Back

ATNS Investigates Ransomware-Linked Cyberattack Affecting South African Airports

At a glance

  • ATNS detected ransomware-linked malware in a weather services OT network.
  • Incident affected Port Elizabeth Airport, with possible impact at East London Airport.
  • Forensic investigators have been engaged to assess the extent of the breach.

The Air Traffic and Navigation Services (ATNS), responsible for managing air traffic control and weather operations across a substantial portion of global airspace, has reported a cyber incident involving ransomware-linked malware in its operational technology network.

The incident was identified in systems supporting weather-related air traffic services, with suspicious activity detected by monitoring tools. Preliminary findings indicated the presence of malware commonly associated with the early stages of ransomware attacks.

ATNS published a request for quotes on 18 September 2026, seeking cyber-forensics expertise to investigate both the malware incident and a potential insider data theft. The request outlined the need for a comprehensive assessment of the breach, including the possibility of a second attack involving internal actors.

Network monitoring revealed indications of possible data exfiltration to external IP addresses located in China. The investigation also covers a separate potential insider data theft incident at Maputo International Airport in Mozambique.

What the numbers show

  • The RFQ for digital forensic services opened on 18 September 2026 and closed on 25 September 2026.
  • The estimated value of the forensic services contract ranged from R850,000 to R26 million.
  • ATNS manages air traffic and weather operations for approximately 6–10% of global airspace.

The malware was detected at Port Elizabeth Airport, with East London Airport also possibly affected by the same incident. ATNS’s operational technology network, which supports weather-related services, was the main target of the attack.

Forensic investigators have been engaged by ATNS to determine the root cause of the breach, the extent of the compromise, and any remaining risks. The investigation aims to clarify whether insider involvement contributed to the data theft and to identify any ongoing threats to the network.

The request for quotes for digital forensic services was valued between R850,000 and R26 million, with a median estimate of R12 million. The procurement process concluded on 25 September 2026, and the selected firm will be responsible for analyzing the incident and providing recommendations.

ATNS continues to assess the situation in collaboration with external experts. The company is focused on restoring secure operations and addressing any vulnerabilities identified during the investigation.

* This article is based on publicly available information at the time of writing.