Skip to main content

San Francisco transit systems targeted by hackers

San Francisco’s Municipal Transportation System has apparently been targeted by hackers over the Thanksgiving holiday weekend, the agency to shut down its light-rail ticketing machines and point-of-payment systems and allowing passengers to ride for free. Agency computers displayed the message "You Hacked, ALL Data Encrypted", the San Francisco Examiner reported on Saturday. According to the BBC, the hackers have made a ransom demand of 100 Bitcoin, which amounts to about $70,000 (£56,000). Jon Ge
November 28, 2016 Read time: 2 mins
San Francisco’s Municipal Transportation System has apparently been targeted by hackers over the Thanksgiving holiday weekend, the agency to shut down its light-rail ticketing machines and point-of-payment systems and allowing passengers to ride for free.

Agency computers displayed the message "You Hacked, ALL Data Encrypted", the San Francisco Examiner reported on Saturday.

According to the BBC, the hackers have made a ransom demand of 100 Bitcoin, which amounts to about $70,000 (£56,000).

Jon Geater, chief technology officer, Thales e-Security, said: “Cyber-security is not and cannot be a choice between ‘black and white’ or on and off – it’s about making an economic decision. This breach didn't directly take the barriers off line: the operator chose to turn them off and forego revenue, or catching fare cheats, in favour of protecting the wider system and possible further data-losses.

“Customers are likely to recognise this commitment and favour a company actively taking steps to protect its wider data eco-system.  Indeed, recent Thales e-Security research found only 16 per cent of consumers would continue to use a company’s products or services as usual following a breach – highlighting the profound consequences a cyber-breach can have on a company’s trust.”

Mishcon de Reya cyber security lead Joe Hancock commented: "This attack is intended to extort money from the San Francisco Municipal Railway by denying access to ticket machines, e-mail and personnel systems. The hackers have encrypted over 2000 machines and demanded 100 bitcoin, showing this to be a larger scale attack others we have seen - usually it's limited to just a few machines and 1 or 2 bitcoins per system.”

He said that if the ransom is paid, it was possible that other similar attacks would occur. He believes that regulation around anonymous crypto currencies, like bitcoin, may now become a priority: removing the ability to receive anonymous payments will stop many of these criminal attacks, and should be a focus for government.

San Francisco’s Municipal Transportation System spokesman Paul Rose told the San Francisco Chronicle that there was no indication of any impact to customers and the agency was carrying out a full investigation. The system was said to be restored by Sunday morning, but the agency did not say how the situation was resolved.

Related Content

  • March 28, 2017
    Commuting habits come under scrutiny
    Cities have a moral responsibility to encourage the smart use of transportation and Andrew Bardin Williams hears a few suggestions. Given the choice of getting a root canal, doing household chores, filing taxes, eating anchovies or commuting to work, nearly two-thirds of Americans said that they wouldn’t mind commuting into work—at least according to a poll conducted by Xerox (now Conduent) over its social media channels at the end of 2016.
  • January 28, 2016
    MTC awards funding to modernise Bay Area transit systems
    San Francisco’s Metropolitan Transportation Commission (MTC) has allocated US$494 million to help more than 20 Bay Area transit agencies replace or rehabilitate aging buses, ferries, rail cars, tracks and bridges; update safety, control and communications systems; install new fare-collection equipment; maintain services for elderly and disabled passengers; and make other capital improvements. The commitment includes US$447 million of federal transportation funds, supplemented by US$47 million of revenues fr
  • January 6, 2017
    VW faces first legal test case over emissions in Germany
    German consumer rights champion myRight filed the first legal test case against Volkswagen (VW) in Germany on Tuesday, raising pressure on the carmaker to compensate customers in Europe over the emissions scandal, according to Reuters. VW has pledged billions to compensate US owners of its diesel-powered cars, but has so far rejected any compensation for the 8.5 million affected vehicles in Europe where different legal rules weaken the chances of affected customers winning a pay-out. Instead, VW is in
  • November 4, 2014
    Online fraud still a stumbling block for mobile payments, say experts
    Confidence in e-commerce continues to suffer due to the incidence of online fraud. “The question of security and trust is a growing concern,” says Pierre-Antoine Vacheron, managing director, Ingenico Payment Services. “E-commerce makes up 15% of total commerce, but attracts 60% of fraud.”