The Kansas City Area Transportation Authority (KCATA) suffered a ransomware attack on Jan 23 which impacted all its communication systems.
KCATA is a public transit agency in metropolitan Kansas City which operates the Metro Area Express (MAX) bus rapid transit service in Kansas City, Missouri, and 78 local bus routes in seven counties of Missouri and Kansas.
The company reports that 10.5 million people use their services in a year.
The company disclosed the attack on January 24, and immediately launched an investigation into the incident and notified appropriate authorities. The company also hired external experts to restore impacted systems.
The KCATA states that the incident has not affected its services, including fixed-route buses, as well as the Freedom and Freedom-On-Demand paratransit services.
The main customer impact is the inability to make calls to regional RideKC call centers, including any KCATA landline.
However, KCATA did not disclose specific information about the attack, including details about the ransomware family that compromised its systems or whether a data breach occurred.
Meantime, the Medusa ransomware gang claimed responsibility for the attack against KCATA. The ransomware gang added the company to its Tor leak site and published samples of the alleged stolen data as proof of the data breach.
The ransomware gang threatens to release all the stolen data unless the company pays a $2 million ransom within 10 days. The Medusa group also offers the victims the option to extend the deadline by paying $100,000/day.














Comments