According to a recent Freedom of Information request, local authorities in the UK report 10,000 attempted cyber-attacks every day. Most successful attacks on local authorities to date have been ransomware attacks on their enterprise (corporate IT) systems, with some incidents costing millions of pounds. However, as smart streets and smart cities systems become more widespread, an increasing number of cyber-attacks have targeted these cyber-physical systems. Few of these are published publicly due to a combination of national security concerns, a lack of regulatory obligation, embarrassment and fear of fallout. Those that are published are generally attacks where a security researcher was involved.

2020 Sheffield Clean Air Zone ANPR Data Leak

The best recent example is the 2020 compromise of Sheffield City Council’s Automatic Number Plate Recognition (ANPR) system used for their new clean air zone. Security researchers gained access to Sheffield’s ANPR management system, which provided access to 8.6 million driver records covering private journey data. The impact of this incident was limited by the fact security researchers quickly informed the council. However, evidence suggests similar attacks have also been carried out by malicious actors, as leaked data from UK authority ANPR systems has been found available on the dark web.

2020 Netherlands Cycling App to ITS Interface Compromise

Another 2020 smart streets system compromise happened in the Netherlands. Researchers hacked Dutch cycling apps that were connected into authorities’ traffic control systems. Using modified versions of the apps, they were able to trigger traffic lights remotely all across the Netherlands. The incident demonstrates that one of the major use cases proposed in this Manual for Smart Streets – integrating intelligent traffic systems (ITS) with third-party consumer apps – can provide an attack vector for malicious parties.

2021 Oldsmar Drinking Water Poisoning

Not all connected place cyber incidents have been benign, however. The City of Oldsmar, Florida (where water is a local authority service) made international headlines in 2021 after its drinking water was directly poisoned by a cyber-attack. A vulnerable remote maintenance portal of a SCADA system was used to inject significant amounts of lye into the publicly managed water supply.

Additional non-public incidents were discussed with the Manual for Smart Streets team during the development of this guidance. General feedback is that several cyber incidents have occurred where the cost of the cyber-attack on the connected place cyber-physical system has been greater than the cost savings from opting for “low security” solutions.

Other Recent Incidents

Between January 2021 and October 2022, the European Union Agency for Cybersecurity logged significant cyber incidents in the transport sector worldwide. A total of 24 significant cyber incidents were recorded in the road-transport sector, though this should be regarded as a non-exhaustive list. These are attacks are reported in the 2023 ENISA Transport Threat Landscape.

Noteable examples included:

Date Location Attack
August 2021 Sweden Skånetrafiken customer-facing systems were brought down, halting bus ticket sales.
September 2021 United States Tesla vehicle software leaked to attackers.
October 2021 France Major French transport operator had credentials, personal data and software source code leaked to attackers.
October 2021 Germany Mercedes-Benz vehicle software source code leaked to attackers.
December 2021 Iceland Major Icelandic transport operator had all sensitive employee data leaked including salaries, performance reports, criminal records, passports, shift schedules etc.
May 2022 Australia Transport for New South Wales had significant internal and personal data leaked. It was identified that the authority had not implemented local cyber security guidance.
May 2022 Czechia Directorate of Roads and Highways was targeted with a denial-of-service attack by Killnet, resulting in web-based services being disrupted.
July 2022 Latvia Russia-supporting hacking groups targeted Latvian government and public services including road and rail transport. Various systems such as ticketing, parking payment and traffic management were brought down by the attacks.
August 2022 Russia Hacktivist group Anonymous hacked the Yandex Taxi app and rerouted all taxis in order to cause traffic jams.
September 2022 United Kingdom Bus and driver scheduling software used by Go-Ahead was brought offline by a cyber-attack.
September 2022 United States Uber had data on their cyber security vulnerabilities leaked by an attacker.
September 2022 Russia Hacktivist group OneFist attacked the Novosibirsk City Transport Traffic Management System in retaliation for the Ukraine invasion. Buses, taxis, trams were stopped for days as a result. Attack was timed to be coordinated with other attacks on local telecoms infrastructure.