VERSE PRESS

Crypto News, Global First.

Islamabad's Civic Billing System Hit by Cyberattack, Hackers Demand Bitcoin Payment

Unknown attackers breached the Capital Development Authority's billing infrastructure during Pakistan's fiscal year close, leaving large numbers of residents unable to pay property and water dues online for at least three days.

|

Hackers broke into the Capital Development Authority's property and water billing system in Islamabad and demanded a ransom in Bitcoin, the Pakistani government body confirmed on Thursday. The attack, reported by Dawn on June 19, knocked the CDA's online payment portal offline and compromised data covering residential and commercial property charges, conservancy charges, and water billing records. Attackers are threatening to publish the exfiltrated data on the dark web unless their demand is met.

The ransom amount has not been publicly disclosed. At current market prices, Bitcoin is trading between $63,000 and $65,000 per coin, meaning even a conservative demand of one to two BTC would translate to $63,000 or more. No on-chain transaction has been publicly attributed to the attack.

The timing appears deliberate. June marks the close of Pakistan's fiscal year, a period when large numbers of Islamabad residents and businesses settle property taxes and outstanding dues. A CDA Revenue Directorate official told Dawn: "Since it is June (closing month), and a large number of people clear their property and tax dues this month, our systems have been hacked for the last three days." The three-day outage created direct financial risk for residents with outstanding balances during one of the busiest payment periods of the year.

CDA spokesperson Shahid Kiani pushed back against reports that six months of billing data had no backup. "CDA is currently recovering all billing-related data from its secure backup servers to ensure nothing is lost," he said, adding that technical teams expected to restore the online system soon. A separate unnamed official, however, told Dawn that neither the CDA nor its IT vendor, the National Radio & Telecommunication Corporation (NRTC), had backup data covering the past six months. That contradiction remains unresolved. Kiani separately confirmed that prior online payments were not at risk, because those transactions were processed through 1-Link, Pakistan's interbank payment switch connecting more than 37 banks and certified under PCI DSS security standards. The billing backend and the payment processing layer appear to have been separate systems.

NRTC, the vendor named in the recovery effort, is a state-owned enterprise under Pakistan's Ministry of Defence Production. Its involvement raises questions about security segmentation: a defence-linked government supplier was managing civilian billing records without verified backup integrity. The CDA had already hired a private cybersecurity firm following a 2024 incident in which Indian hackers breached its public website and posted data online, an episode serious enough to draw direct attention from Pakistan's Prime Minister's Office. The remediation apparently did not cover the billing backend, or the billing backend remained a separate and unprotected attack surface.

The attack fits a pattern of escalating cyber pressure on Pakistani public infrastructure. Kaspersky recorded 5.3 million on-device cyberattacks in Pakistan in the first nine months of 2025 alone. Seven advanced persistent threat groups have been specifically identified as targeting Pakistani government, telecoms, financial services, critical infrastructure, and defence sectors. In August 2025, the Blue Locker ransomware gang hit Pakistan Petroleum Limited, prompting Pakistan's national cybersecurity authority to issue high-alert advisories to 39 key government ministries and institutions. The Babuk2 group separately claimed to have taken 120 gigabytes of data from Parliament House and listed NADRA, the national identity database, as a victim. A 2024 NADRA breach had already exposed credentials belonging to 2.7 million Pakistani citizens.

The closest structural comparison to the CDA attack is the 2020 Netwalker ransomware strike against K-Electric, Pakistan's largest private power utility. In that case, attackers demanded $3.85 million in Bitcoin, escalating to $7.7 million after a week, and stole data before encrypting systems. Like the CDA incident, K-Electric's billing and online services went down while core operations continued.

The incident carries implications beyond the billing disruption itself. Bitcoin's role as a ransom currency will likely add pressure to an already cautious Pakistani regulatory environment; the State Bank of Pakistan has historically warned against crypto adoption, and high-profile government ransom demands provide straightforward political cover for restrictive policies. The more systemic concern is the procurement model. Until Pakistan's public sector agencies enforce mandatory security audits on IT vendors handling citizen data, regardless of those vendors' defence affiliations, the attack surface will remain wide open. NRTC has not issued a public statement. Neither has Pakistan's national cybersecurity response authority, NCERT, nor NCCS, the National Cyber Crime and Security body.