Drooid Logo
Back to story perspectives

Full Breakdown

Chinese and Indian-Linked Hackers Target Pakistani Police Agencies

7/10/2026, 1:52:09 PM

Cyberespionage Campaigns Against Pakistani Law Enforcement

Between February 2024 and April 2026, multiple Pakistani law-enforcement bodies were infiltrated in separate hacking operations attributed to groups linked to China and India, according to a SentinelOne analysis released on July 9 2026. The campaigns focused on the Balochistan police, Khyber Pakhtunkhwa police, Islamabad police and the Punjab Safe Cities Authority, compromising network equipment, web servers and applications such as the Balochistan force’s Complaint Management System.

Motivations and Target Value

SentinelOne researchers said the convergence of several state-level cyber-espionage actors against a single nation signals the high value of the targets: “one that holds the government’s internal security picture, what it knows about the threats inside its borders, and how it acts against them.” The report linked Chinese interest to the safety of Chinese nationals working in Pakistan, who have faced deadly attacks, while Indian-linked activity appears tied to ongoing Pakistan–India tensions and broader security postures.

Official Statements and Responses

The Chinese Embassy in Washington, through spokesperson Liu Chang, asserted that China “firmly opposes and combats all forms of cyberattacks in accordance with the law, and does not allow any country or individual to engage in such illegal activities within China’s territory or by using China’s infrastructure.” The Khyber Pakhtunkhwa police issued a statement emphasizing that system security is “a matter of the highest priority” and that “there is no evidence that any core KP police system, network, or critical application has been successfully compromised.” The agency also noted an increase in attempted cyber activity during heightened Pakistan–India tensions, citing one isolated incident of compromised user credentials. The Indian Embassy in Washington declined to comment, and the Islamabad Police, Punjab Safe Cities Authority and Pakistan’s Ministry of Interior did not respond to requests for comment.

Criticism, Gaps and Unverified Claims

SentinelOne’s findings rely on technical indicators but do not confirm successful data exfiltration beyond the isolated credential breach. The lack of comment from several targeted agencies and the Indian embassy leaves the full scope of the operations unclear.

Verbatim Quotes

  • “When multiple cyberespionage actors operate against law enforcement institutions of a single state, the convergence itself is a signal of target value,” — Aleksandar Milenkoski, principal threat researcher, SentinelOne
  • “firmly opposes and combats all forms of cyberattacks in accordance with the law, and does not allow any country or individual to engage in such illegal activities within China's territory or by using China's infrastructure.” — Liu Chang, spokesperson, Chinese Embassy in Washington
  • “there is no evidence that any core KP police system, network, or critical application has been successfully compromised.” — Khyber Pakhtunkhwa police statement
  • “It is pertinent to mention that during the heightened Pakistan–India tensions last year, KP Police experienced an increase in attempted cyber activities,” — Khyber Pakhtunkhwa police statement