A ransomware gang calling itself The Gentlemen has added Los Angeles Metro to its dark web leak site, threatening exposure of data from an agency that serves millions of transit riders.
A ransomware group known as The Gentlemen has listed the Los Angeles County Metropolitan Transportation Authority, commonly known as LA Metro, on its dark web leak site, according to the group’s own posting. The notice appeared on September 7, and the attackers set a nine-day deadline for the transit agency to respond.
No data samples have been released so far, leaving the scope and nature of any exposed information unconfirmed. Ransomware operators frequently follow an initial listing with sample data releases later, a tactic used to increase pressure on victims to pay.
It is not yet possible to determine what type of data may have been taken. The information could be operational in nature, though passenger data is considered a likely target given its higher value on underground markets.
LA Metro manages ticket sales across its transit network and relies on the Transit Access Pass, or TAP, system as its primary fare payment method. Riders can load fares through station vending machines, a mobile app, or the agency’s website. LA Metro operates both bus and rail lines, serving a metropolitan population of approximately 12.9 million people. If attackers accessed the agency’s systems, the potential scale of compromised individual data could be substantial.
If the new claims prove true, this would mark the second attack on LA Metro in 2026. The agency previously suffered a significant breach in March 2026, when attackers exfiltrated 700 gigabytes of internal data, including emails and backup files, and partially disrupted its systems. A pro-Iranian hacking group claimed responsibility for that incident.
LA Metro is not alone in facing cyberattacks within the U.S. transportation industry. In 2025, the Texas Department of Transportation was hacked, resulting in the theft of 300,000 car crash reports. The compromised records included names, addresses, driver’s license numbers, license plate numbers, insurance policy details, and injury descriptions drawn from crash narratives.
Separately, at the start of 2026, the Qilin ransomware gang leaked files belonging to 700,000 New York City transit workers. The exposed data reportedly included pension information, salaries, benefits, medical records, insurance details, and disciplinary records.
Click Here For The Original Source.
