South Africa's air traffic agency ATNS probes ransomware-linked malware in its weather and air-navigation network
South Africa's state-owned ATNS said it found ransomware-linked malware in operational-technology systems supporting weather and air-navigation services, with signs of data exfiltration to China.
- Victim
- Air Traffic and Navigation Services (ATNS)
On 26 September 2026, it was reported that Air Traffic and Navigation Services (ATNS) β the South African state-owned company responsible for air traffic control and aeronautical services β was investigating ransomware-linked malware discovered inside the operational-technology (OT) environment that supports weather-related air-navigation services. ATNS manages air traffic across 21 aerodromes in South Africa and controls more than 6% of the world's airspace, also providing aeronautical satellite communication across dozens of states in Africa and the Middle East, making any disruption a potential safety and continuity concern.
According to reporting, monitoring systems detected suspicious activity in the OT environment and preliminary investigations identified malware commonly associated with the early stages of ransomware attacks. The affected systems handle flight-planning inputs, visibility data, and communication lines between meteorological providers and control towers. Network monitoring indicated possible data exfiltration to external IP addresses located in China, and a separate thread of the investigation concerns allegations that employees may have unlawfully accessed and exfiltrated personal information β claims that initial inquiries could not substantiate.
Response
ATNS said its internal technical teams had implemented containment measures and removed the malware, and the agency began procuring external cyber-forensic services β with the formal request issued on 18 September 2026 β to run a comprehensive investigation into both the malware intrusion and the alleged insider data theft. No ransomware group publicly claimed the attack, and no specific flight disruptions were documented in initial reporting.
Why it matters
Air-navigation providers sit at the heart of aviation safety, and malware in the OT systems feeding weather and flight-planning data is a serious critical-infrastructure risk even when controllers can fall back on manual procedures. The reported exfiltration to overseas IP addresses, combined with the parallel insider-theft inquiry, points to a complex incident that blends possible espionage, extortion-stage tooling and internal-access concerns. With containment measures in place but a full forensic investigation still underway, the incident's status was recorded as contained.
Timeline
ATNS requests cyber-forensic services after monitoring detects suspicious activity in its operational-technology environment.
Media report that ATNS is investigating ransomware-linked malware and possible data exfiltration to external IP addresses in China.
Sources
- timeslive.co.zahttps://www.timeslive.co.za/news/business/2026-09-26-air-traffic-agency-probes-cyberattack/
- darkreading.comhttps://www.darkreading.com/cyberattacks-data-breaches/south-africa-help-cyberattack-air-traffic-control
- scworld.comhttps://www.scworld.com/brief/south-african-air-traffic-control-firm-investigates-ransomware-linked-malware-in-ot-network