Muni computer systems were compromised late Friday after an SFMTA employee apparently downloaded what is called “ransomware,” a form of malware that allows an attacker to lock up a victim’s computers, and demand a ransom to release them for use.  (Joe Fitzgerald Rodriguez/S.F. Examiner)

Muni computer systems were compromised late Friday after an SFMTA employee apparently downloaded what is called “ransomware,” a form of malware that allows an attacker to lock up a victim’s computers, and demand a ransom to release them for use. (Joe Fitzgerald Rodriguez/S.F. Examiner)

Muni guarantees customer data not at risk as hacker sends new threat

The San Francisco Municipal Transportation Agency has guaranteed its transit customers are not at risk amid a malware attack over the weekend that targeted Muni, San Francisco’s public transit system.

The alleged attacker has demanded $73,000 in ransom for stolen city data.

SEE RELATED: Alleged Muni ‘hacker’ demands $73,000 ransom, some computers in stations restored

“Personal information of Muni customers were not compromised as part of this incident,” Paul Rose, a spokesperson for the SFMTA, said Monday.

“We’ve never considered paying the ransom,” he added, “because we have in-house staff capable of recovering all systems, and we’re doing that now.”

SEE RELATED: ‘You Hacked’ appears at Muni stations as fare payment system crashes

There are many ways the SFMTA collects identifiable information, such as payment of parking tickets, or paying Muni fares via its mobile app, Muni Mobile.

Muni computer systems were compromised late Friday after an SFMTA employee apparently downloaded what is called “ransomware,” a form of malware that allows an attacker to lock up a victim’s computers, and demand a ransom to release them for use.

However, despite Rose’s guarantee of customer safeguards, the alleged malware attacker –– known only by a pseudonym, “Andy Saolis” –– issued a new threat to Muni via news agencies claiming customer data was compromised.

“But if ugly hacker’s attack to Operational Railways System’s, what happen to You?” the alleged attacker wrote, “Anyone See Something like that in Hollywood Movies But it’s Completely Possible in Real World!”

The alleged attacker wrote they gained access through a Windows 2000 PC server at the SFMTA including “all payment kiosk and internal automation and Email,” and threatened to release 30 gigabytes worth of contracts, employee data, “LLD plans,” customer data, and more.

The SFMTA’s deadline to pay the ransom is Friday, the alleged attacker said, though previously the deadline was Monday.

The alleged attacked said they are not attempting to gain control of train operations, which are run by computer.

Saolis did not say what customer data they had, specifically.

Hoodline obtained a list of about 2,000 computers in the control of the alleged attacker (out of SFMTA’s 8,000 or so computer systems), which may give some indication of the data the attackers have at their fingertips.

Among them were a computer belonging to Kate Toran, head of SFMTA taxi services, Muni “CCTVS” which may stand for Closed Circuit TV (a surveillance system), Muni HR-DMV, and a computer named “DATSERVICES.”

Another computer, MUNIFLYNN, may contain data from Muni’s Flynn Division, a bus yard.

Rose said he had not seen the list of computers.

“Our firewalls were never penetrated,” Rose said, and reiterated that the SFMTA would not pay the ransom.
hackMuniransomSFMTATransit

If you find our journalism valuable and relevant, please consider joining our Examiner membership program.
Find out more at www.sfexaminer.com/join/

Just Posted

District Attorney Chesa Boudin announces charges against former SFPD Officer Christopher Samoyoa in the 2017 fatal shooting of Keita O’Neill at a press conference outside the Hall of Justice on Monday, Nov. 23, 2020. (Kevin N. Hume/S.F. Examiner)
DA Boudin charges fired SFPD officer with manslaughter over fatal shooting

Ex-Officer Christopher Samayoa to face criminal charges in killing of Keita O’Neil

The area near the Castro Muni Metro Station is expected to be affected by construction work on the Twin Peaks Tunnel, with lane closures on Market Street and some loss of parking. (Kevin N. Hume/S.F. Examiner)
Construction on Twin Peaks Tunnel to begin November 30

Area around Castro Muni Station will see greatest impacts including lane closures on Market Street

(Genaro Molina/Pool/Los Angeles Times/TNS)
Newsom calls latest surge of COVID-19 cases ‘unprecendented’

By Eli Walsh Bay City News Foundation California’s latest surge of COVID-19… Continue reading

Dr. Barbara Ferrer, director of the Los Angeles County Department of Public Health, during a news conference on March 10, 2020. (Myung J. Chun/Los Angeles Times/TNS)
LA County suspends outdoor dining at restaurants as coronavirus surges

By Alex Wigglesworth Los Angeles Times Los Angeles County public health officials… Continue reading

Renderings of the main entrance to upcoming Mission Bay elementary school on Owens Street. (Courtesy photo)
SFUSD offers first look at planned Mission Bay elementary school

San Francisco school officials this month unveiled the design of a planned… Continue reading

Most Read