CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2249

As cited

Copy frozen at (site build).

threat intel

One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement

SentinelLabs has tracked cyberespionage activity against Pakistani law enforcement organizations from February 2024 to April 2026, with both China-nexus and India-nexus threat actors targeting Balochistan Police and other agencies. The attackers compromised servers hosting sensitive police and citizen data including biometric records, criminal files, and personnel records, with one China-linked actor deploying custom implants in a web application used by both police staff and the public. The convergence of multiple state-backed actors on these targets reflects their value as repositories of Pakistan's internal security information and threat assessments.

Why it matters: Law enforcement and security agencies worldwide should assess whether similar espionage activity targets their own agencies, as compromised police networks expose both operational intelligence and citizen data; this case demonstrates how web-facing police applications can become attack surfaces for state-sponsored actors seeking insight into counterinsurgency operations and critical infrastructure security.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary