
Pahalgam Attacks: A Year On, India's Terror Gap Remains Open
A year after the Pahalgam attacks, India has new counter-terror doctrine but critical gaps in intelligence and infiltration detection remain dangerously open.

- 1.0x
- 1.25x
- 1.5x
- 2.0x
A year ago today, gunmen emerged from the forests fringing the Baisaran Valley near Pahalgam and opened fire on a group of tourists, killing 26 people in what became the deadliest terrorist attack on Indian civilians since the 2008 Mumbai massacre. The April 22, 2025 Pahalgam attacks — carried out by operatives of The Resistance Front (TRF), a proxy outfit of the Pakistan-based Lashkar-e-Taiba — was not merely an act of mass violence. It was a systemic stress test: of intelligence networks, of forward deployment doctrine, and of the assumptions underlying Jammu and Kashmir's counter-terrorism architecture. Twelve months on, some hard lessons have been absorbed. But the harder work — building a counter-terror grid capable of getting ahead of a threat that is evolving faster than the institutions designed to contain it — remains unfinished.
Support Independent Journalism. Public interest stories that affect ordinary citizens — especially those without power or voice — requires time, resources, and independence. Your support — even a modest contribution — allows us to uncover stories that would otherwise remain hidden. Support The Probe by contributing to projects that resonate with you (Click Here), or Become a Member of The Probe to stand with us (Click Here). |
Also Read: Pahalgam Terror: A Chilling Indicator of Kashmir’s Fragile Stability
What the Pahalgam Attacks Changed: Three Shifts in J&K's Security Thinking
The Pahalgam attacks did not just demand a reckoning — they forced one. Over the past year, three concrete shifts have emerged in how security forces approach Jammu and Kashmir's counter-terror architecture, even if the distance between doctrine and ground reality remains wide.
The first is strategic visibility. Forces are now positioned with greater deliberateness, and the establishment of temporary forward operating bases — notably in the upper reaches of Dachigam and adjoining forest belts during Operation Mahadev — reflects a recognition that static deployment cannot cover terrain where battle-hardened militants move through dense forest over hundreds of kilometres.
The second shift is in operational response. Operation Mahadev itself, the 93-day pursuit that ended on July 28, 2025 with the killing of the three LeT operatives responsible for the Pahalgam attacks, demonstrated something that reactive counter-terror rarely does: sustained, intelligence-fused pressure until the job is done.
The third shift is doctrinal. In February 2026, the Ministry of Home Affairs released PRAHAAR — India's first formally codified National Counter-Terrorism Policy — a seven-pillar framework built around prevention, swift response, inter-agency coordination, and the attenuation of radicalisation.
Yet for every visible gain, there is a corresponding gap.
The Red Fort blast of November 10, 2025 is the most instructive. Srinagar Police did eventually unravel the white-collar terror module behind it — tracing a network of professionally educated recruits through JeM posters on a Srinagar wall to a 2,900-kilogram cache of explosives in Faridabad. But the blast still happened, triggered when a panicked cell member drove an explosive-laden car outside the Red Fort after the network began to unravel.
More telling still: a key figure in the module, Dr Muzaffar Ahmad Rather, a paediatrician and a resident of South Kashmir, had left India for Afghanistan approximately two and a half months before the blast — reportedly to liaise between the Kashmir cell and Afghan-based jihadists for training in bomb-making and assault techniques. His departure went undetected in real time. He has since been declared a proclaimed offender, with an Interpol Red Corner Notice in process.
The intelligence miss was real, and it exposes a persistent gap: the recognition of changing terror patterns has not yet translated into the pre-emptive detection architecture that PRAHAAR's framework demands.
After the Pahalgam Attacks, a Familiar Problem: Why Terror Networks Outlast the Strategies Designed to Stop Them
The limits of India's counter-terror response become clearer when viewed against a structural question: why do Pakistan-backed terror organisations consistently outlast the designations, sanctions, and doctrinal frameworks arrayed against them? Three features explain their durability, and all three are on visible display in J&K today.
The first is the safe haven and porous border advantage. Physical sanctuary — in ungoverned or state-protected territory — allows groups to train, recruit, and plan beyond the reach of designation regimes. After 9/11, Al-Qaeda relocated to Pakistan's tribal belt to evade US military pressure.
After the December 2001 attack on India's Parliament, LeT reorganised under the cover of Jamaat-ud-Dawa — a charitable front operating schools, hospitals, and social services across Pakistan — allowing it to sustain operations under ISI protection while presenting a civilian face to the world. When the 2008 Mumbai attacks brought renewed international pressure, that cover was already in place. TRF follows the same logic today.
Also Read: Red Fort Blast: Bomber Calls It Martyrdom Operation, Not Suicide Bombing
The second is decentralised operations. Cell-based structures insulate organisations from leadership strikes and legal sanctions by distributing operational capacity across semi-autonomous units.
Al-Qaeda built regional affiliates — most notably in the Arabian Peninsula and North Africa — that allowed the broader network to survive repeated targeting of its core leadership, distributing operational capacity across semi-autonomous branches beyond the reach of any single strike. LeT has used a similar model: the Indian Mujahideen, a SIMI-rooted network that received LeT training, funding, and weapons, served as its primary India-facing operational layer — domestically rooted in appearance, externally directed in practice — while TRF now serves as its Kashmir-specific front, operationally sophisticated and deliberately structured to maintain plausible deniability for Pakistan.
The third is alternative financing. Groups with access to hawala networks, charitable fronts, and diaspora donors can route funds through channels that international banking sanctions cannot easily reach.
Al-Qaeda drew on Gulf-based donors and informal transfer networks to finance its operations, including the September 11 attacks. LeT has sustained itself for decades through Jamaat-ud-Dawa, its charitable front that operates schools, hospitals, and social services across Pakistan under ISI protection — allowing it to fund militancy behind a veneer of welfare work.
All three of these structural features are in play with TRF. And the Red Fort blast illustrates how these dynamics now extend beyond traditional recruitment pools. The module behind the blast was unlike any previous major attack in India's recent terror history: its core operatives were doctors — five medically trained professionals who collectively raised funds, procured explosive precursors, and allegedly planned a far larger strike before the operation unravelled prematurely.
Umar Nabi, a doctor employed at Al-Falah University in Faridabad, drove the explosive-laden car that detonated near the Red Fort metro station, killing at least 12 people in what investigators believe was a panicked, premature detonation rather than a planned attack.
The module was not a collection of self-radicalised lone wolves — it was a structured cell, radicalised over years by a Shopian-based cleric, connected to external handlers in Afghanistan, and linked to JeM network. The Pahalgam attacks marked a rupture in Kashmir's security landscape; the Red Fort case suggests the rupture extends well beyond it.
Beyond Reactive Strikes — What a Real Counter-Terror Grid for J&K Must Look Like
The dismantlement of the Indian Mujahideen offers the clearest proof of what a coordinated, intelligence-led counter-terror strategy can achieve. A combination of targeted operations, network mapping, financial disruption, and persistent human intelligence ground down IM's operational capacity over several years, culminating in its effective collapse between 2013 and 2017.
That model — patient, multi-layered, and anchored in understanding an organisation's structure rather than simply reacting to its attacks — is precisely what is needed against TRF today. It is also, as the evidence makes clear, what is still missing.
The operational lineage between IM and TRF is instructive. Both draw on LeT's support infrastructure, both exploit local grievances and communal fault lines to radicalise recruits, and both are designed to maintain plausible deniability for their Pakistani handlers.
The key difference is trajectory. IM was an aggressive, high-visibility organisation that announced itself through mass-casualty bombings. TRF is its more disciplined successor: covert, selective, and focused on high-symbolic-value targets designed to generate maximum psychological impact from minimum operational exposure.
The Pahalgam attacks — tourists singled out by religion, killed in a meadow accessible only by foot or horseback, with no security presence — were a case study in this doctrine.
What makes TRF structurally harder to neutralise than IM is its technological and organisational evolution. The Pahalgam attackers carried M4 carbines and AK-47s, wore body-mounted cameras to document the massacre, and communicated using 'Ultra' devices — suspected Chinese-origin encrypted systems that operate outside Indian mobile networks and cannot be triangulated in real time. They moved through dense forest, stayed off known infiltration routes, and relied on a network of overground workers — locally embedded individuals not on any watchlist — for logistics, shelter, and intelligence. The NIA identified at least 20–25 such overground workers after the Pahalgam attacks alone.
Three structural gaps prevent India's counter-terror architecture from getting ahead of this. First, network-centric operations have not yet penetrated TRF's tightly compartmentalised cells — a failure that reflects the persistent weakness of ground-level human intelligence in rural and forested J&K.
Second, TRF's recruitment of recently radicalised individuals with no prior security footprint makes early detection extremely difficult; these are not people on watchlists.
Third, TRF's tactical adaptability — using hit-and-run patterns to exhaust and disperse security forces, documenting operations for propaganda, and continuously upgrading its communications architecture — means the organisation is not merely sustaining itself. It is improving.
Closing these gaps requires more than operational tempo. It demands a genuine intelligence fusion architecture — combining HUMINT, signals intelligence, drone surveillance, cyber forensics, and satellite imaging into a unified real-time picture — embedded within a broader counter-terror strategy that simultaneously targets TRF's operational cells, financial pathways, and overground support networks.
PRAHAAR provides the doctrinal framework. What remains is the harder, less visible work of building the ground-level capability to make it real. A year after the Pahalgam attacks, that work is urgently unfinished.
Support Independent Journalism. Public interest stories that affect ordinary citizens — especially those without power or voice — requires time, resources, and independence. Your support — even a modest contribution — allows us to uncover stories that would otherwise remain hidden. Support The Probe by contributing to projects that resonate with you (Click Here), or Become a Member of The Probe to stand with us (Click Here). |
Srijan Sharma is a national security analyst specialising in intelligence and security analysis, having wide experience working with national security and foreign policy think tanks of repute. He has extensively written on matters of security and strategic affairs for various institutions, journals, and newspapers: The Telegraph, ThePrint, Organiser, and Fair Observer. He also served as a guest contributor to the JNU School of International Studies.

