Menu
Browse

Cyber Incident Victim: Los Angeles Metro

Date:

Mar 2026

Location:

United States of America

Summary

Los Angeles Metro detected unauthorized activity on its internal network and responded by limiting employee access and shutting down affected systems while keeping rail and bus operations running. The disruption caused some digital arrival boards to go blank and prevented customers from loading funds onto TAP cards online or at kiosks, though the agency confirmed that no customer or employee data was compromised. Officials said they are reviewing approximately 1,400 servers to ensure security before restoring access, and that the investigation into the breach’s origin and scope continues.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On Monday, March 16, 2026, the Los Angeles Metro’s security team discovered unauthorized activity on its internal computer systems and promptly limited employee access to many administrative computers. The agency stated that the detection occurred the previous week, prompting a proactive containment measure. Officials emphasized that the action was taken to prevent further spread while preserving essential rail and bus operations. Metro’s transit safety and security systems remained online throughout the initial response. The agency’s board member later described the effort as a painstaking process to verify each system before restoration.

Cyber Incident Image

By the week of March 20, 2026, the restriction of internal systems expanded to a shutdown of several customer‑facing services, causing digital arrival boards to go blank and preventing commuters from loading funds onto TAP cards online or at ticket kiosks. Riders reported being unable to complete payment attempts at machines and on their phones, leading Metro to advise adding funds at vending machines where possible. The agency confirmed that train and bus schedules continued unaffected and that rider safety was not compromised. Metro also stated that no customer or employee data had been accessed or stolen during the incident.

In response, Metro began reviewing approximately 1,400 servers individually to ensure each was free of malicious code before restoring access, a process described by a board member as necessary given the agency’s size. Law enforcement and cybersecurity specialists continued to investigate the origin and scope of the breach, though officials had not identified the attackers or determined what data, if any, had been targeted. Throughout the investigation, Metro maintained that its core transit services operated without interruption.

Sources
Sources available to members
2 sources