{"id":54974,"date":"2024-01-03T14:26:34","date_gmt":"2024-01-03T14:26:34","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/35354\/How-A-Group-Of-Train-Hackers-Exposed-A-Right-To-Repair-Nightmare.html"},"modified":"2024-01-03T14:26:34","modified_gmt":"2024-01-03T14:26:34","slug":"how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\/","title":{"rendered":"How A Group Of Train Hackers Exposed A Right-To-Repair Nightmare"},"content":{"rendered":"<p class=\"sc-77igqf-0 fnnahv\">Earlier this month, Polish hackers known as Dragon Sector accused one of Poland\u2019s largest train makers, Newag, of intentionally <span><a class=\"sc-1out364-0 dPMosf sc-145m8ut-0 jCErAQ js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;Internal link&quot;,&quot;https:\/\/gizmodo.com\/hackers-hit-with-legal-threats-after-they-fixed-a-brick-1851097424&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/gizmodo.com\/hackers-hit-with-legal-threats-after-they-fixed-a-brick-1851097424\">bricking its own trains <\/a><\/span>when they\u2019re repaired by third parties. Newag threatened to sue Dragon Sector, but the story exploded as an example of why we deserve the right-to-repair and the company is <span><a class=\"sc-1out364-0 dPMosf sc-145m8ut-0 jCErAQ js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;Internal link&quot;,&quot;https:\/\/gizmodo.com\/polish-train-shutdown-hackers-prime-minister-repair-1851111884&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/gizmodo.com\/polish-train-shutdown-hackers-prime-minister-repair-1851111884\">facing an investigation<\/a><\/span> from the Polish Office of Competition and Consumer Protection (UOKIK). On Wednesday, the Polish hackers went on the offensive, telling Newag, \u201cWe\u2019ll see you in court,\u201d on the stage of a conference, and described how Dragon Sector reverse engineered a train.<\/p>\n<div class=\"sc-1needdh-1 czxCOT\">\n<div class=\"sc-1needdh-0 jLsF instream-native-video instream-permalink instream-native-video--mobile\">\n<div class=\"sc-1h0epat-0 jiQRXG\">\n<div class=\"sc-1wkneyl-4 kDKXjm video-html5-playlist\" data-playlist=\"196254,196247,196223\" data-current=\"196254\">\n<div class=\"sc-1wkneyl-0 hAZDOz video-html5-loaded\">\n<div class=\"sc-1wkneyl-1 jShsAa video-html5-player\">\n<div class=\"sc-lhhce6-0 biVjcq video-html5 autoplay muted mobile\" data-video-id=\"196254\" data-monetizable=\"true\" data-position=\"sidebar\" data-video-title=\"Let\u2019s Eat a Chocolate Xbox Controller\" data-video-blog-id=\"4\" data-video-network=\"gizmodo\" data-video-duration=\"405\" readability=\"4.4070796460177\">\n<div class=\"sc-lhhce6-2 emBeiF video-top-bar\" readability=\"7\">\n<p>Let\u2019s Eat a Chocolate Xbox Controller<\/p>\n<\/div>\n<p><video disablepictureinpicture muted playsinline width=\"100%\" height=\"100%\" crossorigin=\"anonymous\" preload=\"none\"><source data-src=\"https:\/\/vid.kinja.com\/prod\/196254\/196254_240p.mp4\" label=\"240p\" type=\"video\/mp4\"><source data-src=\"https:\/\/vid.kinja.com\/prod\/196254\/196254_480p.mp4\" label=\"480p\" type=\"video\/mp4\"><source data-src=\"https:\/\/vid.kinja.com\/prod\/196254\/196254_720p.mp4\" label=\"720p\" type=\"video\/mp4\"><source data-src=\"https:\/\/vid.kinja.com\/prod\/196254\/196254_1080p.mp4\" label=\"1080p\" type=\"video\/mp4\"><track kind=\"captions\" label=\"English\" src=\"https:\/\/kinja.com\/api\/videoupload\/caption\/21802.vtt\" srclang=\"en\"><\/video><\/p>\n<div class=\"sc-1yhvqfu-3 ghtqRH video-controls\">\n<div class=\"sc-1yhvqfu-2 elBHkL\">\n<div class=\"sc-1sfctwm-2 fXTnmP closed-captions-box hide\">\n<div class=\"sc-1sfctwm-1 jglhFk\">\n<div class=\"sc-1sfctwm-0 hbyQRD\">\n<ul>\n<li class=\"selected\" data-label>Off<\/li>\n<li class data-label=\"English\">English<\/li>\n<\/ul>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<p class=\"sc-77igqf-0 fnnahv\">\u201cWe\u2019re 100% sure we were in the right,\u201d said Sergiusz Baza\u0144ski, a member of Dragon Sector at a <span><a class=\"sc-1out364-0 dPMosf sc-145m8ut-0 jCErAQ js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/media.ccc.de\/v\/37c3-12142-breaking_drm_in_polish_trains#t=3269&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/media.ccc.de\/v\/37c3-12142-breaking_drm_in_polish_trains#t=3269\" target=\"_blank\" rel=\"noopener noreferrer\">German cybersecurity conference<\/a><\/span>. \u201cWe\u2019re 100% sure we were acting in the public interest. It\u2019s Newag that should be scared, not us.\u201d<\/p>\n<div class=\"sc-17kx9cd-5 kDVAgq js_ad-mobile-dynamic js_ad-dynamic ad-mobile-dynamic\">\n<div class=\"sc-17kx9cd-4 bNalPz ad-unit ad-mobile\">\n<p>Advertisement<\/p>\n<\/div>\n<\/div>\n<p class=\"sc-77igqf-0 fnnahv\">Dragon Sector was hired by a repair workshop that was stumped by several Newag trains that wouldn\u2019t start. The hackers quickly found anticompetitive behavior ingrained in the code of Newag trains and went to Polish authorities with the case in 2022. Dragon Sector says in two instances, Newag had written code that would cause a train to fail if it was at a competitor\u2019s workshop. After a year of not seeing much progress with the authorities, the train hackers decided to go public.<\/p>\n<div class=\"sc-17kx9cd-5 kDVAgq js_ad-mobile-dynamic js_ad-dynamic ad-mobile-dynamic\">\n<div class=\"sc-17kx9cd-4 bNalPz ad-unit ad-mobile\">\n<p>Advertisement<\/p>\n<\/div>\n<\/div>\n<figure class=\"sc-1eow4w5-1 rlnFM align--center js_lazy-image js_marquee-assetfigure\" data-id=\"342f5078057bf144a929ea8ace56344e\" data-recommend-id=\"image:\/\/342f5078057bf144a929ea8ace56344e\" data-format=\"jpg\" data-width=\"6000\" data-height=\"3375\" data-lightbox=\"true\" data-recommended=\"false\" data-hide=\"false\" contenteditable=\"false\" draggable=\"false\" readability=\"1\">\n<div class=\"sc-1eow4w5-2 fDJNBs has-data img-wrapper\" contenteditable=\"false\" data-link-reference data-link-target data-syndicationrights=\"true\" data-imagerights=\"shutterstock\" data-hide=\"false\" data-hidecredit=\"false\" readability=\"7\"><span class=\"sc-1eow4w5-0 knmQPh js_lightbox-wrapper\"><\/p>\n<div class=\"sc-1eow4w5-3 hGpdBg\"><picture class=\"sc-epkw7d-0 diKDHf lazy-picture\"><source media=\"(max-width: 37.31em)\" type=\"image\/jpeg\" srcset=\"https:\/\/i.kinja-img.com\/image\/upload\/c_fit,q_60,w_645\/342f5078057bf144a929ea8ace56344e.jpg\"><source media=\"(min-width: 37.37em)\" type=\"image\/jpeg\" srcset=\"https:\/\/i.kinja-img.com\/image\/upload\/c_fit,q_60,w_645\/342f5078057bf144a929ea8ace56344e.jpg\"><img decoding=\"async\" alt=\"Image for article titled How a Group of Train Hackers Exposed a Right-to-Repair Nightmare\" data-chomp-id=\"342f5078057bf144a929ea8ace56344e\" data-format=\"jpg\" data-alt=\"Image for article titled How a Group of Train Hackers Exposed a Right-to-Repair Nightmare\" data-anim-src src=\"https:\/\/i.kinja-img.com\/image\/upload\/c_fit,q_60,w_645\/342f5078057bf144a929ea8ace56344e.jpg\"><\/picture><\/div>\n<p><\/span><\/p>\n<p><figcaption class=\"sc-7s1ndr-0 fPOdhF no-caption\">Photo<!-- -->: <!-- -->Martyn Jandula<!-- --> (<!-- -->Shutterstock<!-- -->)<\/figcaption><\/p>\n<\/div>\n<p><span data-id=\"342f5078057bf144a929ea8ace56344e\" data-recommend-id=\"image:\/\/342f5078057bf144a929ea8ace56344e\" data-format=\"jpg\" data-width=\"6000\" data-height=\"3375\" data-lightbox=\"true\" data-recommended=\"false\" data-hide=\"false\" class=\"js_recommend\"><\/span><\/figure>\n<div class=\"sc-17kx9cd-5 kDVAgq js_ad-mobile-dynamic js_ad-dynamic ad-mobile-dynamic\">\n<div class=\"sc-17kx9cd-4 bNalPz ad-unit ad-mobile\">\n<p>Advertisement<\/p>\n<\/div>\n<\/div>\n<p class=\"sc-77igqf-0 fnnahv\">Dragon Sector was given just a week to unbrick the trains, because the train operator who hired them had so many broken trains it was causing severe service issues. After that, the operator said they would send the trains back to Newag for more expensive servicing (Newag assured them they could fix this issue). <\/p>\n<p class=\"sc-77igqf-0 fnnahv\">Hackers found the bricks by comparing the code of working trains to bricked trains using an algorithm. Dragon Sector found Newag trains were triggered to lock up when reaching geofenced coordinates, sitting still for 10 days, or in one case, a train would simply lock up every year on December 21st. If any of the triggers were met, the train computer\u2019s NVRAM (a memory system) would flip certain bits to zero, putting a gate on the train\u2019s throttle and locking the train from moving. Dragon Sector analyzed 30 Newag trains, and 24 of them had locks, many of them with various triggers and locking mechanisms.<\/p>\n<div class=\"sc-17kx9cd-5 kDVAgq js_ad-mobile-dynamic js_ad-dynamic ad-mobile-dynamic\">\n<div class=\"sc-17kx9cd-4 bNalPz ad-unit ad-mobile\">\n<p>Advertisement<\/p>\n<\/div>\n<\/div>\n<figure class=\"sc-1eow4w5-1 rlnFM align--center js_lazy-image js_marquee-assetfigure\" data-id=\"f5a5f83641bc2f039ba9900f5241dfc6\" data-recommend-id=\"image:\/\/f5a5f83641bc2f039ba9900f5241dfc6\" data-format=\"png\" data-width=\"738\" data-height=\"408\" data-lightbox=\"true\" data-recommended=\"false\" data-hide=\"false\" contenteditable=\"false\" draggable=\"false\" readability=\"1.5\">\n<div class=\"sc-1eow4w5-2 fDJNBs has-data img-wrapper\" contenteditable=\"false\" data-link-reference data-link-target data-syndicationrights=\"false\" data-imagerights=\"other-license\" data-hide=\"false\" data-hidecredit=\"false\" readability=\"8\"><span class=\"sc-1eow4w5-0 knmQPh js_lightbox-wrapper\"><\/p>\n<div class=\"sc-1eow4w5-3 hGpdBg\"><picture class=\"sc-epkw7d-0 diKDHf lazy-picture\"><source media=\"(max-width: 37.31em)\" type=\"image\/jpeg\" srcset=\"https:\/\/i.kinja-img.com\/image\/upload\/c_fit,q_60,w_645\/f5a5f83641bc2f039ba9900f5241dfc6.jpg\"><source media=\"(min-width: 37.37em)\" type=\"image\/jpeg\" srcset=\"https:\/\/i.kinja-img.com\/image\/upload\/c_fit,q_60,w_645\/f5a5f83641bc2f039ba9900f5241dfc6.jpg\"><img decoding=\"async\" alt=\"A slide from Dragon Sector\u2019s presentation detailing Newag\u2019s bricking mechanism.\" data-chomp-id=\"f5a5f83641bc2f039ba9900f5241dfc6\" data-format=\"png\" data-alt=\"A slide from Dragon Sector\u2019s presentation detailing Newag\u2019s bricking mechanism.\" data-anim-src src=\"https:\/\/i.kinja-img.com\/image\/upload\/c_fit,q_60,w_645\/f5a5f83641bc2f039ba9900f5241dfc6.jpg\"><\/picture><\/div>\n<p><\/span><\/p>\n<p><figcaption class=\"sc-1ptbguh-0 dHvBHx caption\">A slide from Dragon Sector\u2019s presentation detailing Newag\u2019s bricking mechanism.<\/figcaption><figcaption class=\"sc-7s1ndr-0 fPOdhF has-caption\">Image<!-- -->: <!-- -->Dragon Sector<\/figcaption><\/p>\n<\/div>\n<p><span data-id=\"f5a5f83641bc2f039ba9900f5241dfc6\" data-recommend-id=\"image:\/\/f5a5f83641bc2f039ba9900f5241dfc6\" data-format=\"png\" data-width=\"738\" data-height=\"408\" data-lightbox=\"true\" data-recommended=\"false\" data-hide=\"false\" class=\"js_recommend\"><\/span><\/figure>\n<p class=\"sc-77igqf-0 fnnahv\">\u201cWe didn\u2019t intend to become whistleblowers,\u201d said Baza\u0144ski in an interview with Gizmodo. \u201cI wanted things to start moving forward because what Newag seems to have done is \u2018not cool\u2019 to put it lightly.\u201d<\/p>\n<div class=\"sc-17kx9cd-5 kDVAgq js_ad-mobile-dynamic js_ad-dynamic ad-mobile-dynamic\">\n<div class=\"sc-17kx9cd-4 bNalPz ad-unit ad-mobile\">\n<p>Advertisement<\/p>\n<\/div>\n<\/div>\n<p class=\"sc-77igqf-0 fnnahv\">Dragon Sector has put Newag\u2019s anticompetitive practices regarding repairs on an international stage. Typically, the right-to-repair movement focuses on manufacturers of small electronic devices, like smartphones and computers. In traditional bricking, manufacturers input software or hardware that makes it difficult for third parties to make repairs, so consumers are forced to pay expensive repair fees to the original company. Newag denies allegations that it has inserted locking mechanisms in its trains, but several Polish train operators have corroborated Dragon Sector\u2019s allegations.<\/p>\n<p class=\"sc-77igqf-0 fnnahv\">A train operator out of Warsaw, SKM Warszawa, told Gizmodo it recorded one case of a Newag train with a locking mechanism, that corresponds to Dragon Sector\u2019s story. Last week, another Polish train operator, Polregio, told the publication <span><a class=\"sc-1out364-0 dPMosf sc-145m8ut-0 jCErAQ js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/wiadomosci.onet.pl\/kraj\/skandal-na-kolei-pociag-newagu-stanal-bo-znowu-nadszedl-21-grudnia\/41mdspf&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/wiadomosci.onet.pl\/kraj\/skandal-na-kolei-pociag-newagu-stanal-bo-znowu-nadszedl-21-grudnia\/41mdspf\" target=\"_blank\" rel=\"noopener noreferrer\">Onet<\/a><\/span>, that its Newag trains were still failing to start due to blocks that align with Dragon Sector\u2019s allegations.<\/p>\n<div class=\"sc-17kx9cd-5 kDVAgq js_ad-mobile-dynamic js_ad-dynamic ad-mobile-dynamic\">\n<div class=\"sc-17kx9cd-4 bNalPz ad-unit ad-mobile\">\n<p>Advertisement<\/p>\n<\/div>\n<\/div>\n<p class=\"sc-77igqf-0 fnnahv\">Newag published a <span><a class=\"sc-1out364-0 dPMosf sc-145m8ut-0 jCErAQ js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/web.archive.org\/web\/20231219135852\/https:\/\/www.newag.pl\/wp-content\/uploads\/2023\/12\/Biala-ksiega_chronologia.pdf&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/web.archive.org\/web\/20231219135852\/https:\/\/www.newag.pl\/wp-content\/uploads\/2023\/12\/Biala-ksiega_chronologia.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">paper<\/a><\/span> denying Dragon Sector\u2019s claims on Dec. 19th, but it has since been <span><a class=\"sc-1out364-0 dPMosf sc-145m8ut-0 jCErAQ js_link\" data-ga=\"[[&quot;Embedded Url&quot;,&quot;External link&quot;,&quot;https:\/\/www.newag.pl\/wp-content\/uploads\/2023\/12\/Biala-ksiega_chronologia.pdf&quot;,{&quot;metric25&quot;:1}]]\" href=\"https:\/\/www.newag.pl\/wp-content\/uploads\/2023\/12\/Biala-ksiega_chronologia.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">removed<\/a><\/span> from its website. In that paper, Newag claims that competing workshops and Dragon Sector don\u2019t have the proper \u201clicense\u201d to work on its train\u2019s software. Dragon Sector, however, says they are authorized users of the train software because they were hired under contract by an authorized train workshop. They\u2019ve never heard of the licenses Newag alleges.<\/p>\n<p class=\"sc-77igqf-0 fnnahv\">Even if the licenses are real, their existence is at odds with the right-to-repair movement. Requiring operators and workshops to obtain a separate license to repair trains, not included in the sale of the train, is unusual altogether. A more traditional system is New York City\u2019s flagship subway operator, the Metropolitan Transportation Authority. The MTA told Gizmodo that after a two-year warranty, the city\u2019s workshops are allowed to conduct regular maintenance and repairs on subway cars.<\/p>\n<div class=\"sc-17kx9cd-5 kDVAgq js_ad-mobile-dynamic js_ad-dynamic ad-mobile-dynamic\">\n<div class=\"sc-17kx9cd-4 bNalPz ad-unit ad-mobile\">\n<p>Advertisement<\/p>\n<\/div>\n<\/div>\n<p class=\"sc-77igqf-0 fnnahv\">In the same paper, Newag alleges that vehicle repairs are a \u201csmall fraction of Newag\u2019s business,\u201d which it estimates at roughly 5%. Newag confirmed this figure to Gizmodo independently. In the manufacturer\u2019s financial statements, vehicle repairs fall under the category of \u201crepairs and modernizations,\u201d which represented nearly 20% of its total revenue for the first nine month of 2022, and roughly 60% in 2023. \u201cRepairs and modernizations\u201d represent a significant portion of the company\u2019s total revenue, but a Newag spokesperson told Gizmodo this section \u201cincludes a much larger volume of services\u201d than just repairs. They went on to stand by the claim that repairs make up about 5% of revenue.<\/p>\n<figure class=\"sc-1eow4w5-1 rlnFM align--center js_lazy-image js_marquee-assetfigure\" data-id=\"c36a6ab463a437507fdd7100763e50d6\" data-recommend-id=\"image:\/\/c36a6ab463a437507fdd7100763e50d6\" data-format=\"jpg\" data-width=\"845\" data-height=\"402\" data-lightbox=\"true\" data-recommended=\"false\" data-hide=\"false\" contenteditable=\"false\" draggable=\"false\" readability=\"1\">\n<div class=\"sc-1eow4w5-2 fDJNBs has-data img-wrapper\" contenteditable=\"false\" data-link-reference data-link-target data-syndicationrights=\"false\" data-imagerights=\"other-license\" data-hide=\"false\" data-hidecredit=\"false\" readability=\"7\"><span class=\"sc-1eow4w5-0 knmQPh js_lightbox-wrapper\"><\/p>\n<div class=\"sc-1eow4w5-3 hGpdBg\"><picture class=\"sc-epkw7d-0 diKDHf lazy-picture\"><source media=\"(max-width: 37.31em)\" type=\"image\/jpeg\" srcset=\"https:\/\/i.kinja-img.com\/image\/upload\/c_fit,q_60,w_645\/c36a6ab463a437507fdd7100763e50d6.jpg\"><source media=\"(min-width: 37.37em)\" type=\"image\/jpeg\" srcset=\"https:\/\/i.kinja-img.com\/image\/upload\/c_fit,q_60,w_645\/c36a6ab463a437507fdd7100763e50d6.jpg\"><img decoding=\"async\" alt=\"Newag\u2019s recent financial statement shared with Gizmodo by an analyst.\" data-chomp-id=\"c36a6ab463a437507fdd7100763e50d6\" data-format=\"jpg\" data-alt=\"Newag\u2019s recent financial statement shared with Gizmodo by an analyst.\" data-anim-src src=\"https:\/\/i.kinja-img.com\/image\/upload\/c_fit,q_60,w_645\/c36a6ab463a437507fdd7100763e50d6.jpg\"><\/picture><\/div>\n<p><\/span><\/p>\n<p><figcaption class=\"sc-1ptbguh-0 dHvBHx caption\">Newag\u2019s recent financial statement shared with Gizmodo by an analyst.<\/figcaption><figcaption class=\"sc-7s1ndr-0 fPOdhF has-caption\">Image<!-- -->: <!-- -->Newag<\/figcaption><\/p>\n<\/div>\n<p><span data-id=\"c36a6ab463a437507fdd7100763e50d6\" data-recommend-id=\"image:\/\/c36a6ab463a437507fdd7100763e50d6\" data-format=\"jpg\" data-width=\"845\" data-height=\"402\" data-lightbox=\"true\" data-recommended=\"false\" data-hide=\"false\" class=\"js_recommend\"><\/span><\/figure>\n<div class=\"sc-17kx9cd-5 kDVAgq js_ad-mobile-dynamic js_ad-dynamic ad-mobile-dynamic\">\n<div class=\"sc-17kx9cd-4 bNalPz ad-unit ad-mobile\">\n<p>Advertisement<\/p>\n<\/div>\n<\/div>\n<p class=\"sc-77igqf-0 fnnahv\">Dragon Sector commends Newag for making great trains but believes they should not be in the repair market if they\u2019re going to be anti-competitive. The other largest train manufacturer in Poland, Pesa, is not in the repair market at all.<\/p>\n<p class=\"sc-77igqf-0 fnnahv\">\u201cWhen those trains were being serviced and couldn\u2019t start running, this affected people. The train system in lower Silesia was overloaded,\u201d said Baza\u0144ski, which the Polish media reported on in 2022. \u201cThere just wasn\u2019t enough rolling stock in service.\u201d<\/p>\n<div class=\"sc-17kx9cd-5 kDVAgq js_ad-mobile-dynamic js_ad-dynamic ad-mobile-dynamic\">\n<div class=\"sc-17kx9cd-4 bNalPz ad-unit ad-mobile\">\n<p>Advertisement<\/p>\n<\/div>\n<\/div>\n<p class=\"sc-77igqf-0 fnnahv\">Dragon Sector wants people to know that they were not malicious in speaking out against Newag, they simply wanted to help the people who were affected. Allowing trains to be repaired swiftly and in a cost-efficient way likely means fewer delays for riders. Infractions of the right-to-repair movement often end up hurting end-users the most. <\/p>\n<p>READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/35354\/How-A-Group-Of-Train-Hackers-Exposed-A-Right-To-Repair-Nightmare.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":54975,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[277],"tags":[140],"class_list":["post-54974","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-blogs","tag-headlinehacker"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How A Group Of Train Hackers Exposed A Right-To-Repair Nightmare 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How A Group Of Train Hackers Exposed A Right-To-Repair Nightmare 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2024-01-03T14:26:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/i.kinja-img.com\/image\/upload\/c_fit,q_60,w_645\/342f5078057bf144a929ea8ace56344e.jpg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"How A Group Of Train Hackers Exposed A Right-To-Repair Nightmare\",\"datePublished\":\"2024-01-03T14:26:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\\\/\"},\"wordCount\":1022,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare.jpg\",\"keywords\":[\"headline,hacker\"],\"articleSection\":[\"CyberSecurity Blogs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\\\/\",\"name\":\"How A Group Of Train Hackers Exposed A Right-To-Repair Nightmare 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare.jpg\",\"datePublished\":\"2024-01-03T14:26:34+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2024\\\/01\\\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare.jpg\",\"width\":645,\"height\":363},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehacker\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"How A Group Of Train Hackers Exposed A Right-To-Repair Nightmare\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How A Group Of Train Hackers Exposed A Right-To-Repair Nightmare 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\/","og_locale":"en_US","og_type":"article","og_title":"How A Group Of Train Hackers Exposed A Right-To-Repair Nightmare 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2024-01-03T14:26:34+00:00","og_image":[{"url":"https:\/\/i.kinja-img.com\/image\/upload\/c_fit,q_60,w_645\/342f5078057bf144a929ea8ace56344e.jpg","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"How A Group Of Train Hackers Exposed A Right-To-Repair Nightmare","datePublished":"2024-01-03T14:26:34+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\/"},"wordCount":1022,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/01\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare.jpg","keywords":["headline,hacker"],"articleSection":["CyberSecurity Blogs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\/","url":"https:\/\/www.threatshub.org\/blog\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\/","name":"How A Group Of Train Hackers Exposed A Right-To-Repair Nightmare 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/01\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare.jpg","datePublished":"2024-01-03T14:26:34+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/01\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2024\/01\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare.jpg","width":645,"height":363},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/how-a-group-of-train-hackers-exposed-a-right-to-repair-nightmare\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehacker\/"},{"@type":"ListItem","position":3,"name":"How A Group Of Train Hackers Exposed A Right-To-Repair Nightmare"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/54974","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=54974"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/54974\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/54975"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=54974"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=54974"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=54974"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}