The Rhysida ransomware group claimed a 2025 attack on the Maryland Transit Administration and said it had stolen Social Security numbers, driver's license details, home addresses, and passport data tied to Maryland residents. The agency confirmed data loss. The state says it did not pay the ransom.
What happened
Maryland's Department of Transportation disclosed a cyberattack on August 24, 2025. It disrupted the Maryland Transit Administration's paratransit booking system and real-time bus tracking. The Rhysida ransomware group publicly claimed responsibility and listed the agency on its data-leak site.
Rhysida demanded 30 bitcoin, worth about $3.3 million at the time, and said it had stolen Social Security numbers, driver's license details, home addresses, passport information, and other legal documents tied to Maryland residents. The group posted sample document scans as proof. The agency confirmed incident-related data loss but said it could not share specifics during the investigation. As of October 2025, the state said it had not paid the ransom.
What was exposed
If Rhysida's claims hold up, the stolen data is the high-value kind: Social Security numbers, driver's licenses, home addresses, dates of birth, and passports. Those are the exact identifiers that drive identity theft and doxxing. A leaked home address paired with a full name and date of birth is enough to tie a person to where they live and to the people in the household.
Breached records do not stay in one place. Data brokers and people-search sites pull from public records, marketing files, and leaked datasets, so information dumped after a breach tends to resurface on broker pages over time.
What this means if you're on the job
Maryland residents whose data passed through MTA systems for any reason are in the exposed pool, and that can include officers, judges, EMTs, and corrections staff.
Maryland's judicial protection is real but narrow. The Judge Andrew F. Wilkinson Judicial Security Act (Md. Code Cts. & Jud. Proc. § 3-2301 et seq.) is named for a Washington County judge shot and killed outside his Hagerstown home in October 2023. It lets judges, magistrates, and court commissioners demand removal of their home address, phone number, and other personal details. Recipients have 72 hours to comply, and willful refusal can bring damages, attorney's fees, and punitive damages.
That law stops at the courthouse door. Rank-and-file officers, firefighters, EMS, and corrections staff are not covered, and Maryland has no equivalent statute forcing brokers to take their information down. The state's address confidentiality program is built for survivors of domestic violence and stalking, not for people whose job creates the risk.
Continuous broker removal is the option that covers the people the judicial law leaves out. Frontline Privacy scans the data broker and people-search sites where leaked identifiers resurface, files removal requests, and keeps checking so it can refile when your information comes back.
What reduces this risk
Maryland has a strong judicial-security law: the Judge Andrew F. Wilkinson Judicial Security Act (Md. Code Cts. & Jud. Proc. § 3-2301 et seq.), which lets judges, magistrates, and court commissioners demand removal of their home address and other personal details, with a 72-hour compliance window and remedies that include damages and attorney's fees. It does not cover officers, firefighters, EMS, or corrections staff, and Maryland has no equivalent broker-removal statute for them. Continuous broker removal is how those groups cover the exposure the judicial law leaves out.
Public sources
- Maryland Cyber Attack Interrupts Bus Tracking, Exposes Data — Government Technology, 2025-09-29
- Maryland Restores Services, Pays No Ransom After Attack — Government Technology, 2025-10-01