CDA Billing System Hacked

A sophisticated outside attack, or a preventable failure of basic cyber hygiene?

Unknown hackers breached the Capital Development Authority's property and water billing system in Islamabad and demanded a ransom in Bitcoin, knocking the online bill-payment service offline for three days in mid-June. The CDA says its backup data is secure and recovery is under way.

What happened
  • Unknown hackers breached the Capital Development Authority (CDA) property, conservancy and water billing system in Islamabad and demanded a ransom in Bitcoin, reported on 19 June 2026.
  • The online "Pay your bills online" service was down for three consecutive days, during the fiscal-closing month when residents settle property and tax dues. The main CDA website stayed up.
  • CDA spokesperson Shahid Kiani says the attack hit billing for property, conservancy and water charges, but backup data is secure, consumer funds are safe through authorised banking channels, and recovery teams from the revenue directorate, the IT department and the vendor NRTC are restoring service.
  • A CDA IT official, quoted in reporting, says the authority and NRTC failed to keep system backups for the previous six months — a direct contradiction of the official line.
  • It is not disclosed how much ransom was demanded, whether it will be paid, or whether the stolen records have been published on the dark web.
  • This is the second major breach since 2024, when Indian hackers put CDA data on the dark web, after which the board authorised external cybersecurity contracts.
How it's framed

The CDA: an outside attack, the data is safe

The authority's official line, given by its spokesperson. This was a cyberattack by unknown hackers on the billing system, but the records are intact on secure backup servers, consumer money is safe in the banking channels, and teams from the revenue directorate, the IT department and the vendor NRTC are restoring service. On this read the breach is a containment story, not a loss.

CDA is currently recovering all billing-related data from its secure backup servers to ensure nothing is lost.
Shahid Kiani, CDA spokesperson (Dawn)

Critics: a preventable lapse, the second in two years

The accountability read, carried by reporting that quotes inside the authority. An IT official says the CDA and its vendor NRTC had not kept system backups for the previous six months, leaving the body exposed, and this is the second serious breach since Indian hackers put CDA data on the dark web in 2024. On this read the question is not who attacked but why a public revenue system was this easy to take down, twice.

...failed to maintain system backups for the preceding six months.
A CDA IT official, via The Current
Each column is a narrative. A source sits under the framing its coverage advances here, not under its usual label.
the conversation

Everyone agrees on the basics: the billing system went down for three days in the fiscal-closing month, a Bitcoin ransom was demanded, and residents could not pay online. The fight is over the backups. The CDA says its duplicate records are safe and nothing is lost. An official inside the same organisation says no backups were kept for six months. Both cannot be fully true, and which one is becomes the whole story: a clean recovery, or a basic failure being smoothed over. The louder voice right now is the official reassurance. What it leaves out is who is accountable for a public revenue system being breached twice in two years, whether the ransom will be paid, and whether the property and water records of Islamabad residents are already on the dark web.

The sources

Coverage is mostly domestic, with one Gulf pickup; no international wire (Reuters, AP, Xinhua) ran it, and no Reddit or X reaction thread surfaced on a 30-day social check, so there is no citizen-framing layer yet. There is also no published CDA statement page, no registered FIR, and no figure for the ransom. Each outlet is its own vantage, not a neutral baseline.

Pakistani tech press2 sources
The specialist outlets that follow cyber incidents; they carry the backup-failure claim in more detail.
ProPakistani"Hackers Demand Ransom in Bitcoin After Breaching CDA Billing System"TechJuice"Hackers Breach CDA Billing System Demanding Bitcoin Ransom"
International1 source
The lone foreign pickup; it echoes the official containment framing and adds the recovery timeline (service expected back by Friday), not a new narrative.
Gulf Today (UAE) — "Hackers breach Pakistan's CDA billing system, demand ransom in bitcoins"