Threat Intelligence

South Africa's Air Traffic Control Hit by Ransomware, International Help Sought

Dark Reading · 30 Sept 2026
Key Takeaway Businesses supporting critical infrastructure should ensure operational technology networks are segmented from corporate IT and regularly tested for ransomware resilience.

South Africa's air traffic control authority has confirmed that a ransomware toolkit was installed on at least one operational network, prompting officials to seek international help in responding to the incident. The attack adds to a growing trend of cybercriminals targeting aviation infrastructure, a sector where disruptions can have serious safety and economic consequences.

While details on the extent of the compromise and the specific ransomware used remain limited, the incident highlights how critical infrastructure operators, including transport and aviation bodies, are increasingly attractive targets for ransomware groups. Such systems often combine legacy technology with modern IT networks, creating gaps that attackers can exploit.

For Australian businesses connected to transport, logistics, or critical infrastructure supply chains, this incident is a reminder that ransomware threats extend well beyond typical office networks and can affect operational technology systems with real-world consequences.

Summarised by CISO AI from Dark Reading. We link back to every original so you can read it yourself.