Skip to main content
Back to overview
High

Pittsburgh Regional Transit Confirms Ransomware Attack

Pittsburgh Regional Transit (PRT) announced on December 24, 2024, that what was initially thought to be a computer glitch affecting its light rail system had been confirmed as a ransomware attack.

Key points

  • Pittsburgh Regional Transit (PRT) confirmed a ransomware attack on December 24, 2024.
  • The incident began on December 19, 2024, affecting rail control systems.
  • PRT activated its Cyber Incident Response Team and involved law enforcement and cybersecurity experts.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Threat source not confirmed

03

Potential impact

Potential operational disruption

Availability

Published
Dec 24, 2024
Updated
Jul 1, 2026
Confidence
High
Evidence
1 source

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch ransomware, endpoint compromise and business interruption exposure.

Business impact

Potential operational disruption
Impact area
Availability

Mentioned entities

RideprtPittsburgh Regional Transit Confirms RansomwareAttack Pittsburgh Regional TransitPRTThursdayPittsburgh Regional Transit

Quick context

Questions about this signal

What happened in this signal?

Pittsburgh Regional Transit (PRT) announced on December 24, 2024, that what was initially thought to be a computer glitch affecting its light rail system had been confirmed as a ransomware attack. The incident began around 4:30 a.m. on the preceding Thursday (December 19, 2024), when computers at the rail control center lost the ability to show rail car locations. PRT launched an investigation, activated its Cyber Incident Response Team, notified law enforcement, and engaged third-party cybersecurity experts. At the time of the announcement, PRT did not believe personal rider information had been compromised.

When was this signal reported?

Shadow Tier lists Dec 24, 2024 as the signal date.

Which organization is connected to this signal?

Rideprt is the organization connected to this public signal.

Explore Rideprt
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents