ThreatPaper
RansomwareOT & Industrial SystemsHigh

ATNS air traffic OT network: ransomware-linked malware found, suspected China-bound data exfiltration (South Africa)

By Sethu Satheesh · 6 Oct 2026 · 13 min read

Threat Actor: Unknown · Target: Air Traffic and Navigation Services (ATNS), South Africa — aviation / air navigation (OT)

Source: www.timeslive.co.za


Executive Summary

South Africa's state-owned Air Traffic and Navigation Services (ATNS) is investigating ransomware-linked malware found in an operational-technology (OT) network that supports weather-related air traffic services. The incident became public on September 26, 2026, when Business Day and the Sunday Times reported that ATNS had engaged external forensic investigators; the detail emerged from ATNS's own procurement documents, a request for quotation (RFQ) for digital-forensics services with an engagement start of September 18, 2026.12 ATNS stated that its "monitoring systems detected suspicious activity within operational technology (OT) environments supporting weather-related services to Air Traffic Services" and that "preliminary investigations identified malware commonly associated with the early stages of ransomware attacks."2

The affected OT environment sits at Chief Dawid Stuurman International Airport in Gqeberha (formerly Port Elizabeth), Eastern Cape, whose ICAO code is FAPE; East London (FAEL) may also have been affected, though the service request is unclear on that point.23 Network monitoring further "indicated possible data exfiltration to external IP addresses located in China," according to ATNS's statement — a destination geolocation, not an attribution.12 A separate strand of the same investigation concerns an insider allegation: "reports received through internal channels indicate that employees may have unlawfully accessed and exfiltrated personal information without authorisation," which ATNS said its initial investigation "was unable to substantiate."1 ATNS believes its internal technical teams contained the activity and removed the malware, but says "a comprehensive forensic investigation is required to determine the root cause, extent of compromise, and any remaining risks."12

No actor has been identified and no ransomware group had claimed the incident as of October 6, 2026. ATNS spokesperson Khulu Phasiwe said the cyberattack took place during the current financial year and that "ATNS is currently unable to comment on the nature or extent of any potentially compromised data until the forensic investigation has been concluded."1 The agency manages air traffic services across 21 aerodromes in South Africa and supports aeronautical communication across much of the continent; coverage variously describes this as "more than 6%" (ATNS figures reported by Business Day) or "approximately 10%" (cyber-press) of the world's airspace.12

Why it matters: this is an OT-network compromise at a national air navigation service provider that was detected early and, on the available evidence, contained before any ransomware deployment or confirmed data loss — the opposite of the headline framing it sometimes received. The record here is deliberately partial: the entry vector, dwell time, malware family, actor, and whether any data actually left the network are all unknown pending forensics. Two downstream errors are worth flagging up front. First, the facility carrying the insider allegation, ICAO code FAMM, is Mmabatho/Mahikeng in South Africa's North West province, not "Maputo International Airport, Mozambique" as some coverage stated.23 Second, this 2026 malware incident is distinct from the unrelated 2025 crisis in which ATNS suspended instrument flight procedures at several South African airports after SACAA approvals lapsed — an administrative, non-cyber failure.4

Verification of Claims

  1. Claim: Ransomware-linked malware was found in an ATNS OT network supporting weather services. → Verified → ATNS's own service request, quoted by Dark Reading and by Business Day/Sunday Times, states monitoring detected suspicious activity in the OT environment and that preliminary investigations identified malware "commonly associated with the early stages of ransomware attacks."12

  2. Claim: Data was exfiltrated to IP addresses in China. → Partially verified → ATNS reported network monitoring "indicated possible data exfiltration to external IP addresses located in China." This is a destination geolocation observed on the network, stated by ATNS as a possibility under investigation — not confirmed data loss and not an attribution to any Chinese actor.12

  3. Claim: Hackers linked to China attacked South Africa's air traffic control. → Unverified → One outlet's headline asserted a China-linked actor. No source establishes an actor; traffic to China-based IPs alone does not show who was responsible, and no ransomware group has claimed the incident. The careful ATNS wording is "possible data exfiltration to external IP addresses located in China."13

  4. Claim: The insider data-theft occurred at Maputo International Airport, Mozambique (FAMM). → Unverified → FAMM is the ICAO code for Mmabatho/Mahikeng Airport in South Africa's North West province (IATA MBD); Maputo International is ICAO FQMA / IATA MPM, in Mozambique. The FA- ICAO prefix is allocated to South Africa, FQ- to Mozambique. Rio Times identified FAMM as Mmabatho.3

  5. Claim: ATNS was hit by a (completed) ransomware attack. → Partially verified → Malware associated with ransomware staging was present, but ATNS describes "the early stages of ransomware attacks" and says it contained and removed the malware; no encryption event, ransom note, or extortion has been reported. Several headlines state a completed "ransomware attack."12

  6. Claim: The insider allegation of unlawful employee data access is established. → Unverified → ATNS said reports via internal channels indicated employees "may have unlawfully accessed and exfiltrated personal information," but that "initial investigations were unable to substantiate the allegations" and an independent forensic investigation is required.1

Timeline

Date Actor Event Source
FY2026/27 (from April 2026) Unknown ATNS says the cyberattack occurred "during the current financial year"; exact date not disclosed 1
September 18, 2026 ATNS RFQ for digital-forensics services issued; engagement start date 23
September 25, 2026 ATNS RFQ bid closing date 3
September 26, 2026 Business Day / Sunday Times First public report; ATNS confirms forensic probe and spokesperson comment 1
September 30, 2026 Dark Reading / SC Media RFQ documents detailed: facilities (FAPE, FAEL, FAMM), early-stage ransomware malware, suspected China-bound exfiltration 25

Incident Anatomy

The mechanism is only partially established. ATNS has published no technical indicators, and the entry vector, malware family, dwell time, and actor are unknown. What follows is the sequence ATNS itself described in its forensic-services request; each unknown is marked.

Detection

ATNS's monitoring systems "detected suspicious activity within operational technology (OT) environments supporting weather-related services to Air Traffic Services."2 The OT environment is the one at Chief Dawid Stuurman International Airport (FAPE), Gqeberha, that supplies weather data; a compromise of it could, in ATNS's own words, "critically disrupt flight planning, visibility data and communication lines between meteorological providers and control towers," though no such disruption occurred.1

Malware identification

Preliminary investigation "identified malware commonly associated with the early stages of ransomware attacks."2 The malware family was not publicly named, and no encryption, ransom note, or leak-site listing has been reported. How the malware reached the OT network — the initial-access vector — is unknown.

Suspected exfiltration

Network monitoring "indicated possible data exfiltration to external IP addresses located in China."12 Whether data actually left the network, how much, and over what channel are unknown; "China" denotes the geolocation of destination IP space, not the identity or location of an operator. No specific IP addresses were published.

Containment

ATNS's "internal technical teams have implemented containment measures and malware removal," and the agency believes it stopped the attack — but states that a comprehensive forensic investigation is still required to establish root cause, scope, and residual risk.12

Parallel insider-theft strand

The same forensic engagement covers a separate allegation that employees "may have unlawfully accessed and exfiltrated personal information without authorisation," reported through internal channels and tied to the facility with ICAO code FAMM (Mmabatho/Mahikeng, South Africa — not Maputo).123 ATNS said initial inquiries "were unable to substantiate the allegations."1 Whether the OT-malware strand and the insider strand are related is unknown.

Loading diagram...

Threat Actor Profile

Name: Unknown / unattributed Aliases: None — no actor has been named Attribution confidence: None. Neither ATNS nor any third party has attributed the incident. No ransomware group had claimed it as of October 6, 2026.13 Motivation: Undetermined. The presence of ransomware-staging malware is consistent with financially motivated extortion, but no ransom demand or extortion has surfaced.2 Sophistication: Undetermined; the intrusion was detected and reportedly contained at an early stage.1

No actor line can be drawn from the public record. The only observable pointing outward is that network monitoring flagged connections to external IP addresses geolocated in China; ATNS presents this as a line of inquiry for the forensic investigation, not a conclusion.12 One outlet's headline escalated this to "China-linked hackers attacked South Africa's air traffic control system," which the underlying reporting does not support — its own body says only that ATNS wants to "trace actors in China which may have stolen data."3 IP geolocation is not attribution: exfiltration destinations are routinely intermediary or compromised hosts.

The techniques below correspond to the activity ATNS reported. Because the entry vector, tooling, and command-and-control are not established, the mapping is partial and these entries are the behaviours the forensic investigation will test, not confirmed tradecraft.

MITRE ATT&CK techniques (IDs verified live on attack.mitre.org):

ID Technique
T1041 Exfiltration Over C2 Channel (reported: suspected exfiltration to external IPs; channel unconfirmed)
T1078 Valid Accounts (alleged, unsubstantiated: insider misuse of authorised access)

OPSEC: Unknown. No infrastructure, tooling, or operational tradecraft has been disclosed.

Technical Indicators

exfiltration_destination: external IP addresses located in China (specific addresses not published)
affected_facilities_icao:
  - 'FAPE  # Chief Dawid Stuurman Intl (Gqeberha / Port Elizabeth), South Africa - OT malware'
  - 'FAEL  # East London, South Africa - possibly affected, unclear'
  - 'FAMM  # Mmabatho / Mahikeng, South Africa - insider allegation (mislabelled Maputo in some coverage)'
malware_family: not publicly identified; described as associated with the early stages of ransomware
file_hashes: none disclosed
c2_domains: none disclosed
ip_addresses: none disclosed
ransom_note: none reported
leak_site_listing: none as of October 6, 2026
note: >
  ATNS has published no technical IOCs. The forensic investigation (RFQ issued
  18 September 2026) was commissioned to establish the entry vector, scope, and
  whether data was exfiltrated. "China" is the geolocation of destination IP
  space, not an attribution.

No law-enforcement action, arrest, or sanction had been publicly tied to this incident as of October 6, 2026, and no criminal group has been named.13 ATNS procured private digital-forensics services through an RFQ rather than announcing a public-sector investigation.2 No public notice from the South African Civil Aviation Authority (SACAA) or the Department of Transport specific to this incident had appeared as of October 6, 2026, and ATNS said it "will provide information, where appropriate, once the investigations have been completed."1

The insider strand carries a statutory dimension: South Africa's Protection of Personal Information Act (PoPIA) requires reporting breaches that involve personal information, which is one reason the alleged unlawful access to personal data falls inside the forensic scope; operational cyber incidents that do not touch personal data face weaker mandatory-reporting obligations.2

This 2026 malware incident should not be conflated with ATNS's unrelated 2025 regulatory crisis, in which instrument flight procedures were suspended at several South African airports after SACAA approvals lapsed and ATNS missed revalidation deadlines — an administrative failure, not a cyberattack, that nonetheless also touched Port Elizabeth among other airports.4

Impact Assessment

  • Confirmed: Malware associated with the early stages of ransomware was found in an OT network supporting weather-related air traffic services; internal teams performed containment and malware removal.12
  • Confirmed: No interruption to air traffic or flights was reported; the potential to "critically disrupt flight planning, visibility data and communication lines" is ATNS's conditional assessment, not an outcome.1
  • Reported, not independently confirmed: Possible data exfiltration to external IP addresses located in China.12
  • Reported, unsubstantiated: Insider allegation that employees unlawfully accessed and exfiltrated personal information (ATNS's initial investigation could not substantiate it).1
  • Estimated / context: Ransomware attacks on the aviation sector rose roughly sixfold in 2025 versus the prior year, with 27 major attacks reported in the 16 months to April 2025, per Thales data cited by Dark Reading.2
  • Unknown: Entry vector, dwell time, malware family, actor, whether and what data left the network, and the relationship (if any) between the OT-malware and insider strands.12

Lessons and Defensive Recommendations

For SOC / OT defenders:

  • The win here was egress monitoring: anomalous connections from an OT segment to external IP space are what surfaced the incident. Baseline OT network egress and alert on any outbound flow from weather/met and other OT systems to the public internet.
  • Segment OT weather-services networks from IT and from each other; an ANSP's meteorological OT should not be able to reach arbitrary external hosts.
  • Treat "early-stage ransomware" tooling as a live intrusion, not a cleaned-up event: preserve forensic images before remediation so entry vector and dwell time can be established — the questions ATNS still cannot answer.

For platform / identity teams:

  • The insider strand turns on authorised access to personal-data stores; enforce least privilege, data-loss-prevention egress controls, and immutable access logging on personal-information repositories so later forensics can produce "defensible findings."

For leadership:

  • Resist the headline. Distinguish "malware associated with early-stage ransomware, contained" from "a ransomware attack," and resist attributing to a nation from destination-IP geolocation alone — both overstatements appeared in coverage of this incident.
  • Mandatory, detailed incident reporting for operational cyber events (not only personal-data breaches under PoPIA) would close the regional blind spot that leaves attacks on critical infrastructure under-tracked.

For researchers / journalists:

  • ICAO codes (four letters, e.g. FAMM) are not IATA codes (three letters, e.g. MBD); the FA- prefix is South Africa and FQ- is Mozambique. FAMM is Mmabatho, not Maputo. Verify the aerodrome before placing an incident in another country.
  • Keep the 2025 SACAA flight-procedure suspensions separate from this 2026 OT-malware incident; both involve ATNS and both touched Port Elizabeth, which invites conflation.

Sources

Footnotes

  1. Business Day / Sunday Times (TimesLIVE) — Air traffic agency probes cyberattack — September 26, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28

  2. Dark Reading — South Africa Seeks Help After Cyberattack Targets Air Traffic Control — September 30, 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25

  3. Rio Times — South Africa's Air Traffic Operator Finds Ransomware-Linked Malware — October 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10

  4. FlightGlobal — Flight procedures re-approved at main South African airports but others suspend services — April 8, 2025 ↩ ↩2

  5. SC Media — South African air traffic control firm investigates ransomware-linked malware in OT network — September 30, 2026 ↩

Topics: #atns#south-africa#aviation#air-traffic-control#operational-technology#ransomware#critical-infrastructure#insider-threat#data-exfiltration
Original Incident Report →

Related Research

Warlock (Storm-2603 / GOLD SALEM / Longlegs) kept exploiting SharePoint ToolShell flaws into 2026, ransoming 33+ hosts at a critical-infrastructure operator via SYSVOL across Europe, Africa and Latin America.

Ransomware

Three men who worked in incident response ran BlackCat attacks. One of them was simultaneously negotiating on behalf of ransomware victims — and passing the attackers his own clients' insurance limits.

RansomwareInsider ThreatExtortion & Blackmail

The BlackSuit ransomware group (a rebrand of Royal Ransomware) compromised CDK Global, the dominant Dealer Management System provider for North American auto dealerships, causing a weeks-long outage affecting ~15,000 dealerships' ability to sell, finance, service, and manage vehicles — one of the most disruptive ransomware incidents against a critical software supplier in 2024.

Ransomware