South Africa Air Traffic Body Finds Ransomware Malware

Key Facts
- —The country South Africa has about 65 million people and Africa’s most industrialised economy, worth about US$427 billion in 2025 (World Bank), a little smaller than Denmark’s. Its air traffic agency manages roughly a tenth of the world’s airspace.
- —Why it matters Ransomware is malicious software that locks or steals an organisation’s data until a ransom is paid. Attacks on airports, ports and utilities can halt services that travellers and exporters depend on.
- —Why now Air Traffic and Navigation Services (ATNS), the state air traffic operator, sought forensic investigators from 18 September. The incident became public between 26 and 30 September.
- —What happened ATNS found malware “commonly associated with the early stages of ransomware” in systems that supply weather data to air traffic services at Gqeberha airport. It says the malware was contained.
- —The numbers A Sophos survey of 135 South African victims, presented on 18 September, put the median ransom demand at US$427,000, down 57 percent on a year earlier.
- —What it means for you No flight disruption has been reported. Firms operating in South Africa should test offline backups: only 40 percent of victims recovered within a week.
- —Still open Who was behind the ATNS intrusion, when it began, and whether data actually left the network. ATNS says it will comment once the forensic probe ends.
South Africa’s state air traffic operator has found ransomware-linked malware in systems that feed weather data to controllers. The case lands as a new survey shows how slowly South African victims recover.
The latest South Africa ransomware scare has reached aviation. Air Traffic and Navigation Services (ATNS), the state air traffic controller, is investigating malware found in its operational systems.
South Africa is the continent’s most industrialised economy and a hub for flights across southern Africa. ATNS manages roughly a tenth of the world’s airspace, according to the cybersecurity news site Dark Reading.
What ATNS disclosed
The details come from a request for quotes that ATNS issued on 18 September, seeking an outside digital forensics firm. Bids closed on 25 September.
“Monitoring systems detected suspicious activity within Operational Technology (OT) environments supporting weather-related services to Air Traffic Services,” the document said. Operational technology means the computers that run physical equipment rather than office work.
“Preliminary investigations identified malware commonly associated with the early stages of ransomware attacks,” ATNS added. Network monitoring also indicated “possible data exfiltration to external IP addresses located in China”.
The affected site is listed under the code FAPE, Chief Dawid Stuurman International Airport in Gqeberha, formerly Port Elizabeth. A separate allegation of insider data theft concerns FAMM, the code for Mahikeng (Mmabatho) airport in North West province.
What is known and what is not
ATNS said its internal teams had contained the threat and removed the malware. It still wants independent experts to establish the root cause, the extent of the compromise and any remaining risk.
The Sunday Times in Johannesburg first reported the probe on 26 September. Dark Reading and other specialist outlets followed on 30 September.
ATNS spokesperson Khulu Phasiwe told the Sunday Times only that the attack took place this financial year. “ATNS is currently unable to comment on the nature or extent of any potentially compromised data until the forensic investigation has been concluded,” he said.
No flight disruption has been reported, and no criminal group has been named. Traffic to IP addresses in China does not, on its own, show who was responsible.
Why weather systems matter for flights
Controllers and pilots depend on weather data for flight planning, visibility reports and runway decisions. If those feeds are locked or altered, airports may have to slow traffic or fall back on manual procedures.
According to the Sunday Times, a compromise could disrupt flight planning and links between weather providers and control towers. That is why the incident draws attention despite the reported containment.
What the new survey shows about South Africa ransomware costs
The ATNS case surfaced days after Sophos, a British cybersecurity company, presented its South African ransomware report on 18 September. It surveyed 135 local organisations hit in the previous year.
The median ransom demand fell 57 percent, from US$1 million in the 2025 report to US$427,000. The median payment fell 28 percent, to US$305,000.
Recovery remains expensive. Excluding any ransom, the average recovery cost was US$1.08 million, down from US$1.31 million a year earlier.
Speed is the weak point. Only 40 percent of South African victims recovered within a week, down from 47 percent. That was the lowest share of any country surveyed.
How attackers get in
Stolen or compromised login details were the most common technical cause, behind 27 percent of attacks. Exploited software flaws followed at 25 percent and malicious email at 22 percent.
Asked about internal weaknesses, 47 percent cited a lack of protection, the highest of any country in the survey. Another 43 percent cited too few staff, and 42 percent a known security gap.
There was progress on backups. Their use to restore encrypted data rose from 35 percent of victims to 54 percent.
Fewer organisations paid to get their data back: 58 percent, down from 71 percent a year earlier.
What it means for foreign businesses and travellers
For travellers, there is no sign of any operational impact on flights so far. The open question is whether the intrusion reached systems beyond weather services.
For foreign companies exposed to South Africa ransomware risk, the survey points to identity security and tested offline backups. Slow recovery, not the ransom itself, is where most of the damage lies.
The forensic findings will show whether state infrastructure has the same gaps that private firms report. ATNS says it will share information once the investigation is complete.
Frequently Asked Questions
What happened at South Africa’s air traffic operator?
ATNS found malware linked to the early stages of ransomware in systems supplying weather data to air traffic services at Gqeberha airport. It says the malware was removed and is seeking forensic investigators.
Were flights in South Africa disrupted?
No flight disruption has been reported. ATNS has not said exactly when the intrusion happened or whether any data was stolen, pending the forensic investigation.
How costly is ransomware for South African organisations?
In a 2026 survey of 135 victims, Sophos found a median ransom demand of US$427,000. Average recovery costs, excluding ransoms, were US$1.08 million.
Why are South African firms slow to recover?
Only 40 percent recovered within a week, the lowest of any country Sophos surveyed. Respondents most often cited a lack of protection, staff shortages and known security gaps left unfixed.
Connected Coverage
Sources
- Dark Reading: South Africa Seeks Aid After Air Traffic Control Cyberattack (30 Sep 2026)
- TimesLIVE / Sunday Times: Air traffic agency probes cyberattack (26 Sep 2026)
- ATNS: request for quotes, digital forensic investigation (18 Sep 2026)
- Sophos: The State of Ransomware in South Africa 2026
- Business Day: Ransomware recovery costing SA organisations (25 Sep 2026)
- IT-Online: Defences improve, but ransomware still threatens SA businesses (18 Sep 2026)
- World Bank: GDP (current US$), South Africa and Denmark
This article was produced by The Rio Times’ automated newsroom system. How we use AI · Report an error · Editorial responsibility: Matthias Camenzind, Editor-in-Chief
LatAm Markets: Live Signals → — real-time movers, turnover leaders and FX across Latin America.