ThreatPaper
Weak Evidence

ATNS was hit by a ransomware attack

Assessment

Several reports state ATNS came under or suffered a ransomware attack. ATNS's own wording is narrower: malware commonly associated with the early stages of ransomware attacks, which its internal teams say they contained and removed. No encryption event, ransom note, extortion demand, or leak-site listing has been reported, and no ransomware family has been named. Describing it as a completed ransomware attack overstates what ATNS and the primary record establish; early-stage, contained malware is not a consummated ransomware deployment.

Where this claim appeared

Business Day / Sunday Times (TimesLIVE) · 2026-09-26

https://www.timeslive.co.za/news/business/2026-09-26-air-traffic-agency-probes-cyberattack/

What “Weak Evidence” means

Evidence exists but is thin, circumstantial, or explicitly qualified as weak by the source that published it. Shared hosting infrastructure between threat clusters is the recurring example.

3 of 5 · rating scale

Assessed in

ATNS air traffic OT network: ransomware-linked malware found, suspected China-bound data exfiltration (South Africa)

Think this assessment is wrong? Report an error.