US Department of Transportation breach exposed data on 237,000 federal employees
- Organization
- U.S. Department of Transportation
- Exploit
- Hacking
- Industry
- Government
The US Department of Transportation notified Congress in May 2023 that a breach of its administrative systems had exposed personal information belonging to about 237,000 current and former federal employees. The department put the split at roughly 114,000 current employees and 123,000 former employees.
The affected system was TRANServe, which administers commuter transit benefits and reimburses federal employees for mass transit costs up to $280 a month. Because TRANServe serves agencies beyond the Transportation Department, the exposure reached federal workers well outside DOT, including congressional staff.
The department said the compromised records could include a benefit recipient's name, their agency, work email address, work phone number, work address, home address, SmarTrip card number and TRANServe card number. It described the incident as isolated to certain systems used for administrative functions and said it did not affect any transportation safety systems.
DOT froze access to the transit benefit system while it investigated. The department's Office of the Chief Information Officer led the work with support from the Cybersecurity and Infrastructure Security Agency, and credit monitoring was offered to affected current and former employees. No responsible party was publicly identified.