Skip to content
LA Metro Restricts Internal Systems After Cybersecurity Incident

LA Metro Restricts Internal Systems After Cybersecurity Incident

First seen 22 Mar 2026, 18:28 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 23, 2026 at 18:00 UTC
  • •Unauthorized activity led LA Metro to restrict access to internal systems.
  • •Fare payment disruptions occurred, affecting TAP card loading and digital arrival boards.
  • •Train and bus operations remained unaffected, and no data breaches were reported.

On March 21, 2026, Los Angeles Metro limited access to its internal administrative systems due to unauthorized activity detected on its network. This security incident disrupted fare payments and caused digital arrival boards to go blank, affecting riders' ability to load funds onto TAP cards. Despite these issues, train and bus operations continued normally, and officials confirmed that customer and employee data had not been compromised. Metro advised riders to use station ticket vending machines for fare loading while internal systems underwent security checks. The agency emphasized that the restrictions were precautionary and aimed at containing the unknown activity. Metro is working to restore affected systems and will keep riders updated on progress. The incident highlights the importance of cybersecurity measures in public transportation systems.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 202d ago How this analysis works

Timeline

2026-03-21
LA Metro detects unauthorized activity and restricts internal system access.
2026-03-21
Metro advises riders to use ticket vending machines for fare loading.
2026-03-22
Metro continues to investigate and restore affected systems.

More articles in this cluster (3)

Following this threat?

Track Los Angeles Metro in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed