For the second time in under a year, LA Metro appears to have fallen victim to an online hacker group.
According to reporting from Cybernews.com, the online hacker group “The Gentleman” has listed Los Angeles County’s transit and transportation agency on its leak site hosted on the darknet.
Cybernews reporter Paulina Okunytė has described The Gentleman as a “rising name among ransomware gangs.”
The hacker group has allegedly obtained some type of undisclosed data from LA Metro, and has publicly given Metro officials nine days to respond. The notice was first posted on the hacker group’s site on Monday, Sept. 7.
“It’s common for attackers to first post company names and release data samples to intensify pressure later,” Okunytė writes. “At this stage, it is impossible to estimate what kind of data attackers may have exfiltrated.”

LA Metro is responsible for managing ticket sales, which are largely completed through its Transit Access Pass (TAP) system. Riders who use the TAP system can load money onto their cards at vending machines at stations, online or through the mobile app.
It’s unclear if any rider data, payment systems or operational information was obtained by the hacker group, but Cybernews says it could be a significant crisis for LA Metro if attackers gained access to its systems.
“It may have resulted in access to massive amounts of individual data,” Okunytė added.
LA Metro says it averages nearly 1 million riders per day across its bus and rail network, meaning millions of people could potentially be exposed to a data leak.
Read More: Bill aims to cut more red tape for CA High-Speed Rail construction
In a statement provided to Rabble News, AI and cyber-security firm BlackFog described this latest ransomware attack as a “targered, patient operation.”
“If the claimed attack on LA Metro is genuine, it fits a pattern we’ve been tracking closely with The Gentlemen,” BlackFog CEO Darren Williams said. “It’s a group that emerged in 2025 and was one of the most active ransomware groups during the second quarter of this year. That kind of scale-up typically takes years, not months, which tells us this isn’t a group of opportunists learning on the job. They’re operating with the tradecraft of an established group from day one.”
Williams said the pattern appears to show the group targeting “mid- to large-sized organizations” across the globe, where the loss of sensitive or private data could result in greater likelihood of a ransom being paid.
“Public transit and infrastructure operators like LA Metro are attractive precisely because attacks have immediate public visibility, which the group can use as extra leverage,” he added.
LA Metro was victim of cyber-attack earlier this year
This is already the second time this year that the LA Metro systems were allegedly compromised in a cyber-attack.
In March, LA Metro was forced to shut down parts of its network after security teams identified “unauthorized activity,” according to the Los Angeles Times.
The full extent of that attack still remains a bit unclear, but an estimated 700GB of data was estimated to have been stolen.
The culprits for that cyber-attack were alleged to be Iranian-backed hackers.
Read More: Raman vows to investigate LAX People mover contractor if elected
Several high-profile and high-powered agencies across Southern California have fallen victim to cyber-attacks in recent years.

In 2022, hackers released a large cache of data stolen from the Los Angeles Unified School District, including hundreds of students records—some of which contained social security numbers.
In 2023, UCLA was hit by a cyber-attack, and, additionally, San Bernardino County paid more than $1 million in ransom after its Sheriff’s Department was hacked.
The Los Angeles County Superior Court suffered its own major ransomware attack in 2024 that led to courthouse closures for multiple days.
Rabble News reached out to LA Metro officials for comment and confirmation of the claims made by The Gentleman and the reporting by Cybernews.com. We are still awaiting comment.
For more stories like this, follow Rabble News on Instagram and Facebook.