ATNS Discovered Ransomware Malware in Operational Network
Air Traffic and Navigation Services detected data exfiltration attempts following a breach at its Port Elizabeth facility.
Updated on Sept. 30, 2026 in Cybersecurity

Live Poll
Do you trust that public infrastructure in your area is sufficiently protected against cyberattacks?
Air Traffic and Navigation Services (ATNS) confirmed the discovery of ransomware-linked malware within its operational technology systems at Port Elizabeth Airport. The organization, which oversees 10% of global airspace, is now investigating this breach alongside a separate case of possible insider data theft at Maputo International Airport.
Why it matters
The incident highlights the growing vulnerability of aviation infrastructure, which has seen a sixfold surge in ransomware attacks during 2025. With eight South African public entities reporting cyber incidents since early 2024, the sector faces an increasingly aggressive threat landscape.
Monitoring systems identified exfiltration activity to external IP addresses located in China after detecting ransomware signatures. The organization currently manages 10% of global airspace, facing an average of 2,086 weekly cyberattacks on national organizations.
The players
Air Traffic and Navigation Services
The South African agency responsible for managing air traffic control and weather operations across 10% of global airspace.
The details
Internal technical teams identified the threat within operational technology environments—the hardware and software that monitor and control physical industrial processes. The response involved implementing containment measures and executing malware removal protocols. The agency has subsequently issued a request for quotes to retain external cyber-forensics firms to analyze the scope of the potential data theft and operational impact.
Timeline
January 2024: Start of tracked South African cyber incidents.
April 2025: End of the 16-month period seeing 27 major aviation ransomware attacks.
August 2026: Total of 1,042 ransomware attacks recorded against global organizations.
September 18, 2026: Official start date requested for hired cyber-forensic services.
The Tech Race
This breach follows a pattern of increasing aggression in the industrial cyber sector, which saw over 1,000 global ransomware incidents in August 2026 alone. Experts anticipate that attackers will continue to integrate AI-driven tools to scale these offensive operations against critical infrastructure.
The incident highlights the potential for physical service disruptions in aviation if operational technology remains compromised. Travelers may face increased scrutiny or potential delays as forensic investigations begin at key regional airports including Port Elizabeth and Maputo.
The takeaway
The aviation sector is currently the target of a rapid escalation in cyber-extortion, making robust endpoint monitoring essential. Stakeholders should monitor the outcomes of the forensics investigation beginning September 18, 2026, for insights into specific containment vulnerabilities.
Further reading
For broader context on the evolving threat landscape, see our latest analysis in Cybersecurity.
Live Poll
Do you trust that public infrastructure in your area is sufficiently protected against cyberattacks?






