In a development that once again places the intersection of national security, cyber espionage and criminal jurisprudence under judicial scrutiny, the Supreme Court has issued notice on an appeal filed by the State of Uttar Pradesh challenging the Bombay High Court’s decision acquitting former BrahMos Aerospace engineer Nishant Agarwal of major charges relating to espionage, cyber terrorism and leaking sensitive defence information to Pakistan. While the Supreme Court has not expressed any opinion on the merits of the allegations, its decision to entertain the appeal indicates that important questions of law concerning the interpretation of the Official Secrets Act, 1923, the Information Technology Act, 2000, and the evidentiary standards governing cyber espionage merit closer examination. The proceedings therefore extend beyond the fate of one accused and touch upon a constitutional dilemma confronting every modern democracy: how should courts balance the imperative of safeguarding national security with the equally fundamental requirement that criminal convictions rest upon proof beyond reasonable doubt?
The matter was mentioned before a Bench comprising Justice Sanjay Kumar and Justice Sanjeev Sachdeva by counsel appearing for the State of Uttar Pradesh, which sought to challenge the Bombay High Court’s judgment acquitting Agarwal of the more serious allegations under the Official Secrets Act and the Information Technology Act. Accepting the request, the Supreme Court issued notice to Nishant Agarwal and the State of Maharashtra and directed that the matter be listed for further hearing on 31 August 2026. Although the criminal trial was conducted in Nagpur and the appeal was decided by the Bombay High Court, the Uttar Pradesh Government has approached the Supreme Court because the investigation was originally carried out by the Anti-Terrorism Squad (ATS), Lucknow, which had registered the case and led the investigation.
The prosecution traces its origins to 2018, when the Uttar Pradesh Anti-Terrorism Squad reportedly received intelligence inputs that fake social media profiles, allegedly operated from Pakistan under the names “Neha Sharma” and “Pooja Ranjan”, were targeting Indian defence personnel through a classic “honey-trap” operation. Investigators alleged that these online identities established contact with defence employees in an attempt to obtain confidential military information. The investigation eventually focused upon Nishant Agarwal, then employed as a Senior Systems Engineer at the BrahMos missile facility in Nagpur and a recipient of the prestigious Young Scientist Award.
According to the prosecution, Agarwal was allegedly in communication with persons operating these fake accounts and had copied secret and restricted documents relating to the BrahMos supersonic cruise missile programme onto his personal laptop and external hard drive. Investigators further alleged that he downloaded certain malware at the instance of an online contact identified as “Sejal Kapoor”, thereby enabling unauthorised access to sensitive defence-related information and facilitating its transmission outside authorised systems. Based upon these allegations, the trial court convicted him under Section 66-F of the Information Technology Act, dealing with cyber terrorism, together with several provisions of the Official Secrets Act, 1923, sentencing him to life imprisonment.
The legal landscape changed dramatically when the Bombay High Court (Nagpur Bench) re-examined the evidence in appeal. The High Court concluded that while the record suggested serious negligence in handling confidential material, the prosecution had failed to establish the essential ingredients of espionage and cyber terrorism beyond reasonable doubt. It observed that the evidence demonstrated possession of sensitive files on personal devices and careless handling of classified information but did not conclusively prove intentional communication of defence secrets to Pakistan or the deliberate commission of acts amounting to cyber terrorism. Consequently, the High Court acquitted Agarwal of the major charges under the Official Secrets Act and Section 66-F of the Information Technology Act, while recognising that his conduct could attract liability for lesser statutory violations relating to handling confidential information.
The Supreme Court is now called upon to examine whether the Bombay High Court correctly appreciated the evidence and applied the governing legal standards while overturning the conviction. At this stage, however, the Court has merely issued notice. It has neither suspended the High Court’s judgment nor expressed any opinion regarding the correctness of the acquittal. The appeal will therefore involve a detailed re-examination of the legal reasoning adopted by the High Court and the evidentiary record relied upon by both sides.
The proceedings are significant because they concern the interpretation of the Official Secrets Act, 1923, one of India’s oldest national security statutes. Enacted during the colonial period, the Act criminalises obtaining, collecting, recording, communicating or retaining information prejudicial to the safety or interests of the State. Sections dealing with espionage require proof that the information was obtained or communicated in circumstances indicating prejudice to national security or with knowledge that such disclosure could assist an enemy. Courts have consistently recognised that mere possession of confidential material and the offence of espionage are not necessarily identical, and the prosecution must establish the statutory ingredients prescribed by law.
Equally important is the allegation under Section 66-F of the Information Technology Act, which criminalises cyber terrorism. This provision is among the most stringent offences contained in India’s cyber law framework. It applies where unauthorised access to computer resources is coupled with an intention to threaten the sovereignty, integrity, security or defence of India or to strike terror by causing specified forms of digital harm. Because of the gravity of the offence, courts have insisted that the prosecution establish not only unauthorised access but also the requisite mens rea, or criminal intent, necessary to satisfy the statutory definition of cyber terrorism.
The Bombay High Court’s reasoning, as reported, reflects a distinction increasingly recognised in modern cybercrime jurisprudence the difference between gross negligence in protecting classified information and intentional espionage. In highly sensitive defence establishments, even careless handling of restricted data may expose national security to substantial risks. Yet criminal liability for espionage ordinarily requires proof that the accused intentionally communicated or facilitated communication of protected information to unauthorised persons in circumstances prejudicial to the State. The High Court appears to have concluded that while Agarwal’s conduct may have demonstrated serious negligence, the evidence did not conclusively establish the deliberate transfer of defence secrets required for conviction on the more serious charges.
From a constitutional perspective, the appeal also illustrates the principles governing appellate review of acquittals. Indian criminal jurisprudence recognises that an appellate court may interfere with an acquittal where the lower court’s findings are manifestly erroneous, perverse or based upon misapplication of law. At the same time, appellate courts traditionally exercise caution because an acquittal reinforces the presumption of innocence already available to every accused. Consequently, where two reasonably possible interpretations of the evidence exist, courts often hesitate to substitute one view merely because another is also plausible. The Supreme Court’s eventual decision will therefore be closely watched for its articulation of the circumstances in which an acquittal in a national security prosecution may legitimately be overturned.
The case also underscores the growing importance of digital evidence in contemporary espionage investigations. Modern defence establishments increasingly rely upon interconnected computer systems, encrypted communications, cloud-based storage and sophisticated software environments. Investigations into cyber espionage consequently depend upon forensic analysis of hard drives, metadata, malware, access logs, digital communications and network activity. Unlike conventional espionage cases involving physical transfer of documents, digital prosecutions require courts to evaluate highly technical evidence capable of supporting multiple competing inferences.
Another important institutional issue concerns the human element of cyber security. Intelligence agencies worldwide increasingly recognise that sophisticated military infrastructure may be compromised not merely through direct hacking but through social engineering, including phishing, fake recruitment offers, fabricated professional networking profiles and emotionally manipulative “honey-trap” operations. The allegations in the present case highlight precisely this evolving threat landscape. Whether or not the prosecution ultimately succeeds, the case serves as a reminder that cyber security is not solely a technological challenge but equally one of organisational awareness and personnel training.
The proceedings also revive discussion regarding the continuing relevance of the Official Secrets Act, 1923 in the digital era. The statute was enacted long before the emergence of cyberspace, digital storage, cloud computing or artificial intelligence. Yet courts continue to interpret its provisions in light of modern technological realities. The present appeal may therefore contribute to the evolving jurisprudence on how traditional national security legislation should be applied to contemporary cyber threats involving electronic transmission of classified information.
At the same time, constitutional criminal law insists that national security concerns cannot dilute the standard of proof required for conviction. Indian courts have consistently maintained that allegations involving terrorism, espionage or offences against the State remain subject to the same fundamental principles governing criminal trials presumption of innocence, proof beyond reasonable doubt and judicial scrutiny of evidence. The seriousness of the allegation may justify robust investigation, but it cannot substitute for legally admissible proof.
Ultimately, the Supreme Court’s decision to issue notice should be viewed not as a comment upon the guilt or innocence of the accused but as recognition that the legal questions raised by the case possess significance extending far beyond the individual prosecution. The eventual judgment is likely to shape the future interpretation of the Official Secrets Act, clarify the evidentiary threshold for cyber espionage prosecutions and define the relationship between carelessness, cyber intrusion and intentional betrayal of national security.
As India continues to strengthen its strategic defence capabilities and confront increasingly sophisticated cyber threats, the judiciary’s role becomes equally critical. Courts must ensure that genuine espionage is effectively punished while simultaneously preserving the constitutional commitment that criminal liability particularly in matters carrying grave consequences must always rest upon legally sustainable evidence rather than suspicion alone. The BrahMos espionage appeal thus represents more than a challenge to one acquittal; it is an important constitutional examination of how the rule of law should operate when national security and individual liberty converge.

