Summary
- UNITEL says a cyberattack detected at 02:20 local time on 28 July disrupted mobile voice, data and internet services across Angola.
- A 30 July market notice said phased restoration began at 11:45 on 29 July and had reached partial service in 13 named provinces.
- The notice said SMS remained unavailable and work continued in the remaining provinces, so its status was recovery in progress rather than full normalisation.
- UNITEL said fixed fibre and wireless services remained operational, preserving one access layer without proving that every fixed user or dependent service was unaffected.
- Twilio still classified SMS delivery delays and failures to UNITEL subscribers as identified and unresolved at 05:26 UTC on 31 July.
- UNITEL has not disclosed an attacker, vector, malware, data-exposure assessment, restoration percentage or final recovery time; its targeted-attack hypothesis remains an investigation, not attribution.
Recovery needs a matrix, not a single green status
The market notice gives three useful dimensions: service, place and time. Mobile voice, mobile data and internet were disrupted nationally. Restoration began at a stated time. Thirteen provinces had some degree of service when the notice was issued. SMS was not yet available, and work continued in other provinces. That is a recovery matrix, even though the company has not published it as one.
Treating the network as simply “up” would discard the distinctions that matter to customers. A person may be able to place a call but not receive an authentication message. A business router may attach to the mobile network while an application times out. A province described as partially restored may contain functioning urban cells and impaired remote sites. Availability can also alternate as engineers reconfigure systems and return traffic to repaired paths.
UNITEL should publish a compact operating table for each province and major service. It need not reveal sensitive topology. It can show voice-call setup success, mobile-data session success, SMS submit and delivery rates, affected customer share and the time each measure returned to a defined threshold. The threshold matters: “traffic is flowing” is not the same as “service has reached its normal error rate”.
The table should include update time and direction. A 90% recovery that is improving is different from a 90% recovery that has stalled. It should also say when a province is being measured through a reduced-capacity configuration. Customers need to know whether apparently restored access is likely to remain stable during the evening peak.
SMS is a small interface with large downstream consequences
The company’s own notice separated SMS from voice and data. Twilio’s status page supplies an external view of that boundary. At 05:26 UTC on 31 July, Twilio still said customers could experience SMS delays and failures when sending to UNITEL subscribers, that the cause had been identified and that work was continuing. The incident had no resolved timestamp.
That signal is narrow. It covers Twilio-originated delivery to UNITEL, not every message path on the operator’s network. It does not establish that all provinces, all message types or all subscribers were failing. It also does not prove that UNITEL alone caused every delay. It does, however, show why a mobile-network recovery cannot be inferred from voice and data returning.
SMS often sits inside processes that are invisible until they fail. Banks send one-time passwords. Employers, clinics and public bodies send alerts. Platforms use messages for account recovery, transaction confirmation or fraud checks. A delayed message can convert a functioning data connection into an unusable service because the customer cannot cross the identity step.
Recovery reporting should therefore measure more than whether the short-message centre accepts traffic. Delivery latency, failure codes, queue depth, retries and the health of inter-operator and international routes are the relevant outcomes. The operator should also distinguish person-to-person messages from application-to-person traffic. A consumer test between two handsets may look healthy while enterprise notification routes remain degraded.
The fixed network created a second path, not immunity
UNITEL’s notice said fixed services delivered over fibre and wireless infrastructure remained operational during the incident. That is operationally important. It suggests that the event did not remove every UNITEL access layer at once and that some businesses and public institutions could retain connectivity through fixed links.
The claim must be kept within its boundary. “Remained operational” does not disclose traffic growth, packet loss, regional reach, customer faults or the condition of upstream applications. It does not mean every mobile-dependent workflow had a fixed substitute. A shop using a mobile payment terminal, a field worker or a household without fixed access could not simply move to fibre.
The value of the fixed network is best understood as architectural diversity. If mobile and fixed services use sufficiently separate access, control and operational systems, one can carry essential traffic while the other is repaired. If they share identity, DNS, backbone, management tools, power or security administration, the independence may be smaller than it appears.
After recovery, UNITEL should describe the fault domains without exposing attack-sensitive detail. Which control layers were common? Which remained independent? Did fixed traffic rise, and was capacity sufficient? Could large customers move traffic automatically, or did they require manual changes? Those answers would help enterprises decide whether a second UNITEL service is genuine redundancy or merely another access product resting on the same critical systems.
Containment, restoration and normalisation are different milestones
TechAfrica News reports that UNITEL described the attack as under control and said response and containment protocols had been activated. Containment means engineers believe the harmful activity has been stopped, isolated or bounded. It is a security state. Restoration means services are being brought back. It is an operating state. Normalisation means service quality, capacity and reliability have returned to a defined baseline. It is an outcome that requires measurement over time.
These states can move in different directions. A company may contain an intruder while customer databases, routing systems or messaging platforms remain offline for validation. It may restore a service and later withdraw it after instability appears. It may operate safely at reduced capacity while forensic work continues. Combining the three into one word encourages premature reassurance.
UNITEL should timestamp each milestone and define who approves it. The security team may determine that malicious access is no longer active. Network operations may approve a service restart. Business owners may verify transactions and customer journeys. An independent review may later decide whether eradication and control changes were adequate.
The final recovery notice should not merely say that all services are back. It should state the observation period, the relevant error and latency thresholds, unresolved limitations and any routes still under monitoring. If temporary controls restrict features or capacity, customers should know. A visible recovery discipline would be more valuable than a confident adjective.
Listing-day suspicion is not attack attribution
UNITEL reportedly said it was investigating whether the cyberattack was deliberate and targeted, noting that it occurred close to the admission and trading of its shares. Timing is a legitimate investigative lead. It is not evidence of who acted, why they acted or whether the stock-market event caused the incident.
Many facts required for attribution are absent. UNITEL has not published an initial-access vector, malicious infrastructure, malware family, ransom demand, affected accounts or forensic indicators. It has not said whether data was accessed or removed. No law-enforcement or regulator conclusion is cited. The public record therefore supports “cyberattack” because the operator uses that term, but not a more specific narrative.
The distinction protects both accuracy and the investigation. Prematurely assigning a motive can steer attention away from other hypotheses, encourage political interpretation and expose innocent parties to suspicion. It can also confuse a market-disclosure obligation with a completed forensic report.
The company can improve the evidence without compromising the case. It can say whether the incident began through identity compromise, an exposed service, a supplier or another broad class once that conclusion is stable. It can disclose whether customer data confidentiality was affected, whether credentials need to be changed and whether regulators or police were notified. If those facts remain unknown, “assessment continuing” is the correct status.
A national operator owes different audiences different recovery evidence
Reuters reported that UNITEL serves more than 21 million customers. At that scale, a single notice cannot satisfy every operational need. Consumers need clear service and safety guidance. Enterprises need dependency and failover information. Public bodies need continuity contacts and priority-restoration arrangements. Investors need material effects, costs and control changes.
Consumer communication should identify working channels, safe account-recovery methods and any need to retry messages or transactions. It should warn against fraud if attackers exploit outage confusion, but it should not invent a data breach that has not been established. Updates need stable timestamps so readers can distinguish current information from screenshots of older notices.
Enterprise customers need an incident bridge or authenticated feed. They should receive region and service status, expected next updates and advice on routing traffic. If SMS is used for authentication, the operator and customers should activate alternative methods that do not weaken security. Help desks need consistent fault codes rather than a generic instruction to wait.
Investors need a different ledger: customer credits, restoration expense, capital replacement, lost revenue, regulatory exposure and insurance treatment. None should be estimated publicly without evidence, but the categories should be addressed when material. The proximity to the share listing raises the importance of disciplined disclosure, not the licence to speculate about motive.
The post-incident review must test dependencies and evidence retention
The first technical question is not “which product should be bought?” It is whether UNITEL retained the evidence needed to reconstruct the incident while restoring service. Logs from identity, network management, DNS, messaging, endpoints, suppliers and privileged access have different retention periods and clocks. A hurried rebuild can destroy the very record needed to distinguish entry, movement and impact.
The review should map service dependencies against the observed recovery. Why could fixed access continue while mobile services failed? Why did SMS lag voice and data? Which provincial differences came from central systems, transport, local infrastructure or the order of restoration? A timeline tied to configuration changes and customer metrics can convert an outage narrative into engineering knowledge.
External dependencies belong in that map. Twilio’s status demonstrates that customers experience the network through interconnection and application providers as well as UNITEL’s own dashboards. The operator should compare its internal recovery time with delivery reports from messaging partners, roaming peers, payment services and large customers. Disagreement is a signal to investigate, not a reason to select the most favourable number.
The review should also test isolation and recovery procedures. Exercises should assume loss of the mobile control layer, compromise of an administrative identity and failure of a messaging dependency. Backup configurations must be restored into clean environments, and privileged credentials rotated without preventing emergency operation. Results can be reported as objectives and achieved ranges without publishing an attack manual.
Full recovery will be credible when independent paths agree
The current record shows progress. A nationwide mobile disruption was followed by phased restoration across named provinces. Fixed connectivity remained available according to the company. The incident was contained, and external SMS delivery was still impaired near the Wave cutoff. Those facts can coexist without contradiction.
What remains missing is a shared end state. UNITEL has not published the percentage of subscribers restored, the quality threshold used, the status of every province, the state of SMS, or the time at which normal operations can be declared. It has not disclosed whether customer data was affected or how the attacker entered. Silence on those points should be recorded as uncertainty, not filled with assumptions.
A credible final notice would combine internal and external evidence: network counters, successful customer journeys, interconnection partners, enterprise confirmation and a period of stable operation. It would separate services that are normal from services still operating under temporary measures. A later review would explain cause and control improvements at the level the investigation permits.
The test is not whether UNITEL can publish a green banner. It is whether a caller, a mobile-data user, an SMS-dependent bank, a fixed-network customer and a partner such as Twilio see the same recovery at the same time. When those paths agree, Angola will have more than containment. It will have evidence that the network is back.

