// 2 ZERO-DAY · 4 CVE · 2 EXPLOIT · 1 ADVISORY IN THE LAST 24H→
Air Traffic and Navigation Services (ATNS), the South African state-owned entity managing roughly 10% of the world's airspace, has discovered pre-ransomware malware inside the operational technology (OT) network at Port Elizabeth Airport. An RFQ dated September 18, 2026 reveals the agency contained the malware internally but requires external forensic investigation to determine root cause, extent of compromise, and residual risks. Logs show data exfiltration to IP addresses in China. A second, potential insider threat incident at Maputo Airport in Mozambique is also under investigation.

Air Traffic and Navigation Services (ATNS), the South African state-owned enterprise that manages approximately 10% of global airspace, has discovered malware associated with the early stages of ransomware attacks inside the operational technology (OT) network at Port Elizabeth Airport (FAPE). The disclosure emerges from a public Request for Quotation (RFQ) issued by the agency, dated September 18, 2026, seeking external contractors for in-depth forensic investigations. The case exposes a recurring pattern in the South African public sector: internal detection, autonomous containment, delayed disclosure, and external assistance sought only when internal systems prove insufficient to establish the damage perimeter.

Key Takeaways
  • Malware "commonly associated with the early stages of ransomware attacks" detected in the OT network delivering weather services to Air Traffic Services at Port Elizabeth, with suspicious activity flagged by internal monitoring systems.
  • Logs show data exfiltration to external IP addresses located in China, without the official document establishing attribution links to specific threat actors.
  • A second incident, covered by the same investigation, involves reports of possible unlawful access and personal data theft at Maputo Airport, Mozambique (FAMM), with unconfirmed insider involvement hypotheses.
  • ATNS contained and removed the malware using internal resources, but the RFQ explicitly admits the need for external forensic investigation to determine root cause, extent of compromise, and residual risks.

How the Attack Surfaced: From Detection to RFQ

ATNS monitoring systems detected suspicious activity "within operational technology (OT) environments supporting weather-related services to Air Traffic Services" at Port Elizabeth Airport. Preliminary investigations identified malware the official document describes as commonly associated with the initial phases of ransomware attacks. Simultaneously, logs recorded "data exfiltration to external IP addresses located in China."

The internal response was immediate but partial: "Internal technical teams have implemented containment measures and malware removal; however, a comprehensive forensic investigation is required to determine the root cause, extent of compromise, and any remaining risks." This admission, quoted verbatim in the RFQ, constitutes the crux of the matter: an entity managing 21 aerodromes in South Africa and supporting satellite communications across 33 African states failed to close the incident autonomously.

The request for quotation, with a start date set for September 18, 2026, seeks specialized cyber-forensics services. The procurement-first approach — publishing an RFQ instead of a structured disclosure — reflects procedural constraints typical of public entities but delays the sharing of indicators of compromise useful to the defensive community.

The Possible Insider Threat at Maputo and the Dossier's Limits

The ATNS document does not limit itself to the Port Elizabeth OT incident. It cites reports received "through internal channels" concerning Maputo International Airport, Mozambique (FAMM), where "employees may have unlawfully accessed and exfiltrated personal information without authorisation." The phrasing is deliberately conditional: the brief does not confirm actual insider involvement, nor does it establish technical or operational connections between the two episodes.

Geographical boundaries of the incident also remain unclear. The RFQ mentions that East London Airport (FAEL) "may have also been affected," but the document does not clarify on what basis. ATNS does not specify the malware family detected, the initial access vector, the volume or nature of potentially exfiltrated data, nor the existence of a ransom demand. Spokesperson Khulu Phasiwe, contacted by Sunday Times, confirmed the incident occurred in the "current financial year" but refused further detail: "ATNS is currently unable to comment on the nature or extent of any potentially compromised data until the forensic investigation has been concluded."

Why Operational Silence Amplifies Systemic Risk

"Across the region, the threat landscape is shifting aggressively toward critical infrastructure" — Avinash Singh, University of Pretoria

The absence of localized, timely data — highlighted by the University of Pretoria expert — produces a cascade effect on defensive models. Without shared indicators of compromise, other African critical infrastructure operators operate blind. The aviation sector recorded 27 significant ransomware attacks in 16 months through April 2025, according to Thales data cited by Dark Reading. South Africa, with an average of 2,086 weekly cyberattacks against a global average of 2,422 (Check Point data), sits in a high-risk band.

The institutional context deepens the concern. South African Airways has suffered previous cyberattacks; Airports Company South Africa (Acsa) classified cyber risk as "relatively high" in its annual report. ATNS employs over 1,000 people: a critical mass that, absent documented internal controls in the RFQ, exposes unquantified internal attack surfaces. The IT/OT separation, a structural premise of industrial infrastructure security, proved insufficient to prevent compromise.

What to Do Now

  • Monitor publication of ATNS RFQ results for any indicators of compromise released to the community.
  • Reassess IT/OT segmentation architectures in weather and air traffic control services, verifying detection systems are positioned on both sides of the perimeter.
  • Demand timely disclosure mechanisms from ATNS and analogous entities, including preliminary disclosures not contingent on completion of full forensic investigations.
  • Treat insider threat reports with independent verification protocols, separating physical security investigations from cybersecurity investigations to avoid conflicts of interest.

The Lesson: When Containment Is Not Enough

ATNS demonstrated immediate reaction capability: internal detection, containment, payload removal. What is missing is forensic reconstruction capability, the prerequisite for any predictive defense. The malware has been expelled, but without knowing how it entered, what paths it traversed, and what it touched, the agency cannot rule out residual persistence or parallel accesses not yet detected.

The pattern — discovery, silence, RFQ — is not a South African anomaly. It is the norm in systems where cybersecurity is still treated as a compliance cost rather than an operational capability. For an entity managing one-tenth of the world's skies, the difference between the two approaches is not semantic. It is the distance between a contained incident and one that, come the next wave, might not be.

Sources

Information verified against cited sources and current as of publication.

Sources


Sources and references
  1. darkreading.com
  2. sundaytimes.timeslive.co.za
  3. nvd.nist.gov
  4. github.com