← Back to Pakistan Cyber Tour

Annex 08 — Balochistan Province Deep Intelligence

Pakistan OSINT Operation — 01 March 2026 — balochistan.gov.pk + sit.balochistan.gov.pk — 6.8 MB extracted

6.8 MBData Extracted
149Gov Pages Dumped
1,456Media Items
298Gwadar Candidates
8Commissioners Named

Strategic Context

Balochistan's provincial government is the only remaining accessible provincial .gov.pk portal during wartime — Punjab, Sindh, and KPK are all down. This makes it the highest-value provincial target for intelligence collection.

MetricValue
Area347,190 km² — 44% of Pakistan's total territory
Population~12.3 million (least populated of the four provinces)
Strategic RoleCPEC corridor, Gwadar Port (China's Indian Ocean access)
Security ContextActive BLA insurgency zone; Afghan + Iranian border province
Wartime RoleCritical frontline province during Pakistan-Afghanistan conflict

Single Admin Vulnerability — Critical Finding

One individual administers both the main provincial government website and the Science & IT Department website, creating a single point of failure for Balochistan's entire government web presence.

Cross-Site Admin Correlation

balochistan.gov.pk     → admin_bal      (ID 4)
sit.balochistan.gov.pk → admin          (ID 1)
                          ↓
                    SAME GRAVATAR HASH
                    49d835e800b2f8de9d230f39d1718274e0364b4aff0a72de4bd274d82dbbf38b
Attack Surface: The WordPress REST API at /wp-json/wp/v2/users exposes this gravatar hash for both sites. Because the Gravatar hash is an MD5 of the registered email address, the administrator's email is directly derivable via rainbow tables or breach database lookup — providing a direct phishing target with known identity.
SiteUsernameUser IDGravatar Hashwp-login.php
balochistan.gov.pkadmin_bal449d835e8...f38b (shared)Accessible
sit.balochistan.gov.pkadmin149d835e8...f38b (shared)Accessible (8.3 KB)
sit.balochistan.gov.pksitbalochistango55170d034...9ac (different)

Exploitation Consequences

Government Officials — Divisional Commissioners

Balochistan's eight divisions each have a commissioner serving as the senior civilian administrator for law and order, revenue collection, and disaster management. All eight were named in extracted WordPress content.

DivisionCommissionerGeographic Significance
QuettaShahzaib Khan KakarProvincial capital; military HQ
ZhobMr. Zeeshan JavedAfghan border zone (north)
SibiMr. Zahid ShahGas pipeline corridor
MakranMr. Dawood Khan KhiljiCoastal; Iranian border; Gwadar
NaseerabadMr. Moin ur RahmanAgricultural zone
KalatMr. Muhammad Naeem BazaiCentral highlands
RakhshanMr. Mujeeb Ur Rehman QambraniWestern border; smuggling routes
LoralaiMr. Saadat HassanActive BLA insurgency zone

Gwadar Safe City Project — CPEC Surveillance

The Gwadar Safe City Project is a CPEC-linked surveillance and command-and-control initiative for the port city central to China's Indian Ocean strategy. Job vacancy pages exposed full staffing data.

PMU Gwadar — Technical Positions (298 Candidates Shortlisted)

PositionGradeCandidates Shortlisted
Legal AdvisorPPS 734
Civil EngineerPPS 722
Software EngineerPPS 724
Network EngineerPPS 718
Electrical EngineerPPS 729
Radio Communication EngineerPPS 725
Admin OfficerPPS 664
Account OfficerPPS 655
Incharge Command & ControlPPS 627
TOTAL298

GSC — Shift Operations Roles

PositionGrade
Shift InchargePPS 5
Technical SupervisorPPS 5
Account AssistantPPS 5
Computer OperatorPPS 5
TechnicianPPS 2
Generator OperatorPPS 2

The "Incharge Command & Control" position confirms centralized surveillance operations. Software, network, and radio communication engineers indicate digital C2 capability. The 298 named shortlisted candidates represent the full technical staffing pipeline for a system designed to monitor one of China's most strategically significant overseas infrastructure assets.

Budget & Financial Data (2020–2026)

The WordPress media API exposes direct download URLs for provincial budget documentation spanning six fiscal years.

Each document URL is a direct unauthenticated download link from the WordPress media library, containing original filenames with upload timestamps.

Departmental Legislation Exposed

WordPress pages contain full text or direct references to legislation governing 14 departments:

DepartmentActs/Rules Available
Board of RevenueRevenue rules and land administration
Forest & WildlifeEnvironmental protection regulations
Home & Tribal AffairsSecurity and tribal governance
Industries & CommerceIndustrial policy
IrrigationWater resource management
Law & Parliamentary AffairsLegal framework documentation
LabourEmployment regulations
FoodFood security and distribution
InformationMedia and communications law
ProsecutionCriminal justice framework
Population WelfareFamily planning and welfare
Planning & DevelopmentDevelopment planning framework
Mines & MineralsResource extraction (critical for Balochistan's economy)
Local GovernmentMunicipal governance structure

Dual TLD Confusion — Impersonation Risk

Balochistan operates government services across two top-level domains simultaneously: .gov.pk and .gob.pk. This inconsistency creates a direct impersonation and phishing vector.

URLTLDService
balochistan.gov.pk.gov.pkMain provincial government portal
cm.balochistan.gob.pk.gob.pkChief Minister complaint portal
digibizz.gob.pk.gob.pkYouth freelancing program
btevta.gob.pk.gob.pkTechnical/vocational education
estamping.gob.pk.gob.pkLegal document digitization
finance.gob.pk.gob.pkFinance department (AI chatbot)
homedept.balochistan.gob.pk.gob.pkHome department

Citizens conditioned to trust .gob.pk domains for Balochistan services are potentially unable to distinguish them from typosquat domains. A threat actor registering balochistan.gob.pk.example.com or similar could intercept citizen interactions.

WordPress Content Summary

Metricbalochistan.gov.pksit.balochistan.gov.pk
Pages14930
Posts128
Media Items1,297 (4.6 MB metadata)159
Categories54
CMS/PluginsWordPress + ElementorWordPress
wp-login.phpAccessibleAccessible (8.3 KB)
API Schema235 KB247 KB

robots.txt Note

The balochistan.gov.pk robots.txt explicitly blocks AI crawlers including ClaudeBot, GPTBot, Google-Extended, Bytespider, and Applebot-Extended. It also contains Cloudflare Managed Content signals: ai-train=no. Despite this, the WordPress REST API is completely unprotected — robots.txt applies only to polite crawlers, not targeted API enumeration.

Risk Assessment Summary

Risk FactorRatingDetail
Single admin across two sitesCRITICALOne compromised account = 2 government sites down/owned
wp-login.php accessible (both)HIGHDirect brute-force / credential-stuffing target
298 Gwadar candidates exposedHIGHCPEC surveillance personnel pipeline data
8 divisional commissioners namedHIGHSenior civilian administrator directory
Budget documents accessibleHIGHProvincial financial strategy and allocations
Dual TLD confusionMEDIUMImpersonation/phishing surface for citizens and officials
Legislation content exposedMEDIUMRegulatory framework across 14 departments