CSIDB logo
Incident

San Francisco Municipal Transportation Agency

Incident posture

Attack window
Nov 2016
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-12-08 00:00

Linked entities

Victim
San Francisco Municipal Transportation Agency
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Nov 2016
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack targeted San Francisco's public transit system, encrypting internal computer systems and disrupting operations. The perpetrator demanded a ransom payment in Bitcoin to restore access. During the incident, fare collection systems were compromised, allowing passengers to ride without paying. The organization managed to recover systems without fulfilling the ransom demand, restoring normal service after the disruption.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

I will answer the last question.

A ransomware attack affected the San Francisco Muni transit system, with the attacker demanding $73,000 in exchange for restoring access to computers and systems. The attack compromised the availability of the systems, and the confidentiality of the data was also at risk due to the threat of data dump. The attacker, who was not identified, used a data attack tactic, which involved the manipulation, destruction, or encryption of data. The motive behind the attack was likely personal gain, as the attacker demanded a ransom in exchange for restoring access to the systems. The attack highlights the importance of having robust cybersecurity measures in place to prevent such incidents.

Sources

Sources available to members: 1 source.

CSIDB