Company Details
nymta
20,625
111,022
4851
mta.info
0
MET_1782673
In-progress

Metropolitan Transportation Authority Company CyberSecurity Posture
mta.infoThe Metropolitan Transportation Authority is North America's largest transportation network, serving a population of 15.3 million people in the 5,000-square-mile area fanning out from New York City through Long Island, southeastern New York State, and Connecticut. The MTA comprises six agencies: MTA New York City Transit, MTA Bus Company, MTA Long Island Rail Road, MTA Metro-North Railroad, MTA Bridges and Tunnels, and MTA Construction & Development. The MTA network has the nation’s largest bus fleet and more subway and commuter rail cars than all other U.S. transit systems combined. It provides around 2.6 billion trips each year, accounting for about one-third of the nation’s mass transit users and two-thirds of its commuter rail passengers. MTA Bridges and Tunnels, which recorded a record 329 million crossings in 2019, carries more vehicles than any other bridge and tunnel authority in the nation. Interested in doing great work that impacts the lives of millions every day? Apply for a position today. You’ll not only have an opportunity to bring your skills to a mission in which you can take pride, you’ll enjoy first-class benefits including pension and 401(k) retirement savings plans, Wellness programs, Insurance plans, Healthcare plans, a generous vacation and leave package, and medical coverage for spouses, domestic partners, and dependents. The MTA’s provision of safe, clean, efficient public transportation is the lifeblood of the New York City area.
Company Details
nymta
20,625
111,022
4851
mta.info
0
MET_1782673
In-progress
Between 750 and 799

MTA Global Score (TPRM)XXXX

Description: The Metropolitan Transportation Authority, the biggest mass transit system in the country that transports millions of people everyday in and around New York City, had several of its computer systems compromised by hackers. The attack impacted three of the transit agency's 18 systems. The MTA required a password change as an extra security step for 3,700 users and transferred distant users to different VPNs as a precaution.


No incidents recorded for Metropolitan Transportation Authority in 2025.
No incidents recorded for Metropolitan Transportation Authority in 2025.
No incidents recorded for Metropolitan Transportation Authority in 2025.
MTA cyber incidents detection timeline including parent company and subsidiaries

The Metropolitan Transportation Authority is North America's largest transportation network, serving a population of 15.3 million people in the 5,000-square-mile area fanning out from New York City through Long Island, southeastern New York State, and Connecticut. The MTA comprises six agencies: MTA New York City Transit, MTA Bus Company, MTA Long Island Rail Road, MTA Metro-North Railroad, MTA Bridges and Tunnels, and MTA Construction & Development. The MTA network has the nation’s largest bus fleet and more subway and commuter rail cars than all other U.S. transit systems combined. It provides around 2.6 billion trips each year, accounting for about one-third of the nation’s mass transit users and two-thirds of its commuter rail passengers. MTA Bridges and Tunnels, which recorded a record 329 million crossings in 2019, carries more vehicles than any other bridge and tunnel authority in the nation. Interested in doing great work that impacts the lives of millions every day? Apply for a position today. You’ll not only have an opportunity to bring your skills to a mission in which you can take pride, you’ll enjoy first-class benefits including pension and 401(k) retirement savings plans, Wellness programs, Insurance plans, Healthcare plans, a generous vacation and leave package, and medical coverage for spouses, domestic partners, and dependents. The MTA’s provision of safe, clean, efficient public transportation is the lifeblood of the New York City area.

🗺 Transdev is a leading public transport company, delivering high quality transportation services around the world. We offer integrated & multimodal mobility solutions that contribute to the development of territories & the well-being of their inhabitants. Our teams use our wealth of local knowledg

The RATP Group is the world's third largest public transport company, carrying 12 million people every day in France and around the world. It boasts unrivalled experience in design, project management, operation and maintenance of all types of urban and suburban transport, making it an industry lead
.png)
A judge has blocked the Trump administration from withholding nearly $34M in funding earmarked to protect NYC's transit system from...
Photo – Metropolitan Transportation Authority. MTA Security Grants in Peril due to Federal Cuts. Governor Kathy Hochul has criticized the...
Maryland officials say no ransom was paid and services have been fully restored in the wake of a ransomware attack that exposed personal...
The grant dollars are intended to prevent and respond to terrorist threats in transit.
The Maryland Transit Administration recently confirmed that a cyberattack has resulted in "incident-related data loss."
Maryland Transit Administration's Mobility Link service is back in operation after a cyberattack last month. On Aug. 24, the MTA said it was...
MTA said data was compromised in a cybersecurity breach that targeted some of its systems, according to state officials.
BALTIMORE, MD—The Maryland Transit Administration has provided an update on the cybersecurity incident affecting Mobility reservations and...
The Maryland Transit Administration announced Friday an emergency transportation service for riders with mobility devices.

Explore insights on cybersecurity incidents, risk posture, and Rankiteo's assessments.
The official website of Metropolitan Transportation Authority is https://new.mta.info/.
According to Rankiteo, Metropolitan Transportation Authority’s AI-generated cybersecurity score is 776, reflecting their Fair security posture.
According to Rankiteo, Metropolitan Transportation Authority currently holds 0 security badges, indicating that no recognized compliance certifications are currently verified for the organization.
According to Rankiteo, Metropolitan Transportation Authority is not certified under SOC 2 Type 1.
According to Rankiteo, Metropolitan Transportation Authority does not hold a SOC 2 Type 2 certification.
According to Rankiteo, Metropolitan Transportation Authority is not listed as GDPR compliant.
According to Rankiteo, Metropolitan Transportation Authority does not currently maintain PCI DSS compliance.
According to Rankiteo, Metropolitan Transportation Authority is not compliant with HIPAA regulations.
According to Rankiteo,Metropolitan Transportation Authority is not certified under ISO 27001, indicating the absence of a formally recognized information security management framework.
Metropolitan Transportation Authority operates primarily in the Urban Transit Services industry.
Metropolitan Transportation Authority employs approximately 20,625 people worldwide.
Metropolitan Transportation Authority presently has no subsidiaries across any sectors.
Metropolitan Transportation Authority’s official LinkedIn profile has approximately 111,022 followers.
Metropolitan Transportation Authority is classified under the NAICS code 4851, which corresponds to Urban Transit Systems.
No, Metropolitan Transportation Authority does not have a profile on Crunchbase.
Yes, Metropolitan Transportation Authority maintains an official LinkedIn profile, which is actively utilized for branding and talent engagement, which can be accessed here: https://www.linkedin.com/company/nymta.
As of December 05, 2025, Rankiteo reports that Metropolitan Transportation Authority has experienced 1 cybersecurity incidents.
Metropolitan Transportation Authority has an estimated 78 peer or competitor companies worldwide.
Incident Types: The types of cybersecurity incidents that have occurred include Cyber Attack.
Detection and Response: The company detects and responds to cybersecurity incidents through an containment measures with password change for 3,700 users, containment measures with transfer of distant users to different vpns..
Title: MTA Cyber Attack
Description: The Metropolitan Transportation Authority, the biggest mass transit system in the country that transports millions of people everyday in and around New York City, had several of its computer systems compromised by hackers.
Type: Cyber Attack
Common Attack Types: The most common types of attacks the company has faced is Cyber Attack.

Systems Affected: 3 out of 18 systems

Entity Name: Metropolitan Transportation Authority
Entity Type: Government Agency
Industry: Transportation
Location: New York City

Containment Measures: Password change for 3,700 usersTransfer of distant users to different VPNs
Handling of PII Incidents: The company handles incidents involving personally identifiable information (PII) through by password change for 3,700 users, transfer of distant users to different vpns and .
Most Significant System Affected: The most significant system affected in an incident was 3 out of 18 systems.
Containment Measures in Most Recent Incident: The containment measures taken in the most recent incident were Password change for 3 and700 usersTransfer of distant users to different VPNs.
.png)
Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.0.3, Function api.ParseJSONRequest currently splits (via a call to strings.Split) an optionally-provided OID (which is untrusted data) on periods. Similarly, function api.getContentType splits the Content-Type header (which is also untrusted data) on an application string. As a result, in the face of a malicious request with either an excessively long OID in the payload containing many period characters or a malformed Content-Type header, a call to api.ParseJSONRequest or api.getContentType incurs allocations of O(n) bytes (where n stands for the length of the function's argument). This vulnerability is fixed in 2.0.3.
Monkeytype is a minimalistic and customizable typing test. In 25.49.0 and earlier, there is improper handling of user input which allows an attacker to execute malicious javascript on anyone viewing a malicious quote submission. quote.text and quote.source are user input, and they're inserted straight into the DOM. If they contain HTML tags, they will be rendered (after some escaping using quotes and textarea tags).
SysReptor is a fully customizable pentest reporting platform. Prior to 2025.102, there is a Stored Cross-Site Scripting (XSS) vulnerability allows authenticated users to execute malicious JavaScript in the context of other logged-in users by uploading malicious JavaScript files in the web UI. This vulnerability is fixed in 2025.102.
Taiko Alethia is an Ethereum-equivalent, permissionless, based rollup designed to scale Ethereum without compromising its fundamental properties. In 2.3.1 and earlier, TaikoInbox._verifyBatches (packages/protocol/contracts/layer1/based/TaikoInbox.sol:627-678) advanced the local tid to whatever transition matched the current blockHash before knowing whether that batch would actually be verified. When the loop later broke (e.g., cooldown window not yet passed or transition invalidated), the function still wrote that newer tid into batches[lastVerifiedBatchId].verifiedTransitionId after decrementing batchId. Result: the last verified batch could end up pointing at a transition index from the next batch (often zeroed), corrupting the verified chain pointer.
A flaw has been found in youlaitech youlai-mall 1.0.0/2.0.0. Affected is the function getById/updateAddress/deleteAddress of the file /mall-ums/app-api/v1/addresses/. Executing manipulation can lead to improper control of dynamically-identified variables. The attack can be executed remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Get company history
Every week, Rankiteo analyzes billions of signals to give organizations a sharper, faster view of emerging risks. With deeper, more actionable intelligence at their fingertips, security teams can outpace threat actors, respond instantly to Zero-Day attacks, and dramatically shrink their risk exposure window.
Identify exposed access points, detect misconfigured SSL certificates, and uncover vulnerabilities across the network infrastructure.
Gain visibility into the software components used within an organization to detect vulnerabilities, manage risk, and ensure supply chain security.
Monitor and manage all IT assets and their configurations to ensure accurate, real-time visibility across the company's technology environment.
Leverage real-time insights on active threats, malware campaigns, and emerging vulnerabilities to proactively defend against evolving cyberattacks.