
Uganda: INTERPOL Warns of Cybercrime Threat to Critical Infrastructure
From Uganda's electricity transmission network to telecommunications and financial systems, INTERPOL says Africa is facing an increasingly sophisticated cybercrime threat as criminals turn their attention to critical infrastructure, reports Ronald Musoke. On August 18, 2025, the Qilin ransomware group claimed Uganda Electricity Transmission Company Limited (UETCL) as a victim. The group, which operates a ransomware-as-a-service model, listed the Ugandan electricity transmission company on its leak site and said it had breached its systems. The claim was recorded the following day, August 19, 2025, by cyber-threat intelligence platforms tracking ransomware activity around the world. The material Qilin said it had obtained included "internal contracts, identity documents, financial statements and service agreements." The target was significant. UETCL is Uganda's state-owned electricity transmission utility, responsible for moving bulk electricity across the country and beyond national borders through its high-voltage transmission network. A successful cyber intrusion against such an agency is therefore not simply a corporate data breach. It raises questions about the security of infrastructure on which millions of homes, businesses, hospitals and other essential services depend. Keep up with the latest headlines on WhatsApp | LinkedIn Qilin's claim came with the familiar threat of ransomware gangs: publish the stolen information if the victim does not comply. But the story did not end with the group's dark-web posting. The INTERPOL African Cyberthreat Assessment Report 2026 published on Aug. 3, 2026, now places the August 2025 UETCL incident within a much wider African cyber threat. INTERPOL or the International Criminal Police Organization, which is based in Lyon, France, describes what happened at UETCL as a suspected ransomware incident in which monitoring systems for Uganda's national power grid were compromised. Electricity service was restored through backup protocols. The significance of the episode is therefore larger than the fortunes of one ransomware group. It is a warning about what happens when Africa's rapid digital transformation collides with increasingly sophisticated cybercrime. A power grid is now a digital target Electricity infrastructure has always been vulnerable to physical threats. Transmission towers can be vandalized. Substations can be damaged. Equipment can fail. But modern electricity systems have another layer of vulnerability: the digital systems used to monitor, communicate and manage them. Power grids increasingly rely on sensors, automated controls, communications networks, real-time data and connected devices. The technology improves efficiency and allows operators to monitor complex networks in real time. It also expands the number of systems that must be protected. That makes electricity utilities attractive targets for ransomware operators and other cybercriminals. The danger is not that every ransomware attack against a power company will automatically cause a blackout. It is that an intrusion can target the digital infrastructure supporting the physical infrastructure. The global energy sector has already seen the consequences. European electricity industry data has recorded a sharp increase in cyberattacks against energy infrastructure, while documented incidents in different parts of the world have shown how ransomware, phishing, denial-of-service attacks and compromised suppliers can be used against energy companies. The underlying vulnerability is straightforward: the more connected an electricity network becomes, the more important cybersecurity becomes to the reliability of the physical network. That is why the UETCL incident matters. It shows how an organisation responsible for a country's electricity infrastructure can become a target in a criminal economy that operates across borders and does not require attackers to be physically present in Uganda. And UETCL is not alone. UETCL'
How does this affect you?
Get an AI analysis of this article grounded in your jurisdictions, practice areas, and any policy documents you've uploaded to Wansom.
Wansom is AI and can make mistakes.
