Pierce Transit
Incident posture
Linked entities
- Victim
- Pierce Transit
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
A Washington state public transportation provider serving around 18,000 daily riders in the Tacoma area fell victim to a ransomware attack that disrupted some agency systems, prompting temporary administrative workarounds and triggering a network and phone outage. The organization engaged third-party forensic experts to investigate and contain the threat, and law enforcement was notified, though transportation services continued operating normally and the majority of operations were later fully restored. The LockBit ransomware group claimed responsibility for the incident, alleging it had exfiltrated postal correspondence, NDA agreements, customer personal data, and contracts, and demanded nearly two million dollars for the data's destruction or return. The transit authority declined to pay the ransom, after which the group published the stolen information.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Pierce Transit, officially known as the Pierce County Public Transportation Benefit Area Corporation and serving approximately 18,000 daily riders in Tacoma, Washington and surrounding areas, fell victim to a ransomware attack that struck on February 14, 2023. The organization first publicly acknowledged an issue a day later on February 15, when it posted on Facebook about a service disruption. The initial public communication was limited, with Pierce Transit stating only that its phones were experiencing an outage due to a network issue. This brief notice did not disclose the nature or severity of what had actually occurred behind the scenes. The company did not go into greater detail about the incident until March 1, 2023, when a spokesperson provided additional information to local news outlet Komo News, confirming that the disruption had been caused by a ransomware event rather than a simple network problem. The delay between the initial outage reports and the detailed public disclosure spans roughly two weeks, during which the organization worked behind the scenes to understand the scope of the intrusion and coordinate its response.
According to the statement Pierce Transit provided to Komo News, the agency experienced a ransomware incident that temporarily disrupted some of its agency systems. Upon discovering the attack, the organization's internal team took immediate action to contain and isolate the threat. Pierce Transit engaged third-party forensic experts to conduct a thorough investigation into the nature and scope of the incident, and law enforcement authorities were notified. Despite the disruption, the agency emphasized that all transportation services continued to operate as normal. However, temporary workarounds were implemented for certain affected administrative systems in the initial hours and days following the incident. By the time of the public disclosure in early March, the majority of operations had been fully restored. The incident did not affect Pierce Transit's core ability to move passengers, but it did compromise various back-office and administrative functions that support the transit operation.
The ransomware group LockBit claimed responsibility for the attack and demanded a ransom payment of US$1,999,999 from Pierce Transit. According to LockBit's claims, the group exfiltrated a substantial amount of data prior to encrypting systems, including postal correspondence, NDA agreements, personal data of customers, contracts, and additional unspecified information. The ransom demand included a deadline of February 28, 2023, after which the threat actors threatened either to publish the stolen data or destroy it, depending on the terms. Pierce Transit declined to pay the ransom, aligning with guidance from the US government and the FBI, which advise organizations not to pay ransoms in such attacks in order to reduce the financial incentives that drive ransomware operations. Following Pierce Transit's refusal to comply, LockBit published the stolen information, exposing the contents of those files publicly.
LockBit has established itself as a prolific and prolifically active ransomware operation over the preceding twelve months, operating both as a direct threat actor and as a ransomware-as-a-service provider that enables affiliated groups to deploy its tools in exchange for a share of profits. The group has claimed responsibility for numerous high-profile attacks, including incidents targeting the Italian tax office and the bookstore chain WH Smith. LockBit's activity has also extended to Australia, where the Australian Cyber Security Centre issued an alert the previous year following a noticeable spike in LockBit ransomware incidents across the country. The group is believed to operate from a Russian-speaking base and has been active since at least 2019, developing its infrastructure and tooling over several years to become one of the more disruptive ransomware operations currently tracked. The Pierce Transit incident fits within this broader pattern of LockBit targeting organizations across multiple sectors and geographies, with public transit agencies being among the types of victims the group has pursued.
The operational impact on Pierce Transit centered on administrative systems rather than the core transit functions that move passengers each day. Phone systems were among the first reported symptoms of the disruption, with the agency's Facebook post on February 15 describing a phone outage tied to the underlying network issue. Temporary workarounds allowed staff and customers to continue essential interactions even while certain back-office functions were impaired. The agency engaged forensic investigators to map the full scope of the intrusion, determine what data had been accessed or taken, and confirm the integrity of remaining systems before bringing them back online. Law enforcement involvement added another layer to the response, providing Pierce Transit with channels for sharing indicators of compromise and potentially coordinating with broader efforts to track LockBit operations. By early March, the majority of affected operations had been restored, though the publication of stolen data by LockBit meant that the consequences of the attack extended beyond the immediate operational disruption into longer-running issues related to the exposure of internal documents and customer information. The incident underscored the persistent risk ransomware groups pose to public sector and transportation entities, particularly those whose administrative systems contain sensitive contractual, personnel, and operational data that threat actors consider valuable for leverage or publication.
Sources
Sources available to members: 1 source.