July 15, 2025
The bug in the train that took 20 years to fix
(Or why cybersecurity awareness is an uphill task)
By Gautam Mengle
1 min read
A train hack that took 20 years to be taken seriously.
In 2012, a researcher discovered that U.S. freight trains were vulnerable to a remote braking attack. With a $500 software-defined radio, someone could impersonate the signal from the head of the train and trigger emergency brakes at the rear.
He reported it. He demonstrated it. And for more than a decade, the response was: "But that would never happen."
Only now, in 2025, is the system finally being fixed after intervention from CISA.
This is why awareness is so difficult. Not because the technology is too complex, but because the threat doesn't feel real. If something hasn't happened yet, it's dismissed as theoretical. And when you dismiss the theoretical, you delay the fix until after the cost begins to climb.
As someone who works in awareness, I think about this all the time. How do you get people to act on invisible risks? How do you help them understand that the absence of an incident doesn't equal safety?
It's not just about knowledge. It's about belief. And belief requires more than definitions or data. It needs stories, context, and a connection to the world people live in.
This particular story is about trains. But it could just as easily be about the software update ignored, the strange email that wasn't reported, or the access left open because it was "just internal."
The hardest part of awareness is not explaining the risk. It's making people care before the damage begins.