Hackers linked to China and India spent more than two years inside Pakistani police networks, with Balochistan Police hit most heavily and its public complaint website used to expose visitors to fake software updates. SentinelOne says the intrusions ran from February 2024 to April 2026 and involved activity clusters using PlugX, ShadowPad, Cobalt Strike, and Remcos malware against servers tied to biometric databases, criminal case files, personnel records, and citizen-facing systems.
Why it matters: This is a significant government and privacy breach affecting police operations, sensitive biometric and personnel data, and potentially members of the public who used the complaint portal. Pakistani government defenders should investigate for the named malware families and review all systems connected to Balochistan Police’s public web services; users and staff should treat past update prompts from that portal as suspicious.
2026.07.10
98% relevant
This is the same underlying event: separate China- and India-linked campaigns compromised Balochistan Police over 2024-2026, including tampering with the public complaint portal to deliver malware. The article adds motive context for both countries, a clearer date range, and more detail on the types of police and citizen data exposed through the affected systems.
Eduard Kovacs
2026.07.10
100% relevant
This article establishes a distinct espionage story: dual China- and India-linked intrusions into the same Pakistani police force over 2024-2026, with malware planted on a public-facing police complaint system.
← Back to all stories