Skip to main content

San Francisco transit systems targeted by hackers

San Francisco’s Municipal Transportation System has apparently been targeted by hackers over the Thanksgiving holiday weekend, the agency to shut down its light-rail ticketing machines and point-of-payment systems and allowing passengers to ride for free. Agency computers displayed the message "You Hacked, ALL Data Encrypted", the San Francisco Examiner reported on Saturday. According to the BBC, the hackers have made a ransom demand of 100 Bitcoin, which amounts to about $70,000 (£56,000). Jon Ge
November 28, 2016 Read time: 2 mins
San Francisco’s Municipal Transportation System has apparently been targeted by hackers over the Thanksgiving holiday weekend, the agency to shut down its light-rail ticketing machines and point-of-payment systems and allowing passengers to ride for free.

Agency computers displayed the message "You Hacked, ALL Data Encrypted", the San Francisco Examiner reported on Saturday.

According to the BBC, the hackers have made a ransom demand of 100 Bitcoin, which amounts to about $70,000 (£56,000).

Jon Geater, chief technology officer, Thales e-Security, said: “Cyber-security is not and cannot be a choice between ‘black and white’ or on and off – it’s about making an economic decision. This breach didn't directly take the barriers off line: the operator chose to turn them off and forego revenue, or catching fare cheats, in favour of protecting the wider system and possible further data-losses.

“Customers are likely to recognise this commitment and favour a company actively taking steps to protect its wider data eco-system.  Indeed, recent Thales e-Security research found only 16 per cent of consumers would continue to use a company’s products or services as usual following a breach – highlighting the profound consequences a cyber-breach can have on a company’s trust.”

Mishcon de Reya cyber security lead Joe Hancock commented: "This attack is intended to extort money from the San Francisco Municipal Railway by denying access to ticket machines, e-mail and personnel systems. The hackers have encrypted over 2000 machines and demanded 100 bitcoin, showing this to be a larger scale attack others we have seen - usually it's limited to just a few machines and 1 or 2 bitcoins per system.”

He said that if the ransom is paid, it was possible that other similar attacks would occur. He believes that regulation around anonymous crypto currencies, like bitcoin, may now become a priority: removing the ability to receive anonymous payments will stop many of these criminal attacks, and should be a focus for government.

San Francisco’s Municipal Transportation System spokesman Paul Rose told the San Francisco Chronicle that there was no indication of any impact to customers and the agency was carrying out a full investigation. The system was said to be restored by Sunday morning, but the agency did not say how the situation was resolved.

Related Content

  • November 19, 2013
    Thales uses standard smartphones to revolutionise mobile point of sale sector at CARTES 2013
    Thales, the UK-based information systems and communications security specialist, is planning to re-shape the mobile point of sale sector at CARTES 2013. The company will be sharing and demonstrating a range of solutions from leading mPOS device manufacturers on its stand at the show, as well as showing off the newly-announced members of its multi-partner ecosystem. “By working with Thales, Miura has been able to simplify and remove the complexity of delivering leading P2PE and Remote Key Injection services
  • November 28, 2017
    US and UK Respondents call for stricter data security regulations for Connected Cars
    Over 40% of both 1,000 US and UK adult consumers who took part in a new study feel that the government should apply stricter data security regulations for connected cars (CCs), according to Thales’ E-Security IoT Survey. A combined 60% of both respondents believe that CCs pose security concerns with integrity and malfunctions at the top of the list of apprehensions when asked to identify internet-connected devices which they felt were most vulnerable to hacking.
  • February 22, 2016
    Concern over Uber’s vetting processes after US shooting
    The arrest of an Uber driver in Kalamazoo, Michigan, has prompted renewed interest in the company’s driver vetting process. Uber has confirmed that Jason Brian Dalton, accused of injuring two and killing six people over the 20-21 February 2016 weekend in Kalamazoo, Michigan, was an Uber driver who had passed the background checks with no criminal records. The company’s website says that Uber operates an extensive driver screening process which includes collecting detailed information from potential d
  • January 27, 2012
    Rapid growth of bus rapid transit schemes on US Pacific coast
    This section pulls together all the multi-modal topics in each issue. Subject matter will include smartcards; ticketing and payment systems; passenger information systems; fleet management for buses, trains and light rail; park and ride systems; on-line access to real-time information via Internet portals