California Department of Transportation

Unauthorized users altered accessible pedestrian-signal audio in Palo Alto, Menlo Park and Redwood City in April 2025, replacing standard guidance with spoofed celebrity voices. Records later showed default passwords remained on devices; Caltrans disabled and restored audio and updated credentials.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Unauthorized access to systems, accounts, networks, or data.
Theft, exposure, or abuse of user or administrator credentials.
Data was intentionally changed, falsified, manipulated, or otherwise modified without authorization.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Transit, aviation, rail, maritime, logistics, fleet, traffic, ticketing, or related transportation operations were materially affected.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The disruption created or increased a risk to physical safety, public safety, patient safety, industrial safety, or safe operations.
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
Our reporting confirms with high confidence that unauthorized users accessed Caltrans-controlled accessible pedestrian signals using valid or default credentials. The event was a credential-related device takeover, not ransomware, and no named actor claim was located.
Altered audio replaced standard crossing guidance at intersections, creating an accessibility and safety concern. Caltrans disabled the audio feature during response, later restored it and changed credentials; local agencies and vendors added further protections.
The impacted municipalities are Palo Alto in Santa Clara County and Menlo Park and Redwood City in San Mateo County, California.
Confidence is high that unauthorized access and weak credential controls caused the audio manipulation because released Caltrans emails and manufacturer statements support that finding. No evidence of data theft, extortion or broader transportation-system compromise was located.
Caltrans records and local reporting documented the cyber mechanism and operational response, supporting organization-confirmed cyber and disruption transparency.
The incident is resolved because the audio feature was restored and credentials and security controls were changed.
The public record does not establish the perpetrators, exact access path for every device, number of intersections, duration at each location or whether any centralized system was accessed.

Menlo Park is a documented municipality with altered accessible pedestrian signals. This area link identifies the city where devices were affected; it does not assert citywide disruption.
Caltrans-controlled accessible pedestrian signals in Menlo Park were altered; the municipality anchors the affected device sites, without claiming all intersections were affected.
Palo Alto is a documented municipality with altered accessible pedestrian signals. This area link identifies the city where devices were affected; it does not assert citywide disruption.
Caltrans-controlled accessible pedestrian signals in Palo Alto were altered; the municipality anchors the affected device sites, without claiming all intersections were affected.
Redwood City is a documented municipality with altered accessible pedestrian signals. This area link identifies the city where devices were affected; it does not assert citywide disruption.
Caltrans-controlled accessible pedestrian signals in Redwood City were altered; the municipality anchors the affected device sites, without claiming all intersections were affected.
DysruptionHub reported released emails showing default passwords on altered pedestrian-signal devices in three cities.
Local agencies and vendors described credential and connectivity protections added after the incident.
Public-records reporting linked the device takeover to weak or default credentials.
Signed-in members can report an error, update, or missing source.