Ransomware Toolkit Discovered on South Africa’s Air Traffic Control Network
A ransomware toolkit was found on at least one operational network supporting South Africa’s air traffic control, leading the aviation authority to seek external help. The incident highlights the need for auditable incident‑response controls that satisfy multiple compliance frameworks.
ADTP Breach Watch· September 30, 2026· Dark Reading
SeverityCritical
Type💀 Ransomware
ConfidenceHigh
ReportedSep 30, 2026
Transportation & LogisticsAviation/transport government agenciesMalwareRansomware
What happened
A ransomware toolkit was installed on at least one operational network that underpins South Africa’s air traffic control system. The discovery triggered a request for external cyber‑security assistance to contain and remediate the threat.
Why it matters for trust and compliance
The event underscores why continuous control‑assurance and documented incident‑response processes are essential for safety‑critical infrastructure, providing defensible evidence for regulators and auditors.
Map the ransomware incident to your incident‑response control objective and capture forensic evidence as audit‑ready documentation.
Validate backup and recovery procedures to ensure rapid service restoration without regulatory penalties.
Who is affected
Aviation/transport government agencies
Recommended actions
Align the incident with your incident‑response and recovery controls; collect logs, forensic data, and remediation steps for audit readiness.
Test and verify backup/restore capabilities under realistic disruption scenarios.
Coordinate with national cyber‑response teams or vetted third‑party experts for containment and remediation.
Get the Breach Digest
The incidents that matter for your vendors and your data, analysed for practitioners, in one email.