A data breach at Metro Mobility, the Twin Cities transit service for people with disabilities,have exposed the personal information of up to 15,000 individuals.
Metro Mobility has notified customers that an employee’s e-mail account was hacked by an unauthorized person.
The data compromised include accessed individual rider names, pickup and drop-off addresses, times of rides and special instructions for Metro Mobility drivers.
It was found that the hackers have personal ride information between June 13 and Aug. 14, when the breach was discovered.
TPRM report: https://scoringcyber.rankiteo.com/company/metromobility
"id": "met155613423",
"linkid": "metromobility",
"type": "Breach",
"date": "09/2019",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '15,000',
'industry': 'Transportation',
'location': 'Twin Cities',
'name': 'Metro Mobility',
'type': 'Transit Service'}],
'attack_vector': 'Email Account Hack',
'data_breach': {'number_of_records_exposed': '15,000',
'personally_identifiable_information': ['Rider Names',
'Pickup and Drop-off '
'Addresses'],
'sensitivity_of_data': 'Medium',
'type_of_data_compromised': ['Rider Names',
'Pickup and Drop-off Addresses',
'Times of Rides',
'Special Instructions for '
'Drivers']},
'date_detected': '2023-08-14',
'description': 'A data breach at Metro Mobility, the Twin Cities transit '
'service for people with disabilities, exposed the personal '
'information of up to 15,000 individuals. An unauthorized '
'person hacked an employee’s e-mail account, compromising '
'individual rider names, pickup and drop-off addresses, times '
'of rides, and special instructions for Metro Mobility '
'drivers. The breach occurred between June 13 and August 14.',
'impact': {'data_compromised': ['Rider Names',
'Pickup and Drop-off Addresses',
'Times of Rides',
'Special Instructions for Drivers']},
'threat_actor': 'Unauthorized Person',
'title': 'Data Breach at Metro Mobility',
'type': 'Data Breach',
'vulnerability_exploited': 'Compromised Email Account'}