Unknown hackers have breached the Capital Development Authority’s (CDA) digital property and water billing network, demanding a ransom payment in Bitcoin. The cyberattack has paralyzed the civic body’s revenue infrastructure for three consecutive days during June, the critical fiscal closing month when a high volume of residents attempt to settle outstanding tax and property liabilities.

The compromised infrastructure holds sensitive data regarding Islamabad’s urban property records and conservancy charges.

The perpetrators have threatened to leak this information onto the dark web if the administrative body refuses to meet the cryptocurrency ransom demands. To counter the breach, the CDA revenue directorate, the IT department, and the authority’s technical vendor, National Radio & Telecommunication Corporation (NRTC), have deployed teams to reclaim the network.

An official representing the CDA revenue directorate highlighted the operational impact of the timing, stating, “Since it is June (closing month), and a large number of people clear their property and tax dues this month, our systems have been hacked for the last three days”.

The official expressed expectations that technical teams would fix the issue by Friday.

The disruption has directly affected local residents, who reported an inability to process tax payments because internal digital links are down. While the primary CDA portal remains visible to visitors, the specific “Pay your bills online” utility became completely unavailable.

Structurally, the CDA manages data for all allotted commercial and residential plots within urban limits, while rural property records are maintained separately by the district government’s revenue department.

The incident marks the second major digital security failure for the authority in recent years. In 2024, an online breach attributed to Indian hackers resulted in CDA data being published on the dark web.

That intrusion disrupted the portal for several days and led to security interventions from the Prime Minister’s Office. Consequently, the CDA board had authorized the emergency hiring of an external cybersecurity firm under a running contract to monitor and protect its digital infrastructure.

The current breach has exposed internal friction regarding the agency’s technical readiness. An official within the IT division claimed that the CDA and NRTC had failed to maintain system backups for the preceding six months. CDA Spokesperson Shahid Kiani explicitly denied this claim, countering that the authority’s duplicate records are entirely secure.

“CDA is currently recovering all billing-related data from its secure backup servers to ensure nothing is lost. Technical teams are working, and the online system will be made functional again very soon,” Kiani stated. He added that consumer funds remain secure, noting, “All online payments made so far are completely safe as they were processed through the 1-Link system or other authorised online banking channels”.