South African Air Traffic Control Systems Hit by Ransomware Attack
Air traffic control systems in South Africa have been compromised by a sophisticated ransomware attack, highlighting the growing threat to aviation infrastructure worldwide. The incident, which has left officials scrambling for answers, underscores the vulnerability of critical systems to cyber threats.
The attack targeted Air Traffic and Navigation Services (ATNS), a state-owned company responsible for providing air traffic control and weather operations for approximately 10% of the world’s airspace. According to public documents released this month, technical teams detected suspicious activity in operational technology (OT) networks supporting weather-related services to air traffic services. Preliminary investigations revealed malware commonly associated with ransomware attacks.
The attack is believed to have occurred sometime before September 18, when ATNS issued a request for quotes (RFQ) seeking cyber-forensics firms to investigate the incident. The company stated that internal technical teams had implemented containment measures and malware removal but acknowledged that a comprehensive forensic investigation was necessary to determine the root cause, extent of compromise, and any remaining risks.
The incident is particularly concerning due to its potential impact on global aviation operations. Ransomware attacks targeting the aviation industry surged sixfold in 2025 from the previous year, according to Thales, an aviation and defense firm. The attack highlights the increasing risks for aviation infrastructure as ransomware gangs look to cash in on vulnerabilities in the critical sector.
Aviation systems and other critical infrastructure are popular targets due to their high visibility and potential impact. Grounded flights and stranded passengers cannot be hidden, making them attractive to cyber attackers seeking to disrupt critical services. For Africa, the threat landscape is shifting aggressively toward critical infrastructure, with South African organizations facing heavy, sustained pressure from cyber threats.
The incident at ATNS has raised questions about the effectiveness of cybersecurity measures in place to protect aviation systems. While the company’s technical teams may have contained the attack, a thorough investigation is necessary to determine the root cause and extent of compromise. The use of artificial intelligence (AI) by cyber attackers is also a concern, as it enables more sophisticated and targeted attacks.
As the aviation industry continues to grapple with the threat of ransomware attacks, organizations must prioritize cybersecurity measures to protect critical systems. This includes regular security audits, employee education, and implementation of robust incident response plans. While no system is completely secure, being proactive and prepared can minimize the impact of a potential cyber attack.
In the wake of this incident, it’s essential for aviation organizations to review their cybersecurity posture and take steps to enhance their defenses. This includes implementing multi-layered security measures, conducting regular penetration testing, and staying up-to-date with the latest threat intelligence. By taking these precautions, organizations can reduce their risk exposure and minimize the potential impact of a cyber attack.
Source: Dark Reading — 2026-09-30