Skip to content
TECH CEO Daily

ATNS cyberattack: South Africa air traffic agency reportedly finds ransomware-linked malware in OT systems

Reported preliminary findings point to malware tied to early-stage ransomware in systems supporting weather and flight services, prompting outside forensic help.

By · Editor

· 2 min read · Fact-checked

The 60-second brief

  • 1South Africa's Air Traffic and Navigation Services reportedly found malware linked to early-stage ransomware attacks.
  • 2The activity was reported in operational technology supporting weather and flight services, including regional airport facilities.
  • 3ATNS management sought urgent help from outside cyber-forensics firms; no flight disruption was reported in the summary.

The news

South Africa's Air Traffic and Navigation Services (ATNS), the state-owned company that runs the country's air traffic control, is investigating a cyberattack after preliminary findings reportedly uncovered malware associated with early-stage ransomware attacks. The ATNS cyberattack was reported by Dark Reading and summarized by OODA Loop on October 1, 2026.

According to OODA Loop's summary, the suspicious activity was found in operational technology (OT) environments that support weather and flight services. OT refers to the computers and control systems that run physical operations, as opposed to office IT such as email and accounting.

The investigation reportedly covers network compromises affecting regional airport facilities, including operations at Port Elizabeth and possibly East London, according to reports. OODA Loop also reported preliminary evidence of potential data exfiltration, meaning data may have been copied out of the network. That point is described as a possibility, not a confirmed theft.

Dark Reading reported that internal technical teams had put containment measures in place and removed malware, but that a full forensic investigation was needed to establish the root cause and extent of the compromise. ATNS management sought external cyber-forensics firms for that work, according to the summary. The report did not describe flight disruptions or passenger impacts, and it did not name a ransomware group or say whether any files were encrypted.

Malware associated with the early stages of a ransomware attack typically includes tools that attackers use to move around a network, steal credentials and prepare for encryption. Finding it before encryption can give defenders a chance to remove the intruder, although the full scope of this incident had not been publicly reported.

Why CEOs should care

The detail that matters for executives is where the malware turned up: in operational systems, not just office IT. Ransomware crews have spent years hitting corporate networks, and critical-infrastructure operators often keep OT separate for that reason. Signs of ransomware tooling inside systems tied to weather and flight support suggest those boundaries can be crossed.

For CISOs at utilities, transport, manufacturing and healthcare, ask three questions. Do we know every connection between our IT and OT networks? Would we detect attacker tools in OT before encryption, not after? And do we have a forensics firm on retainer, so we are not shopping for one during an incident, as ATNS reportedly had to seek outside help?

For boards and CFOs, operational downtime is the costliest outcome of an OT incident. Make sure business continuity plans cover running safely with key systems offline, and that cyber insurance terms cover operational disruption, not only data breaches.

The bigger picture

Attacks on critical infrastructure are increasingly aimed at the systems that keep services running. Our recent coverage of Warlock ransomware attacks on a water utility and a telecom provider, and cyberattacks that drew the Coast Guard and FBI to oil tankers, shows the same pattern of attackers reaching beyond office networks.

Aviation is a sensitive target because disruption is immediate and highly visible. Even when flights keep moving, an investigation like this one forces operators to verify the integrity of systems that controllers and pilots rely on.

What’s next

Watch for an official statement from ATNS or South African authorities on the incident's scope, whether data was taken, and whether any group claims responsibility. Operators elsewhere should use the case to test how quickly they could detect and contain ransomware tooling inside their own OT environments.

What “Fact-checked” means

Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.

What we checked
Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
How
A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
Who
The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, . A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
If something is wrong
“Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error

How we fact-check →

ATNSSouth AfricaAviationOperational technology

Written by

Editor · Technology & Business Writer

Hussein is a writer and business technology enthusiast focused on the intersection of technology, entrepreneurship, finance, artificial intelligence, and digital innovation.

CoversAICybersecurityBig TechSaaSStartupsFintech

About this story. Researched from primary sources whenever they are available and fact-checked before publication.

Published by Tech CEO Daily, an independent publication. Masthead · Editorial standards

Follow Tech CEO Daily on Facebook for the day’s top stories in your feed.

Free newsletters

The technology briefing for people running businesses.

Daily, weekly, bi-weekly or monthly. You choose.

How often

The Daily Brief · Monday to Saturday, 7 a.m. ET

Free forever. One click to unsubscribe. We never sell your email.