Air Traffic Control Systems in South Africa Hit by Ransomware Attack
A devastating ransomware attack has struck the air traffic control systems in South Africa, leaving investigators scrambling to determine the extent of the damage. The incident, which is still under investigation, highlights the growing threat of cyberattacks on critical infrastructure and underscores the need for robust cybersecurity measures.
Air Traffic and Navigation Services (ATNS), a state-owned company that provides air traffic control and weather operations for approximately 10% of the world’s airspace, has been affected by the attack. According to public documents released this month, malware associated with ransomware attacks was detected in an operational technology (OT) network supporting weather-related services to Air Traffic Services. The technical teams at ATNS believe they have contained the attack, but a comprehensive forensic investigation is required to determine the root cause and extent of the compromise.
The attack on air traffic control systems in South Africa is just the latest example of the growing threat of ransomware attacks on critical infrastructure. In 2025, ransomware attacks targeting the aviation industry surged sixfold from the previous year, with 27 major incidents reported over a 16-month period. Aviation firms are particularly vulnerable to these types of attacks because they often rely on complex systems and networks that can be difficult to defend.
The incident in South Africa also raises concerns about insider threats, as investigators have found evidence of data exfiltration to external IP addresses located in China. This suggests that the attackers may have had help from someone within the organization or gained access through a compromised account. The use of AI-powered tools by cyberattackers is also becoming more common, making it increasingly difficult for organizations to detect and respond to attacks.
The impact of this type of attack can be catastrophic, with grounded flights and stranded passengers causing significant disruptions to air travel. In Africa, critical infrastructure such as aviation systems are increasingly targeted by attackers, who seek to exploit vulnerabilities in these complex networks. The threat landscape is shifting aggressively toward critical infrastructure, making it essential for organizations to invest in robust cybersecurity measures.
In response to the incident, ATNS has issued a request for quotes (RFQ) seeking cyber-forensics firms to investigate the attack and determine the root cause of the compromise. The company also acknowledged that internal technical teams have implemented containment measures and malware removal but recognized the need for a comprehensive forensic investigation to ensure the integrity of their systems.
As the aviation industry continues to face an increasing number of ransomware attacks, it is essential for organizations to prioritize cybersecurity and invest in robust defenses against these types of threats. By doing so, they can minimize the risk of disruptions to air travel and protect themselves from the devastating consequences of a successful attack.
In practical terms, this means that airlines, airports, and other aviation-related organizations should take immediate action to assess their cybersecurity posture and implement additional measures to prevent similar attacks in the future. This includes conducting regular security audits, implementing robust incident response plans, and investing in advanced threat detection tools. By taking these steps, they can reduce the risk of a successful attack and ensure the continued smooth operation of air traffic control systems.
Source: Dark Reading — 2026-09-30