Threats · 63 days ago
A public police portal became more than a complaint channel. It gave rival nation-state operators a trusted path into the same records stack, so one civic-facing system now exposes biometric and identity data to multiple espionage campaigns at once.
SentinelLabs says China- and India-aligned activity converged on Balochistan Police between February 2024 and April 2026. The affected systems included complaint management, biometric records, criminal case files, tenant registrations, personnel data, and other identity-linked records; clusters were tied to PlugX, ShadowPad, Cobalt Strike, Remcos, and TAG-179.
The risk is broader than one police force. Any public portal that reaches internal records can turn normal user interaction into a foothold on data that supports surveillance, targeting, and cross-domain intelligence collection.
4 sources covering this story
Pakistani Police Systems Hit by Chinese and Indian Espionage
Chinese and Indian spies converged on the same Balochistan police force, SentinelLabs found
Hackers Weaponize Balochistan Police Portal in Multi-Group Espionage Campaigns
Suspected China- and India-aligned actors targeted Pakistani police systems with PlugX, ShadowPad, Remcos, and Cobalt Strike from 2024 to 2026.
The Record from Recorded Future
China, India ran separate spying campaigns against same Pakistani police force
The activity, in some cases breaching the exact same systems, ran between February 2024 and April 2026 and centered on the force responsible for the country’s southwestern province that has been the site of a long-running separatist insurgency.
China, India-Linked Hackers Both Targeted Same Pakistani Police Force
Both foes and allies have targeted the Balochistan Police force in Pakistan for at least two years, according to SentinelOne.
Part of the PlainSec briefing for 2026-07-13