Skip to main content

San Francisco transit systems targeted by hackers

San Francisco’s Municipal Transportation System has apparently been targeted by hackers over the Thanksgiving holiday weekend, the agency to shut down its light-rail ticketing machines and point-of-payment systems and allowing passengers to ride for free. Agency computers displayed the message "You Hacked, ALL Data Encrypted", the San Francisco Examiner reported on Saturday. According to the BBC, the hackers have made a ransom demand of 100 Bitcoin, which amounts to about $70,000 (£56,000). Jon Ge
November 28, 2016 Read time: 2 mins
San Francisco’s Municipal Transportation System has apparently been targeted by hackers over the Thanksgiving holiday weekend, the agency to shut down its light-rail ticketing machines and point-of-payment systems and allowing passengers to ride for free.

Agency computers displayed the message "You Hacked, ALL Data Encrypted", the San Francisco Examiner reported on Saturday.

According to the BBC, the hackers have made a ransom demand of 100 Bitcoin, which amounts to about $70,000 (£56,000).

Jon Geater, chief technology officer, Thales e-Security, said: “Cyber-security is not and cannot be a choice between ‘black and white’ or on and off – it’s about making an economic decision. This breach didn't directly take the barriers off line: the operator chose to turn them off and forego revenue, or catching fare cheats, in favour of protecting the wider system and possible further data-losses.

“Customers are likely to recognise this commitment and favour a company actively taking steps to protect its wider data eco-system.  Indeed, recent Thales e-Security research found only 16 per cent of consumers would continue to use a company’s products or services as usual following a breach – highlighting the profound consequences a cyber-breach can have on a company’s trust.”

Mishcon de Reya cyber security lead Joe Hancock commented: "This attack is intended to extort money from the San Francisco Municipal Railway by denying access to ticket machines, e-mail and personnel systems. The hackers have encrypted over 2000 machines and demanded 100 bitcoin, showing this to be a larger scale attack others we have seen - usually it's limited to just a few machines and 1 or 2 bitcoins per system.”

He said that if the ransom is paid, it was possible that other similar attacks would occur. He believes that regulation around anonymous crypto currencies, like bitcoin, may now become a priority: removing the ability to receive anonymous payments will stop many of these criminal attacks, and should be a focus for government.

San Francisco’s Municipal Transportation System spokesman Paul Rose told the San Francisco Chronicle that there was no indication of any impact to customers and the agency was carrying out a full investigation. The system was said to be restored by Sunday morning, but the agency did not say how the situation was resolved.

Related Content

  • April 17, 2012
    Seoul building cyber attack-resistant traffic and transport control system
    According to a report in the Korea Times today, Seoul city officials are city urgently undertaking the development and of an integrated traffic information and operation system resistant to cyber terrorism to guard the city's traffic network from outside attacks. The Seoul Metropolitan Government said it plans to build an advanced transport management system that monitors the total traffic network around the clock by the end of this year, as part of efforts to vigilantly respond against any security threat.
  • February 7, 2017
    Redflex resolves final US inquiry from 2013 investigation
    Following this week’s announcement of a settlement with the City of Chicago, Redflex Traffic Systems (RTSI) says it has resolved all criminal and civil matters in the US arising out of the Company's 2013 investigation into allegations of corruption by former executives. The company has agreed to pay the City of Chicago US$20 million, with $10 million payable by the end of 2017 and the balance to be paid in various annual instalments by the end of 2023, unless extended by the terms of the agreement.
  • January 25, 2018
    Enforcement ensures equity for toll road users
    All-electronic tolling boosts traffic flow but introduces the tricky question of enforcement. Workable solutions are starting to emerge. Enforcement is an essential part of tolling and one of the most important ways for a mobility agency to keep faith with its investors, its community stakeholders and the vast majority of its users. It can also be one of the most unpopular and contentious things a toll authority has to undertake. If tolling is about paying for the roads, then everyone has to pay their
  • September 8, 2015
    Hackers can fool self-driving car sensors into evasive action
    The laser ranging (LIDAR) systems that most self-driving cars rely on to sense obstacles can be hacked by a setup costing just US$60, a security researcher has told IEEE spectrum. According to Jonathan Petit, principal scientist at software security company Security Innovation, he can take echoes of a fake car, pedestrian or wall and put them in any location. Using such a system, which he designed using a low-power laser and pulse generator, attackers could trick a self-driving car into thinking somethin