logo_tag
Back

South Africa's Air Traffic Control Operator ATNS Discovers Ransomware on OT Network, Seeks Cyber-Forensics Help

Why It MattersThe incident underscores rising ransomware exposure across aviation infrastructure in a region where documented security controls often outpace actual implementation and skills capacity.

South Africa's state-owned Air Traffic and Navigation Services (ATNS), which manages air traffic control and weather operations for roughly 10% of the world's airspace, has discovered ransomware-linked malware in an operational technology network supporting weather-related services to air traffic operations. Public documents released in September 2026 show monitoring systems detected suspicious activity in the OT environment, with preliminary investigations identifying malware commonly linked to early-stage ransomware attacks and indications of data exfiltration to external IP addresses located in China.

South Africa's Air Traffic Control Operator ATNS Discovers Ransomware on OT Network, Seeks Cyber-Forensics Help

ATNS believes its internal teams stopped the attack and put containment and malware-removal measures in place, but the organization has issued a request for quotes seeking cyber-forensics firms to investigate the incident. East London Airport (FAEL) may also have been affected by the OT compromise, though the RFQ documents are unclear on that point, and ATNS did not respond to a request for comment.

Thales recorded 27 major ransomware attacks on aviation firms in the 16 months leading up to April 2025, a sixfold increase over the prior year, while Check Point Software Technologies logged at least 1,042 ransomware attacks globally in August 2026. Check Point's head of security consulting for Africa, Hendrik de Bruin, said South African organizations faced an average of 2,086 cyberattacks per week, and that at least eight South African national government departments and public entities have suffered confirmed cyber incidents since the start of 2024. South Africa's Protection of Personal Information Act requires reporting of breaches involving personal information, but mandatory reporting for operational cyber incidents remains limited.

Related Coverage · 1 stories

South Africa Seeks Aid After Air Traffic Control Cyberattack - Dark Readingdarkreading.com
Keep Exploring