Skip to main content
FrontlinePrivacy
Address exposure

Rhysida ransomware group claimed a 2025 attack on the Maryland Transit Administration, exposing addresses and IDs

FILE 091Maryland2025-08-24
CLOSED

The Rhysida ransomware group claimed a 2025 attack on the Maryland Transit Administration and said it had stolen Social Security numbers, driver's license details, home addresses, and passport data tied to Maryland residents. The agency confirmed data loss. The state says it did not pay the ransom.

What reduces this risk

Maryland has a strong judicial-security law: the Judge Andrew F. Wilkinson Judicial Security Act (Md. Code Cts. & Jud. Proc. § 3-2301 et seq.), which lets judges, magistrates, and court commissioners demand removal of their home address and other personal details, with a 72-hour compliance window and remedies that include damages and attorney's fees. It does not cover officers, firefighters, EMS, or corrections staff, and Maryland has no equivalent broker-removal statute for them. Continuous broker removal is how those groups cover the exposure the judicial law leaves out.

Public sources