Clearance CLR-6350 · SAF559

SAFRAN

Safety & OperationsClearance sheet

Ransomware-Linked Malware Hit ATNS Network Serving 10% of World Airspace

ATNS, which manages ATC over about 10% of global airspace, found ransomware-linked malware in an OT network and is hiring forensic investigators after suspected data exfiltration.

Read-back

  1. ATNS, responsible for ATC and weather services over roughly 10% of the world's airspace, detected ransomware-linked malware in an OT network supporting weather services to air traffic control.
  2. Incidents struck Port Elizabeth Airport (FAPE), possibly East London Airport (FAEL), and Maputo International Airport (FAMM), with forensic services requested from September 18.
  3. Investigators found evidence of data exfiltration to external IP addresses in China; Thales recorded a sixfold year-on-year surge in aviation ransomware attacks through April 2025.
South Africa Seeks Aid After Air Traffic Control Cyberattack - Dark Reading
PlateSouth Africa Seeks Aid After Air Traffic Control Cyberattack - Dark Reading — AI-generated

Air Traffic and Navigation Services (ATNS), the South African state-owned company that manages air traffic control and meteorological services across roughly 10% of the world's airspace, has launched a procurement process for cyber-forensic contractors after detecting ransomware-linked malware in an operational technology (OT) network.

Public documents released this month show ATNS issued a request for quotes (RFQ) seeking investigators, with services requested from September 18. The exact date of the intrusion remains unclear. The company believes its internal technical team stopped the attack and removed the malware, but it concedes in the RFQ that "a comprehensive forensic investigation is required to determine the root cause, extent of compromise, and any remaining risks."

The incident package covers two separate events at facilities identified by their IATA codes. The OT compromise occurred at Port Elizabeth Airport in South Africa (FAPE), with East London Airport (FAEL) possibly affected as well — the service request is ambiguous on that point. A second incident, potentially an insider theft of data, took place at Maputo International Airport in Mozambique (FAMM).

"Monitoring systems detected suspicious activity within operational technology (OT) environments supporting weather-related services to Air Traffic Services," ATNS stated in its service request. "Preliminary investigations identified malware commonly associated with the early stages of ransomware attacks."

The technical teams also found indications of "data exfiltration to external IP addresses located in China," according to the document. ATNS did not respond to a request for comment before publication.

The disclosure lands amid a measurable escalation in attacks on aviation infrastructure. Thales, the aviation and defense group, counted 27 major ransomware attacks on aviation firms in the 16 months to April 2025 — a sixfold year-on-year increase. Globally, Check Point Software Technologies recorded at least 1,042 ransomware attacks in August alone, nearly double the figure for the same month a year earlier.

South African organizations face sustained pressure. They recorded an average of 2,086 cyberattacks per week, slightly below the global average of 2,422, according to Hendrik de Bruin, Check Point's head of security consulting for Africa. "Since the start of 2024, at least eight national government departments and public entities have suffered confirmed cyber incidents, and aviation-related organizations are now part of that pattern," he said.

Avinash Singh, a lecturer in the University of Pretoria's computer science department, said the regional threat picture is shifting toward critical infrastructure because the consequences are visible and hard to deny. "Grounded flights and stranded passengers cannot be hidden," he said.

The practical weaknesses are often prosaic. De Bruin pointed to a recent incident Check Point investigated at a large organization in a country neighboring South Africa, where compliance documentation existed but defenses had not been configured. "There was a firewall, but nobody had asked whether it was switched on and doing its job," he said. "Public reporting suggests similar themes locally, including security governance gaps, limited skills capacity, and aging, fragmented systems."

Reporting obligations compound the problem. South Africa's Protection of Personal Information Act (PoPIA) mandates disclosure of breaches involving personal information, but no equivalent requirement covers purely operational cyber incidents, which encourages quiet remediation. Singh said this creates a significant blind spot: without accurate localized incident data, defensive tools end up relying on threat intelligence biased toward Northern Hemisphere attack patterns that may not reflect the tactics used against the region.

For now, ATNS reports its containment measures are in place and its weather-related OT services continue to support air traffic operations. The scope of the compromise — and whether the suspected exfiltration to Chinese IP addresses extended beyond the Port Elizabeth site — will only become clear once the contracted forensic investigation concludes.

via eu-images.contentstack.com (Original)

Filed under

  • cybersecurity
  • atns
  • ransomware
  • air-traffic-control
  • south-africa
Share this article:

More from Sophie Lindqvist

Sophie Lindqvist

Show full bio

Senior reporter covering industry trends and analytics at Flightdeck Report.

161 articles

Same bay

« Previous articleNext article »