Menu
Browse

Cyber Incident Victim: Toronto Transit Commission

Date:

Oct 2021

Location:

Canada

Summary

The Toronto Transit Commission experienced a ransomware attack disrupting multiple operational systems, including real-time communications between operators and Transit Control, digital schedule displays across platforms and applications, email functionality, and online booking services. The organization detected unusual network activity before the attack escalated, though no significant service interruptions or safety risks emerged. Internal IT teams collaborated with law enforcement, cybersecurity experts, and municipal IT services to investigate the incident, which marked the third ransomware attack on a major Canadian transit system within a year. The responsible threat actor remained unidentified.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

The Toronto Transit Commission (TTC) experienced a ransomware attack beginning on or before October 29, 2021. IT staff initially detected unusual network activity, prompting an investigation. The attack escalated by midday on October 29 when hackers expanded their compromise to network servers. This disruption affected multiple operational systems but did not cause significant service interruptions or pose safety risks to employees or customers. The TTC publicly confirmed the ransomware incident in a statement released on Friday, October 29, though the responsible threat actor remained unidentified.

Cyber Incident Image

Impacted systems included the Vision communication system used by operators to coordinate with Transit Control, disabling critical operational communications. Real-time next vehicle information became unavailable on platform screens, trip-planning applications, and the TTC website. Online Wheel-Trans booking services were also disrupted. The TTC engaged law enforcement and cybersecurity experts to investigate the attack’s full scope while collaborating with the City of Toronto’s IT department. Email systems were crippled, forcing conductors to rely on radio communications. Despite functional transit services, the attack represented the third ransomware incident targeting a major Canadian metro system within a year, following previous attacks on Montreal and Vancouver’s transit networks in late 2020. Recovery efforts focused on restoring affected digital services while maintaining minimal physical transit disruptions throughout the incident response period.

Sources
Sources available to members
1 source