Skip to main content

San Francisco transit systems targeted by hackers

San Francisco’s Municipal Transportation System has apparently been targeted by hackers over the Thanksgiving holiday weekend, the agency to shut down its light-rail ticketing machines and point-of-payment systems and allowing passengers to ride for free. Agency computers displayed the message "You Hacked, ALL Data Encrypted", the San Francisco Examiner reported on Saturday. According to the BBC, the hackers have made a ransom demand of 100 Bitcoin, which amounts to about $70,000 (£56,000). Jon Ge
November 28, 2016 Read time: 2 mins
San Francisco’s Municipal Transportation System has apparently been targeted by hackers over the Thanksgiving holiday weekend, the agency to shut down its light-rail ticketing machines and point-of-payment systems and allowing passengers to ride for free.

Agency computers displayed the message "You Hacked, ALL Data Encrypted", the San Francisco Examiner reported on Saturday.

According to the BBC, the hackers have made a ransom demand of 100 Bitcoin, which amounts to about $70,000 (£56,000).

Jon Geater, chief technology officer, Thales e-Security, said: “Cyber-security is not and cannot be a choice between ‘black and white’ or on and off – it’s about making an economic decision. This breach didn't directly take the barriers off line: the operator chose to turn them off and forego revenue, or catching fare cheats, in favour of protecting the wider system and possible further data-losses.

“Customers are likely to recognise this commitment and favour a company actively taking steps to protect its wider data eco-system.  Indeed, recent Thales e-Security research found only 16 per cent of consumers would continue to use a company’s products or services as usual following a breach – highlighting the profound consequences a cyber-breach can have on a company’s trust.”

Mishcon de Reya cyber security lead Joe Hancock commented: "This attack is intended to extort money from the San Francisco Municipal Railway by denying access to ticket machines, e-mail and personnel systems. The hackers have encrypted over 2000 machines and demanded 100 bitcoin, showing this to be a larger scale attack others we have seen - usually it's limited to just a few machines and 1 or 2 bitcoins per system.”

He said that if the ransom is paid, it was possible that other similar attacks would occur. He believes that regulation around anonymous crypto currencies, like bitcoin, may now become a priority: removing the ability to receive anonymous payments will stop many of these criminal attacks, and should be a focus for government.

San Francisco’s Municipal Transportation System spokesman Paul Rose told the San Francisco Chronicle that there was no indication of any impact to customers and the agency was carrying out a full investigation. The system was said to be restored by Sunday morning, but the agency did not say how the situation was resolved.

Related Content

  • April 2, 2014
    Plastic is fantastic for payment platform interoperability
    The Sino Visitor Pass aims to promote trade between Singapore and China by making travel easier, as Jon Masters finds out. Singapore has notched up another first in transportation innovation with announcement of a dual-currency payment card in partnership with the province of Guangdong in China. From the middle of 2014, visitors to Singapore and Guangdong will be able to use a ‘Sino Visitor Pass’ to pay for use of public transportation among other things.
  • May 28, 2014
    US cities opt for variable-rate parking
    Los Angeles and San Francisco are among the US cities opting to use variable-rate parking to make it easier to find a parking space. Los Angeles is piloting LA Express Park, program covering a 4.5 square-mile area of downtown using technology to match on-street parking prices with demand. The objective is to ensure that between 10 and 30 per cent of the parking spaces on each block are open throughout the day. Smart meters and sensors compile occupancy and payment data and based on that information, a pr
  • March 1, 2013
    Bringing enforcement standards into line
    Difficulties with the apparent accuracy of enforcement systems have been making the headlines in the United States over recent months. Jon Masters investigates the causes and possible cures. Online newspaper reports in the United States over recent months have painted a picture of the authorities struggling to keep on top of their speed and red light enforcement pro­grammes. Among a host of stories put out by the Washington Post and others on the subject of speed cameras during January, there were reports
  • December 21, 2015
    EU inquiry committee to investigate car emission breaches
    The European Parliament has voted to approve the creation of an inquiry committee to investigate breaches of EU rules on car emission measurements. The committee will be tasked with carrying out a thorough investigation of the VW scandal. Following this examination, it will aim to set up a new procedure that will effectively prohibit similar emissions cheating in the future.