NEWS

South Africa Seeks Help After Cyberattack Targets Air Traffic Control

ATNS found ransomware-linked malware on an operational network tied to weather data, and is probing possible exfiltration to China-based IPs.

Dylan H.

News Desk

September 30, 2026
7 min read
South Africa Seeks Help After Cyberattack Targets Air Traffic Control

South Africa's Air Traffic Agency Confirms Ransomware Intrusion on Operational Network

Air Traffic and Navigation Services (ATNS), the state-owned agency that manages air traffic control across South Africa and provides aeronautical communication services for a large share of African airspace, has confirmed that ransomware-linked malware was found on an operational technology (OT) network supporting weather-related air traffic services. Public procurement documents show ATNS issued a request for quotes (RFQ) on September 18, 2026, seeking outside digital forensics firms to investigate the incident, which agency spokesperson Khulu Phasiwe said occurred sometime during the "current financial year" without specifying an exact date. ATNS says its internal technical team has already contained the intrusion and removed the malware, but a full forensic investigation is still required to determine root cause and the extent of any compromise. The agency's OT environment feeds flight planning, visibility data, and communication links between meteorological providers and control towers — systems that, if disrupted, could have serious knock-on effects for commercial aviation.


AttributeValue
Victim organizationAir Traffic and Navigation Services (ATNS), South Africa
Scope of ATNS operationsManages upwards of 6% of global airspace across 21 South African aerodromes; supports aeronautical satellite communication across 33 African states
Incident typeRansomware-linked malware discovered on an OT network
Affected systemOT environment supporting weather-related air traffic services (flight planning, visibility data, met-to-tower communications)
Facility named (OT incident)Port Elizabeth Airport (IATA/ICAO code FAPE)
Second, separate incidentSuspected insider data theft under investigation at Maputo International Airport, Mozambique (FAMM)
Suspected exfiltration destinationExternal IP addresses located in China
Forensics RFQ issuedSeptember 18, 2026
Public disclosureAround September 26, 2026, via procurement documents and local reporting
Ransomware group attributionNot publicly confirmed at time of writing
Reported flight disruptionNone publicly confirmed

What ATNS Has Disclosed

Malware Found in a Weather-Data OT Environment

According to the RFQ documents, ATNS network monitoring detected suspicious activity within the OT environment that supports weather-related services for air traffic control. Preliminary investigation identified malware commonly associated with the early stages of ransomware attacks. Because this environment underpins flight planning, visibility data, and the communication chain between meteorological providers and control towers, ATNS characterized a successful compromise as capable of "critically disrupt[ing]" those functions — though the agency says its technical team stopped the attack before it reached that point.

Two Separate Investigations, Two Airports

The RFQ actually covers two distinct incidents at two different facilities. The ransomware-linked OT incident is tied to Port Elizabeth Airport (FAPE) in South Africa. A second, separate matter concerns Maputo International Airport (FAMM) in Mozambique, where internal reports allege that employees may have unlawfully accessed and exfiltrated personal information without authorization. ATNS said its initial investigation was unable to substantiate those insider-threat allegations, and it is seeking an independent forensic review to establish the facts, identify any policy or legislative violations, and produce defensible findings — including whether any employees may have collaborated with external attackers.

Possible Exfiltration to China-Linked Infrastructure

Network monitoring tied to the ransomware incident turned up indications of possible data exfiltration to external IP addresses located in China, according to the documents. ATNS has not detailed what data, if any, actually left the network, and a spokesperson said the agency cannot comment further on "the nature or extent of any potentially compromised data" until the forensic investigation concludes.

Containment Claimed, but Root Cause Still Unconfirmed

ATNS says internal technical teams have already implemented containment measures and completed malware removal on the affected OT systems. However, the agency has been explicit that a comprehensive third-party forensic investigation is still needed to determine the root cause, the full extent of compromise, and whether any residual risk remains — meaning the incident is not considered fully resolved internally, even though operations were not publicly reported as disrupted.

Impact Assessment

Impact AreaDescription
Operational technology exposureMalware associated with early-stage ransomware reached a network supporting weather data feeding flight planning and met-to-tower communications
Aviation safety risk (potential)ATNS itself acknowledged a successful compromise could have disrupted flight planning and visibility data — a direct safety and operations concern, even though no disruption was confirmed
Data exposure uncertaintySuspected exfiltration to China-linked IPs is unconfirmed in scope; ATNS has declined to detail what data may have been taken pending forensics
Insider threat exposureA parallel, unrelated allegation of employee data theft at Maputo International Airport broadens the investigation beyond a single external actor
Regional/critical infrastructure concernATNS supports aeronautical communications across 33 African states, meaning downstream reliance on its systems extends well beyond South Africa
Attribution gapNo ransomware group has been publicly named, and the precise attack timeline (initial access date) has not been disclosed

Recommendations

For Aviation and Critical Infrastructure Operators

  • Segment OT/ICS networks that touch flight-critical data (weather, planning, tower communications) from corporate IT, and monitor for lateral-movement attempts between the two.
  • Treat any malware associated with ransomware "staging" behavior (credential harvesting, disabling backups, beaconing) as a full incident even if encryption never executes — early detection is what prevented disruption here.
  • Maintain offline, tested backups of OT configuration and flight-safety-adjacent data so containment doesn't have to race against an encryption deadline.

For Security Operations Teams

  • Monitor egress traffic from OT and weather-data segments for connections to unexpected geographic regions or newly registered infrastructure; unusual outbound flows were the first signal of exfiltration in this case.
  • Bring in independent forensic investigators early when OT systems are touched — internal "contained and removed" assessments are not a substitute for root-cause and scope validation, as ATNS itself acknowledged.
  • Audit insider-access logs for OT and personal-data systems in parallel with external-intrusion investigations; this incident shows the two threat vectors can surface at the same time across different facilities.

For Regional Aviation Authorities and Partners

  • Airlines, airports, and meteorological partners connected to ATNS systems should request status updates and confirm whether any shared data feeds were affected while the forensic investigation is ongoing.
  • Governments and regulators overseeing shared aeronautical communication infrastructure (ATNS supports 33 African states) should treat this as a prompt to review incident-notification obligations across borders.
  • International cybersecurity assistance — from vendors, national CERTs, or allied aviation-security bodies — should be evaluated given ATNS's own request for external forensic support.

Key Takeaways

  1. ATNS, South Africa's air traffic control and navigation agency, found ransomware-linked malware on an operational technology network that supports weather data for flight planning and control-tower communications.
  2. ATNS says its internal team contained and removed the malware, and no flight disruption has been publicly confirmed — but a full third-party forensic investigation, requested via an RFQ issued September 18, 2026, is still pending.
  3. The incident is tied to Port Elizabeth Airport (FAPE); a separate, unrelated insider-theft investigation covers Maputo International Airport (FAMM) in Mozambique.
  4. Investigators flagged possible data exfiltration to IP addresses located in China, though ATNS has not confirmed what data, if any, was actually taken.
  5. No ransomware group has been publicly attributed, and the exact date of initial compromise remains undisclosed — ATNS has only said the incident occurred within the current financial year.
  6. The case underscores growing ransomware pressure on aviation and other critical infrastructure operators, where even a contained, non-disruptive intrusion still demands full forensic scrutiny given the safety stakes involved.

Sources