HomeIntelligenceBrief
BREACH BRIEF🟠 High Breach

China and India Conduct Parallel Espionage Campaigns Against Pakistan’s Balochistan Police

SentinelOne identified two independent nation‑state hacking operations that compromised the Balochistan Police’s complaint‑management portal, stealing criminal, biometric and citizen data. The breach underscores the need for SOC 2 privacy controls, continuous change‑management monitoring, and robust consent/DSAR processes.

LiveThreat™ Intelligence · 📅 July 11, 2026· 📰 therecord.media
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
3 recommended
📰
Source
therecord.media

China and India Conduct Parallel Espionage Campaigns Against Pakistan’s Balochistan Police

What Happened — SentinelOne’s research team uncovered two independent, nation‑state‑linked hacking operations—one Chinese, one Indian—that infiltrated the Balochistan Police’s internal networks from February 2024 through April 2026. Both groups accessed the same systems, exfiltrating criminal‑record, biometric, personnel, and citizen‑complaint data. The Chinese‑linked actors delivered a malicious “portal update” executable that infected users of the police complaint‑management web portal.

Why It Matters for Compliance & Audit Readiness

  • The incident illustrates how a single compromised public‑facing portal can expose both internal law‑enforcement data and citizen‑submitted information, a scenario SOC 2 privacy (CC6.1) and data‑protection controls are designed to prevent and evidence.
  • Continuous monitoring of third‑party applications and rigorous change‑management logs provide the audit‑ready evidence needed to demonstrate that updates were authorized and verified.
  • Mapping this breach to a privacy‑focused capability (CookiePLUS) helps organizations prove DSAR readiness, consent management, and cross‑border data‑transfer safeguards in a SOC 2 audit.

Who Is Affected

  • Government & public‑sector agencies (law‑enforcement, internal security)
  • Citizens whose biometric and complaint data were stored in the compromised portal

Recommended Actions

  • Conduct an immediate forensic review of all web‑portal change‑management processes and validate code‑signing integrity.
  • Map the incident to SOC 2 CC6.1 (Privacy) and CC7.1 (System Operations) controls, collect logs as audit evidence, and update your continuous‑compliance evidence repository.
  • Review and tighten consent and data‑retention policies for citizen‑submitted information; ensure DSAR procedures can address potential requests stemming from the breach.

Source: The Record – China, India ran separate spying campaigns against same Pakistani police force

Technical Notes

  • Attack vector: malicious executable masquerading as a portal update (malware).
  • Tools observed: PlugX and ShadowPad backdoors (Chinese‑linked), custom credential‑stealing modules (Indian‑linked).
  • Data types compromised: criminal records, biometric/fingerprint data, personnel files, citizen complaints, hotel/tenant registrations linked to national IDs.

Source: SentinelOne report, 2024‑2026

📰 Original Source
https://therecord.media/china-india-ran-separate-spy-campaigns-against-same-police-force

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · PrivacyOps · CookiePLUS

A privacy incident is a question about your consent record.

CookiePLUS and Verisq AI Trust Operations keep consent, DSAR, and data-handling evidence continuously ready — so a data-exposure event finds you prepared, not scrambling.

See how Verisq AI Trust Operations handles privacy →