Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

San Francisco Municipal Transportation Agency (SFMTA) was hit by ransomware in November 2016, but the available reporting does not show that the malware had been inside Muni systems continuously for two months. CyberScoop reported that researchers saw similarities between the SFMTA incident and a separate ransomware case they had analyzed in September, leading them to say the attack may have been a mutated offspring of the earlier variant.

What happened to SFMTA

SFMTA said it became aware of a potential computer-security issue, including email, on Friday, November 25, 2016. The agency’s November 28 update said the malware primarily affected office computers and temporarily limited access to some systems.

SFMTA estimated that approximately 900 office computers were affected. Payroll continued operating, although access was temporarily disrupted, and the agency said employees’ pay would not be affected.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

As a precaution, SFMTA and its Clipper operating partner switched off ticket machines and Muni Metro fare gates from Friday until 9 a.m. Sunday. SFMTA said transit operations and safety were not affected, and stated: “Muni operations and safety were not affected.”

The agency also said customer payment systems were not hacked and that no data had been accessed from its servers. Its November 28 status statement said, “The situation is now contained”—a description of the incident at that time, not a current security assessment.

Was Muni service affected?

Regular Muni operations continued, and SFMTA reported no effect on transit safety. The practical disruption was to fare-collection equipment: ticket machines and Metro fare gates were temporarily turned off while the agency and Clipper operator assessed the incident.

Rank #2
Sale
Network Security, Firewalls, and VPNs: . (Issa)
  • Available with the Cloud Labs which provide a hands-on, immersive mock IT infrastructure enabling students to test their skills with realistic security scenarios
  • New Chapter on detailing network topologies
  • The Table of Contents has been fully restructured to offer a more logical sequencing of subject matter
  • Introduces the basics of network security—exploring the details of firewall security and how VPNs operate
  • Increased coverage on device implantation and configuration

What was affected

  • Approximately 900 SFMTA office computers, according to the agency.
  • Email and access to some internal systems.
  • Fare gates and ticket machines, temporarily disabled as a precaution.

What SFMTA said was not affected

  • Muni operations and safety.
  • Employee pay, despite temporary payroll-system access problems.
  • Customer payment systems.
  • Data stored on the agency’s servers, according to SFMTA’s statement.

Where the “two months” claim comes from

The time span refers to a comparison, not a confirmed infection timeline. CyberScoop reported that Morphus Labs researcher Renato Marinho had analyzed a ransomware incident in September involving servers at a company with subsidiaries in the United States, Brazil and India. Marinho said that case and the SFMTA event shared notable characteristics.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

CyberScoop described the earlier malware as Mamba, which used DiskCryptor for full-disk encryption. The report also noted a connection to a hacker using the pseudonym Andy Saolis. Researchers had not found information that established who was behind that pseudonym.

Rank #3
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q

Those similarities support the cautious wording that the SFMTA malware may have been a mutated offspring of the earlier variant. They do not prove that identical malware had been targeting SFMTA for two months, that the same operators conducted both attacks, or when the SFMTA intrusion actually began.

What is known—and unknown—about the attackers

Unresolved entry method

The available contemporaneous reports do not identify how the attackers first entered SFMTA’s network. Marinho suspected phishing in the separate September case he studied, but neither SFMTA nor the purported attacker publicly explained the original SFMTA intrusion method. Phishing therefore should not be presented as a confirmed route into Muni systems.

Unverified identity and lineage

The Andy Saolis pseudonym and the reported Mamba similarities are clues, not proof of identity or control. The source set contains no confirmed attribution to a person, criminal group or state actor, and no later finding that resolves the malware’s exact lineage.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How the reported numbers differ

Contemporaneous accounts gave different machine counts. SFMTA’s figure is the agency’s estimate; the larger numbers came from a message attributed to the attacker and were not independently verified.

Figure Who reported it How to interpret it
Approximately 900 affected office computers SFMTA, November 2016 Agency estimate of its primary impact
More than 2,112 computers CyberScoop, reporting a hacker’s claim Unverified; described as roughly a quarter of the network
About 2,000 infected server/PC systems The Verge, reproducing a message attributed to the hacker Attacker’s claim, not an audited count
Approximately $73,000 in bitcoin CyberScoop Reported ransom demand; no verified payment is established

How SFMTA recovered

SFMTA said it did not consider paying the ransom. Its information-technology team used existing backups to restore most affected computers by Monday morning, November 28, and expected the remainder to return within a day or two.

That response illustrates why infrastructure operators separate office technology from safety-critical operations, maintain recoverable backups and plan for temporary loss of administrative systems. CyberScoop quoted Avast executive Sinan Eren recommending patched operating systems, endpoint protection and centralized disaster-recovery backups for critical infrastructure. Those are category-level safeguards, not evidence that a particular vendor supplied SFMTA’s defenses.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
Network Security, Firewalls, and VPNs: . (Issa)
Network Security, Firewalls, and VPNs: . (Issa)
New Chapter on detailing network topologies; Increased coverage on device implantation and configuration
$60.31
SaleBestseller No. 3

What the evidence supports

  • Ransomware disrupted SFMTA office computing, email access and some fare equipment in late November 2016.
  • SFMTA reported no effect on Muni operations or safety, no compromise of customer payment systems and no access to data on its servers.
  • Existing backups enabled restoration without a reported ransom payment.
  • Researchers reported similarities to a September ransomware case, which is the basis for the qualified “two months” wording.
  • The exact entry route, confirmed malware family, attacker identity and verified total of infected machines remain unsettled in the contemporaneous record.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.