Law enforcement authorities have successfully dismantled an intricate cross-border extortion network that was targeting prominent business figures in the national capital. Operating across the United Arab Emirates and several Indian states, the criminal syndicate sought to extort substantial sums by invoking the name of notorious gangster Goldy Brar. Beyond demanding ransom, the syndicate had actively coordinated a dangerous plan to open fire at the residence of a target who refused to pay. Decisive intervention by security agencies averted the imminent shooting, leading to the apprehension of three central suspects involved in running the syndicate's operations on the ground.
Extortion Call Demands Massive Payoff
The sequence of criminal intimidation came to light on the night of September 16, 2026, when complainant Praveen Jain observed three missed calls on his personal phone around 8:15 PM. Shortly thereafter, at 9:27 PM, an overseas call originating from a UAE-registered mobile number connected to his son Ayush. The caller introduced himself as an operative of Goldy Brar and placed an extortion demand of Rs 1 crore directly before the family. To instill fear, the caller warned of severe repercussions if the money was not delivered promptly, later reiterating the ultimatum through repeated phone contact.
Police Form Specialized Joint Team
Following the distress complaint lodged by the family, the local Roop Nagar police station registered First Information Report number 162/2026 on September 17, 2026. The case invoked sections 308(4) and 351(4) under the Bharatiya Nyaya Sanhita. Recognizing the high stakes and transnational communication links, North District Special Task Force joined forces with Roop Nagar police. Under the supervision of DCP North Niharika Bhatt, an operational squad was formed comprising ACP Operations Vishesh Dhatterwal, STF Inspector Ashish Dubey, and Roop Nagar SHO Inspector Ramesh Kaushik to neutralize the threat.
Digital Forensics Uncover European Proxy Servers
Investigators initiated technical monitoring and scoured digital trails to pierce through the anonymity of the perpetrators. Digital forensic scrutiny revealed that the culprits avoided standard cellular routes, routing voice communications through internet protocols and specialized remote servers. An IP address, 51.91.249.248, was traced back to French hosting provider OVH SAS. This confirmed that the extortionists deployed virtual private server networks and offshore data center infrastructure to conceal their physical whereabouts while routing calls to targets in Delhi.
Tracing the Syndicate to UAE Hub
Further analysis of linked accounts led officers to suspect individuals operating out of the UAE. Attention turned to a person identified as Abuzar, whose travel records indicated he had left for Dubai on June 13, 2026. Authorities also analyzed the active usage of a SIM registered under Usman in Dubai alongside the specific IMEI signature of the communicating handset. These leads directed police to interrogate Zubair, Maroof, and Usman across Dehradun and Karnal. The technical evidence established that the voice making the overseas extortion calls belonged to Aarish, a brother to both Usman and Abuzar, based in Dubai.
Local Conspirators and Calculated Deception
Sustained questioning brought forward the pivotal role of Arif alias Pistol, a resident of Rasulpur Gujran in the Shamli district of Uttar Pradesh. Arif functioned as the critical operational axis within India, coordinating between the callers and ground elements. He had promised substantial financial compensation to Aarish in exchange for placing the extortion calls and specifically instructed him to adopt a Haryanvi dialect. This linguistic camouflage was intended to trick the victim into believing that a homegrown local gangster from the capital region was running the extortion plot. Simultaneously, Mubarik alias Gullu from Titwada surfaced as the primary local architect of the conspiracy.
Second Industrialist Targeted in Rohini
While investigations were progressing, another city businessman faced an identical extortion attempt on September 19. The younger brother of Manoj Malik, a construction firm owner based in Rohini Sector-1, received two WhatsApp calls from the exact same UAE mobile number at 10:11 PM and 10:12 PM. The caller subsequently transmitted a 37-second audio message, identifying himself as Vikrant from Mahendragarh with ties to Goldy Brar. He demanded Rs 1 crore within a strict 48-hour deadline, threatening gun violence at the family home upon non-compliance. Vijay Vihar police station in Rohini formally registered FIR number 0520/2026 on September 24, 2026, under BNS sections 308(2) and 351(2).
Foiling the Planned Home Shooting
The recurrence of the identical foreign number across both cases provided conclusive proof that a singular criminal syndicate was orchestrating the intimidation wave. Intelligence gathering soon uncovered that the syndicate had finalized blueprints to carry out a multi-round shooting at the Roop Nagar residence because the first target had refused to pay. The attack plan had been hatched approximately two days prior to the targeted date, designed to terrorize the businessman before renewing ransom calls. Moving swiftly, Roop Nagar police fortified the perimeter of the residence, preemptively shutting down the shooting plan before the hitmen could strike.
Arif Apprehended in Gujarat Hideout
Focusing on the movement of Arif alias Pistol, Delhi STF monitored his digital footprint to Ahmedabad, Gujarat. Operating in tandem with Ahmedabad local police, the joint team raided a hideout in the Vezalpur area on September 24, 2026, successfully arresting Arif. The 32-year-old operative resided in Fatehwadi, Ahmedabad, while hailing from Shamli. Police databases showed that Arif carried a serious criminal pedigree, with 12 distinct criminal cases filed against him at Kairana police station in Shamli between 2016 and 2026. These cases included charges of attempted murder, extortion, rioting, criminal intimidation, and violations of the Arms Act.
Logistics Network and Train Interception
Interrogation of Arif unraveled the operational logistics of the syndicate, confirming that contract shooters were actively mobilized to enforce the threats. Mubarik alias Gullu had rented a safe house in Delhi's Kirari locality and paid the lease to shelter the hired gunmen. Mubarik was arrested in Delhi on September 25, 2026. Investigators revealed that Mubarik is the biological brother of Dilshad, the business associate of the complainant. A manhunt on October 1, 2026, snared Nawab Ali alias Sonij, a native of Khalapar in Muzaffarnagar and one of the four enlisted shooters. Moving on specific inputs, officers intercepted Nawab Ali aboard a moving train between Rewari and Alwar with timely coordination from the Railway Protection Force.
Expanding Probe into Overseas Financiers
Investigators continue their efforts to locate three other absconding shooters, two linked to Panipat and another from Muzaffarnagar's Khalapar pocket. Alongside field operations, authorities are coordinating steps to track down Aarish in Dubai. Financial investigators are examining call detail records, banking trails, and informal transaction channels to map the entire monetary spine of the network, while verifying if this identical UAE number was deployed to threaten additional traders in other parts of the country.



















