public transportation system, the Société de transport de Montréal (STM), has been hit by a ransomware attack by RansomExx, affecting services and online systems. On October 19, the STM experienced outages that affected its systems , website, and customer service.
While these outages did not affect the operation of buses or subway systems, people with disabilities who rely on the STM's door-to-door paratransit are affected, as it uses an online registration system.

Earlier this week, the STM announced that the outages were caused by a computer virus that significantly affected various platforms. Later, the Montreal public transport system confirmed that it had been attacked by ransomware, stressing that it was working with authorities and security to restore systems and investigate the attack. The official statement issued on the security incident stated the following: “The Société de transport de Montréal (STM) wishes to inform its customers that the outages that occurred on the afternoon of October 19th are the consequence of a type of ransomware, which targets all applications, despite the various defenses in place to mitigate and prevent such risks.”

In addition, the STM website is currently down, but visitors are redirected to www.lastm.info, where information about public transport and the attack is published.
A source familiar with the situation said that STM was attacked by RansomExx ransomware. This is a new variant of Defray777 ransomware that was observed last June, having carried out attacks against organizations such as the Texas Department of Transportation, Konica Minolta, IPG Photonics and Tyler Technologies.

As BleepingComputer reports, the RansomExx operators aim to compromise a network and steal unencrypted files . Once they gain access to the Windows domain controller , they deploy the ransomware to all devices on the network. At this time, it is not known whether STM has contacted the ransomware operators or negotiated a ransom payment.
