Unitel Angola Cyberattack Disrupts Telecom Services Nationwide Hours Before Record IPO

Unitel Angola Cyberattack Disrupts Telecom Services Nationwide Hours Before Record IPO

Executive Summary

In the early hours of 28 July 2026 (~02:00–02:20 local), Unitel S.A.—Angola’s largest mobile operator—detected a cyberattack against its technology infrastructure and activated incident response and containment. The incident caused nationwide disruption of mobile voice, data, internet, and messaging for more than 21 million customers (other coverage cites ~20.8 million; ~76% market share).

Timing: the outage began on OFS settlement day on BODIVA; trading admission was 29 July 2026. The state sold 7.5 million shares (15%) at AOA 40,040, raising AOA 300.3 billion (~$321–329 million); subscription was ~120.72%, with 11,264 new investors. It was the first non-financial BODIVA listing. Trading proceeded despite the outage. No BODIVA/CMC public statement tying the cyber incident to IPO process changes was identified (The Record, 29 July 2026).

Telemetry reported by The Record: Unitel prefixes stayed in RIPE; Cloudflare Radar showed a traffic collapse that was Unitel-specific; POS and digital services were disrupted. Around 3 August, a criminal investigation was opened (Aguinaldo Jaime); BODIVA leadership noted customer and business impact. On 5 August, core mobile and third-party services were restored (ANGOP, 6 August). Around 20 August, nationwide restore was affirmed (wait-tone excepted); forensic work had identified no personal-data compromise to date; automatic compensation was announced. The operator characterized the event as a deliberate attack of extraordinary magnitude and sophistication.

As of 14 September 2026 OSINT: no public indicators of compromise, malware families, named actors, or CVE have been published. This is an availability-focused critical-telecom TPRM narrative under capital-markets pressure—not a product CVE bulletin.

Technical Information

Public reporting describes a deliberate, targeted cyberattack that caused extended nationwide outages. The exact technical mechanism has not been published. Confirmed impact is on voice, data, messaging, POS, and third-party services on Unitel. Other Angolan MNOs and BODIVA trading systems were not reported as affected.

MITRE ATT&CK mappings below are Rescana analytical alignments to the confirmed availability impact only; they are not Unitel-confirmed:

This advisory does not attribute the incident to a named APT. The operator stated around 20 August that no personal-data compromise had been identified to date.

Affected Product Versions

N/A — this is not a CVE or product-build advisory. The named operator is Unitel S.A.

Workaround and Mitigation

For enterprises, banks, and fintechs that depend on Unitel:

  • Inventory hard dependencies (voice, data, SMS OTP, POS, WAN).
  • Maintain alternate-MNO, satellite, and offline-POS playbooks for 24–216 hour outages.
  • Heighten monitoring and assurance asks around IPO and M&A event windows.
  • Close confidentiality and availability findings separately in the supplier file.
  • Require contractual notice SLAs and a high-level RCA even when no IoCs are published.

Do not invent indicators of compromise or APT claims.

Indicators of Compromise

No public indicators of compromise have been published as of this advisory. Treat that as an honest empty set—not as proof of non-compromise—and validate any future indicators before enforcement.

References

Third-Party Risk Bridge: Critical National MNO Dependency

Unitel is a critical national MNO dependency—availability, capital-event risk, and supplier concentration. Refresh the critical-telecom inventory; require event-window monitoring and failover evidence; and keep availability evidence in the supplier file even if no PII compromise is claimed.

Book a demo to see how Rescana maps single-MNO and critical-telecom third-party concentration, and whether event-window monitoring and failover evidence is on file before residual availability risk is closed.

Forward this advisory to your TPRM owner if Unitel, Angolan mobile, or single-MNO dependencies sit in the critical tier.

Contact us / Book a demo

Talk to Rescana about this advisory, or book a demo of the platform.