Ransomware Group Targets LA Metro, Threatens Data Leak

Ransomware Group Targets LA Metro, Threatens Data Leak

First seen 9 Sep 2026, 10:45 UTC CybernewsTeiss 54.8

Article Content

Browse articles
ThreatCluster

The Gentlemen ransomware group has claimed responsibility for targeting the Los Angeles County Metropolitan Transportation Authority (LA Metro), listing it on their dark web leak site on September 7, 2026. The group has given LA Metro a nine-day deadline to respond, but no data samples have been released yet, leaving the nature of the compromised data unconfirmed. Given LA Metro's extensive operations, which include managing ticket sales for approximately 12.9 million riders, the potential impact on passenger data could be significant. This incident marks the second attack on LA Metro in 2026, following a previous breach in March where 700 gigabytes of internal data were stolen. The transportation sector has increasingly become a target for cyberattacks, with notable incidents affecting other agencies in recent years.

Key Points: • The Gentlemen ransomware group has targeted LA Metro, demanding a response within nine days. • No data samples have been released, leaving the scope of the breach unclear. • This is the second cyberattack on LA Metro in 2026, following a major breach in March.

Ask AI about this cluster

Timeline

2025-01-01
Texas Department of Transportation hacked
300,000 car crash reports were stolen, including sensitive personal information.
Teiss
2026-01-01
Qilin ransomware gang leaks NYC transit worker files
Files belonging to 700,000 workers were leaked, including sensitive personal data.
Teiss
2026-03-01
LA Metro suffers major data breach
Hackers exfiltrated 700GB of internal data, including emails and backups, partially disrupting systems.
Teiss
2026-09-07
The Gentlemen list LA Metro on dark web
The ransomware group claims responsibility and sets a nine-day deadline for the agency to respond.
Cybernews