Ghaziabad Man Arrested Over Hoax Bomb Threat Emails to NIA, ISRO, DRDO

Contents

A single set of emails triggered security alerts at some of India’s most sensitive institutions — and an international flight. Here’s how it unfolded, and what it exposes about email-based hoax threats.

Based on Delhi Police statements · July 2026

On June 29, 2026, emails claiming bombs had been planted at several of India’s most high-security institutions landed in official inboxes. Within a day, Delhi Police had traced the messages to a residential address in Ghaziabad. The case is now closed on an arrest — but it’s worth looking at both how fast the trace happened and what it says about the vulnerability these hoaxes exploit.

Who Was Targeted

The June 29 emails claimed explosives were planted at:

  • National Investigation Agency (NIA) headquarters
  • Indian Space Research Organisation (ISRO)
  • Defence Research and Development Organisation (DRDO)
  • Nuclear Power Corporation of India Limited (NPCIL)
  • Ministry of Civil Aviation (MoCA)
  • An Air India flight from New Delhi to New York

Every one of these is a body that either handles national security directly or, in the case of the Air India flight, could have put hundreds of people through an emergency diversion or evacuation. That combination — internal security agencies plus a live international flight — meant the response had to be immediate and simultaneous across multiple organizations, even though, as police later confirmed, every single threat was false.

How Fast the Investigation Moved

Jun 29Threat emails sent to NIA, ISRO, DRDO, NPCIL, MoCA, and flagged for the Air India flight; standard security protocols triggered at each location.

Jun 29–30Investigators trace the two email accounts used to send the messages and identify a linked phone number through the email trail.

Jun 30Technical surveillance leads police to Sanyog Nagar, Ghaziabad, where the suspect is located and questioned at his home.

Jul 2Delhi Police confirm the arrest of Nishant Tyagi, 36, publicly identifying him as the accused.

That’s roughly 48 hours from the emails landing to a named suspect in custody — a fast turnaround that reflects how much digital evidence an email threat leaves behind. Unlike an anonymous phone call, an email carries account metadata, IP information, and a trail that, once investigators have the two source accounts, tends to lead somewhere concrete fairly quickly.

What We Know About the Accused

Police have identified the accused as Nishant Tyagi, 36. According to officials, he studied through open schooling and had enrolled in a bachelor’s degree program in 2010 without completing it. Reports also state that he has been receiving treatment for a mental illness since 2008. Police have not yet publicly detailed a motive, and investigators are reportedly still working to determine whether this was an isolated act or connected to any wider network.

A note on caution here: Details about a person’s mental health history, as reported by police, don’t by themselves explain intent or motive — and jumping to conclusions from a single reported fact risks both unfairness to the accused and unhelpful stigma around mental illness generally. The responsible reading is simply that the investigation is ongoing and a motive hasn’t been publicly established.

Why Hoax Threats Are Still Effective — and Costly

Even though every threat in this case turned out to be false, none of the institutions involved had the option of ignoring it. A bomb threat against a nuclear facility, a defence research body, or a live international flight has to be treated as credible until proven otherwise, which means full security sweeps, possible evacuations, flight security checks, and coordination across multiple agencies — all triggered by a handful of emails that cost the sender nothing to send.

This asymmetry is exactly why hoax threats against government and security institutions are treated as serious crimes in most jurisdictions, including India: the disruption and cost to the state is entirely disproportionate to the effort required to cause it.

A Pattern, Not a One-Off

This isn’t an isolated incident. Bomb hoax emails targeting Indian airlines, airports, and institutions have recurred periodically in recent years, often prompting the same costly cycle of evacuations and security sweeps before being confirmed as false. Separately, reports have also noted a bomb threat email that led to an evacuation at ISRO’s Bengaluru headquarters around the same period — a reminder that even after one hoax is resolved, security agencies can’t assume the next one won’t be real.

Bottom Line

The Ghaziabad case is, in one sense, a success story: investigators traced a threat against six sensitive targets to a specific address within two days using email metadata alone. But the underlying problem it highlights is unresolved — a few minutes spent writing threatening emails can force some of India’s most sensitive institutions into hours of mandatory, expensive, and disruptive security response, every single time.

Picture of Adarsh Singhal & Associates
Adarsh Singhal & Associates

Leave a Reply

Your email address will not be published. Required fields are marked *