Metrobus, the public transit operator in St. John’s, Newfoundland, is investigating a cybersecurity incident that knocked out its Automatic Vehicle Location system, the tracking layer behind live bus arrival information.
The agency said it found the intrusion on its internal network Tuesday and moved quickly to secure systems. Riders using apps and services fed by the location data may see missing or stale information, though buses kept running. Fare accounts look safe: Metrobus said mCard balances sit on a separate, externally hosted platform that is not believed to have been caught up in the event.
Details remain thin. The transit operator went public Friday afternoon, three days after detection, and declined to describe the intrusion further while investigators work. It also said it would contact employees or customers directly if the review turns up any impact on them.
Automatic vehicle location is standard connected-fleet plumbing. Onboard hardware reports each bus position over a wireless link so dispatchers and passenger apps can follow the vehicles, which makes the feed an attractive target for disruption. An outage ripples outward to every third-party app that consumes it.
Metrobus has not named a cause and no criminal group has claimed responsibility. Until the review closes, riders should treat arrival predictions as unreliable and lean on posted schedules.