China, India-Linked Hackers Targeted Same Pakistan Police Network: Report

A new cybersecurity report has claimed that suspected state-linked hacking groups from China and India independently targeted the same Pakistani law enforcement agency over a two-year period, highlighting the strategic importance of Balochistan in regional security dynamics.

According to a report released by cybersecurity firm SentinelLABS, four separate cyber espionage campaigns targeted Pakistan’s law enforcement agencies between February 2024 and April 2026. The primary target was the Balochistan Police, which operates in Pakistan’s largest province and has long been at the centre of insurgency-related security concerns. The report also identified cyber activity involving Khyber Pakhtunkhwa Police, Islamabad Police and the Punjab Safe Cities Authority.

- Advertisement -

Add as preferred source on Google

If you enjoyed reading this article, you can help support our journalism by adding OHeraldo as a preferred source.

Researchers said the attackers gained varying levels of access to multiple police systems. They reportedly reached servers hosting applications containing personnel records, criminal case files, stolen vehicle databases, hotel guest registrations, landlord-tenant records and biometric information. However, SentinelLABS noted that while the hackers had access to these servers, there was no confirmed evidence that sensitive data was stolen from most of the systems.

The most significant breach involved the Complaint Management System (CMS), a public portal used by citizens to register complaints against police. Investigators found that hackers uploaded malware disguised as a routine software update, displaying a message reading, “Update Complete! Please refresh the page.” The malware was allegedly designed to infect both police personnel and members of the public using the portal, potentially providing attackers with deeper access to connected systems.

SentinelLABS attributed three of the four hacking campaigns to suspected China-linked actors with varying degrees of confidence, while another campaign was linked to an India-associated cyber group tracked by cybersecurity researchers. The firm said attribution was based on malware analysis, command-and-control infrastructure, coding patterns and previous targeting behaviour.

The report added that several aspects of the cyber campaigns remain unclear, including the final payload of the malware used in the CMS attack and whether any classified information was ultimately exfiltrated. Neither Indian nor Pakistani authorities have officially commented on the findings.

- Advertisement -
Share This Article