Thursday, August 6, 2026

angola foste / take it

 


Breaking cybersecurity news, news analysis, commentary, and other content from around the world, with an initial focus on the Middle East & Africa, the Asia Pacific, Europe, and Latin America.

Angola's Largest Telco Breached Hours Before IPO

Unitel, Angola's dominant mobile operator, continues to recover from a cyberattack that caused outages the day of the government-owned telco's public offering.

Robert Lemos,Contributing Writer

August 5, 2026

3 Min Read
A SIM cards with the Angola flag.
Source: Novikov Aleksey via Shutterstock

Angola's top mobile telecommunication provider, Unitel, continued to recover this week from a cyberattack that hit the operator on July 28, the same day the government closed a public offering for 15% of the carrier.

The purported attack caused widespread outages across the telecom's networks — the mobile operator restored 2G and 3G service on July 30 and SMS service on July 31, but its 4G and 5G — as well as some digital services — reportedly continue to have problems. In a statement in Portuguese posted to Facebook on Aug. 1, Unitel called the incident a "deliberate and malicious cyberattack on its technological infrastructure."

"Unitel will keep the market and investors informed of any relevant developments, in compliance with the legal rules to which it is bound as a publicly traded company, and remains engaged in the complete normalization of its services over the coming days," the company said in its statement.

Related:AI Agent Drives Espionage Attack on Thai Ministry of Finance

Unitel is the latest telecommunications provider in Africa to be hit with a disruptive cyberattack. In April 2025, mobile operator MTN Group, which operates in nearly a score of markets across Africa and the Middle East, suffered a breach that potentially exposed the data of its more than 200 million customers. In late 2024, cyberattackers successfully compromised Telecom Namibia, leaking customer information online in an apparent ransom scheme.

Unitel's Really Good, Really Bad Day

The cyberattack against Unitel kicked off at 2:20 am on July 28, the same day that the company began trading on the Angola BODIVA stock exchange. The Angola government had auctioned off 7.5 million shares of the company for a 15% stake, taking in more than 300 billion kwanzas, or about $320 million. Unitel's stock shot up almost 25% that day, but declined nearly 13% the next.

The danger for the mobile operator is that the disruption of services will send customers to seek out other mobile providers, even though Unitel commands a hefty majority of the market, with estimates of its share varying between 66% and 76%. While the majority state-owned operator has little competition, consumers and business in Africa rely on mobile networking for digital services, making the restoration of services a priority.

On Aug. 4, for example, business people in the capital of Luanda had to turn to cash because some popular financial services, such as Multicaixa Express, no longer worked, according to a Ver Angola news report. In 2025, Multicaixa Express accounts for 62% of financial transactions over networks, the report stated.

Related:Brazilian Banking Trojan Actively Spreading in Portugal

Typically, recovery from major telecom breaches requires anywhere from 24 hours to several days, depending on scope of the compromise and the preparedness of the operator. Because budgets are tight in most African regions, organizations should consider compromises inevitable and work to limit the damage through reducing the attack surface, says Kevin Cardwell, chief information officer at Cybastion, a digital services and cybersecurity provider that has signed an MOU to fast track Angola's digitalization and cybersecurity.

"The countries [need to] identify where their high risk areas are at, and then ... mitigate the risk," he says. "If you do take that hit ... you can isolate that damage, and the attackers only take out, maybe, that segment."

Reduce Attack Surfaces

Overall, Africa's heavy reliance on mobile infrastructure often exposes a different set of cybersecurity vulnerabilities that may not be addressed by the security models for fixed-line infrastructure, Cardwell says. The Unitel attack shows the dangers of insufficient network segmentation in critical infrastructure as well, he adds.

"You need an entire process, one that starts with evaluating your network and knowing where your risk points are at and then mitigating the risk points by trying to reduce your attack surface to the outside of an attacker," he says.

Related:Ransomware Attack Puts a Chill on Japanese Frozen-Food Chain

Critical infrastructure providers such as Unitel need to have practiced processes to quickly get back up and running in the event of a cyberattacks, says Eric Howard, a malware researcher with cybersecurity firm ESET.

"Upstream infrastructure could be separated between services, which would make it possible for some services to remain online," Howard says, although upstream core issues including regional routing, authentication bottlenecks, or internal backend services could remain disrupted and block access.

About the Author

Robert Lemos

Contributing Writer

Rob is an award-winning, veteran technology journalist of more than 30 years, reporting on global cybersecurity issues, the latest offensive and defensive technologies, malware incidents, cyber conflict, and AI's impact on software and cybersecurity.

A former research engineer, Rob has written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. He has received five awards for journalism, including Best Deadline Journalism (Online) in 2003 for his coverage of the Blaster worm. Rob also analyzes data on various trends using Python and R for both his reporting and his clients. Recent reports include analyses of the shortage in cybersecurity workers, annual vulnerability trends, and annual threat reports.

Rob holds degrees from Cornell University in Electrical Engineering and Computer Science (double major).

Informa

Copyright © 2026 TechTarget, Inc. d/b/a Informa TechTarget. This website is owned and operated by Informa TechTarget, part of a global network that informs, influences and connects the world’s technology buyers and sellers. All copyright resides with them. Informa PLC’s registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. TechTarget, Inc.’s registered office is 275 Grove St. Newton, MA 02466.




No comments:

Post a Comment