ATNS Discovered Ransomware in Aviation Networks

Air Traffic and Navigation Services detected malicious activity within its operational technology environments.

Updated on Sept. 30, 2026 in Cybersecurity

Bold flat-color editorial illustration featuring a geometric industrial cable connector, symbolizing the vulnerability of aviation infrastructure.
Air Traffic and Navigation Services is investigating a ransomware attack that infiltrated its operational technology networks at Port Elizabeth and Maputo airports. AI Illustration. Upload story photo >

Live Poll

Do you trust that public infrastructure in your area is sufficiently protected against cyberattacks?

Air Traffic and Navigation Services has uncovered ransomware-linked malware in its operational technology network. The incident occurred at Port Elizabeth Airport while the company also investigates a possible insider data theft at Maputo International Airport.

Why it matters

The security breach highlights growing vulnerabilities in critical aviation infrastructure that manages 10% of global airspace. Technical teams identified data exfiltration to IP addresses based in China, prompting an urgent search for external forensic support.

Monitoring systems identified malware during standard operations, with technical teams confirming indicators of external data exfiltration. The company manages air traffic control and weather operations for 10% of world airspace.

The players

Air Traffic and Navigation Services

This entity manages critical air traffic control and weather operations for approximately 10% of global airspace.

The details

Internal teams implemented containment measures and malware removal following the detection of suspicious activity. The company has officially requested quotes from cyber-forensics firms to assist with a comprehensive investigation into both the malware and the potential insider data theft.

Timeline

  1. January 2024 marked the start of a period of tracked South African cyber incidents.

  2. April 2025 concluded a 16-month period featuring 27 major aviation ransomware attacks.

  3. August 2026 saw 1,042 ransomware attacks targeting organizations globally.

  4. September 18, 2026, serves as the start date for requested cyber-forensic services.

The Tech Race

This breach follows the pattern of the sixfold surge in ransomware attacks targeting the aviation industry in 2025, confirming the persistent threat level to global transit hubs. Industry experts project that cyberattackers will increasingly leverage AI to power more sophisticated future attacks.

Travelers may face operational delays as authorities implement heightened security protocols across aviation networks. The investigation and subsequent containment measures ensure that sensitive systems remain protected from unauthorized external access.

The takeaway

Critical infrastructure providers are increasingly targeted as cyberattackers employ more advanced tactics to compromise sensitive operational technology. Organizations must prioritize robust forensic auditing and insider threat monitoring to maintain global airspace safety.

What happens next

Cyber-forensic services are scheduled to commence on September 18, 2026.

Further reading

Learn more about evolving digital threats in the Cybersecurity section.

Live Poll

Do you trust that public infrastructure in your area is sufficiently protected against cyberattacks?