Skip to main content

San Francisco transit systems targeted by hackers

San Francisco’s Municipal Transportation System has apparently been targeted by hackers over the Thanksgiving holiday weekend, the agency to shut down its light-rail ticketing machines and point-of-payment systems and allowing passengers to ride for free. Agency computers displayed the message "You Hacked, ALL Data Encrypted", the San Francisco Examiner reported on Saturday. According to the BBC, the hackers have made a ransom demand of 100 Bitcoin, which amounts to about $70,000 (£56,000). Jon Ge
November 28, 2016 Read time: 2 mins
San Francisco’s Municipal Transportation System has apparently been targeted by hackers over the Thanksgiving holiday weekend, the agency to shut down its light-rail ticketing machines and point-of-payment systems and allowing passengers to ride for free.

Agency computers displayed the message "You Hacked, ALL Data Encrypted", the San Francisco Examiner reported on Saturday.

According to the BBC, the hackers have made a ransom demand of 100 Bitcoin, which amounts to about $70,000 (£56,000).

Jon Geater, chief technology officer, Thales e-Security, said: “Cyber-security is not and cannot be a choice between ‘black and white’ or on and off – it’s about making an economic decision. This breach didn't directly take the barriers off line: the operator chose to turn them off and forego revenue, or catching fare cheats, in favour of protecting the wider system and possible further data-losses.

“Customers are likely to recognise this commitment and favour a company actively taking steps to protect its wider data eco-system.  Indeed, recent Thales e-Security research found only 16 per cent of consumers would continue to use a company’s products or services as usual following a breach – highlighting the profound consequences a cyber-breach can have on a company’s trust.”

Mishcon de Reya cyber security lead Joe Hancock commented: "This attack is intended to extort money from the San Francisco Municipal Railway by denying access to ticket machines, e-mail and personnel systems. The hackers have encrypted over 2000 machines and demanded 100 bitcoin, showing this to be a larger scale attack others we have seen - usually it's limited to just a few machines and 1 or 2 bitcoins per system.”

He said that if the ransom is paid, it was possible that other similar attacks would occur. He believes that regulation around anonymous crypto currencies, like bitcoin, may now become a priority: removing the ability to receive anonymous payments will stop many of these criminal attacks, and should be a focus for government.

San Francisco’s Municipal Transportation System spokesman Paul Rose told the San Francisco Chronicle that there was no indication of any impact to customers and the agency was carrying out a full investigation. The system was said to be restored by Sunday morning, but the agency did not say how the situation was resolved.

Related Content

  • SCANaCAR and VideoBadge counter parking’s prickly problems.
    June 4, 2014
    Colin Sowman discovers how the latest systems can boost productivity and reduce conflict in parking enforcement. Parking enforcement is something of a ‘Cinderella’ service for local authorities: while necessary to keep the roads open and the traffic flowing, it is an expensive operation and can be loss-making. It is also labour intensive and parking enforcement officers are routinely verbally abused and sometimes physically attacked. Some authorities are now looking to automate parking enforcement in orde
  • Safelane automates work zone perimeter guarding
    June 12, 2015
    The safety of workers during road closures and working alongside, or above, live lanes is becoming an automated process. Ten workers suffered major injuries while working on or near motorways and major A roads in England in 2013, and between 2009 and 2013 eight had been killed. It was against that background that the first commercial application Safelane, the automated traffic management system designed to detect work zone incursions, was carried out during the temporary closure of a motorway.
  • Cloud-based app paves way for near field ticketing
    December 17, 2013
    Cubic latest introduction provides a short cut for transit authorities looking to offer travellers mobile, smart phone payment options. Transit operators wanting to provide travellers with a mobile fare payment option now have an ‘off-the-shelf’ solution in Cubic’s NextWave. Through the use of near field communications (NFC) technology, NextWave turns travellers’ mobile phones and tablets into the equivalent of a ticket vending machine able to instantly re-load contactless transit cards. It also enables the
  • Data handling important for autonomous vehicles
    December 8, 2016
    Data handling is becoming an ever-greater part of transportation and never more so than with autonomous vehicles, as Andrew Bardin Williams hears from some big names.