Darkreading South Africa's Air Traffic Control Faces Ransomware Attack
Article Content
- •ATNS detected ransomware in its operational technology network supporting air traffic services.
- •Possible data exfiltration to external IP addresses in China raises concerns about insider involvement.
- •Ransomware attacks on aviation infrastructure have surged, highlighting increasing cybersecurity risks.
Air Traffic and Services (ATNS) in South Africa reported a ransomware attack targeting its operational technology network, which supports weather-related air traffic services. The attack could have severely disrupted commercial aviation activities. Preliminary investigations indicated potential data exfiltration to external IP addresses in China, and there are concerns about possible insider involvement. ATNS has engaged forensic investigators to assess the extent of the compromise and to identify any remaining risks. The agency manages over 6% of the world's airspace and has implemented containment measures. The attack is part of a worrying trend, as ransomware attacks on aviation infrastructure have surged significantly. The exact date of the incident remains unclear, but ATNS began seeking forensic services on September 18, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track South African Airways in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited Citrix disclosed two critical zero-day vulnerabilities, CVE-2026-88771 and CVE-2026-88772, affecting NetScaler ADC and Gateway systems, which are being actively exploited. Both vulnerabilities have a CVSS score of 9.5 and allow unauthenticated attackers to execute arbitrary commands remotely. CVE-2026-88771 arises…