Washington Metro cybersecurity audit reveals rising vulnerabilities in transit system

Date:

Share post:

A cybersecurity audit performed on Metro in Washington highlighted that the agency remains vulnerable to attacks that might endanger the security system. The audit report was submitted to Metro’s board of directors in late last month, but the key facts are being kept secret due to the risk from scammers.

“By its nature, such an audit in the wrong hands could expose vulnerabilities and thereby undermine our shared goal of making (Metro’s) IT environment even more secure,” Metro Inspector General Geoffrey A. Cherrington said in a statement. “For that reason, we have made an exception to our standard practice of posting audits to our website, and this one will be withheld from release.”

The report specifically mentioned the Metro’s incident response measures and whether the security experts in the agency know how to detect and respond to a cyber attack. In a response to the report, the Metro officials announced that they’re focussing on the security improvements in the entire transport system.

There are various incidents of cyber attacks on transport system earlier. On October 24, 2017, Ukraine’s Odessa airport and metro system in Kiev was targeted by a malware called “BadRabbit” and prompted state-run Computer Emergency Response Team (CERT) to ask transport networks to be on alert. However, the country’s banking services remained unaffected.

Kiev metro system reported that its payment system was attacked while Odessa airport said it had to delay some flights, as it beefed up its security arrangements. Ukraine suspects that its neighbor Russia is behind these cyberattacks and is planning to draft a national strategy to overcome such attacks and to keep major institutions and companies safe.

 

Subscribe

Name(Required)
Privacy(Required)

Upcoming Events

Related articles

Atlanta Set to Host Hacker Halted and Global CISO Forum 2026, Uniting Practitioners and C-Suite Leaders

The Westin Peachtree Plaza will anchor a week of hands-on training, offensive security research, and closed-door executive dialogue...

From Awareness to Relevance: Rethinking How We Teach Cybersecurity

Cybersecurity lessons have a better chance to endure when people first understand how the same risks affect their...

CyberSec Delhi Conference 2026

Securing India’s Power, Defence, Manufacturing & Industrial Ecosystems The CyberSec Delhi Conference 2026 will bring together policymakers, government stakeholders,...

SBOM, VEX, and AI: Dr. Allan Friedman on the Future of Software Supply Chain Security

A conversation on why software transparency is no longer optional, and how AI is about to make it...