Briefing

Sustained Cyber‑Espionage Against Pakistani Law Enforcement by China‑ and India‑Aligned Actors

security
by [email protected] (The Hacker News) ·

Perform a comprehensive security assessment of all web applications, enforce least‑privilege access, enable MFA, and monitor logs for suspicious activity.

What to do now

Conduct a full security audit of all web applications handling police and citizen data, enforce least‑privilege access, enable MFA, and monitor logs for suspicious activity.

Summary

Cybersecurity researchers have disclosed details of sustained cyber‑espionage activity against several Pakistani law‑enforcement organisations undertaken by suspected China‑ and India‑aligned threat actors between February 2024 and April 2026. At Balochistan Police, the compromised assets included servers hosting web applications that manage police and citizen data, such as criminal and civil records. The attackers used compromised credentials and malware to gain persistence and exfiltrate sensitive information. The espionage campaigns exploited vulnerabilities in web‑application security and leveraged social‑engineering tactics. The attacks involved data exfiltration and surveillance of law‑enforcement personnel. The incident highlights the need for stronger security posture in law‑enforcement systems. Immediate action is required to secure servers, enforce MFA, and monitor for suspicious activity.

Key changes

  • Sustained cyber‑espionage activity against Pakistani law‑enforcement organisations from Feb 2024 to Apr 2026
  • Suspected China‑ and India‑aligned threat actors are responsible
  • Compromised assets included servers hosting web applications that manage police and citizen data
  • The Balochistan Police servers were targeted, exposing criminal and citizen data
  • Attackers used compromised credentials and malware to gain persistence and exfiltrate sensitive information
  • The espionage campaigns involved data exfiltration and surveillance of law‑enforcement personnel
  • The attacks exploited vulnerabilities in web‑application security and leveraged social‑engineering tactics
  • The incident highlights the need for stronger security posture in law‑enforcement systems

Affects

none

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting