The Maryland Transit Administration (MTA) experienced a significant cyberattack that resulted in the theft of sensitive data and disruption of certain services. The incident came to light when Maryland officials reported that several state departments, including the MTA, were affected by a cyberattack that impacted systems used to coordinate transportation for disabled individuals. The MTA confirmed that data was stolen during the attack, but did not disclose the number of affected individuals or the specific types of data compromised, citing the sensitivity of the ongoing investigation. The Rhysida ransomware gang, known for targeting government entities, claimed responsibility for the attack and demanded a ransom of 30 bitcoin, equivalent to approximately $3.3 to $3.4 million, giving the MTA seven days to comply. Rhysida published samples of the stolen data, which reportedly included passports, driver’s licenses, contracts, and other documents. The attack did not affect the MTA’s core transportation services such as bus lines, subways, and light rail, but it did disrupt real-time information systems and tools used for the Mobility service, which provides specialized transportation for people with disabilities. The Mobility service was restored through an interim call system on August 29, but the MTA has not specified the duration of the disruption. The Maryland Department of Information Technology is collaborating with cybersecurity experts and law enforcement agencies to investigate the breach and mitigate its impact. Analysis of Rhysida’s dark web post indicated the presence of internal financial and budget documents, though it is unclear if private personal details were included. Rhysida’s operation has compromised over 220 organizations globally, including high-profile victims such as the Seattle-Tacoma International Airport and the Anne & Robert H. Lurie Children's Hospital. The MTA has not confirmed whether the breach claimed by Rhysida is the same as the one it reported, but the timing and details strongly suggest a connection. The incident highlights the ongoing threat posed by ransomware groups to critical infrastructure and government services. The MTA has not indicated whether it intends to pay the ransom or negotiate with the attackers. The breach underscores the importance of robust cybersecurity measures and incident response planning for public sector organizations. The investigation is ongoing, and further details about the scope of the data loss and the attackers’ methods may emerge as authorities continue their work.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
MDOT said that some systems within its Transit Administration were affected by a cyberattack. The agency did not confirm whether the incident it acknowledged was the same one claimed by Rhysida.
The Rhysida ransomware group posted claims that it had stolen data from the Maryland Department of Transportation's Transit Administration, alleging the haul included sensitive documents such as IDs, passports, and background checks. The gang demanded about $3.3 million to prevent release of the data.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.