Press "Enter" to skip to content

Ransomware group claims LA Metro as a victim months after earlier cyberattack

A ransomware group known as The Gentlemen has listed the Los Angeles County Metropolitan Transportation Authority, better known as LA Metro, on its dark web leak site, according to a September 8 report from Cybernews.

At this point, that is exactly what we have: a claim.

The attackers have apparently given Metro nine days to respond, but Cybernews reports that The Gentlemen has not published samples of any allegedly stolen data. Cybernews also contacted Metro for comment.

That means we do not yet have independent confirmation that Metro was breached by this group, nor do we know what information, if any, may have been taken.

This is a developing story, and those distinctions are important.

Who are The Gentlemen?

The Gentlemen is a relatively new ransomware operation, but it has grown very quickly.

Microsoft Threat Intelligence, which tracks the operators behind the ransomware as Storm-2697, says The Gentlemen operates using a ransomware-as-a-service, or RaaS, model.

Ransomware-as-a-service works somewhat like a criminal version of a legitimate software service. The people operating the RaaS platform develop and maintain the ransomware and supporting infrastructure, while affiliates use those tools to compromise victims and conduct attacks. The proceeds are then divided between the operators and affiliates according to the program’s arrangement.

This means that seeing the same ransomware family used against multiple organizations does not necessarily mean the exact same individuals personally carried out every intrusion.

Microsoft says The Gentlemen emerged in mid-2025 and developed into a RaaS operation in September 2025. The ransomware is notable for aggressive lateral movement and self-propagation capabilities that can help it spread across a compromised network once attackers gain access.

The operation has also become significantly more prominent during 2026.

Check Point Research reported that The Gentlemen posted 269 victims during the second quarter of 2026, placing it second globally among ransomware operations by the number of victims posted to data leak sites. It even posted more claimed victims than Qilin during June.

As always, data leak site numbers represent claims made by criminal groups and should not automatically be treated as independently verified breaches. Still, the numbers demonstrate that The Gentlemen is no longer an insignificant ransomware newcomer.

Metro has been here before

The new claim deserves additional attention because Metro suffered a significant cybersecurity incident only several months ago.

This blog has covered that incident previously. Our original April coverage examined what Metro had confirmed and the considerably more extensive claims being made by outside sources. We followed up in May as additional researchers and news organizations began reporting more about who may have been responsible and what happened.

Metro detected unauthorized activity on March 16, 2026 and restricted employee access to many internal administrative systems while it investigated.

The Los Angeles Times reported in April that Metro was examining roughly 1,400 servers individually before allowing them back online. Bus and rail service continued operating, but internal systems took weeks to restore.

At that point, Metro said the full scope and origin of the incident remained under investigation.

Cybernews now describes the March incident as involving approximately 700GB of stolen internal data, including emails and backups, and says a pro-Iranian hacking group claimed responsibility.

There was considerable outside reporting surrounding that incident, but Metro itself publicly disclosed relatively little about exactly what happened, what information was affected, who was responsible or what ultimately changed as a result.

That becomes relevant again now.

What did Metro learn from March?

If The Gentlemen’s latest claim ultimately proves to be legitimate, one of the most important questions will be what Metro learned from the March attack.

That is not the same as saying Metro failed to secure its systems.

Organizations can be compromised more than once even after substantial security work, and two incidents involving the same organization may have completely different entry points, attackers and circumstances.

At this point, we have no evidence that the March incident and this new claim are connected.

But a second confirmed compromise within approximately six months would naturally raise questions.

What was determined to be the initial point of access in March?

Was that access closed?

Were compromised credentials identified and replaced?

Were internet-facing systems, VPNs, firewalls and other edge devices reviewed?

Was an independent security assessment conducted?

What other remediation took place?

And if The Gentlemen did gain access, was that access through something Metro could reasonably have discovered or corrected following the earlier incident?

We simply don’t have those answers.

What we don’t know

Cybernews discusses the possibility that passenger information could be valuable to attackers, but there is currently no evidence presented showing that TAP information, rider accounts or other passenger information was stolen.

That possibility should not be confused with confirmation.

We also don’t know whether The Gentlemen actually encrypted Metro systems, stole information without encrypting anything, obtained limited access, or simply posted Metro’s name as part of an extortion attempt.

Until evidence appears or Metro provides additional information, claims about what was accessed or stolen would be speculation.

That is particularly important when dealing with ransomware leak sites. Criminal organizations have an obvious incentive to make their claims sound as serious as possible. A victim listing tells us that the criminals are making an allegation. It does not independently prove everything they say happened.

Metro should address the claim

Metro serves one of the largest transportation systems in the United States. Its computer systems support a large workforce, transportation infrastructure and services used by millions of people.

That makes cybersecurity a public-interest issue, even when trains and buses continue operating normally.

Metro does not need to disclose technical information that would interfere with an active investigation or create additional security risks. But riders, employees and the public should eventually receive meaningful information about what happened if this latest claim is confirmed.

The March incident already left significant unanswered questions.

Now, several months later, a major ransomware operation has publicly named Metro as a victim.

Perhaps the claim will turn out to be exaggerated or false. Perhaps The Gentlemen obtained something. Perhaps Metro will be able to provide additional information that changes what we currently understand.

We don’t know yet.

What we do know is that The Gentlemen has made the claim, no supporting data samples had been released when Cybernews published its report, and Metro experienced a confirmed cybersecurity incident earlier this year.

That is enough to pay attention.

We’ll update this story as additional verified information becomes available.


Discover more from Jared's Technology podcast network

Subscribe to get the latest posts sent to your email.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.