NATS report finds one-millisecond fault behind airspace disruption
NATS has traced last week’s UK air traffic control failure to a previously unidentified software defect exposed during a one-millisecond window.
The incident on 8 September forced NATS to restrict flights entering UK-controlled airspace while engineers restored the affected flight data system. Normal operations resumed around six hours after the initial failure, but disruption continued into the following days, with more than 300,000 passengers estimated to have been affected.
Initial speculation included a possible cyberattack or problem involving a military flight. NATS has now ruled out both explanations.
Squawk code request exposed software defect
NATS traced the failure to software used to allocate aircraft identification codes.
Aircraft operating in controlled airspace transmit a four-digit transponder code, known as a squawk, which allows air traffic controllers to identify and track them on radar. These codes are normally assigned automatically, although controllers can request one manually.
On 8 September, a valid manual request was made for a squawk code. While the system was processing it, a higher-priority request arrived, temporarily pausing the original task.
Once the higher-priority action had been completed, the system attempted to resume the squawk allocation. A defect within a small subsection of code meant the process restarted incorrectly, producing corrupted data and triggering the wider flight data processing failure.

The vulnerable window lasted approximately one millisecond. NATS said the update would have been completed normally had the second request arrived one millisecond earlier or later.
“This was a software issue in a specific part of our flight data system,” NATS chief executive Martin Rolfe said. An interim mitigation is now in place while a permanent fix undergoes safety testing.
CAA to examine NATS resilience
Although NATS has established the immediate technical cause, the incident raises wider questions about the resilience of critical UK aviation infrastructure and why the defect was not identified during testing.
Transport Secretary Heidi Alexander described the disruption as “completely unacceptable” and instructed the Civil Aviation Authority to conduct an independent review.
The CAA will verify NATS’ technical findings and examine the organisation’s investment plans, operational resilience and regulatory accountability.
Alexander said there was no evidence of a cyberattack but rejected suggestions that the failure was unavoidable. The review will now consider why such a narrow software fault caused several hours of national disruption and whether further investment or regulatory action is required to reduce the consequences of future system failures.
Sign up for our newsletter and get our latest content in your inbox.
Similar Reads
Sign up for our newsletter. Select all sectors relevant to you.
Related















