South Africa's Air Traffic Agency Confirms Ransomware Intrusion on Operational Network
Air Traffic and Navigation Services (ATNS), the state-owned agency that manages air traffic control across South Africa and provides aeronautical communication services for a large share of African airspace, has confirmed that ransomware-linked malware was found on an operational technology (OT) network supporting weather-related air traffic services. Public procurement documents show ATNS issued a request for quotes (RFQ) on September 18, 2026, seeking outside digital forensics firms to investigate the incident, which agency spokesperson Khulu Phasiwe said occurred sometime during the "current financial year" without specifying an exact date. ATNS says its internal technical team has already contained the intrusion and removed the malware, but a full forensic investigation is still required to determine root cause and the extent of any compromise. The agency's OT environment feeds flight planning, visibility data, and communication links between meteorological providers and control towers — systems that, if disrupted, could have serious knock-on effects for commercial aviation.
| Attribute | Value |
|---|---|
| Victim organization | Air Traffic and Navigation Services (ATNS), South Africa |
| Scope of ATNS operations | Manages upwards of 6% of global airspace across 21 South African aerodromes; supports aeronautical satellite communication across 33 African states |
| Incident type | Ransomware-linked malware discovered on an OT network |
| Affected system | OT environment supporting weather-related air traffic services (flight planning, visibility data, met-to-tower communications) |
| Facility named (OT incident) | Port Elizabeth Airport (IATA/ICAO code FAPE) |
| Second, separate incident | Suspected insider data theft under investigation at Maputo International Airport, Mozambique (FAMM) |
| Suspected exfiltration destination | External IP addresses located in China |
| Forensics RFQ issued | September 18, 2026 |
| Public disclosure | Around September 26, 2026, via procurement documents and local reporting |
| Ransomware group attribution | Not publicly confirmed at time of writing |
| Reported flight disruption | None publicly confirmed |
What ATNS Has Disclosed
Malware Found in a Weather-Data OT Environment
According to the RFQ documents, ATNS network monitoring detected suspicious activity within the OT environment that supports weather-related services for air traffic control. Preliminary investigation identified malware commonly associated with the early stages of ransomware attacks. Because this environment underpins flight planning, visibility data, and the communication chain between meteorological providers and control towers, ATNS characterized a successful compromise as capable of "critically disrupt[ing]" those functions — though the agency says its technical team stopped the attack before it reached that point.
Two Separate Investigations, Two Airports
The RFQ actually covers two distinct incidents at two different facilities. The ransomware-linked OT incident is tied to Port Elizabeth Airport (FAPE) in South Africa. A second, separate matter concerns Maputo International Airport (FAMM) in Mozambique, where internal reports allege that employees may have unlawfully accessed and exfiltrated personal information without authorization. ATNS said its initial investigation was unable to substantiate those insider-threat allegations, and it is seeking an independent forensic review to establish the facts, identify any policy or legislative violations, and produce defensible findings — including whether any employees may have collaborated with external attackers.
Possible Exfiltration to China-Linked Infrastructure
Network monitoring tied to the ransomware incident turned up indications of possible data exfiltration to external IP addresses located in China, according to the documents. ATNS has not detailed what data, if any, actually left the network, and a spokesperson said the agency cannot comment further on "the nature or extent of any potentially compromised data" until the forensic investigation concludes.
Containment Claimed, but Root Cause Still Unconfirmed
ATNS says internal technical teams have already implemented containment measures and completed malware removal on the affected OT systems. However, the agency has been explicit that a comprehensive third-party forensic investigation is still needed to determine the root cause, the full extent of compromise, and whether any residual risk remains — meaning the incident is not considered fully resolved internally, even though operations were not publicly reported as disrupted.
Impact Assessment
| Impact Area | Description |
|---|---|
| Operational technology exposure | Malware associated with early-stage ransomware reached a network supporting weather data feeding flight planning and met-to-tower communications |
| Aviation safety risk (potential) | ATNS itself acknowledged a successful compromise could have disrupted flight planning and visibility data — a direct safety and operations concern, even though no disruption was confirmed |
| Data exposure uncertainty | Suspected exfiltration to China-linked IPs is unconfirmed in scope; ATNS has declined to detail what data may have been taken pending forensics |
| Insider threat exposure | A parallel, unrelated allegation of employee data theft at Maputo International Airport broadens the investigation beyond a single external actor |
| Regional/critical infrastructure concern | ATNS supports aeronautical communications across 33 African states, meaning downstream reliance on its systems extends well beyond South Africa |
| Attribution gap | No ransomware group has been publicly named, and the precise attack timeline (initial access date) has not been disclosed |
Recommendations
For Aviation and Critical Infrastructure Operators
- Segment OT/ICS networks that touch flight-critical data (weather, planning, tower communications) from corporate IT, and monitor for lateral-movement attempts between the two.
- Treat any malware associated with ransomware "staging" behavior (credential harvesting, disabling backups, beaconing) as a full incident even if encryption never executes — early detection is what prevented disruption here.
- Maintain offline, tested backups of OT configuration and flight-safety-adjacent data so containment doesn't have to race against an encryption deadline.
For Security Operations Teams
- Monitor egress traffic from OT and weather-data segments for connections to unexpected geographic regions or newly registered infrastructure; unusual outbound flows were the first signal of exfiltration in this case.
- Bring in independent forensic investigators early when OT systems are touched — internal "contained and removed" assessments are not a substitute for root-cause and scope validation, as ATNS itself acknowledged.
- Audit insider-access logs for OT and personal-data systems in parallel with external-intrusion investigations; this incident shows the two threat vectors can surface at the same time across different facilities.
For Regional Aviation Authorities and Partners
- Airlines, airports, and meteorological partners connected to ATNS systems should request status updates and confirm whether any shared data feeds were affected while the forensic investigation is ongoing.
- Governments and regulators overseeing shared aeronautical communication infrastructure (ATNS supports 33 African states) should treat this as a prompt to review incident-notification obligations across borders.
- International cybersecurity assistance — from vendors, national CERTs, or allied aviation-security bodies — should be evaluated given ATNS's own request for external forensic support.
Key Takeaways
- ATNS, South Africa's air traffic control and navigation agency, found ransomware-linked malware on an operational technology network that supports weather data for flight planning and control-tower communications.
- ATNS says its internal team contained and removed the malware, and no flight disruption has been publicly confirmed — but a full third-party forensic investigation, requested via an RFQ issued September 18, 2026, is still pending.
- The incident is tied to Port Elizabeth Airport (
FAPE); a separate, unrelated insider-theft investigation covers Maputo International Airport (FAMM) in Mozambique. - Investigators flagged possible data exfiltration to IP addresses located in China, though ATNS has not confirmed what data, if any, was actually taken.
- No ransomware group has been publicly attributed, and the exact date of initial compromise remains undisclosed — ATNS has only said the incident occurred within the current financial year.
- The case underscores growing ransomware pressure on aviation and other critical infrastructure operators, where even a contained, non-disruptive intrusion still demands full forensic scrutiny given the safety stakes involved.