Contact us today!
866-348-2602

Total Tech Care Blog

Total Tech Care has been serving Florida since 2001, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

This Hacker Messed With the Wrong Transportation Agency

This Hacker Messed With the Wrong Transportation Agency

While San Francisco residents might not be happy that they’ll again have to pay fares to ride the city’s rail system, the reason they again have to do so is understandable. Plus, it provides an excellent example of the importance of maintaining a backup and using complex passwords.

A hacker or group of hackers, operating under the moniker Andy Saolis, managed to halt the collection of fares by the San Francisco Municipal Transportation Agency (or Muni) by hacking their station computer system and introducing a strain of ransomware into it. As a result, Muni employees were unable to access their workstations and some of the agency’s systems were disabled.

However, the hacker claimed to have accomplished more, as ticketing kiosks across the city would only display “you hacked. ALL data encrypted.” The ransom demand for the decryption key was approximately $73,000 in Bitcoin. Despite the hacker’s apparent confidence in their accomplishment, Muni elected to not pay the ransom, deciding instead to restore their systems from a backup and allowing cybersecurity experts to strike back against the hacker, not just once, but twice.

Two independent vigilante hackers managed to access the email account of “Andy Saolis” to collect information that helped to stop the attack, both by correctly guessing the answer to the account’s security question. It would seem that the hacker(s) known as Andy Saolis had been active for a while, but had never before targeted anything other than private companies, which very well may have led to their downfall.

Once the attack was thwarted it came to light that seemingly no data, including that from Muni’s customer payment systems, had been accessed, despite the attack affecting 25 percent of Muni’s network. Saolis, unsurprisingly, gave a considerably different account online.

Claiming to have stolen data from the payment kiosks, as well as 30 gigabytes of data from Muni’s system on their employees, customers, and technical matters, Saolis wasn’t shy about casting himself (or themselves) in the light of the vigilante against an unjust system.

According to an email sent through Russian service Yandex.com, “They give Your Money and everyday Rich more! But they don’t Pay for IT Security and using very old system’s !”

Shortly after the attack ended, security experts were also able to establish that the emailer was based in Iran, and had gained access to the hacker’s servers.

Though Muni never had to pay a ransom for their data, this attack wasn’t cheap, costing them the combined total of the free rides they granted to commuters as their systems were compromised. However, this total would certainly be less than the actual cost of the Bitcoin ransom, and so a good general rule to follow is to never give in to a hacker’s possibly insincere demands.

On the topic of the hacker, whose password was guessed by two separate strangers, how weak must this password have been? While nobody should ever complain about a hacker being foiled, it goes to show how a complete stranger could find their way into your accounts if you aren’t being careful..

This case is far from over, as the Federal Bureau of Investigation and the U.S. Department of Homeland Security are still investigating the matter, which provides proof that public systems are still unable to be fully trusted.

There is a lot for SMBs to learn from this story. How confident are you in your IT security? If you feel it’s time for a security audit in order to determine how protected your business is from all kinds of threats, reach out to Total Tech Care at 866-348-2602.

 

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Guest
Saturday, 05 April 2025
If you'd like to register, please fill in the username, password and name fields.

Blog Archive

Sign Up for Our Newsletter

  • First Name *
  • Last Name *

      Free Consultation

      Sign up today for a
      FREE Network Consultation

      How secure is your IT infrastructure?
      Let us evaluate it for free!

      Sign up Now!

      Free Consultation
       

      Tag Cloud

      Security Tip of the Week Technology Best Practices Business Computing Cloud Privacy Hackers Productivity Hosted Solutions Efficiency Software Network Security Business Google Microsoft Internet Email Malware Backup Workplace Tips Innovation Data User Tips Computer Mobile Devices Hardware IT Services Disaster Recovery Android VoIP communications Business Continuity Smartphones Communication IT Support Smartphone Miscellaneous Mobile Device Small Business Network Browser Productivity Collaboration Quick Tips Cybersecurity Users Business Management Phishing Upgrade Managed IT Services Windows Outsourced IT Ransomware Data Backup Windows 10 Office Cloud Computing Data Recovery Server Save Money Windows 10 Passwords Virtualization Saving Money Holiday Gadgets Social Media Chrome Tech Term Managed IT Services Automation Managed Service Microsoft Office Computers Facebook Artificial Intelligence Operating System Cybercrime BYOD Mobile Device Management Internet of Things Networking IT Support Wi-Fi Hacking Health Spam Covid-19 Office 365 Telephone Systems Alert Information Technology Managed Service Provider Information Remote Router BDR Bandwidth Recovery Employer-Employee Relationship Social Engineering Mobility Applications Remote Monitoring Mobile Computing Application Law Enforcement App History Big Data Password Money Human Resources Data Breach Encryption Mobile Office Government How To Office Tips Private Cloud Training Blockchain Paperless Office Managed IT Data Storage Patch Management VPN Apps Remote Computing HaaS Marketing Google Drive WiFi IT solutions Data Security Entertainment Website Budget Avoiding Downtime Wireless Gmail Bring Your Own Device Vulnerability Settings Data Management Windows 7 Work/Life Balance Word Two-factor Authentication Infrastructure Servers Voice over Internet Protocol Flexibility Mouse Managed Services Safety Display Sports HIPAA User Error Redundancy Meetings Data Protection Keyboard Employee/Employer Relationship USB RMM Risk Management Hacker The Internet of Things Lithium-ion battery Save Time Software as a Service Conferencing Telephone System Staff Machine Learning Cleaning Scam Firewall Connectivity Remote Work Virtual Reality End of Support Apple Vendor Management Education Physical Security Vendor Social Fraud Charger Remote Workers PDF Compliance Remote Worker Processor OneNote Computer Care Current Events Cryptocurrency Printer Telephony Proactive IT Bluetooth Wearable Technology Retail Hard Drive Hard Drives Samsung Best Practice Instant Messaging Robot Comparison YouTube Excel Black Market Value CES Computing Biometrics Virtual Desktop Spam Blocking IT Consultant Electronic Medical Records Business Technology Document Management Content Management Access Control Solid State Drive Wireless Technology Hiring/Firing Humor DDoS How to Downtime Digital Signage Virtual Assistant SharePoint Authentication Data storage Automobile Customer Service Procurement Business Intelligence Environment Update Net Neutrality Workplace Strategy Computing Infrastructure Fax Server Going Green Audit Worker IT Management Help Desk Google Docs Printing SaaS Botnet Identity Theft Virus Battery IT Plan Shadow IT Unified Threat Management Legal Managed Services Provider Computer Accessories Network Congestion Unsupported Software Database Internet Exlporer Augmented Reality eWaste Twitter Windows Server 2008 R2 Tablets Search Engine Notifications Supercomputer NIST Customer relationships Cameras Business Mangement Software Tips Entrepreneur IT Assessment Sync Trending Manufacturing Emails Email Best Practices Smart Tech Addiction Shortcut Amazon Security Cameras Computer Tips Recycling Managed IT Service Relocation Cost Management OneDrive Social Networking Biometric Security Netflix Two Factor Authentication Wiring Virtual CIO Practices Cache Peripheral Video Games Amazon Web Services Root Cause Analysis Knowledge Music Safe Mode Digital Security Cameras Printer Server Worker Commute Criminal Using Data HBO Copiers Skype 5G GDPR Experience Running Cable Hosted Computing Wireless Internet Quick Tip Scalability Online Shopping Data loss Memory Smartwatch Leadership Troubleshooting File Sharing Ergonomics Business Owner Outlook Inventory Development Start Menu Specifications OLED NarrowBand Camera Wire PCI DSS Search Evernote Virtual Machine Screen Mirroring Loyalty Travel Employee Books 2FA Fiber Optics iPhone Frequently Asked Questions Messaging Mobile Millennials Cabling Windows 10s Science Printers Smart Office Policy Wireless Charging Hypervisor Cast webinar Emergency Dark mode Trend Micro Files Tip of the week SMS Professional Services Customer Relationship Management Workforce Default App Chromecast Public Cloud Employer Employee Relationship Virtual Private Network Distributed Denial of Service Consultant Procedure Cables Saving Time Analyitcs Assessment Google Search Uninterrupted Power Supply dark theme Analytics Shopping Colocation Windows Server 2008 Programming Nanotechnology AI Tools Telecommuting IT Infrastructure Project Management Best Available FinTech Cortana Monitor Bing Television WIndows 7 Antivirus Digital Signature Social Network Investment Windows 8 Warranty Public Computer HVAC Employees IT service Google Apps Employee/Employer Relationships Reputation Streaming Media Regulations ISP Tech Support Transportation Windows 365 Content Analysis Devices Video Conferencing Techology ROI Laptop Computer Fan Tablet Rootkit Administrator Enterprise Content Management Sales Domains Bitcoin Customers Shortcuts Cryptomining Workers User Benefits MSP Point of Sale PowerPoint Audiobook Accountants Personal Windows Media Player IaaS Thought Leadership Supply Chain Management Maintenance Credit Cards Touchpad FENG Microchip IBM Password Management Monitoring Password Manager Batteries Bloatware Digitize Advertising Flash Multi-Factor Security Managing Stress Smart Technology Windows 8.1 Politics

      Top Blog

      The reasoning for this is simple: you want to make sure that operations are proceeding as intended, even if you’re not there. If you completely check out from the workplace every time you leave, you could return from your vacation to a complete and total disaster that may have been prevented with y...
      QR-Code