SOUTH Africa’s Air Traffic and Navigation Services (ATNS), the state-owned organisation that runs air traffic control and weather operations for around 10% of global airspace, says ransomware-linked malware was detected in an operational technology (OT) network. ATNS says its technical teams stopped the attack, but has issued a request for quotes to engage cyber-forensics firms to investigate the incident. A second possible incident involving alleged insider data theft is also being probed.
The timing remains unclear, but ATNS notes that it began seeking forensic services from 18 September. Evidence cited in the RFQ describes suspicious OT activity in weather-related services and preliminary findings linking the malware to early-stage ransomware activity, with indicators of data exfiltration to external IP addresses in China.
The case underscores rising risks to aviation infrastructure. Thales data cited by Dark Reading put aviation ransomware attacks at 27 major incidents in the 16 months to April 2025, a marked increase from the prior year.
ATNS identified two facilities in its investigation by IATA airport codes: Port Elizabeth Airport (FAPE) in South Africa for the OT incident, and Maputo International Airport (FAMM) in Mozambique for the possible insider theft; East London Airport (FAEL) may also be involved, though that point remains unclear.
Experts quoted in the piece emphasise the region’s vulnerability, noting governance gaps, skill shortages, and aging systems, with regional regulatory reporting requirements not always mandating disclosure of OT incidents. ATNS has not yet publicised its forensic findings.