Southeast Vermont Transit’s MOOver division was listed on the BianLian ransomware group’s leak site on January 1, 2024. The transportation agency, which provides public transit services across southeastern Vermont, is claimed to have had internal files exfiltrated during a ransomware attack. Anyone who has used MOOver services, received invoices, or had personal information on file with the agency may now be at risk.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Southeast Vermont Transit (MOOver)
Get alerted the next time Southeast Vermont Transit (MOOver) files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Southeast Vermont Transit (MOOver)’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Listing
The BianLian leak site states that MOOver suffered a ransomware incident and that attackers successfully exfiltrated internal files. The listing does not disclose the number of records affected, the exact date of the intrusion, or the specific types of documents taken. It simply states that data was stolen and is now held by the group. The disclosure indicates the agency operates under the Southeast Vermont Transit umbrella and focuses on transportation services. No ransom demand amount or payment deadline appears in the public listing.
Why This Matters for You and Your Family
When a local transit agency loses control of internal files, the exposure often reaches beyond employees. Riders, vendors, and partners frequently appear in scheduling databases, billing records, maintenance logs, or customer service tickets. If your name, address, phone number, email, or payment details were ever shared with MOOver, those records could now sit in an attacker’s archive. Internal files exfiltrated in ransomware attack means the information is no longer protected by the agency’s normal security controls and can be used for identity theft, phishing, or sold on underground markets.
Ordinary families in Vermont and neighboring states rely on these services for daily commutes, medical appointments, and school transport. A breach at this level quietly increases the chance that someone can connect your travel patterns, contact information, and financial details into a single profile.