Skip to main content

San Francisco transit systems targeted by hackers

San Francisco’s Municipal Transportation System has apparently been targeted by hackers over the Thanksgiving holiday weekend, the agency to shut down its light-rail ticketing machines and point-of-payment systems and allowing passengers to ride for free. Agency computers displayed the message "You Hacked, ALL Data Encrypted", the San Francisco Examiner reported on Saturday. According to the BBC, the hackers have made a ransom demand of 100 Bitcoin, which amounts to about $70,000 (£56,000). Jon Ge
November 28, 2016 Read time: 2 mins
San Francisco’s Municipal Transportation System has apparently been targeted by hackers over the Thanksgiving holiday weekend, the agency to shut down its light-rail ticketing machines and point-of-payment systems and allowing passengers to ride for free.

Agency computers displayed the message "You Hacked, ALL Data Encrypted", the San Francisco Examiner reported on Saturday.

According to the BBC, the hackers have made a ransom demand of 100 Bitcoin, which amounts to about $70,000 (£56,000).

Jon Geater, chief technology officer, Thales e-Security, said: “Cyber-security is not and cannot be a choice between ‘black and white’ or on and off – it’s about making an economic decision. This breach didn't directly take the barriers off line: the operator chose to turn them off and forego revenue, or catching fare cheats, in favour of protecting the wider system and possible further data-losses.

“Customers are likely to recognise this commitment and favour a company actively taking steps to protect its wider data eco-system.  Indeed, recent Thales e-Security research found only 16 per cent of consumers would continue to use a company’s products or services as usual following a breach – highlighting the profound consequences a cyber-breach can have on a company’s trust.”

Mishcon de Reya cyber security lead Joe Hancock commented: "This attack is intended to extort money from the San Francisco Municipal Railway by denying access to ticket machines, e-mail and personnel systems. The hackers have encrypted over 2000 machines and demanded 100 bitcoin, showing this to be a larger scale attack others we have seen - usually it's limited to just a few machines and 1 or 2 bitcoins per system.”

He said that if the ransom is paid, it was possible that other similar attacks would occur. He believes that regulation around anonymous crypto currencies, like bitcoin, may now become a priority: removing the ability to receive anonymous payments will stop many of these criminal attacks, and should be a focus for government.

San Francisco’s Municipal Transportation System spokesman Paul Rose told the San Francisco Chronicle that there was no indication of any impact to customers and the agency was carrying out a full investigation. The system was said to be restored by Sunday morning, but the agency did not say how the situation was resolved.

Related Content

  • January 7, 2013
    Reflecting on five years of important ITS progress
    Former head of the ITS Joint Program Office Shelley Row has passed the baton to a new director. Now working as an independent consultant, here she reflects on her five years at the helm of the JPO and what the future may hold for ITS in the US. During a mid-morning in Paris earlier this year, having just landed, I decided to take a trip on the city’s subway (Paris’ underground metro) into the city centre. A family with a small boy – about nine years old – boarded the same train. They were American and we st
  • July 12, 2016
    Global automotive cyber security market to be ‘worth US$31.8 million by 2021’
    A new report from MarketsandMarkets projects the global automotive security market to grow at a CAGR of 13.3 per cent between 2016 and 2021, reaching a market size of US$31.8 million by 2021. According to the report, Automotive Cyber Security Market by Security Type, the major factors behind the growth of the global automotive cyber security market are the growing connected cars being introduced from OEMs and rising security concerns among end-users.
  • October 25, 2013
    US taps into European high-speed rail knowledge
    Representatives of major US high-speed rail projects are to meet with their European counterparts to seek the expertise and knowledge of the leading European high-speed rail companies. The US is planning to invest approximately US$150,000 million over the next ten years in the development of high-speed rail networks, representing a great opportunity for European infrastructure and engineering companies. For the first time, American senior official representatives of these projects will meet in Europe loo
  • May 22, 2020
    VMT rising – but still well below normal, says StreetLight Data
    Many American drivers remain at home in lead-up to Memorial Day weekend