Officials for LA Metro say claims that its systems were hacked and data had been leaked onto the dark web by a notorious ransomware gang are unsubstantiated.
LA Metro released a statement on Thursday, reasserting that data protection and security of its system remain a “top priority,” and said it would continue to monitor for any potential unauthorized data leaks.
“Recent web postings claim that some Metro data is available on the dark web. The data has not been identified, and the postings remain unsubstantiated,” LA Metro said in a statement to Rabble News.
An LA Metro spokesperson added that continued monitoring of its systems and data network was part of the agency’s “standard security protocols.”
Click here for the complete statement from LA Metro.
Data protection and security is a top priority for Metro. Recent web postings claim that some Metro data is available on the dark web. The data has not been identified, and the postings remain unsubstantiated. Nevertheless, as part of its standard security protocols, Metro will continue to actively monitor its systems and data network. “
LA Metro spokesperson
Was LA Metro hacked again?
Earlier this week, an online hacker group called “The Gentleman” listed Los Angeles County’s transit and transportation agency on its leak site hosted on the darknet.
The posting was viewed and captured in a screenshot by online technology website Cybernews.com.
Cybernews reporter Paulina Okunytė described The Gentleman as a “rising name among ransomware gangs,” and said the group listed LA Metro as one of its recent victims and has given the transit agency nine days to respond.
The notice was first posted on the hacker group’s site on Monday, Sept. 7, meaning the nine day deadline will be reached around the middle of next week.
The exact type of data the group alleged to have obtained was not disclosed.

LA Metro’s statement indicates it has not identified or verified any data that could have been obtained by the group.
Does that mean that “The Gentleman” is bluffing? Not necessarily.
It’s not unusual for companies and government agencies to be tight-lipped when dealing with a cybersecurity threat. Investigations are often kept close to the vest, particularly when sensitive data is held for ransom.
Media statements are often intentionally vague for a reason, in my experience.
At the very least, the statement provided by LA Metro confirms that it is aware of the threat from the hacker group, and the agency insists that it is taking it and other security threats seriously.
LA Metro has been hacked before
This is the second time this year that a hacker group claimed to have successfully compromised LA Metro systems.
In March, LA Metro confirmed it had been the victim of a breach that led to “unauthorized activity” of its systems. It was forced to shut down parts of its network temporarily and comb through hundreds of individual servers before bringing them back online, according to the Los Angeles Times.
An estimated 700GB of data was estimated to have been stolen in that March cyber-attack, which was allegedly perpetrated by Iranian-backed hackers.
Read More: BART crime rate plummeted after agency installed newer fare gates
Several high-profile and high-powered agencies across Southern California have fallen victim to cyber-attacks in recent years.
In 2022, hackers released a large cache of data stolen from the Los Angeles Unified School District, including hundreds of students records—some of which contained social security numbers.
In 2023, UCLA was hit by a cyber-attack, and, additionally, San Bernardino County paid more than $1 million in ransom after its Sheriff’s Department was hacked.
The Los Angeles County Superior Court suffered its own major ransomware attack in 2024 that led to courthouse closures for multiple days.
Rabble News will continue to follow this story as it develops.
For more stories like this, follow Rabble News on Instagram and Facebook.
