# Pakistani Law Enforcement Agencies Targeted in Sustained China- and India-Aligned Espionage Campaign


Cybersecurity researchers have uncovered evidence of a sophisticated, multi-year cyber espionage operation against Pakistani law enforcement organizations, with distinct threat groups suspected to be aligned with both China and India exploiting compromised web applications to access sensitive police and citizen records. The campaign, which persisted from February 2024 through April 2026, represents a significant escalation in state-sponsored targeting of South Asian law enforcement infrastructure and raises urgent questions about the security posture of critical government systems in the region.


According to technical disclosures from security researchers, the Balochistan Police portal—one of Pakistan's major provincial law enforcement systems—served as a primary attack vector for multiple threat actors seeking access to databases containing criminal records, citizen information, and operational law enforcement data. The compromise of these assets suggests a sustained intelligence-gathering operation aimed at understanding police capabilities, investigating political opponents, or identifying individuals of interest to foreign intelligence services.


## The Threat: Compromised Infrastructure and Data Exposure


The primary target was the Balochistan Police's web-facing infrastructure, which manages multiple critical functions:


  • Criminal records database: Detailed case files, arrest records, and suspect profiles
  • Citizen data management systems: Personal identification information linked to police inquiries
  • Operational reporting platforms: Internal communications and law enforcement procedures
  • Inter-agency coordination systems: Data shared across Pakistani federal and provincial agencies

  • Researchers identified that the compromised servers were not isolated incidents but rather represented a persistent foothold maintained by multiple threat actors operating simultaneously. This suggests coordination—or at minimum, shared knowledge of vulnerabilities—between distinct espionage groups, though motives and operational objectives likely differed between China- and India-aligned actors.


    The technical infection vector appears to have exploited web application vulnerabilities, possibly including SQL injection, authentication bypass, or unpatched remote code execution flaws. Once attackers gained access, they established persistence mechanisms allowing long-term data exfiltration without triggering detection.


    ## Background and Context: The Geopolitical Dimension


    Pakistan has become an increasingly attractive target for cyber espionage operations, particularly from neighboring countries and major powers with strategic interests in South Asia. The targeting of law enforcement systems carries particular intelligence value:


    Why Law Enforcement?


    | Actor | Likely Objectives |

    |-------|-------------------|

    | China-aligned groups | Identify political opponents, separatist movements, security force activities; monitor cross-border threats |

    | India-aligned groups | Track Pakistani security operations, identify intelligence sources, monitor anti-India activities |

    | Opportunistic criminals | Identity theft, extortion, selling data to other threat actors |


    Balochistan, specifically, has been a region of strategic interest due to ongoing separatist movements and China's substantial investments in the China-Pakistan Economic Corridor (CPEC). The province has experienced decades of political instability, and both regional and global powers maintain active intelligence operations there.


    Previous incidents of Pakistani government hacking include:


  • 2021 Pakistani Ministry of Foreign Affairs breach: Hackers accessed diplomatic cables and correspondence
  • 2020 Pakistan Stock Exchange attack: Targeting of financial infrastructure
  • Recurring targeting of military and intelligence networks: Ongoing intrusion attempts attributed to APT groups

  • This new campaign suggests adversaries have shifted focus to law enforcement as an alternative intelligence source when military and intelligence networks maintain stronger defensive posture.


    ## Technical Details: How the Attack Unfolded


    Security researchers identified multiple stages of the compromise:


    Stage 1: Initial Access

    Attackers exploited vulnerabilities in public-facing web applications, likely including:

  • Unpatched web server vulnerabilities
  • Weak or default credentials on administrative interfaces
  • SQL injection flaws in police portal database queries
  • Missing input validation on form fields

  • Stage 2: Persistence and Lateral Movement

    Once inside, attackers:

  • Created hidden administrative accounts to maintain access
  • Installed web shells for remote code execution
  • Moved laterally to other servers housing citizen and criminal data
  • Established encrypted tunnels to exfiltrate data
  • Modified logs to cover their tracks

  • Stage 3: Data Exfiltration

    Intelligence suggests multiple data collection operations:

  • Bulk downloads of criminal records
  • Extraction of citizen information tied to police investigations
  • Copying of operational procedures and organizational charts
  • Collection of inter-agency communications

  • The extended timeframe (26+ months) indicates sophisticated operators who prioritized stealth over speed, collecting data gradually rather than launching rapid, detectable exfiltrations.


    ## Implications: Scope of Potential Exposure


    The compromise has potentially exposed:


    1. Investigative subjects: Individuals under police investigation may be identified to foreign intelligence services or criminal networks

    2. Police operational capacity: Foreign actors now understand Pakistani police tactics, capabilities, and response procedures

    3. Citizen privacy: Millions of records tied to police inquiries, creating exposure for identity theft and extortion

    4. Inter-agency operations: If the portal connects to federal agencies, the compromise may extend beyond Balochistan

    5. Witness protection: Individuals cooperating with police may be exposed to retaliation

    6. Political intelligence: Activists, journalists, and opposition figures under investigation were potentially identified


    For ordinary citizens, the exposure creates significant secondary risks: stolen identity data could fuel document fraud, extortion schemes, or be weaponized for targeted hacking campaigns.


    ## Recommendations: Immediate and Long-Term Actions


    Immediate response:

  • Disconnect affected systems from networks to prevent further exfiltration
  • Conduct forensic analysis to identify all accessed data and affected records
  • Notify individuals whose data was exposed
  • Reset all administrative credentials and API keys
  • Deploy intrusion detection systems to identify remaining backdoors

  • Medium-term remediation:

  • Conduct comprehensive security audit of all provincial police portals
  • Implement network segmentation to limit lateral movement
  • Deploy multi-factor authentication on all administrative interfaces
  • Establish data loss prevention (DLP) tools to detect exfiltration
  • Implement end-to-end encryption for sensitive databases

  • Long-term resilience:

  • Establish a Pakistani government cyber incident response team
  • Create regular penetration testing and vulnerability assessment programs
  • Implement security awareness training for law enforcement personnel
  • Develop information sharing agreements with allied nations on cyber threats
  • Consider moving critical systems to isolated, air-gapped networks

  • ## HackWire Analysis


    This campaign exemplifies how state-sponsored cyber operations have evolved beyond targeting military and intelligence agencies to focus on second-tier infrastructure that often maintains weaker defenses but provides equally valuable intelligence. Pakistani law enforcement systems represent an attractive target because they combine political sensitivity (investigations into opposition figures, separatists, and critics) with technical vulnerability—most police departments globally lack the cybersecurity expertise and funding of defense ministries.


    What's particularly concerning here is the persistence: a 26-month undetected presence suggests Pakistani authorities either lack the monitoring capability to detect the breach or that detection occurred but remained undisclosed for an extended period. This raises questions about disclosure timelines—how long was this live before researchers identified it?


    The simultaneous presence of China- and India-aligned threat actors also signals a troubling trend: South Asian cyber espionage is becoming industrialized, with multiple state actors maintaining separate operational access to the same target. This isn't new—competing intelligence services have shared targets for decades—but the sophistication and technical coordination suggest formal (or informal) alliances in cyberspace.


    For defenders globally, this case illustrates why public-sector web applications must be treated as critical infrastructure. A police portal doesn't sound as sensitive as a military network, but it's precisely this mismatch between actual intelligence value and perceived security requirements that makes these systems appealing targets. Organizations managing law enforcement, corrections, immigration, or social services data should assume they are being actively targeted and operate defensively accordingly.


    The deeper issue: Pakistan's law enforcement institutions lack the centralized cyber defense capabilities of some other nations. Individual provincial police departments operate semi-autonomously, making coordinated defense difficult. This is a governance problem, not just a technical one, and likely mirrors challenges across South Asia and the developing world.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)