South Africa’s Air Traffic Services Provider Investigates Cyberattack on OT Network

· Original article ↗

Summary

South Africa’s ATNS found ransomware-associated malware in an operational technology network supporting air traffic weather services and is seeking forensic investigators. A separate possible data theft at a Mozambique airport is also under investigation.

Key points

  • ATNS detected suspicious activity and malware commonly associated with early-stage ransomware in an OT environment supporting weather services.
  • The OT incident occurred at Port Elizabeth Airport; East London Airport may also have been affected.
  • Investigators found indications of data exfiltration to external IP addresses in China.
  • A separate possible insider data theft at Maputo International Airport is included in the forensic investigation request.
  • ATNS said internal teams contained the activity and removed malware, but requested a comprehensive investigation to establish the cause, scope, and remaining risks.

Article Details

Victim Organization
Air Traffic and Navigation Services (ATNS)
Incident Type
Ransomware-linked malware detected in an operational technology network; a separate possible insider data-theft incident is also under investigation.
Operational Impact
ATNS said its technical team believed it stopped the attack and implemented containment measures and malware removal. No service disruption was reported. The extent of compromise and any remaining risks are under investigation. Possible data exfiltration was identified as a preliminary finding, not confirmed.
Ransom Or Extortion
No ransom demand or extortion was reported. The malware was described as commonly associated with early stages of ransomware attacks.
Claim Status
confirmed

People

Vendors

Countries

Industries