New Delhi, August 9, 2026 — A serving Indian Air Force Wing Commander, arrested earlier this year for allegedly leaking classified defence information, has been accused of installing data-stealing software on a colleague’s mobile phone as part of a suspected Pakistani intelligence-linked espionage operation. The 44-year-old officer remains in judicial custody in Tihar Jail after a chargesheet was filed under the Official Secrets Act.
Delhi Police and Indian Air Force sources say the officer, posted at a critical field unit on the Western Front, fell victim to a social media honey trap orchestrated by a woman acting on behalf of Pakistani handlers. After gaining his confidence, the woman allegedly persuaded him not only to share sensitive military documents and operational details but also to plant spyware on a fellow officer’s device in an attempt to expand access to classified information.
How the Spyware Allegation Emerged
According to senior Delhi Police sources, the Wing Commander was approached on a social media platform earlier in 2026 while navigating personal difficulties. What began as casual chats progressed to regular video calls and conversations on encrypted messaging applications. Once trust was established, the woman began requesting photographs, videos, and details about troop deployments, military unit movements, and strategic operational activity along the border.
Investigators allege that the officer transmitted “crucial documents and data” through digital channels. In a further escalation, the handler instructed him to install a specific application on a colleague’s mobile phone. Police describe the app as targeted spyware or remote-access malware designed to steal device data, track real-time locations, and intercept communications. The alleged installation was intended to give external handlers broader control over information stored on the second officer’s device.
The exact technical nature of the software and the volume of data, if any, that may have been extracted remain under forensic examination. Agencies are analysing whether the malware successfully compromised the colleague’s phone and the potential national security implications of any such breach.
Timeline of the Case
Electronic monitoring by the Delhi Police Special Cell began in January 2026 after an international telephone number linked to Pakistani intelligence operatives showed frequent encrypted communications with an Indian mobile number later identified as belonging to the Wing Commander. IAF counter-intelligence units subsequently placed the officer under physical and digital surveillance.
Conclusive evidence was gathered over the following months. On 30 May 2026 (or the night of 31 May, according to some accounts), IAF authorities lodged a formal complaint and handed the officer over to the Delhi Police Special Cell. He was initially held in police custody before being remanded to judicial custody in Tihar Jail in June. A comprehensive chargesheet was submitted before a competent court (reports identify the Saket court) on 30 July 2026. The matter is currently sub-judice.
Official Responses
A Delhi Police statement confirmed: “Based upon a complaint by Indian Airforce authorities, a serving airforce officer was arrested on May 30, 2026, for allegations of being honey trapped by a Pakistani Intelligence Operative. Post investigation, a charge sheet was submitted before the competent court on July 30, 2026 and the matter is sub-judice.”
An IAF spokesperson said the officer “was under active surveillance and was handed over to the suitable law enforcement agencies,” adding that proactive measures enabled authorities to contain the leak. The force has reiterated its zero-tolerance policy toward security breaches and espionage.
Police sources have characterised the episode as part of a larger espionage network aimed at collecting strategic military intelligence. They are examining the digital trail of communications, identifying possible overseas handlers, assessing the extent of information compromised, and checking whether the woman who contacted the Wing Commander had approached other IAF personnel.
Broader Pattern of Honey-Trap Operations
The case fits a recurring pattern of alleged Pakistani intelligence operations that use social media profiles, emotional manipulation, and malware to target Indian defence personnel. A comparable incident occurred in February 2018 when Delhi Police arrested an IAF Group Captain after he was honey-trapped via a fake Facebook profile and accused of passing classified documents related to defence space and cyber agencies.
Security agencies note that even fragmented information on deployments, movements, and internal communications can hold significant value for foreign intelligence services. In the present case, investigators continue to evaluate whether the material allegedly shared—or any data potentially accessed via the spyware—could have compromised operational security or facilitated hostile activity.
Current Status
The Wing Commander’s identity has not been made public. He remains lodged in Tihar Jail under judicial custody. Forensic analysis of electronic devices, the full scope of the alleged spyware installation, and the possibility of a wider network are still under active investigation by the Delhi Police Special Cell, IAF intelligence, and central agencies.
The Indian Air Force has emphasised that the officer’s activities were detected through internal surveillance before greater damage could occur. As the case proceeds through the courts, further details on the precise nature of the classified information and the technical assessment of the malware are expected to emerge only within the formal legal process.
This report is based on official statements from Delhi Police and the Indian Air Force, along with consistent accounts provided by senior police sources to multiple national media organisations.
