San Francisco Muni Hack Could Have Been a Catastrophe

The Internet of Things will continue to be a concern for cities, the ransomeware that struck the San Francisco transit system could have been much worse. A future attack will be.

2 minute read

December 11, 2016, 1:00 PM PST

By Casey Brazeal @northandclark


San Francisco STreetcar

superjoseph / Shutterstock

Shortly after Thanksgiving, the San Francisco Municipal Transit Agency came under attack. "Someone had attacked Muni’s computer system and was demanding a ransom. Monitors in station agent booths were seen with the message, 'You Hacked. ALL data encrypted,' and the culprit allegedly demanded 100 Bitcoin (about $73,000)," Jack Stewart writes in a story for Wired.

Some riders may not even have considered that the payment machines they were using were connected to the internet, but they were. While Muni says they did not pay off the hackers, many (like this Kansas hospital) do. Like hospitals, transit systems make easy targets because, as Jack Stewart explains, "Many are aging and underfunded, with barely enough money to keep the trains running, let alone invest in IT security upgrades." This means private information about customers and employees is vulnerable. 

Worse still, the problem is not just one of budgets. Connectivity is the natural consequence of a world that can do so much with internet, so more and more devices are coming online all the time and there are more and more places bad actors can take advantage of vulnerabilities. Also, digital locks, like DRM, create paths for criminals to use to break into our systems. For transit systems those devices must be accessible to the public 24 hours a day.

Stewart suggests that transit systems need to be prepared for the problem, writing, "They should create procedures for a cyber attack, then communicate, review, and update them on a regular basis." There's also work our legislators could do to make it safer to expose security risks that agencies like SFMTA and hospitals may be exposing their customers to.

Monday, November 28, 2016 in Wired

portrait of professional woman

I love the variety of courses, many practical, and all richly illustrated. They have inspired many ideas that I've applied in practice, and in my own teaching. Mary G., Urban Planner

I love the variety of courses, many practical, and all richly illustrated. They have inspired many ideas that I've applied in practice, and in my own teaching.

Mary G., Urban Planner

Get top-rated, practical training

Red 1972 Ford Pinto with black racing stripes on display with man sitting in driver's seat.

Analysis: Cybertruck Fatality Rate Far Exceeds That of Ford Pinto

The Tesla Cybertruck was recalled seven times last year.

July 2, 2025 - Mother Jones

Close-up of park ranger in green jacket and khaki hat looking out at Bryce Canyon National Park red rock formations.

National Parks Layoffs Will Cause Communities to Lose Billions

Thousands of essential park workers were laid off this week, just before the busy spring break season.

February 18, 2025 - National Parks Traveler

Paved walking path next to canal in The Woodlands, Texas with office buildings in background.

Retro-silient?: America’s First “Eco-burb,” The Woodlands Turns 50

A master-planned community north of Houston offers lessons on green infrastructure and resilient design, but falls short of its founder’s lofty affordability and walkability goals.

February 19, 2025 - Greg Flisram

Screenshot of shade map of Buffalo, New York with legend.

Test News Post 1

This is a summary

0 seconds ago - 2TheAdvocate.com

Red 1972 Ford Pinto with black racing stripes on display with man sitting in driver's seat.

Analysis: Cybertruck Fatality Rate Far Exceeds That of Ford Pinto

The Tesla Cybertruck was recalled seven times last year.

18 minutes ago - Mother Jones

test alt text

Test News Headline 46

Test for the image on the front page.

March 5 - Cleantech blog