CSIDB logo
Incident

Ministry of Finance of Angola

Incident posture

Attack window
Feb 2021
Location
Angola
Status
Historical
CIA posture
Available to members
Updated
2025-10-26 00:00

Linked entities

Victim
Ministry of Finance of Angola
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The Angolan Ministry of Finance experienced a cyber attack targeting its technological platform, compromising email and shared folder access. While the origin and motives remained unidentified, critical financial systems including salary processing and revenue collection services remained operational during the incident.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On February 23, 2021, the Angolan Ministry of Finance experienced a cyber attack targeting its technological support platform, disrupting access to email systems and shared folders. The incident occurred on a Thursday, though the exact time of initial compromise and duration of disruption were not specified in public statements. The Ministry confirmed the attack through an official announcement but did not identify the threat actors’ origins or motivations. No technical details regarding the attack vector—such as malware, phishing, or exploitation techniques—were disclosed. The institution’s primary technological infrastructure, which facilitated routine administrative operations and communications, was confirmed as the focal point of the breach.

Despite the disruption, the Ministry emphasized that critical financial systems remained operational throughout the incident. Salary processing services and revenue collection platforms—including SIGT (Sistema Integrado de Gestão Tributária), ASYCUDA (Automated System for Customs Data), taxpayer service portals, municipal systems, and the Integrated State Financial Management System (SIGFE)—were unaffected and continued functioning normally. The Ministry’s public reassurance aimed to mitigate concerns over potential delays in public sector payments or revenue collection activities. No evidence suggested data exfiltration, financial theft, or secondary disruptions to external economic systems. The incident response appeared limited to internal assessments and public communication, with no disclosed collaboration with external cybersecurity entities or law enforcement. Restoration timelines for the compromised email and file-sharing services were not provided in the available reporting.

Sources

Sources available to members: 1 source.

CSIDB