Skip to content

Caltrans crosswalk audio credential hack

Summary

California Department of Transportation logo

Unauthorized users altered accessible pedestrian-signal audio in Palo Alto, Menlo Park and Redwood City in April 2025, replacing standard guidance with spoofed celebrity voices. Records later showed default passwords remained on devices; Caltrans disabled and restored audio and updated credentials.

Key facts

Timeline

  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

Data impacts

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Transportation operations disrupted

    Transit, aviation, rail, maritime, logistics, fleet, traffic, ticketing, or related transportation operations were materially affected.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

  • Safety risk or operational hazard

    The disruption created or increased a risk to physical safety, public safety, patient safety, industrial safety, or safe operations.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

Our reporting confirms with high confidence that unauthorized users accessed Caltrans-controlled accessible pedestrian signals using valid or default credentials. The event was a credential-related device takeover, not ransomware, and no named actor claim was located.

Operational significance

Altered audio replaced standard crossing guidance at intersections, creating an accessibility and safety concern. Caltrans disabled the audio feature during response, later restored it and changed credentials; local agencies and vendors added further protections.

The impacted municipalities are Palo Alto in Santa Clara County and Menlo Park and Redwood City in San Mateo County, California.

Confidence and uncertainty

Confidence is high that unauthorized access and weak credential controls caused the audio manipulation because released Caltrans emails and manufacturer statements support that finding. No evidence of data theft, extortion or broader transportation-system compromise was located.

Disclosure posture

Caltrans records and local reporting documented the cyber mechanism and operational response, supporting organization-confirmed cyber and disruption transparency.

Current status

The incident is resolved because the audio feature was restored and credentials and security controls were changed.

Analytic gaps

The public record does not establish the perpetrators, exact access path for every device, number of intersections, duration at each location or whether any centralized system was accessed.

Organizations involved

Impacted locations

  • Menlo Park, California

    Menlo Park is a documented municipality with altered accessible pedestrian signals. This area link identifies the city where devices were affected; it does not assert citywide disruption.

    Caltrans-controlled accessible pedestrian signals in Menlo Park were altered; the municipality anchors the affected device sites, without claiming all intersections were affected.

  • Palo Alto, California

    Palo Alto is a documented municipality with altered accessible pedestrian signals. This area link identifies the city where devices were affected; it does not assert citywide disruption.

    Caltrans-controlled accessible pedestrian signals in Palo Alto were altered; the municipality anchors the affected device sites, without claiming all intersections were affected.

  • Redwood City, California

    Redwood City is a documented municipality with altered accessible pedestrian signals. This area link identifies the city where devices were affected; it does not assert citywide disruption.

    Caltrans-controlled accessible pedestrian signals in Redwood City were altered; the municipality anchors the affected device sites, without claiming all intersections were affected.

Sources

Caltrans crosswalk audio hack tied to default passwords

DysruptionHub reported released emails showing default passwords on altered pedestrian-signal devices in three cities.

Cities say they fixed vulnerability behind crosswalk voices

Local agencies and vendors described credential and connectivity protections added after the incident.

Crosswalk signals were hacked because of a weak password

Public-records reporting linked the device takeover to weak or default credentials.

See something that needs correction?

Signed-in members can report an error, update, or missing source.