New research from SentinelOne shows that cyberespionage groups linked to both China and India spent more than two years quietly breaking into Pakistani law enforcement networks, with Balochistan Police getting hit from both sides of the region’s rivalries.

According to the security firm’s SentinelLabs threat intelligence unit, the intrusions ran from February 2024 through April 2026 and targeted several Pakistani police organizations, with Balochistan Police absorbing the bulk of the activity. The attackers reached servers tied to biometric databases, criminal case files, personnel records, and citizen-facing systems.

The researchers grouped the intrusions into four clusters based on the malware and infrastructure involved: PlugX, ShadowPad, Cobalt Strike, and Remcos. They cautioned that clusters built on shared or commodity malware — unlike the Remcos activity, tied to a single tracked actor — may each involve more than one operator.

What stands out is the presence of China-linked cyberspies inside a police force belonging to one of Beijing’s closest regional partners. SentinelLabs frames the likely motive as self-interest.

Specifically, Chinese nationals working on Belt and Road projects in Pakistan have been repeatedly targeted in attacks tied to Baloch separatist militants, and Chinese officials have openly criticized Islamabad’s ability to protect them. Gaining direct access to Pakistani police data would allow Beijing to evaluate the threat on its own.