Cyber Incident Victim: Los Angeles Metro
Date:
Mar 2026
Location:
United States of America
Summary
Los Angeles Metro detected unauthorized activity on its internal network and responded by limiting employee access and shutting down affected systems while keeping rail and bus operations running. The disruption caused some digital arrival boards to go blank and prevented customers from loading funds onto TAP cards online or at kiosks, though the agency confirmed that no customer or employee data was compromised. Officials said they are reviewing approximately 1,400 servers to ensure security before restoring access, and that the investigation into the breach’s origin and scope continues.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On Monday, March 16, 2026, the Los Angeles Metro’s security team discovered unauthorized activity on its internal computer systems and promptly limited employee access to many administrative computers. The agency stated that the detection occurred the previous week, prompting a proactive containment measure. Officials emphasized that the action was taken to prevent further spread while preserving essential rail and bus operations. Metro’s transit safety and security systems remained online throughout the initial response. The agency’s board member later described the effort as a painstaking process to verify each system before restoration.

By the week of March 20, 2026, the restriction of internal systems expanded to a shutdown of several customer‑facing services, causing digital arrival boards to go blank and preventing commuters from loading funds onto TAP cards online or at ticket kiosks. Riders reported being unable to complete payment attempts at machines and on their phones, leading Metro to advise adding funds at vending machines where possible. The agency confirmed that train and bus schedules continued unaffected and that rider safety was not compromised. Metro also stated that no customer or employee data had been accessed or stolen during the incident.
In response, Metro began reviewing approximately 1,400 servers individually to ensure each was free of malicious code before restoring access, a process described by a board member as necessary given the agency’s size. Law enforcement and cybersecurity specialists continued to investigate the origin and scope of the breach, though officials had not identified the attackers or determined what data, if any, had been targeted. Throughout the investigation, Metro maintained that its core transit services operated without interruption.
