ThreatPaper
Weak Evidence

China-linked hackers attacked SA's air traffic control

Assessment

The assertion comes from a headline. The underlying record is only that ATNS's network monitoring indicated possible data exfiltration to external IP addresses located in China, which ATNS presents as a line of inquiry, not a conclusion. IP geolocation is not attribution: exfiltration destinations are commonly intermediary or compromised hosts. No actor has been named by ATNS or any third party, and no ransomware group has claimed the incident. mybroadband's own body is more measured, saying ATNS wants to trace actors in China which may have stolen data.

Where this claim appeared

mybroadband · 2026-09-30

https://mybroadband.co.za/news/security/670359-china-linked-hackers-attacked-south-africas-air-traffic-control-system.html

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

ATNS air traffic OT network: ransomware-linked malware found, suspected China-bound data exfiltration (South Africa)

Think this assessment is wrong? Report an error.