Skip to content
Ransomware group claims LA Metro as latest target, threatens data leak

Ransomware group claims LA Metro as latest target, threatens data leak

Teiss September 9, 2026

A ransomware group known as The Gentlemen has listed the Los Angeles County Metropolitan Transportation Authority, commonly known as LA Metro, on its dark web leak site, according to the group’s own posting. The notice appeared on September 7, and the attackers set a nine-day deadline for the transit agency to respond.

No data samples have been released so far, leaving the scope and nature of any exposed information unconfirmed. Ransomware operators frequently follow an initial listing with sample data releases later, a tactic used to increase pressure on victims to pay.

It is not yet possible to determine what type of data may have been taken. The information could be operational in nature, though passenger data is considered a likely target given its higher value on underground markets.

LA Metro manages ticket sales across its transit network and relies on the Transit Access Pass, or TAP, system as its primary fare payment method. Riders can load fares through station vending machines, a mobile app, or the agency’s website. LA Metro operates both bus and rail lines, serving a metropolitan population of approximately 12.9 million people. If attackers accessed the agency’s systems, the potential scale of compromised individual data could be substantial.

If the new claims prove true, this would mark the second attack on LA Metro in 2026. The agency previously suffered a significant breach in March 2026, when attackers exfiltrated 700 gigabytes of internal data, including emails and backup files, and partially disrupted its systems. A pro-Iranian hacking group claimed responsibility for that incident.

LA Metro is not alone in facing cyberattacks within the U.S. transportation industry. In 2025, the Texas Department of Transportation was hacked, resulting in the theft of 300,000 car crash reports. The compromised records included names, addresses, driver’s license numbers, license plate numbers, insurance policy details, and injury descriptions drawn from crash narratives.

Separately, at the start of 2026, the Qilin ransomware gang leaked files belonging to 700,000 New York City transit workers. The exposed data reportedly included pension information, salaries, benefits, medical records, insurance details, and disciplinary records.

Please take 30 seconds to register

Already have an account? Sign in

"If we think of usability and security as mutually exclusive - we have failed" - Jerrod Chong, Yubico

#teissLondon2018: On the internet, nobody knows you are a fridge

1 in 6 gamers disable all AV in the pursuit of the highest possible speeds

10 malicious Python Libraries discovered on PyPI Repository

126,000 affected by cyberattack on New Zealand patient portal Manage My Health

"If we think of usability and security as mutually exclusive - we have failed" - Jerrod Chong, Yubico

#teissLondon2018: On the internet, nobody knows you are a fridge

1 in 6 gamers disable all AV in the pursuit of the highest possible speeds

10 malicious Python Libraries discovered on PyPI Repository

126,000 affected by cyberattack on New Zealand patient portal Manage My Health

19-year-old claims he hacked into over 25 Tesla cars in 13 countries

2020 cybersecurity trends and resolutions

2025 in review: why cyber-security became a boardroom crisis

Sécuriser les infrastructures critiques à l’ère de NIS2 : confiance, conformité, performance et résilience

Building cyber-resilience across your digital supply chain

Closing the exposure window — unifying continuous threat exposure management

Winston House, 3rd Floor, Units 306-309, 2-4 Dollis park, London, N3 1HF