Cyber Incident Victim: Société de transport de Montréal
Date:
Oct 2020
Location:
Canada
Summary
A ransomware attack targeted Montréal's transit agency, with attackers demanding $2.8 million which was refused. The incident disrupted the adapted transit reservation system and affected approximately 1,000 servers, including 624 operationally critical ones, though bus and metro services remained operational. No data exfiltration occurred. Systems were progressively restored, with the reservation service returning within days and most servers recovered subsequently. Employee payments proceeded nearly normally while supplier payments were unaffected. The attack originated from a phishing email and shared similarities with RansomExx ransomware, with investigations ongoing.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
On October 19, 2020, the Société de transport de Montréal (STM) experienced a ransomware attack that disrupted its network operations. The attack compromised approximately 1,000 of the agency’s 1,600 servers, including 624 classified as operationally sensitive. Primary impact centered on STM’s reservation system for adapted transit services, which was forced offline. The incident did not affect Montreal’s bus and metro operations, and no data exfiltration occurred. After over a week without communication, the attacker contacted STM to demand a US $2.8 million ransom for restoring network access. STM publicly refused the demand on October 30, reaffirming its non-compliance stance. By October 25, the paratransit reservation system had been fully restored. As of October 29, 77% of affected servers had been recovered. Employee payroll processing for 11,000 staff proceeded with minimal disruption, while supplier payments remained unaffected throughout the incident.

Initial investigative findings indicated the attacker gained network access through a phishing email. STM characterized the ransomware’s behavior as similar to RansomExx but withheld further technical details pending the ongoing investigation. Recovery efforts prioritized restoring critical operational systems while maintaining public transit services. One week post-incident, a separate ransomware attack targeted CIUSSS du Centre-Ouest-de-l'Île-de-Montréal, a regional health agency, though no evidence linked the two events. The health agency implemented containment measures including network disconnections and remote access restrictions. STM continued server restoration and forensic analysis without disclosing additional attacker tactics or potential security control enhancements.
