One police force, two foreign intelligence services: how China and India ended up spying on the same Pakistani database- 290
July 11, 2026
Cybersecurity researchers have documented something unusual even by the standards of state-linked cyberespionage: hacking groups tied to China and to India independently broke into the same Pakistani police force's computer systems over more than two years, pursuing entirely different strategic goals, with no evidence either side knew the other was there.
SentinelLabs, the research arm of SentinelOne, traced the overlapping intrusions to between February 2024 and April 2026, both centered on the Balochistan Police — the force covering Pakistan's restive southwestern province, long the site of a separatist insurgency. The appeal of the target is straightforward from an intelligence standpoint: modern police networks concentrate a state's internal-security data in one place, and in this case that meant criminal records, biometric and fingerprint data, personnel files, hotel and tenant registrations tied to national identity records, and citizen complaints — a rich single repository for anyone wanting insight into who the province's security apparatus is watching and why.

The two operations appear to have been driven by mirror-image motives. Researchers
assess the China-linked activity was primarily about protecting Chinese nationals working in Pakistan under the China-Pakistan Economic Corridor, citing a March 2024 suicide bombing and an October 2024 attack near Karachi's airport, both of which affected Chinese workers, as likely drivers. Rather than rely on Pakistani government security assurances, the assessment is that Beijing's operators wanted to independently verify the threat picture themselves. India's motive, by contrast, is assessed as tied to the long-running India-Pakistan rivalry: Islamabad accuses New Delhi of backing the Balochistan insurgency directly, calling the Balochistan Liberation Army an Indian proxy, while India makes parallel accusations over Kashmir. Neither government accepts the other's claims — but access to the province's police data would give either side visibility into exactly that contested relationship.
The clearest evidence of overlap came through the Balochistan Police's Complaint Management System, a public-facing portal used both by officers logging in on the job and by ordinary citizens checking on the status of complaints they'd filed. A China-linked operator planted malware disguised as a routine portal software update — an executable that displayed a convincing "update complete" message to visitors while quietly infecting their device in the background. Because both police personnel and members of the public used the same tampered page, the compromise exposed both groups simultaneously. Researchers found Chinese-language log strings and other developer artifacts embedded in the malicious code, pointing to a Chinese-speaking author.

Rather than name specific groups outright, SentinelLabs organized the activity by the toolsets involved. The China-nexus side centered on PlugX and ShadowPad, two backdoor tools long shared across multiple Chinese state-linked hacking groups, alongside a broader pattern of victims spanning Asian governments and, in one instance, Tibetan organizations based in Taiwan — a victim profile consistent with established Chinese cyberespionage priorities well beyond this one police force. The India-nexus intrusions were tied, with lower confidence, to an actor SentinelLabs tracks as TAG-179, which overlaps with groups other researchers call Bitter and Mysterious Elephant — an assessment partly built on a phishing lure document themed around the repatriation of undocumented foreigners.
The broader trend the researchers flag is a structural one rather than specific to this case: as Pakistan continues centralizing and digitizing its policing systems, aided in part by European modernization programs, it will keep concentrating exactly the kind of high-value data that multiple foreign intelligence services — not necessarily coordinating with each other, and not necessarily even aware of each other's presence — will keep finding worth targeting independently.