Rise in aviation ransomware attacks, 2025 vs. 2024: Sixfold (Source: Thales, as reported by Dark Reading (September 30, 2026))
What the public documents show
Some security incidents are announced. This one is described in a request for quotes.
Dark Reading reports that public documents released this month show a South African state-owned company found ransomware-linked malware on an operational network. The company is Air Traffic and Navigation Services (ATNS). Dark Reading says it handles air traffic control and weather operations across roughly a tenth of the world's airspace.
The documents are a request for quotes (RFQ) from cyber-forensics firms. ATNS asked for services to start on September 18. The documents do not say when the incident happened.
Dark Reading asked ATNS for comment. The company had not replied by publication time. The source does not say whether ATNS has made any other disclosure.
The lesson here is that procurement paperwork can hold real incident detail. Leaders who depend on a critical supplier may want to read it.
What ATNS says it found
In the RFQ, ATNS says its monitoring picked up suspicious activity. It was in operational technology (OT) behind weather services for air traffic control. OT means the systems that run day-to-day operations, as opposed to office IT such as email and payroll.
First checks found malware of a type often seen early in ransomware attacks, the RFQ says. Technical teams also saw signs that data may have been sent to addresses in China.
ATNS says its internal teams contained the incident and removed the malware. It adds that a full forensic investigation must establish the root cause, the extent of the compromise and any remaining risks.
ATNS says its monitoring detected the activity. The extent of the compromise will also show how far the intruders got before detection. That link is this article's inference. The RFQ does not state it.
Two sites are named. The OT problem was at Port Elizabeth Airport in South Africa. A possible theft of data by an insider was at Maputo International Airport in Mozambique. The RFQ is unclear on whether East London Airport was also affected by the OT problem. The report names no attacker.
Why removing malware is not the end
Ransomware usually arrives in stages. Attackers get in, spread, then lock systems. The malware ATNS found is linked with the early stages.
Deleting it does not show how the attackers got in. It does not show what they took. That gap is why ATNS is asking for forensics.
Paper controls versus tested controls
Hendrik de Bruin leads security consulting for Africa at Check Point. He says compliance checks show that controls exist on paper. Attackers find out whether they work.
He described a recent Check Point case at a large organization in a neighboring country. "There was a firewall, but nobody had asked whether it was switched on and doing its job," he says.
The figures below are Thales and Check Point data. They set the context. They do not describe ATNS. Check Point's figure for South Africa is also slightly below the global average.
A regional gap in reporting
Avinash Singh is a computer science lecturer at the University of Pretoria. His comments are about organizations across the region. He was not speaking about ATNS.
Singh argues that firms in the region disclose too little about the attacks they suffer. In his telling, some fix problems in private. They want to protect their reputation, avoid alarming customers or stay clear of regulators.
South Africa's Protection of Personal Information Act requires reporting of breaches involving personal data. Dark Reading notes there is less mandatory reporting for purely operational incidents. Singh says that creates a significant blind spot in tracking attacks.
He also names a practical cost. Defensive tools built on global threat data lean heavily on the Northern Hemisphere. That data may not match the methods used against this region.
Questions for your team
Does monitoring cover operational systems such as weather, scheduling or plant controls, or only office IT?
If monitoring flags something, how will you learn how far intruders got before it did? ATNS is asking outside experts to establish the root cause and extent of the compromise.
Can your team show that each key control is switched on and working? Ask for test results, not a compliance certificate.
Do your rules send operational incidents to the board, even when no law requires a report? Who decides what is disclosed?
Could you start a forensic investigation quickly, without a fresh buying process? Do your key suppliers have that ability?
A compliance check shows a control exists. Only a test shows that it works.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Dark Reading.





