A public police portal became more than a complaint channel. It gave rival nation-state operators a trusted path into the same records stack, so one civic-facing system now exposes biometric and identity data to multiple espionage campaigns at once.
SentinelLabs says China- and India-aligned activity converged on Balochistan Police between February 2024 and April 2026. The affected systems included complaint management, biometric records, criminal case files, tenant registrations, personnel data, and other identity-linked records; clusters were tied to PlugX, ShadowPad, Cobalt Strike, Remcos, and TAG-179.
The risk is broader than one police force. Any public portal that reaches internal records can turn normal user interaction into a foothold on data that supports surveillance, targeting, and cross-domain intelligence collection.
China, India ran separate spying campaigns against same Pakistani police force
The activity, in some cases breaching the exact same systems, ran between February 2024 and April 2026 and centered on the force responsible for the country’s southwestern province that has been the site of a long-running separatist insurgency.