May 20, 2026, 10:06 PM
Uganda’s top-level domains, including .ug, .co.ug, and .go.ug, have been hit by a massive cyberattack, causing widespread disruptions across the country's digital infrastructure. The attack reportedly affected approximately 45,000 websites and left major platforms inaccessible for hours.
According to data shared on cybersecurity platforms, the attack was orchestrated by a hacker known as RevoNzy, allegedly an administrator of the "İmhaTeam" group. The operation reportedly utilized a mass DNS poisoning (hijacking) method, redirecting thousands of legitimate websites to servers controlled by the attackers.
Global Giants and Government Infrastructure TargetedThe compromised domains include the Ugandan extensions of major global brands, such as:
"Uganda’s Internet Paralyzed for Hours"Reports indicate that the cyberattack began late on the night of May 19 and its disruptive effects persisted until the morning of May 20. By altering the DNS (Domain Name System) records, the attackers successfully redirected users trying to access legitimate services to malicious servers instead.
Cybersecurity experts warned that a DNS attack of this magnitude carries severe risks, capable of triggering a domino effect across critical services, including:
While the attacker's claims continue to circulate widely on the dark web and underground forums, local authorities and IT teams are working to fully restore and secure the affected domain registries.
According to data shared on cybersecurity platforms, the attack was orchestrated by a hacker known as RevoNzy, allegedly an administrator of the "İmhaTeam" group. The operation reportedly utilized a mass DNS poisoning (hijacking) method, redirecting thousands of legitimate websites to servers controlled by the attackers.
Global Giants and Government Infrastructure TargetedThe compromised domains include the Ugandan extensions of major global brands, such as:
- Google ()
google.ug
- PayPal ()
paypal.ug
- Yahoo
- Apple
- Microsoft
- Facebook
- Instagram
"Uganda’s Internet Paralyzed for Hours"Reports indicate that the cyberattack began late on the night of May 19 and its disruptive effects persisted until the morning of May 20. By altering the DNS (Domain Name System) records, the attackers successfully redirected users trying to access legitimate services to malicious servers instead.
Cybersecurity experts warned that a DNS attack of this magnitude carries severe risks, capable of triggering a domino effect across critical services, including:
- Online banking and financial transactions
- Essential government digital services
- Corporate and institutional email systems
- Hospital and healthcare infrastructure
While the attacker's claims continue to circulate widely on the dark web and underground forums, local authorities and IT teams are working to fully restore and secure the affected domain registries.
