A Weather OT Network Inside an Air Navigation Provider: What ATNS Has Not Yet Established
South Africa's air navigation provider found ransomware-stage malware in the operational technology supporting weather services to air traffic control. Containment was declared before forensics began, and ICAO Annex 3 asks for something containment cannot supply.

What the documents say
Air Traffic and Navigation Services (ATNS), the state-owned provider of air traffic services across South African airspace, has gone to market for outside forensic help after finding malware inside an operational technology network. The request for quotation, open from 18 September, states that “Monitoring systems detected suspicious activity within operational technology (OT) environments supporting weather-related services to Air Traffic Services” and that “Preliminary investigations identified malware commonly associated with the early stages of ransomware attacks” [1].
The same documents record indications of “data exfiltration to external IP addresses located in China” [1][2]. That line needs precision: it is a network-monitoring observation written into a procurement document, with no published telemetry, no named actor and no statement of what was taken. It is a reason to investigate, not an attribution.
ATNS has published no incident date; the procurement timeline is the only firm timestamp in the public record [1][5]. Spokesperson Khulu Phasiwe said ATNS was “currently unable to comment on the nature or extent” of the data involved [3]. The tender is reported as valued under R50 million and as covering two matters: the OT malware, and a suspected insider theft of employee personal information [1][2].
Two statements that describe different states of knowledge
The record contains a pairing that recurs in operational-technology incidents at infrastructure operators. ATNS says “Internal technical teams have implemented containment measures and malware removal”, and in the same breath that “a comprehensive forensic investigation is required to determine the root cause, extent of compromise, and any remaining risks” [1][3].
Both can be true at once, but the order in which they happened constrains what the second can now deliver. Removal performed before forensic acquisition reduces the evidence available to establish dwell time, lateral movement and what left the network. In an OT environment the pressure to restore the host is immediate and legitimate; the evidentiary requirement competes directly with it. Operators that have not decided in advance which wins, on which class of asset, decide it under pressure and usually in favour of restoration. The investigation ATNS is now procuring may accordingly establish less than it could have a fortnight ago.
Where the reporting diverges
Two disagreements are worth publishing rather than resolving. The first is which aerodromes are in scope. Dark Reading reads the ICAO designator FAMM as Maputo International Airport in Mozambique and lists it under the possible insider data theft [1]. MyBroadband places the insider matter at Mahikeng Airport [2]. ICAO’s FA- location-indicator prefix is allocated to South Africa, which fits Mahikeng rather than Maputo, whose designator is FQMA. Readers should treat the Mozambique reading as unconfirmed.
The OT incident itself is placed at the Eastern Cape aerodrome that MyBroadband names as Chief Dawid Stuurman International Airport and that other reporting identifies by its former name, Port Elizabeth, designator FAPE [1][2]. East London (FAEL) is reported as possibly affected, with the qualification that the procurement documents are “unclear on that point” [4].
The second divergence is scale. ATNS’s own site claims responsibility for South African airspace “as well as 10% of the world’s airspace” [8]; Business Day puts the figure at over 6% [3]. Neither changes the technical picture, but a reader should know which number came from the operator.
Why a weather network sits inside air navigation
Aeronautical meteorology is not a service bolted onto air traffic control. Instruments on the aerodrome produce observations; those become routine and special reports and terminal forecasts; and current values reach flight crews through the automatic terminal information service and meteorological broadcasts, as well as controllers directly. Business Day reported that disruption in this environment could have affected “flight planning, visibility data and communication lines between meteorological providers and control towers” [3].
That is a sensing and dissemination chain in the same sense surveillance and navigation are: sensors, a processing stage, and a broadcast or datalink path to users who act on the output. It is also the part most often left outside an OT boundary drawn around radar and navigation aids.
Nothing in the published material indicates that radar, navigation aids or air-ground communications were touched; the documents confine the described activity to the weather OT environment [1][4][5][6][7]. The durable observation is narrower: the OT boundary at an air navigation service provider holds more than surveillance and navigation, and the meteorological side of it is often governed by a different standard, team and audit.
What Annex 3 asks for, and what it cannot yet be given
ICAO Annex 3 requires each Contracting State to ensure that its designated meteorological authority “establishes and implements a properly organized quality system comprising procedures, processes and resources necessary to provide for the quality management of the meteorological information to be supplied to the users” [9]. It recommends that the framework conform to the ISO 9000 series and be certified by an approved organisation, and it requires that “Demonstration of compliance of the quality system applied shall be by audit” [9].
Read against the ATNS statements, that is where the open question sits. The Annex 3 obligation is evidentiary, not merely procedural: the quality of the information supplied has to be demonstrable, over a period, to an auditor. When the extent and the window of an OT compromise are unknown, the operator cannot yet evidence the quality of what it supplied during that window. This is not the same as saying any product was wrong. It is saying the assurance argument has a hole in it until forensics closes it.
That is the distinction most incident communications skip. “We removed the malware” answers a containment question; “we can account for the integrity of what we published between these two dates” answers the Annex 3 question, and ATNS has said it cannot answer that yet [1][3].
The institutional backdrop
This is the second availability or integrity event affecting the region’s aviation meteorological chain in roughly eighteen months, at two different organisations. In 2025 a security breach took the South African Weather Service offline, affecting aviation and marine products and the distribution of regional meteorological data, with its website still down days later [10].
ATNS has also been under operational pressure unrelated to security. On 4 January 2026, flights at OR Tambo International were disrupted; ATNS first cited human resource constraints at the control station, then blamed severe weather, and an airline publicly rejected that explanation [11]. The same reporting noted suspended instrument flight procedures, some withdrawn in December after their validity lapsed, and the transport minister suspending the chief executive and appointing an intervention team [11]. None of that caused the intrusion, but it bears on how quickly a forensic finding can be absorbed.
What to take from this
- Map which parts of your meteorological observation and dissemination chain sit inside the OT boundary and which do not. The boundary is frequently drawn on the surveillance and navigation side only.
- Decide now, in the OT incident procedure rather than the IT one, whether a weather OT host gets cleaned or imaged first, and who has the authority to make the call.
- Hold the evidence an audit will ask for: which meteorological products were produced, by which systems, during which window, and with what integrity controls [9].
- When an indicator such as an exfiltration destination appears in a procurement document rather than an advisory, record it with that provenance and nothing more [1].
- If you consume regional operational meteorological data, establish whether you could detect a stale or substituted product, and what you would do if you could not.
ATNS has not said what it lost, and may not yet know. Nothing published suggests a safety event. What the record shows is an air navigation provider declaring an operational network clean while stating it cannot describe the compromise, against a standard that asks it to describe exactly that.
Sources
Every R3KONX article cites its primary material. 11 sources, in order of first citation. Links open the original publication.
- South Africa Seeks Help After Cyberattack Targets Air Traffic Control Dark Reading · 2026-09-30
- China-linked hackers attacked South Africa's air traffic control system MyBroadband · 2026-09-30
- Air traffic agency probes cyberattack Business Day / Sunday Times · 2026-09-26
- South Africa's Air Traffic Control Operator ATNS Discovers Ransomware on OT Network, Seeks Cyber-Forensics Help avi-go · 2026-09-30
- South African air traffic control firm investigates ransomware-linked malware in OT network SC Media · 2026-10-01
- South Africa seeks help after cyberattack targets air traffic control OODA Loop · 2026-10-01
- Cyber News Roundup, 2 October 2026 Integrity360 · 2026-10-02
- Air Traffic and Navigation Services official website ATNS · 2026-10-03
- Annex 3 to the Convention on International Civil Aviation: Meteorological Service for International Air Navigation ICAO (copy published by the Swiss Federal Office of Civil Aviation) · 2018-07-01
- South African Weather Service hit by cyberattack, affecting critical operations Digital Watch Observatory · 2025-01-29
- Flight disruptions restored, but SA air traffic services blames bad weather, not staff shortages Daily Maverick · 2026-01-05
Researched and written by the R3KONX analysis desk from the cited primary material. ATNS has published no incident date and no forensic findings; every factual claim here is traced to the procurement record or to named reporting of it, and the exfiltration indicator is recorded as an observation in that record rather than as an attribution. Corrections to event@r3konx.asia.
