Ransomware victim disclosure
← All victimsLiberty Lines Transit
listed as Liberty Lines · Claimed by Losttrust · listed 3 years ago
Status timeline
- ListedSep 26, 2023
- Data leakeddate unknown
At a glance
- Group
- Losttrust
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Sep 26, 2023
About the victim
AI dossier — public-source company profileLiberty Lines Transit is one of the largest privately owned transportation companies in New York State, providing local bus services throughout Westchester County on 59 routes in partnership with the Westchester County Department of Transportation. The company transports approximately 30 million passengers annually and covers over 10 million miles per year. It has grown from a 4-vehicle operation founded in 1953 through mergers and acquisitions.
- Industry
- Public Bus Transportation
- Address
- 475 Saw Mill River Road, Yonkers, NY 10701
- Founded
- 1953
Attack summary
Severity: high — Data has been confirmed as published (data_published status) by the threat actor against a public transit operator serving 30 million passengers annually, likely involving employee PII and potentially sensitive operational/infrastructure data for a critical public transportation service.The Losttrust ransomware group claims to have attacked Liberty Lines Transit and has published data, though no ransom amount or specific data volume was stated. The disclosed status indicates data has been published, suggesting exfiltration of company data.
Data the group says was taken
AI dossier — extracted from the leak post- Company operational data
- Employee records
- Transportation route information
- Business/financial documents
What the group claims
Since its meager beginnings in 1953 as a 4 vehicle operation, Liberty Lines has grown through merger and acquisition to become one of the largest privately owned transportation companies in New York State.
Sources
- Victim sitelibertylines.com
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

