China- and India-linked hackers breached Balochistan police
Cyber actors linked to China and India infiltrated Pakistani police networks, targeting Balochistan Police and accessing biometric, case and personnel records from Feb 2024 to Apr 2026.
SentinelOne’s threat unit SentinelLabs found that cyber actors linked to China and India infiltrated Pakistani police networks between February 2024 and April 2026. The intrusions affected several police organisations and concentrated on Balochistan Police. Attackers reached servers that store biometric identifiers, criminal case files, officer personnel records and public-facing systems.
SentinelLabs grouped the activity into four clusters based on malware and infrastructure: PlugX, ShadowPad, Cobalt Strike and Remcos. The firm reported that Remcos activity maps to a single tracked actor, while clusters using shared or commodity malware may involve multiple operators.
Researchers found malicious files placed on Balochistan Police’s public Complaint Management System disguised as software updates. The fake update prompt would have appeared to users of the portal, including officers and civilians, and could have delivered remote access tools or other malware. Some samples contained Chinese-language coding patterns and artifacts that linked parts of the activity to a developer using Chinese-language conventions.
The report sets out likely motives tied to regional security concerns. For activity linked to China, SentinelLabs noted repeated attacks on Chinese nationals working on Belt and Road projects in Balochistan and indicated that access to police records would allow assessment of threats to those personnel. The India-linked activity aligns with long-running tensions between Islamabad and New Delhi; Pakistan has accused India of supporting Baloch militants, an allegation India denies.
The intrusions spanned more than two years, giving attackers persistent access to systems that hold identity and investigative information. SentinelLabs warned that access to biometric databases and personnel files can expose the identities of officers and informants, and that case files can reveal investigative priorities, methods and active operations.
SentinelLabs reported that shared tooling complicates definitive attribution and recommended ongoing monitoring and analysis to determine the full scope of the incidents. The firm disclosed its findings and the February 2024–April 2026 timeframe after reviewing malware samples, infrastructure and artifacts linked to the intrusions.








