I’d replace your current
LONDON — A previously unknown software defect with an exposure window of about one millisecond corrupted flight data at the UK's main air traffic control provider on September 8, triggering restrictions that left more than 2,000 flights delayed, canceled or diverted, NATS said in its preliminary report on the failure. NATS says the full scale of the disruption will take time to confirm.
The 18-page preliminary investigation report, dated September 16 and released on September 18, is NATS's first technical account of the failure. When Airways reported on the outage on September 12, the company had published only short status updates. Secretary of State for Transport Heidi Alexander requested the report, and a full Major Incident Investigation report is due within 60 days of the incident.
"This was a software issue in a specific part of our flight data system, that we have traced to a small subsection of coding," NATS chief executive Martin Rolfe said in the company's statement accompanying the report. "The issue has been identified and mitigation is in place while a permanent fix is safety tested and deployed."
The defect sat in the National Airspace System (NAS), the core flight data system behind many of the control systems in NATS's domestic centers. The NAS maintains flight plans, processes amendments and controller inputs, and allocates the discrete identification codes, or squawks, that let controllers match an aircraft on radar to its flight plan. The report says the incident is unrelated to the August 2023 failure of FPRSA-R, the flight plan reception system at the center of that outage.
NATS says squawk codes are usually allocated automatically. According to the report, the September 8 sequence began at 10:00 with a manual request for one, a timeline NATS gives without stating a time zone. The report says the request was valid, made correctly, and linked to a flight plan with "nothing abnormal or invalid" about it.
While that request was being processed, the NAS received a higher-priority message and paused the squawk allocation to deal with it. The report describes that kind of switching as a normal function of the system. When the allocation resumed, the defect meant it "did not resume correctly and the resulting output was corrupted," and the corrupted data then affected some subsequent flight data updates.
According to NATS, the scenario had not occurred before because the window was so narrow. The higher-priority message had to arrive during the millisecond in which the original request was part-way through updating a value. Had it arrived one millisecond earlier or later, the report says, "the update would have completed normally." NATS describes the defect as "legacy," and says investigators are still working out the precise timing involved and whether anything else in the wider system made the defect more likely to be triggered.
At 10:02, a system error notification showed that the link between the London Area Control (LAC) system and the NAS had dropped. LAC handles flights mainly above 24,500ft over England and Wales. The link recovered after 45 seconds. Engineers logged the event, found no hardware fault, and began investigating whether a specific piece of flight data was involved. The report says that until 12:32 there were "no indications of underlying data corruption."
The report says the link was being dropped as designed. Each time the LAC system tried to process the corrupted data, the attempt timed out and the connection was cut, then re-established, to protect the integrity of both systems. From 12:32 the drops became more frequent and some automation stopped being available to controllers. At 12:45 NATS limited the number of aircraft allowed into certain sectors and stopped departures from UK airports. At 13:32 the link dropped and did not recover, and controllers switched to fallback procedures.
Under those procedures, controllers coordinate handovers of aircraft with neighboring UK and international units manually, a task the system normally performs. The report says the added workload is why the number of aircraft permitted in the airspace was reduced. At 13:38 NATS agreed restrictions intended to hold entry into LAC sectors to 30 aircraft per hour as far as possible, and it capped arrivals at some UK airports, which limited UK-bound departures from foreign airports. NATS says controllers could speak to aircraft and monitor them on radar throughout, and "all aircraft stayed safely separated."
The problem affected LAC traffic, but the recovery reached across the UK. By 13:45 engineers and the Major Incident Manager had concluded that the optimum recovery strategy was a controlled restart of the NAS and a reload of flight data from the LAC system. That is a documented procedure, but the NAS also supplies flight data to other national and international control units and to several UK airports, and NATS says restrictions had to be placed across the UK so that the NAS could be restarted and flight data reloaded. NATS further reduced traffic to minimize the number of aircraft airborne during the restart, which ran from 15:17 to 16:09.
With more aircraft arriving than departing, some airports became congested on the ground, and from 15:20 NATS invoked procedures to divert inbound flights. After the restart, engineers spent until 18:50 reconciling data that had fallen out of step while the systems were disconnected, including duplicate flight plans and mismatches between squawk codes and callsigns. Departure stops and diversion procedures were lifted in stages, and all airspace restrictions were lifted at 19:30.
The report says the departure stop totaled around four and a half hours across a six-hour period. NATS had forecast about 8,000 flights for the day. Citing EUROCONTROL records, it says it handled 6,094. NATS says it took more than two days to clear the backlog of passenger disruption.
Rolfe wrote in the report's foreword that the incident was not related to the 2023 FPRSA failure or to "the radar issue in July last year." He also wrote that it was "not caused by any incorrect actions by either military or civil operators," and the press release says he "dismissed speculation that it was caused by military intervention."
A Financial Times report, covered by Airways on September 12, said flight data filed for a UK military aircraft had set off the failure. NATS's statement addresses whether any operator acted incorrectly. The preliminary report does not identify the flight for which the squawk code was requested.
On cyber activity, the report says there is no evidence at this stage that a malicious actor or cyber-related activity caused the incident.
NATS says its supplier has already developed and delivered a permanent fix to the NAS software, which is now under test and will be deployed once testing is complete. The report does not name the supplier.
In the meantime, NATS says it has put an additional engineering framework in place to manage any link drops between the LAC system and the NAS. Suspected link failures will be escalated under defined reporting arrangements, and if the problem recurs, NATS says, it can now carry out a faster recovery.
Alexander said she was pleased that passenger safety had been protected, but "it's clear we need to urgently understand why this issue was not discovered and fixed before it caused chaos," according to the Associated Press report on the findings. The government asked the Civil Aviation Authority for an independent review of the outage after September 8, as Airways reported. According to AP, Alexander said the regulator's review will check NATS's findings and examine its investment plans for future resilience, along with regulatory accountability.
Ryanair (FR) called on Rolfe to resign or for Alexander to dismiss him. "After three UK ATC system collapses in the last 4 years, Martin Rolfe has run out of excuses," Neal McMahon, the airline's chief operations officer, said. Ryanair's count includes the July 2025 radar problem, which NATS says is unrelated to the September 8 failure.
Rolfe apologized again in NATS's statement. "Our primary role is to keep our skies safe, and everyone who flies through them," he said. "At no point last week was safety in question."
The preliminary report describes the mechanism of the failure. It does not say how long the defective code had been in service, whether it had recently been changed, or how often squawk codes are requested manually. Nor does it address Alexander's question of why the defect was not found before September 8. The terms of reference for the full investigation include a review of defect records, system health monitoring, change activity, and asset lifecycle management for the failed equipment, and NATS says the investigation will also review how effective its traffic measures were.
The preliminary report also does not say whether corrupted flight data could in future be isolated without restarting the NAS. Its short-term mitigation is aimed at a faster recovery if the problem recurs. NATS says the Major Incident Investigation "may lead to amendments" of the preliminary report.


.avif)