Air Traffic and Navigation Services (ATNS) has launched a comprehensive forensic investigation into a cyberattack on its systems, which could have brought commercial aviation activities in South Africa to a halt. The attack, which occurred during the current financial year, targeted the agency's operational technology environment supporting weather-related air traffic services. This system is critical for flight planning, visibility data, and communication lines between meteorological providers and control towers.
Preliminary investigation revealed that the attack was a ransomware attack, with possible data exfiltration to external IP addresses located in China. ATNS has implemented containment measures and malware removal, but an independent forensic investigation is required to determine the root cause, extent of compromise, and any remaining risks. The agency has also received reports that employees may have unlawfully accessed and exfiltrated personal information without authorization.
ATNS manages more than 6% of the world's airspace and employs over 1,000 staff to ensure safe, efficient, and orderly air traffic services across 21 aerodromes in South Africa. The agency also supports aeronautical satellite communication across 33 states in the broader African region, connecting the continent from Cape to Cairo and extending to the Middle East. ATNS spokesperson Khulu Phasiwe stated that the agency is treating the matter with seriousness and will provide information once the investigations are completed.
The cyberattack on ATNS is not an isolated incident, as South Africa's aviation assets have increasingly become targets of cyberattacks. South African Airways was hit by a significant cyberattack that temporarily disrupted its official website, mobile application, and several internal operational and communication systems. Airports Company South Africa (Acsa), which operates the country's commercial airports, has also warned of a high cyber threat risk due to inadequate security governance and information security management systems.
Acsa's annual report flagged ICT inefficiencies, including outdated systems and fragmented, non-integrated digital infrastructure, as contributing factors to its cybersecurity risk. The organization has announced the appointment of Siphamandla Mthethwa as its new CEO, who will be responsible for accelerating the modernization of outdated ICT systems and infrastructure. Mthethwa previously held the role of CFO before leaving the organization in 2023.
Acsa chair Irvin Phenyane stated that Mthethwa's combination of institutional knowledge and financial acumen will serve the entity well as it enters its next phase of growth. Mthethwa will help Acsa navigate its major airport infrastructure investment programme and build on the progress made during his previous tenure. His appointment comes at a critical moment in Acsa's journey, as the organization seeks to strengthen its cybersecurity and modernize its ICT systems.
The investigation into the cyberattack on ATNS is ongoing, with the agency working to determine the extent of the compromise and any remaining risks. ATNS has assured that it will provide updates on the investigation as more information becomes available. The incident highlights the growing threat of cyberattacks on critical infrastructure in South Africa's aviation sector.
Key points
- ATNS investigates ransomware attack that could have disrupted commercial aviation
- Cyberattacks on South Africa's aviation assets are on the rise
- Acsa appoints new CEO to modernize ICT systems and infrastructure