Suspected Chinese and Indian Spies Both Targeted Pakistani Police, Researchers Say

A two-year campaign hit Balochistan Police and other law enforcement bodies, with servers holding criminal records among the compromised assets.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
A dimly lit government office at night, rows of empty desks with old CRT and flat-screen monitors glowing faintly with generic login prompts, a single overhead
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Researchers say Pakistani law enforcement bodies were targeted in a sustained spying campaign that ran from February 2024 to April 2026.
  • Balochistan Police servers holding criminal and citizen data were among the systems broken into.
  • Two separate clusters of hackers, one linked to China and one linked to India, appear to have hit the same victims.
  • Attribution remains at medium confidence, with overlapping targeting rather than shared tooling.

Security researchers have pieced together a long-running spying operation aimed at police forces in Pakistan, and the picture is unusual. Two different sets of hackers, one lining up with Chinese interests and one lining up with Indian interests, appear to have gone after the same targets over roughly two years, according to a report first surfaced by The Hacker News.

One of the clearest hits was on Balochistan Police. The hackers reached servers running the force's web applications, the tools officers use to look up criminal records and manage citizen data. That's the kind of access a foreign intelligence service would very much like to have.

Who was behind the attacks?

Researchers are pointing at two separate groups, and they're careful about it. One cluster is described as China-aligned, with targeting and tooling that fits patterns previously seen from crews such as Mustang Panda, the name CrowdStrike uses for that group. We covered Mustang Panda's parallel operations against Indian government ministries on 29 June in our earlier story. The second cluster is described as India-aligned, with behaviour overlapping groups tracked as SideWinder or Patchwork.

Neither government has claimed the activity, and Pakistan has made no formal accusation against either. The assessment sits at medium confidence: the evidence is consistent but not conclusive. Overlapping victim lists are not the same as shared infrastructure or shared malware, and single-source attribution in this region has a habit of shifting as more data surfaces.

What makes this case worth watching is the overlap itself. Two rival services, on opposite sides of a long-running regional dispute, appear to have independently decided Pakistani police networks were worth the effort.

What did the hackers actually take?

The report describes access to servers hosting police web applications, the internal databases officers use day to day. Criminal case files and citizen records tend to live on systems like these.

Researchers haven't published a full inventory of what was exfiltrated. That's common when the victim is a government body and the investigation is still live.

The techniques described match what both groups have used elsewhere in South Asia. Spear-phishing, where an attacker sends a carefully crafted email to trick a specific person into opening a malicious file, is a staple for both. So is exploiting internet-facing web applications that haven't been patched.

Should ordinary people be worried?

If you're a Pakistani citizen whose details sit in a police database, the honest answer is: your information may have been read by a foreign intelligence service, and there's nothing you can personally do about that. This is a government-level problem, not a consumer one.

For everyone else, the story illustrates something CTI analysts repeat often. Capability is not the same as intent. Both groups have long had the technical reach to break into police networks. What this campaign shows is sustained intent, over two years, from two directions at once. That's the detail that matters most here, and it's being undersold in the initial coverage relative to the attribution questions that will likely dominate the follow-up.

Attribution may firm up or shift as researchers publish indicators of compromise and Pakistani authorities respond. The first report on a campaign like this is rarely the last word.

© 2026 Threat Vectr