According to SentinelLabs, the research arm of the security firm SentinelOne, two suspected state-linked espionage operations — one assessed as China-nexus and the other as India-nexus — separately targeted the same Pakistani police force over more than two years, in research published on 9 July 2026. Before anything else, the framing matters: these are the findings and assessments of a private security firm, not adjudicated facts or admissions. China has denied involvement, India did not comment, and the affected police force did not respond to questions.
What the report describes
SentinelLabs says the two sets of activity were parallel and unconnected, running between February 2024 and April 2026, and that in some cases the two nexuses breached the very same systems. The primary target was the Balochistan Police, the force serving Pakistan's southwestern province of the same name, a region with a long-running separatist insurgency. The report also identifies activity against the Khyber Pakhtunkhwa Police, the Islamabad Police and the Punjab Safe Cities Authority.
Police networks make a particular kind of target, and the report is precise about why: they concentrate a state's internal-security data in one place. SentinelLabs reports that the compromised systems contained biometric and fingerprint records, criminal case files, personnel records, hotel and tenant registrations tied to national identity records, and citizen complaints. SentinelLabs further assesses that one suspected China-nexus actor compromised a web application used by both police personnel and members of the public, deploying custom implants disguised as a routine portal update — which placed both user groups within the operators' reach. This article does not reproduce the technical indicators, implant details or command-and-control infrastructure described in the report.
The attribution, kept at the level the researchers stated it
This is where discipline matters, because the subject is three rival states. SentinelLabs frames its findings as suspected, nexus-level attribution, not proof of state direction. On motive, the firm assesses — and assessment is the operative word — that the China-linked interest was driven primarily by the safety of Chinese nationals in Pakistan, many connected to the China-Pakistan Economic Corridor, who have been targeted in deadly attacks; on this reading, gaining independent visibility into the security environment matters more than trusting a partner's assurances. For the India-linked activity, concentrated on Balochistan, the report judges the adversarial security relationship between the two countries to be the most likely driver. The firm also says it connected one malware sample to a Chinese-speaking developer on the basis of coding artefacts and development-environment indicators. Each of these is an analytical judgement by SentinelLabs, and should be read as one.
The responses belong right here, not buried at the end. A spokesperson for the Chinese Embassy in Washington rejected the findings, saying China opposes and combats all forms of cyberattacks and does not permit such activity from its territory or infrastructure. The Indian Embassy did not answer questions about the analysis. The Balochistan Police did not respond to a request for comment. Cyber-attribution is inherently probabilistic and can be imitated, and none of this has been tested in any court or confirmed by any government — so the accusations and the denials sit side by side, which is the honest way to leave them.
Why the convergence is the interesting part
Set aside the question of who, which may never be settled publicly, and a genuinely useful observation remains. When multiple independent espionage actors converge on the same institution, the convergence itself is a strong indicator of the target's intelligence value, regardless of which actor ultimately conducted each operation. A provincial police force is not an obvious high-profile target, but the data it holds — identity records, biometrics, movement and registration data, the internal workings of an internal-security apparatus — is exactly what a state needs to assess the security environment in a contested region, whether its concern is protecting its nationals or understanding an adversary. That is the transferable lesson for defenders everywhere: institutions that aggregate identity and internal-security data are high-value intelligence targets regardless of their apparent profile, and the compromise of a citizen-facing application turns routine public services into a collection surface. The specifics here are geopolitical and contested; the underlying pattern is not.
Key Takeaways
SentinelLabs reported on 9 July 2026 that suspected China-nexus and India-nexus groups separately targeted Pakistani law enforcement between February 2024 and April 2026, sometimes hitting the same systems.
The main target was the Balochistan Police; other targets included the Khyber Pakhtunkhwa Police, Islamabad Police and Punjab Safe Cities Authority.
SentinelLabs reports the compromised systems contained biometric records, criminal files, personnel data and identity-linked registrations; it assesses that a suspected China-nexus actor used implants disguised as a portal update on a citizen-facing app.
The attribution and motives are SentinelLabs' assessments, not proven facts; China denied involvement, India did not comment, and the police force did not respond.
The durable lesson is target selection: institutions aggregating identity and internal-security data are high-value espionage targets regardless of profile, and citizen-facing apps widen the exposure.