Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstalliTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
San Francisco Municipal Transportation Agency (SFMTA) was hit by ransomware in November 2016, but the available reporting does not show that the malware had been inside Muni systems continuously for two months. CyberScoop reported that researchers saw similarities between the SFMTA incident and a separate ransomware case they had analyzed in September, leading them to say the attack may have been a mutated offspring of the earlier variant.
What happened to SFMTA
SFMTA said it became aware of a potential computer-security issue, including email, on Friday, November 25, 2016. The agency’s November 28 update said the malware primarily affected office computers and temporarily limited access to some systems.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Network Security, Firewalls, and VPNs | $66.62 | Buy on Amazon |
| 2 |
|
Network Security, Firewalls, and VPNs: . (Issa) | $60.31 | Buy on Amazon |
| 3 |
|
TP-Link ER605, Wired Gigabit VPN Router | $49.99 | Buy on Amazon |
| 4 |
|
Cybersecurity for Small Networks: A Guide for the Reasonably Paranoid | $33.90 | Buy on Amazon |
SFMTA estimated that approximately 900 office computers were affected. Payroll continued operating, although access was temporarily disrupted, and the agency said employees’ pay would not be affected.
Recommended Free Tools
As a precaution, SFMTA and its Clipper operating partner switched off ticket machines and Muni Metro fare gates from Friday until 9 a.m. Sunday. SFMTA said transit operations and safety were not affected, and stated: “Muni operations and safety were not affected.”
#1 Best Overall
The agency also said customer payment systems were not hacked and that no data had been accessed from its servers. Its November 28 status statement said, “The situation is now contained”—a description of the incident at that time, not a current security assessment.
Was Muni service affected?
Regular Muni operations continued, and SFMTA reported no effect on transit safety. The practical disruption was to fare-collection equipment: ticket machines and Metro fare gates were temporarily turned off while the agency and Clipper operator assessed the incident.
Rank #2
- Available with the Cloud Labs which provide a hands-on, immersive mock IT infrastructure enabling students to test their skills with realistic security scenarios
- New Chapter on detailing network topologies
- The Table of Contents has been fully restructured to offer a more logical sequencing of subject matter
- Introduces the basics of network security—exploring the details of firewall security and how VPNs operate
- Increased coverage on device implantation and configuration
What was affected
- Approximately 900 SFMTA office computers, according to the agency.
- Email and access to some internal systems.
- Fare gates and ticket machines, temporarily disabled as a precaution.
What SFMTA said was not affected
- Muni operations and safety.
- Employee pay, despite temporary payroll-system access problems.
- Customer payment systems.
- Data stored on the agency’s servers, according to SFMTA’s statement.
Where the “two months” claim comes from
The time span refers to a comparison, not a confirmed infection timeline. CyberScoop reported that Morphus Labs researcher Renato Marinho had analyzed a ransomware incident in September involving servers at a company with subsidiaries in the United States, Brazil and India. Marinho said that case and the SFMTA event shared notable characteristics.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
CyberScoop described the earlier malware as Mamba, which used DiskCryptor for full-disk encryption. The report also noted a connection to a hacker using the pseudonym Andy Saolis. Researchers had not found information that established who was behind that pseudonym.
Rank #3
- 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
- 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
- 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
- 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
- Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q
Those similarities support the cautious wording that the SFMTA malware may have been a mutated offspring of the earlier variant. They do not prove that identical malware had been targeting SFMTA for two months, that the same operators conducted both attacks, or when the SFMTA intrusion actually began.
What is known—and unknown—about the attackers
Unresolved entry method
The available contemporaneous reports do not identify how the attackers first entered SFMTA’s network. Marinho suspected phishing in the separate September case he studied, but neither SFMTA nor the purported attacker publicly explained the original SFMTA intrusion method. Phishing therefore should not be presented as a confirmed route into Muni systems.
Unverified identity and lineage
The Andy Saolis pseudonym and the reported Mamba similarities are clues, not proof of identity or control. The source set contains no confirmed attribution to a person, criminal group or state actor, and no later finding that resolves the malware’s exact lineage.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesHow the reported numbers differ
Contemporaneous accounts gave different machine counts. SFMTA’s figure is the agency’s estimate; the larger numbers came from a message attributed to the attacker and were not independently verified.
| Figure | Who reported it | How to interpret it |
|---|---|---|
| Approximately 900 affected office computers | SFMTA, November 2016 | Agency estimate of its primary impact |
| More than 2,112 computers | CyberScoop, reporting a hacker’s claim | Unverified; described as roughly a quarter of the network |
| About 2,000 infected server/PC systems | The Verge, reproducing a message attributed to the hacker | Attacker’s claim, not an audited count |
| Approximately $73,000 in bitcoin | CyberScoop | Reported ransom demand; no verified payment is established |
How SFMTA recovered
SFMTA said it did not consider paying the ransom. Its information-technology team used existing backups to restore most affected computers by Monday morning, November 28, and expected the remainder to return within a day or two.
That response illustrates why infrastructure operators separate office technology from safety-critical operations, maintain recoverable backups and plan for temporary loss of administrative systems. CyberScoop quoted Avast executive Sinan Eren recommending patched operating systems, endpoint protection and centralized disaster-recovery backups for critical infrastructure. Those are category-level safeguards, not evidence that a particular vendor supplied SFMTA’s defenses.
Quick Recap
What the evidence supports
- Ransomware disrupted SFMTA office computing, email access and some fare equipment in late November 2016.
- SFMTA reported no effect on Muni operations or safety, no compromise of customer payment systems and no access to data on its servers.
- Existing backups enabled restoration without a reported ransom payment.
- Researchers reported similarities to a September ransomware case, which is the basis for the qualified “two months” wording.
- The exact entry route, confirmed malware family, attacker identity and verified total of infected machines remain unsettled in the contemporaneous record.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

