Hackers Weaponize Balochistan Police Portal in Multi‑Group Espionage Campaign
What Happened — Researchers uncovered a sustained espionage operation targeting Pakistani law‑enforcement agencies. Between February 2024 and April 2026, threat actors aligned with China and India compromised servers that host the Balochistan Police web portal, gaining access to applications that store criminal records and citizen‑identifying data.
Why It Matters for Compliance & Audit Readiness
- The incident exemplifies a failure of access‑control governance—a core SOC 2 Trust Services Criterion (CC6.1). Continuous monitoring of privileged access and evidence of least‑privilege enforcement are essential to demonstrate readiness.
- Demonstrable audit evidence (e.g., privileged‑account logs, MFA enforcement) can mitigate the impact of a breach and satisfy auditors that the organization maintains a defensible control environment.
- Verisq’s SOC 2 Access Controls capability provides automated collection of access‑control evidence, helping you prove that policies are enforced and that any deviation is flagged in real time.
Who Is Affected — Government & public‑sector agencies (law enforcement), citizen data custodians.
Recommended Actions
- Conduct an immediate privileged‑access review of all portal‑related accounts; enforce MFA and least‑privilege principles.
- Deploy continuous monitoring for anomalous privileged activity and retain immutable logs for audit purposes.
- Update incident‑response playbooks to include espionage‑specific indicators (e.g., unusual data‑exfiltration patterns).
- Perform a SOC 2 access‑control readiness assessment to identify gaps and collect evidence for auditors.
Source: The Hacker News
Technical Notes
- Attack vector: suspected credential compromise and exploitation of unpatched web‑application servers (exact CVEs not disclosed).
- Data types exposed: criminal records, personal identifiers, and other citizen‑level information.