09

Case history

Cyber incidents in transport do not stay digital for long.

Real incidents are the fastest way to explain why readiness matters. The pattern repeats across the sector: ticketing, passenger information, suppliers, and legacy systems all turn into service disruption.

Recurring patterns

What keeps showing up

Rail operators carry customer data, supplier dependency, operational technology, and public trust at the same time. Small judgment calls, a clicked link or an ignored anomaly, decide how far an incident spreads.

  • Third-party and supplier dependencies keep showing up in real transport incidents.
  • Passenger-facing systems may not be safety-critical, but they still create disruption, reputational damage, and operational workload.
  • Legacy radio and OT environments can stay exposed for years when authentication and segmentation lag behind.
  • Teams with credible manual fallback processes usually absorb impact better.

Tabletop prompts

Questions worth asking after every case

  1. 01Which services would we have to run manually for the first 24 hours if core systems were unavailable?
  2. 02Which suppliers or support tools could interrupt operations even if our own network stayed intact?
  3. 03How would we separate customer-information disruption from genuinely safety-critical degradation?
  4. 04Who needs to be told first when an incident affects service delivery, customer data, and public confidence at the same time?

Incident line

Seven incidents worth retelling

2017-2025
  1. 2017Shipping and logistics

    NotPetya at Maersk

    Impact
    Port and cargo operations were disrupted globally, and Maersk later said the incident could cost $250 million to $300 million.
    Why it matters
    A destructive IT event can become a transport operations crisis quickly, even when attackers never touch safety systems directly.
    Source: Reuters / FortuneRead the report
  2. 2022Rail IT systems

    Belarusian Railway disruption

    Impact
    Ticketing and internal railway systems were disrupted after activists said they had breached and encrypted systems to slow Russian troop movement.
    Why it matters
    Rail systems can become direct targets in broader geopolitical conflict, and customer-facing disruption may only be one part of the impact.
    Source: Railway TechnologyRead the report
  3. 2022Third-party compromise

    DSB supply-chain outage

    Impact
    A compromise at subcontractor Supeo led to several hours of train standstill in Denmark because drivers could not access a key support application.
    Why it matters
    A supplier issue can still stop the railway, even when core infrastructure is not the direct target.
    Source: Reuters / EuronewsRead the report
  4. 2023Legacy rail communications

    PKP radio stop-signal hack

    Impact
    More than 20 trains were halted in Poland after attackers abused an unauthenticated emergency radio-stop command.
    Why it matters
    Old signalling and radio assumptions can leave safety-adjacent systems exposed long after the weakness is publicly known.
    Source: WIREDRead the report
  5. 2024Urban transport platform

    Transport for London cyber incident

    Impact
    TfL detected a cyber incident on 1 September 2024 and only restored some customer functions, such as journey histories and refund features, in December.
    Why it matters
    Even when services keep running, recovery for customer systems, data handling, and public confidence can be long and resource-heavy.
    Source: Transport for LondonRead the report
  6. 2024Passenger-facing systems

    Network Rail station Wi-Fi incident

    Impact
    Wi-Fi at 19 major UK stations was suspended after an unauthorised change to a landing page pushed extremist content to passengers.
    Why it matters
    Systems that look peripheral can still create public alarm, reputational damage, and immediate operational overhead.
    Source: The Guardian / Network Rail statementRead the report
  7. 2025National rail IT services

    Ukrzaliznytsia cyberattack

    Impact
    Ukraine's state railway said a targeted cyberattack hit passenger and freight systems, forcing ticket sales back to stations and trains until services were partially restored.
    Why it matters
    Manual fallback, staffed counters, and resilient offline processes are not old-fashioned. They are part of continuity.
    Source: ReutersRead the report