South Africa’s Air Traffic and Navigation Services (ATNS), the state-owned company that manages more than 6% of the world’s airspace, is investigating a ransomware-linked compromise of operational technology supporting weather-related services for air traffic control.[1][2] The agency recently issued a request for external digital forensics firms after monitoring systems flagged suspicious activity and malware associated with the early stages of a ransomware attack on at least one operational network.[1][2][3]
According to procurement documents and statements from ATNS, the incident affected operational technology environments tied to meteorological data feeds used by controllers at facilities including Port Elizabeth Airport in South Africa and Maputo International Airport in Mozambique, with a possible impact at East London Airport still under review.[2] Internal teams reported indications of data exfiltration to external IP addresses geolocated to China, prompting concerns that both operational and personal information may have been accessed without authorization.[1][2][6]
ATNS has said its technical staff implemented containment measures and removed the malware, and there have been no publicly reported disruptions to commercial flights or core air traffic services as a result of the compromise.[1][2] However, the agency acknowledged that if the affected systems had been fully compromised, flight planning, visibility data and communications between meteorological providers and control towers could have been critically disrupted, potentially halting aviation operations across South Africa’s busy airspace.[1][6] ATNS manages air traffic services at 21 aerodromes and employs more than 1,000 staff, underscoring the scale of the risk posed by any successful ransomware attack on its infrastructure.[1]
In parallel with the technical investigation, ATNS is probing whether insiders may have played a role, noting in its forensic tender that reports received through internal channels alleged employees unlawfully accessed and exfiltrated personal information.[1][6] Initial internal inquiries were unable to substantiate those claims, and the agency has asked independent investigators to establish the facts, identify any policy or legislative violations, and provide defensible findings for regulators and law enforcement.[1][2]
Public documents describing the incident do not name any specific ransomware family, exploited vulnerability, or affected product, and no CVE identifiers or vendor advisories have yet been linked to the compromise.[1][2][3] The malware is characterized only as tooling commonly seen in the early stages of ransomware campaigns, suggesting the attackers may have been conducting reconnaissance and establishing persistence before any encryption or extortion attempts.[2][3] While network telemetry points to data moving to infrastructure in China, ATNS has not attributed the attack to any particular threat group, and IP geolocation alone is insufficient to draw reliable conclusions about the actors involved.[1][2][6]
The probe comes amid a broader surge in cyberattacks on South Africa’s critical infrastructure and aviation sector, including a 2025 incident where South African Airways reported a cyberattack that disrupted its website, mobile app and internal systems but was contained before affecting flight operations.[12][13] Researchers documenting regional trends note that ransomware crews have previously targeted government departments, energy utilities, financial institutions and even the national weather service, highlighting how aviation-related data and services have become a valuable target in double-extortion campaigns.[10][13]
For air navigation providers and airport operators elsewhere, the ATNS case underscores the importance of strictly segmenting operational technology from corporate IT networks, enforcing multi-factor authentication for remote access and maintaining well-tested incident response playbooks. Organizations running weather, navigation and flight-planning systems should ensure backups are isolated from production environments, monitor for abnormal data flows from OT networks and engage with national CERTs to share indicators when suspected ransomware tooling is detected.
References
- Air traffic agency probes cyberattack
- South Africa Seeks Aid After Air Traffic Control Cyberattack
- Cybersecurity News — Breaches, Vulnerabilities and Patches
- Press Coverage
- SKYwatch
- Cyber Digest, June 2025 – idsa.in
- Cyber Threats in the Sky: Aviation Industry Steps Up …
