The South African state-owned company that provides air traffic control (ATC) and weather operations for approximately 10% of the world’s airspace discovered ransomware-linked malware in an operational technology (OT) network, according to public documents released this month.

The company, Air Traffic and Navigation Services (ATNS), believes that its technical team stopped the attack, but it issued a request for quotes (RFQ) seeking cyber-forensics firms to investigate the incident. A second attack, possibly an insider’s theft of data, is also part of the investigation request.

It’s unclear when the incident actually occurred, but ATNS requested cyber-forensic services starting Sept. 18, according to the documents.

“Monitoring systems detected suspicious activity within operational technology (OT) environments supporting weather-related services to Air Traffic Services,” the company stated in its service request. “Preliminary investigations identified malware commonly associated with the early stages of ransomware attacks.”

Related:Ghost Service Accounts Enable M365 Data Theft in Chile

The technical teams also found suggestions of “data exfiltration to external IP addresses located in China,” the document stated.

The attack highlights the increasing risks for aviation infrastructure, as ransomware gangs look to cash in on vulnerabilities in the critical sector. Ransomware attacks targeting the aviation industry surged sixfold in 2025 from the previous year, according to aviation and defense firm Thales. Aviation firms reported 27 major ransomware attacks in the 16 months leading up to April 2025, according to Thales data.

For Africa, aviation and other critical infrastructures are increasingly targeted, says Avinash Singh, a lecturer in the Department of Computer Science at the University of Pretoria (UP) in South Africa.

“Across the region, the threat landscape is shifting aggressively toward critical infrastructure,” he says. Aviation systems and other critical infrastructure are popular targets because the impact is often impossible to hide, adding, “grounded flights and stranded passengers cannot be hidden.”

Wanted: A Comprehensive Forensic Investigation

The cyber incidents happened at two facilities identified by their International Air Transport Association (IATA) codes: The OT incident occurred at Port Elizabeth Airport in South Africa (FAPE), while the possible insider cyber theft occurred at Maputo International Airport, Mozambique (FAMM). A second facility — East London Airport, South Africa (FAEL) — may have also been affected by the OT compromise, but the service request is unclear on that point.

Related:China’s FamousSparrow APT Spies on US Politics in Latin America

“Internal technical teams have implemented containment measures and malware removal,” the company stated in the RFQ. “[H]owever, a comprehensive forensic investigation is required to determine the root cause, extent of compromise, and any remaining risks.”

Dark Reading reached out to ATNS, but the company did not respond by publication time.

Cyberattackers’ adoption of AI is likely powering more attacks, according to experts. In August, at least 1,042 ransomware attacks targeted organizations across the globe, nearly double the same month in 2025, according to Check Point Software Technologies. South African organizations specifically recorded an average of 2,086 cyberattacks per week, slightly below the global average of 2,422, according to Hendrik de Bruin, head of security consulting for Africa, at Check Point.

“South African organizations face heavy, sustained pressure,” he says. “Since the start of 2024, at least eight national government departments and public entities have suffered confirmed cyber incidents, and aviation-related organizations are now part of that pattern.”

Hey, Is This Firewall On?

A critical problem for most organizations in the region is one that has affected businesses worldwide: Compliance checks prove that controls exist on paper, but attackers test whether they work in practice, says Check Point’s de Bruin. For example, in a recent incident investigated by Check Point in a large organization in a nation neighboring South Africa, the cyber defenses were not even set up properly.

Related:Cyber Op Targets South Korean Media & Automotive Sectors

“[T]here was a firewall, but nobody had asked whether it was switched on and doing its job,” he says. “Public reporting suggests similar themes locally, including security governance gaps, limited skills capacity, and aging, fragmented systems.”

Organizations in the region also need to report attacks more often and in more detail, rather than quietly remediating incidents to avoid reputational damage, panicked consumers, or regulatory scrutiny, says UP’s Singh. Some regulations, such as the Protection of Personal Information Act (PoPIA), require reporting data breaches involving personal information, but there is less mandatory reporting strictly for operational cyber incidents.

This creates a significant blind spot in tracking attacks, he adds.

“When developing automated preemptive ransomware investigation tools, accurate, localized data is vital to identify specific feature sets and behavioral patterns,” Singh says. “Without it, defensive models rely on global threat intelligence that heavily biases Northern Hemisphere data, which may not accurately reflect the specific attack vectors, domain abuse tactics, or infrastructure vulnerabilities favored by threat actors targeting this region.”





Source link

#

No responses yet

Leave a Reply

Your email address will not be published. Required fields are marked *