Hackers claim breach of LA Metro, which serves millions of Americans
Attackers are putting pressure on LA Metro.

Photo by Sarah Reingewirtz via GettyImages
- The Gentlemen ransomware gang listed LA Metro on its dark web leak site but has not shared data samples.
- LA Metro serves about 12.9 million people, so exposed passenger data could affect many riders.
- Attackers gave the publicly owned transit agency nine days to respond to the claim.
- LA Metro had a major breach in March 2026, when hackers stole 700GB of internal data.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The Gentlemen, a rising name among ransomware gangs, has listed LA Metro on its leak site on the dark net.
The attackers have not yet released any data samples. Therefore, it’s unclear what LA Metro user data is exposed.
It’s common for attackers to first post company names and release data samples to intensify pressure later.
The notice came up on September 7th, and the attackers gave the publicly owned LA transporter 9 days to respond.
Passenger data would be a treasure trove for attackers
At this stage, it is impossible to estimate what kind of data attackers may have exfiltrated. It could be operational data, but it is also likely that attackers targeted passengers' data, as such data is more profitable in underground markets.
LA Metro is the owner and primary manager of ticket sales. The company uses the TAP (Transit Access Pass) system as its primary fare payment method, collecting payments for rides via vending machines at stations, mobile apps, or a website.
The company operates both metro and buses, serving approximately 12.9 million people in the broader Los Angeles metropolitan area.
If attackers gained access to the company’s systems, it may have resulted in access to massive amounts of individual data.
Cybernews has reached out to Metro for comment.
LA Metro has already been breached this year
If newly released claims prove to be legitimate, this may be the second attack this year affected the LA Metro. It suffered a significant data breach in March 2026.
Attackers exfiltrated 700GB of internal data, including emails and backups, and partially shut down the systems. A pro-Iranian hacking group claimed responsibility for the attack.
The transportation sector has been a common target
The LA Metro breach is not the only blow that the US transportation sector has suffered in recent years.
In 2025, the Texas Department of Transportation was hacked, and 300,000 car crash reports were stolen. The stolen data included names, addresses, driver's license numbers, license plate numbers, insurance policy details, and injury descriptions from crash narratives.
At the beginning of 2026, the Qilin ransomware gang leaked 700,000 NYC transit worker files. Exposed data reportedly includes pensions, salaries, benefits, medical, insurance information, and disciplinary records.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.