The Los Angeles County Metropolitan Transportation Authority (LA Metro) has appeared on the leak site of The Gentlemen ransomware group, raising the possibility of another cybersecurity incident at the transit agency this year.
The Gentlemen added LA Metro to its site on September 7 and gave the agency nine days to respond. The listing is commonly used by ransomware groups as a way to pressure organizations into contacting them before allegedly stolen information is released.
For now, however, the hackers have provided no data samples to support their claim. LA Metro has also not publicly confirmed that The Gentlemen breached its systems.
That means the nature and potential scale of the incident remain unknown. There is currently no verified information showing what data the group may have obtained, how much information could be involved, or whether passenger records are among the allegedly stolen files.
LA Metro is the public transportation agency serving Los Angeles County, operating an extensive network of bus and rail services. It also manages fare payments through the TAP system, which allows riders to pay through physical cards and digital services.
The new ransomware claim follows a separate cybersecurity incident that disrupted some LA Metro systems in March 2026. During that incident, the agency detected unauthorized activity and restricted employee access to a number of internal administrative systems as part of its containment measures.
Bus and rail services continued operating, but customers experienced problems with some digital services, including station arrival displays and certain TAP functions.
The March incident was later associated with claims that attackers had taken hundreds of gigabytes of internal information. The latest listing by The Gentlemen should not automatically be treated as evidence that the two events are connected.
The Gentlemen has emerged as a prolific ransomware operation, regularly naming organizations on its leak site as part of its extortion activity. Such listings alone do not establish that a breach occurred or prove that the attackers possess the data they claim to have obtained.
As of September 9, no files have been published to substantiate the group’s latest LA Metro claim. The agency has not publicly confirmed a new breach, leaving both the authenticity of the claim and the potential exposure of any data unresolved.
