Skip to main content

San Francisco transit systems targeted by hackers

San Francisco’s Municipal Transportation System has apparently been targeted by hackers over the Thanksgiving holiday weekend, the agency to shut down its light-rail ticketing machines and point-of-payment systems and allowing passengers to ride for free. Agency computers displayed the message "You Hacked, ALL Data Encrypted", the San Francisco Examiner reported on Saturday. According to the BBC, the hackers have made a ransom demand of 100 Bitcoin, which amounts to about $70,000 (£56,000). Jon Ge
November 28, 2016 Read time: 2 mins
San Francisco’s Municipal Transportation System has apparently been targeted by hackers over the Thanksgiving holiday weekend, the agency to shut down its light-rail ticketing machines and point-of-payment systems and allowing passengers to ride for free.

Agency computers displayed the message "You Hacked, ALL Data Encrypted", the San Francisco Examiner reported on Saturday.

According to the BBC, the hackers have made a ransom demand of 100 Bitcoin, which amounts to about $70,000 (£56,000).

Jon Geater, chief technology officer, Thales e-Security, said: “Cyber-security is not and cannot be a choice between ‘black and white’ or on and off – it’s about making an economic decision. This breach didn't directly take the barriers off line: the operator chose to turn them off and forego revenue, or catching fare cheats, in favour of protecting the wider system and possible further data-losses.

“Customers are likely to recognise this commitment and favour a company actively taking steps to protect its wider data eco-system.  Indeed, recent Thales e-Security research found only 16 per cent of consumers would continue to use a company’s products or services as usual following a breach – highlighting the profound consequences a cyber-breach can have on a company’s trust.”

Mishcon de Reya cyber security lead Joe Hancock commented: "This attack is intended to extort money from the San Francisco Municipal Railway by denying access to ticket machines, e-mail and personnel systems. The hackers have encrypted over 2000 machines and demanded 100 bitcoin, showing this to be a larger scale attack others we have seen - usually it's limited to just a few machines and 1 or 2 bitcoins per system.”

He said that if the ransom is paid, it was possible that other similar attacks would occur. He believes that regulation around anonymous crypto currencies, like bitcoin, may now become a priority: removing the ability to receive anonymous payments will stop many of these criminal attacks, and should be a focus for government.

San Francisco’s Municipal Transportation System spokesman Paul Rose told the San Francisco Chronicle that there was no indication of any impact to customers and the agency was carrying out a full investigation. The system was said to be restored by Sunday morning, but the agency did not say how the situation was resolved.

Related Content

  • November 6, 2017
    SwRI investigates cybersecurity weaknesses in transportation management systems
    Southwest Research Institute (SwRI), in San Antonio, has been awarded a $750,000 (£573,000) contract from the Transportation Research Board to help state and local agencies address cyber-attack risks on current transportation systems and those posed by future connected vehicles. Cyber security firm, Praetorian will support SwRI by conducting a security audit of traffic management systems and develop a web-based guide to help transportation agencies learn how to safeguard equipment.
  • March 1, 2013
    Imtech faces €100m write-down after ‘possible irregularities’ in Poland
    Dutch technical services provid­er Royal Imtech has announced the write-off of at least €100m in Poland after the discovery of “possible irregularities” in four of its projects there. The discovery relates to three projects for Adventure World Warsaw and one project involving energy-generating bio-power stations in Warsaw with a combined value of €757m. It is understood that advance payments for the four projects did not comply with the agreements made between Im­tech and its customer in terms of the availa
  • January 30, 2012
    Use of ITS technology grows more prevalent in safety applications
    Transportation agencies and governments are using ITS technology to protect critical infrastructure from terrorist attack and other threats to economic security and public safety. Andrew Bardin Williams reports. It is no secret that we live in a potentially dangerous world. Terrorism as seen on 9/11 in the United States, subsequent attacks in London, Moscow and Madrid and other acts of violence across the developing world have made vigilance the watchword for ensuring security. Key infrastructure is now bei
  • November 10, 2017
    Keeping cyber criminals from your website
    If a hacker can penetrate your website, they can do business as you. Joe Dysart explains how you and your customers may not discover the fraud for some time. In the latest twist on identity theft, hackers are clandestinely taking over business websites - and then brazenly billing visiting customers as if the sites are their own.