Skip to content

Executive Summary

The South African state-owned company responsible for air traffic control and weather operations, Air Traffic and Navigation Services (ATNS), has detected ransomware-linked malware within its operational technology (OT) network. An investigation is underway by the company, which is seeking cyber-forensics firms to examine the incident and potential data theft. Suspicious activity was observed in OT environments supporting weather services, pointing to malware associated with early-stage ransomware attacks. Furthermore, there are indications that data may have been exfiltrated to external IP addresses in China. The investigation is focusing on facilities including Port Elizabeth Airport (FAPE) and potentially East London Airport (FAEL), as well as Maputo International Airport (FAMM), regarding possible insider data theft. This event highlights increased risks to aviation infrastructure, which experienced a sixfold rise in ransomware attacks in 2025, particularly concerning critical infrastructure in Africa.

Facts Only

* Air Traffic and Navigation Services (ATNS) discovered ransomware-linked malware in its operational technology (OT) network.
* The company is seeking cyber-forensics firms to investigate the incident and potential data theft.
* Suspicious activity was detected in OT environments supporting weather services.
* Preliminary findings suggested malware commonly associated with early stages of ransomware attacks.
* Suggestions of data exfiltration to external IP addresses in China were noted.
* The investigation examines Port Elizabeth Airport (FAPE) and potentially East London Airport (FAEL).
* The investigation also includes Maputo International Airport (FAMM) regarding possible insider data theft.
* The incident involves systems managing approximately 10% of the world's airspace.
* A sixfold increase in ransomware attacks occurred in the aviation sector in 2025.

Full Take

The narrative presents a clear linkage between high-value critical infrastructure, specific geographic locations within Africa, and sophisticated cyber threats, framed by the context of escalating global ransomware risks. The focus on OT environments in air traffic and weather services suggests a vulnerability not just in IT systems but at the physical control layer necessary for operational safety. The suggestion of data exfiltration to China introduces geopolitical dimensions into the technical investigation, prompting an examination of state-sponsored or state-aligned motives beyond simple financial gain. Furthermore, tracing potential insider threats across multiple international locations—South Africa and Mozambique—shifts the focus from purely external threat actors to assessing internal governance structures, skills deficits, and security protocols within state-owned entities. The pattern suggests that the risk is amplified where operational complexity (managing airspace) intersects with geopolitical sensitivity, creating a high-stakes target for disruption. What are the specific governance gaps that permit such sophisticated intrusions into essential services, and how does the visibility of these disruptions influence the perceived vulnerability of African critical infrastructure?

From the original · SC Magazine

Coverage from Dark Reading indicates that the South African state-owned company responsible for air traffic control and weather operations, Air Traffic and Navigation Services (ATNS), has discovered ransomware-linked malware within its operational technology (OT) network.
Read the full story at scworld.com

Sentinel — Human

Confidence

This text reads like a factual report aggregating findings from multiple sources regarding a specific cybersecurity incident in critical infrastructure, exhibiting the structure of journalistic reporting.

Signals Detected
low severity: Sentence length variance appears reasonable; the text flows logically without excessive mechanical uniformity.
low severity: The narrative smoothly integrates operational details (ATNS, malware) with geopolitical implications (data exfiltration to China, African infrastructure risk).
low severity: Attribution is clearly linked to the stated source ('Dark Reading', 'Critical Infrastructure Security') and focuses on reporting discovered facts rather than synthesizing existing arguments.
low severity: Specific entities (ATNS, FAPE, FAEL, FAMM) and the context of cybersecurity incidents are grounded in real-world operational concerns, suggesting factual reporting rather than pure fabrication.
Human Indicators
The structure mimics typical news reporting by presenting a primary finding followed by secondary investigative leads and contextual implications.
The inclusion of specific named locations (Port Elizabeth, Maputo) combined with abstract risk statements suggests journalistic grounding.
South African air traffic control firm investigates ransomware | Huntaegis