CyberSecurity

Hackers Turn Balochistan Police Portal Into a Weapon in Multi-Group Espionage Campaigns

Published

on

A Portal Under Siege

For more than two years, a quiet war has been waged inside the digital infrastructure of Pakistan’s law enforcement agencies. The target: the Balochistan Police portal, a web application that processes criminal records, citizen data, and internal police communications. According to cybersecurity researchers, at least two distinct threat groups — one suspected to be aligned with China, the other with India — have been exploiting vulnerabilities in this portal since February 2024.

The attacks didn’t stop there. The campaign, which ran through April 2026, also hit several other Pakistani law enforcement bodies. But the Balochistan Police portal was the crown jewel: a single compromised server that gave hackers a window into sensitive police and citizen data, including criminal records and personal identification details.

Who’s Behind the Attacks?

The researchers, who published their findings after months of forensic analysis, identified two primary clusters of activity. The first, linked to a China-aligned group known as Mandiant‘s tracked APT10, targeted the portal’s web application layer. The second, tied to an India-aligned group, focused on exfiltrating data through a backdoor planted in the same system.

Both groups appear to have operated independently, but they shared a common goal: harvesting intelligence from Pakistan’s law enforcement databases. The Balochistan Police portal — originally designed to streamline case management and record-keeping — became a battleground.

How the Hackers Operated

The attackers didn’t rely on zero-day exploits or sophisticated malware. Instead, they used a combination of SQL injection, cross-site scripting, and credential theft — classic techniques that remain effective because many government portals still run outdated software.

Once inside, the China-aligned group installed a custom webshell that allowed them to browse the database at will. The India-aligned group, meanwhile, used a different backdoor that focused on silently copying files to external servers. Both groups maintained persistent access for months, exfiltrating data in small batches to avoid detection.

The Data at Risk

The compromised servers contained a wide range of information:

  • Criminal records and case files
  • Personal identification data of citizens (CNIC numbers, addresses, phone numbers)
  • Internal police communications and reports
  • Login credentials for other government systems

This kind of data is a goldmine for intelligence agencies. It can be used for blackmail, recruitment of informants, or simply to map out the inner workings of a provincial police force.

Why the Balochistan Police Portal?

Balochistan is Pakistan’s largest province by area, but also its most volatile. It shares borders with Iran and Afghanistan, and has been the site of a long-running insurgency. For external intelligence services, access to police data from this region provides a window into security operations, counter-insurgency efforts, and the movements of both security forces and militant groups.

“The Balochistan Police portal is not just a database — it’s a strategic asset,” said one cybersecurity analyst familiar with the investigation. “Compromising it gives a foreign actor real-time insight into how the state operates in a conflict zone.”

Lessons for Law Enforcement

This campaign is a stark reminder that government portals are often the weakest link in national security. While much attention goes to securing military networks or nuclear facilities, local police databases are frequently left running on outdated systems with minimal cybersecurity staffing.

For Pakistan’s law enforcement agencies, the path forward involves more than just patching the Balochistan Police portal. It requires a fundamental shift in how police data is stored, accessed, and monitored. That means regular security audits, multi-factor authentication, and — crucially — training for officers who may not realize they’re handling intelligence-grade information.

The researchers noted that both threat groups remain active. The portal has been patched, but the underlying vulnerabilities in Pakistan’s law enforcement IT infrastructure are far from resolved.

What Happens Next?

For now, the Balochistan Police portal is back online, but the damage is done. The exfiltrated data is likely already being analyzed by foreign intelligence agencies. The question is not whether it will be used, but how.

This case also highlights the growing trend of multi-group cyber espionage, where rival nations exploit the same target without coordinating — or even knowing about each other. It’s a dangerous new normal for law enforcement agencies worldwide.

As one researcher put it: “Your portal is never just your portal. Once it’s on the internet, it’s everyone’s portal.”

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version