• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia
Tech

Hackers Threaten to Release 30GB of Stolen Data From San Francisco’s Municipal Railway

Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
Robert Hackett
By
Robert Hackett
Robert Hackett
Down Arrow Button Icon
November 28, 2016, 2:17 PM ET

Hackers infected a computer network operated by San Francisco’s public railway system with malicious software over Thanksgiving weekend.

After two days of interrupted ticketing service and free rides for passengers, the railway’s station kiosks went back online on Sunday. A day later though, the hackers were still threatening to expose 30 Gigabytes of stolen employee and customer data, Fortune learned through a series of email exchanges with the alleged attackers.

The group said that it would release the supposedly stolen information if the agency failed to fix its vulnerable systems and pay an undisclosed sum by Friday. The attackers refused to send Fortune a sample of the data for verification, writing that “i show you later if they don’t contact us.”

Get Data Sheet, Fortune’s technology newsletter.

The San Francisco Municipal Transportation Agency did not immediately reply to Fortune’s request for comment about whether it planned to make the payment or address the issue in some other way.

Paul Rose, an agency spokesperson, has said that “there is an ongoing investigation and it wouldn’t be appropriate to provide additional details,” according to the San Francisco Examiner, which first reported the computer network outage.

What happened

Starting Friday afternoon, the ticketing machines of San Francisco’s railway, known locally as Muni, read “You Hacked, ALL Data Encrypted.” The message, consistent with a ransomware attack, urged people to contact the operator of the email address cryptom27@yandex.com for a key.

The “key” referenced is an encryption tool that can scramble and unscramble data. Cybercriminals commonly use these keys in conjunction with phishing scams to lock people out of their digital files, and to extort them for regained access.

In this case, the attackers reportedly demanded 100 Bitcoins, or roughly $73,000, in ransom, according to the Examiner. So far, the Bitcoin address in question has recorded three transactions totaling a mere 0.002409 Bitcoin, or less than $2.

https://twitter.com/SF_CA_RR/status/802702146793783298

Who the hackers are

In response to an emailed inquiry from Fortune, the hacker group identified itself as “Andy Saolis,” a pseudonym linked to a number of other ransomware incidents.

Saolis told Fortune that the railway computer network ransomware strike was an automated attack rather than a targeted one, that it exploited outdated software used by the agency, and that the breach extended beyond station kiosks.

The agency is “using very old system’s !” the person behind the email address said. “We Hacked 2000 server/pc in SFMTA including all payment kiosk and internal Automation and Email and …!”

“We Gain Access Completely Random and Our Virus Working Automatically !” he continued. “We Don’t Have Targeted Attack to them ! It’s wonderful !”

Saolis suggested that the hack involved a team based outside the U.S., although it was impossible to confirm the claim.

“We Don’t live in USA,” he said. “Sorry For My English anyway ;)”

Fortune requested a sample of stolen information to verify the attackers’ claims of having access to 30 GB of stolen data, but the email address administrator declined.

Hoodline, a Bay Area news blog, reported that it had, however, seen evidence suggesting that the compromise extended beyond Muni ticket payment terminals. The breach also appears to encompass “payroll, email servers, Quickbooks, NextBus operations, various MySQL database servers, staff training and personal computers for hundreds of employees,” the blog reported, citing documents released by the attackers.

The hackers also claimed to have control of 2,112 computers, or about a quarter of the 8,656 computer on the agency’s network, Hoodline reported.

A CBS News affiliate posted on Twitter an image reportedly depicting an employee’s affected Dell desktop PC.

.@sfmta_muni giving free rides today because hackers shut down the computer system. Employee computers showing this pic.twitter.com/fvVnUayWVG

— CBS News Bay Area (@KPIXtv) November 27, 2016

The malware

The software used to hijack these computers is believed to belong to the malware strain known as HDDCryptor or Mamba. The program affects Microsoft Windows computers by encrypting their hard drives until unlocked by a certain password.

Computer security experts call the kind of cybercriminal tactic that led to the infection “spray and pray.” Crooks, in other words, use an automated system to blast prospective victims with links to malware, or lure them to a boobytrapped webpage.

In this case, the attackers said that an IT admin at the transportation agency downloaded one of their malware-laced a torrent files, a type of data format, according to the Examiner.

Reports of ransomware infections have been on the rise recently. The Federal Bureau of Investigation has been warning businesses to be on the lookout for attacks.

About the Author
Robert Hackett
By Robert Hackett
Instagram iconLinkedIn iconTwitter icon
See full bioRight Arrow Button Icon

Latest in Tech

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Tech

vegan cheese
AITech
A Mark Cuban-backed vegan cheese company trained AI to scrutinize cardboard boxes. It’s saved $400,000
By Jake AngeloMay 1, 2026
17 minutes ago
Young trade worker learning on job
SuccessHiring
Forget Big Tech: Small businesses will hire nearly 1 million grads in 2026—and some of the hottest roles are gloriously AI-proof
By Emma BurleighMay 1, 2026
2 hours ago
Andrew McAfee
SuccessCareers
MIT AI expert warns automating Gen Z entry-level jobs could backfire—and cost companies their future workforce
By Preston ForeMay 1, 2026
2 hours ago
duke
Big TechAmazon
Amazon Prime Video reaches deal with Duke Blue Devils to air 3 games per season
By The Associated PressMay 1, 2026
4 hours ago
valerie
CommentaryLayoffs
Tesla’s former HR chief: the AI layoff panic Is built on a false premise—here’s what most workers need to know
By Valerie Capers WorkmanMay 1, 2026
4 hours ago
AI
AIdisruption
Meet the Americans dismissing AI hype and using it with ingenuity: ‘The efficiencies gained out of it have been tremendous’
By Cathy Bussewitz and The Associated PressMay 1, 2026
4 hours ago

Most Popular

China dominates the world's lithium supply. The U.S. just found 328 years' worth in its own backyard
North America
China dominates the world's lithium supply. The U.S. just found 328 years' worth in its own backyard
By Jake AngeloApril 30, 2026
23 hours ago
Accenture's Julie Sweet blew up 50 years of company history. She says the hardest part is still ahead
Conferences
Accenture's Julie Sweet blew up 50 years of company history. She says the hardest part is still ahead
By Nick LichtenbergApril 29, 2026
2 days ago
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
Success
Apple cofounder Ronald Wayne—whose stake would be worth up to $400 billion had he not sold it in 1976—says that at 91, he has no regrets
By Preston ForeApril 27, 2026
4 days ago
The U.S. economy is booming — just not where 50 million Americans live
Commentary
The U.S. economy is booming — just not where 50 million Americans live
By Derek KilmerMay 1, 2026
9 hours ago
Exclusive: America's largest Black-owned bank launches podcast with mission to unlock hidden shame holding back generational wealth
Banking
Exclusive: America's largest Black-owned bank launches podcast with mission to unlock hidden shame holding back generational wealth
By Nick LichtenbergApril 29, 2026
2 days ago
America shot its arsenal empty in 2 wars. Now it needs Beijing's permission to reload
Commentary
America shot its arsenal empty in 2 wars. Now it needs Beijing's permission to reload
By Steve H. Hanke and Jeffrey WengApril 30, 2026
1 day ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.