RANSOMWARE GANG CLAIMS ATTACK ON LA METRO

The Gentlemen ransomware group has listed the Los Angeles County Metropolitan Transportation Authority (LA Metro) on its dark web leak site, suggesting the public transit agency may have suffered a cyberattack. The notice appeared on September 7, 2026, and reportedly gave LA Metro nine days to respond.

The attackers have not published any data samples, making it impossible to confirm the breach or determine what information may have been stolen. Ransomware groups often name organizations before releasing samples to increase pressure during extortion negotiations.

LA Metro operates bus and rail services across Los Angeles County and manages fare collection through the TAP payment system. If passenger or payment-related systems were compromised, the incident could potentially expose valuable personal and financial information. However, no evidence currently confirms that customer data was accessed.

LA METRO PREVIOUSLY TARGETED IN 2026

If the latest claim is verified, it could represent the second significant cyberattack involving LA Metro in 2026. The agency reportedly experienced a breach in March in which attackers claimed to have stolen approximately 700GB of internal emails and backups while disrupting some systems.

LA Metro has not publicly confirmed the latest ransomware claim. Until additional evidence or an official statement becomes available, passengers should monitor their TAP and financial accounts, use unique passwords, and remain alert for phishing messages impersonating the transit agency.

Leave a Comment

Your email address will not be published. Required fields are marked *