Skip to main content

San Francisco transit systems targeted by hackers

San Francisco’s Municipal Transportation System has apparently been targeted by hackers over the Thanksgiving holiday weekend, the agency to shut down its light-rail ticketing machines and point-of-payment systems and allowing passengers to ride for free. Agency computers displayed the message "You Hacked, ALL Data Encrypted", the San Francisco Examiner reported on Saturday. According to the BBC, the hackers have made a ransom demand of 100 Bitcoin, which amounts to about $70,000 (£56,000). Jon Ge
November 28, 2016 Read time: 2 mins
San Francisco’s Municipal Transportation System has apparently been targeted by hackers over the Thanksgiving holiday weekend, the agency to shut down its light-rail ticketing machines and point-of-payment systems and allowing passengers to ride for free.

Agency computers displayed the message "You Hacked, ALL Data Encrypted", the San Francisco Examiner reported on Saturday.

According to the BBC, the hackers have made a ransom demand of 100 Bitcoin, which amounts to about $70,000 (£56,000).

Jon Geater, chief technology officer, Thales e-Security, said: “Cyber-security is not and cannot be a choice between ‘black and white’ or on and off – it’s about making an economic decision. This breach didn't directly take the barriers off line: the operator chose to turn them off and forego revenue, or catching fare cheats, in favour of protecting the wider system and possible further data-losses.

“Customers are likely to recognise this commitment and favour a company actively taking steps to protect its wider data eco-system.  Indeed, recent Thales e-Security research found only 16 per cent of consumers would continue to use a company’s products or services as usual following a breach – highlighting the profound consequences a cyber-breach can have on a company’s trust.”

Mishcon de Reya cyber security lead Joe Hancock commented: "This attack is intended to extort money from the San Francisco Municipal Railway by denying access to ticket machines, e-mail and personnel systems. The hackers have encrypted over 2000 machines and demanded 100 bitcoin, showing this to be a larger scale attack others we have seen - usually it's limited to just a few machines and 1 or 2 bitcoins per system.”

He said that if the ransom is paid, it was possible that other similar attacks would occur. He believes that regulation around anonymous crypto currencies, like bitcoin, may now become a priority: removing the ability to receive anonymous payments will stop many of these criminal attacks, and should be a focus for government.

San Francisco’s Municipal Transportation System spokesman Paul Rose told the San Francisco Chronicle that there was no indication of any impact to customers and the agency was carrying out a full investigation. The system was said to be restored by Sunday morning, but the agency did not say how the situation was resolved.

Related Content

  • February 25, 2015
    San Francisco plans express lane network across Bay Area
    Colin Sowman looks at plans to convert 240km (150 miles) of HOV/car pool lanes. While some authorities have debated the conversion of high occupancy vehicle lanes (HOV) into express or managed lanes allowing toll paying single-occupant vehicles to avoid congestion, San Francisco’s Bay Area Metropolitan Transportation Commission (MTC) has acted. It is converting 240km (150 miles) of HOV/car pool lanes to express lanes and last fall the MTC’s Bay Area Infrastructure Financing Authority selected TransCore to d
  • October 30, 2015
    MEPs discuss guidelines for drone use and safety
    As commercial services using drones take off and their recreational use becomes ever more popular, it must be ensured that they pose no threat to public safety or personal privacy, said MEPs in a resolution passed on Thursday on the initiative of the EP transport committee. Drones, which could be used to provide various services, such as inspecting rail tracks, dams, and power plants, assessing natural disasters, crop spraying, film production and parcel delivery have great potential for stimulating economi
  • November 18, 2015
    Real-world testing is needed in wake of VW emissions scandal, says expert
    As vehicle manufacturers, regulators and governments around the world seek solutions to prevent another emissions cheating scandal similar to the Volkswagen case, a major vehicle emissions inspection company has compiled and analysed on-road emissions data indicating that emissions violations of vehicles under real-world driving conditions may well go far beyond VW diesels. Opus Inspection says a two-pronged approach that continuously monitors real-world emissions is the only effective remedy. Lothar Ge
  • March 9, 2016
    Roadside monitoring used to target non-compliant trucks
    The UK’s DVSA is utilising existing technology to identify non-compliant commercial vehicles and target repeat offenders while avoiding law-abiding companies. Enforcing the compliance of commercial vehicles (goods vehicles over 3.5 tonnes and vehicles with eight or more passenger seats) on the UK’s roads is the responsibility of the DVSA (the Driver and Vehicle Standards Agency). The Department for Transport created the executive agency about 18 months ago by merging the Driving Standards Agency (DSA) and t