LA Metro Hit by Ransomware, 153M Licenses for Sale, AI Breaches a Network in 10 Hours
LA Metro, the transit system that moves nearly 10 million people in Los Angeles, just appeared on a ransomware gang’s extortion site. A dark-web service is selling 153 million scanned driver’s licenses. And security researchers watched AI break into a company and steal the master keys in under 10 hours. Three stories, one uncomfortable pattern. *Cybercrime is now an industry, and speed is the whole game.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week’s stories for executives, owners, and operators who can’t follow every cyber headline but can’t afford to be blindsided. First up: LA Metro. A fast-growing ransomware crew called The Gentlemen posted the country’s second-busiest transit system to its leak site, claiming it stole internal data. Here’s what most coverage skips: this is a claim on a leak site, not a confirmed breach. There’s no ransom demand and no statement from the agency. Bryan explains how to read a scary headline without confusing an allegation for a fact. These crews choose targets based on how much disruption they can cause, and public infrastructure is squarely in their sights. If your business creates real-world chaos when it goes down, you fit the profile. Then Randy tackles the story that should worry every business that scans an ID. A service called Nexus appeared offering searchable access to more than 153 million driver’s licenses from the US and Canada. Investigative reporter Brian Krebs traced the data to an identity-verification vendor called IDScan.net. The FBI’s New Orleans office opened a case the same day, reportedly after finding IDs belonging to a US Defense Secretary and an FBI Assistant Director in the pile. The vendor runs 21 million ID checks a month for names like Hertz, Target, and FedEx, so a leak there becomes a problem for many other companies. If a business scanned your license, your photo and address may have passed through a vendor you never chose and can’t see. Reginald closes with the story that connects everything. Palo Alto Networks’ Unit 42 documented a real attack in which a person directed AI agents at a company and let them run the break-in. The agents mapped the network, raided passwords hidden in the company’s own code, and grabbed the master credentials in under 10 hours. That work would take a human team about two weeks. One boring control stopped them cold: a basic protection on the code pipeline blocked the backdoor. The lesson for owners is blunt. The fundamentals still work, but your window to catch an attack is now hours, not days. In this episode, we discuss: • A ransomware gang claims LA Metro, and how to tell a claim from a confirmed breach • A dark-web service selling 153 million driver’s licenses and the FBI probe into the vendor behind it • AI agents that breached a company and stole root access in under 10 hours • Why cybercrime now scales like a business, and why speed is the whole game • The internet-facing gear and hidden passwords attackers hit first • What to ask every vendor that touches your customers’ data Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #Ransomware #LAMetro #DataBreach #FBI #ArtificialIntelligence #VendorRisk #BusinessRisk #SMB #IdentityTheft #MSP