lessons for enhancing surveillance, disrupting funding networks, and preventing reconnaissance activities. Strengthened border management and real-time intelligence capabilities are expected to play a central role in preventing similar incidents.
