When The Green Signal Lies: Lessons From The Brooklyn Train Collision
- Safety Jon

- Jul 12
- 8 min read
On 06 May 90, a heritage passenger train hauled by steam locomotive 3801 stalled while climbing the Cowan Bank, approximately five kilometres south of Brooklyn on the Sydney to Newcastle railway. A following CityRail interurban passenger train received a proceed indication and struck the rear of the stationary excursion train, killing six people and injuring 93.
The final carriage of the excursion train was destroyed and the front of the interurban train was extensively damaged. What makes Brooklyn particularly important from a safety engineering perspective is that the following driver did not disregard a stop signal, the signalling system presented a green indication when the section ahead was occupied.
The system did exactly what a safety-critical system must never do, it converted uncertainty into permission. Brooklyn was not simply a case of equipment breaking; it was an operating interface producing a dangerous but apparently valid instruction.
Sand, Traction And An Unrecognised Interface
Locomotive 3801 was returning passengers from the Morpeth Jazz Festival when it began experiencing wheel slip on the steep gradient from the Hawkesbury River towards Cowan. Sand was applied to the rail to improve adhesion, but the train eventually came to a stop near the Boronia tunnels.
The coronial inquiry found that the sand interfered with the track circuit used to detect the train’s presence. Public summaries of the inquiry also report that a handbrake on one of the excursion train’s carriages may have been partially applied, contributing to the train slowing and being unable to restart.
The following interurban service had initially been held at a red signal. The signal subsequently changed to green because the track circuit no longer reliably indicated that 3801’s train was occupying the section, and the interurban train proceeded into what appeared to be a clear block.
Sand was not foreign material carelessly left on the railway. It was an operational traction aid being used for its intended purpose, but its interaction with the train-detection system had not been controlled sufficiently to prevent a wrong-side signalling failure.
That distinction matters. A hazard is not adequately managed merely because each individual component is approved, maintained or performing its intended function.
How A Track Circuit Can Lose A Train
A conventional track circuit passes an electrical current through the rails. When a train enters the section, its wheelsets electrically connect the rails, commonly described as shunting the circuit, and the signalling system interprets the section as occupied.
Sand, rust, oil, vegetation, chemicals and other contaminants can interfere with the electrical contact between the wheel and rail. ONRSR specifically identifies excessive sand from rolling-stock traction or braking systems as a railhead contaminant capable of affecting train detection.
A properly functioning safety system should respond to uncertain or unreliable train detection conservatively. It should retain or revert to the restrictive state, generate an alarm, prevent a proceed authority or otherwise require verification before another train enters the section.
At Brooklyn, the dangerous outcome was the opposite. The failure produced a plausible clear indication, which is why the event is described as a wrong-side failure.
A right-side failure inconveniences the railway by stopping trains when the track may actually be clear. A wrong-side failure exposes trains to collision by indicating that the track is clear when it is not, and commercial pressure can never justify preferring availability over safe train separation.
Fail-Safe Must Describe System Behaviour
The term fail-safe is frequently used as though it were an inherent property attached to a piece of equipment. In reality, a system is only fail-safe in relation to defined failures, operating conditions, interfaces and assumptions.
A track circuit may perform reliably under standard rolling-stock operations and still become unsafe when exposed to unusual sanding quantities, different wheel profiles, light axle loads, contaminated railheads or non-standard train movements. The relevant question is not whether the circuit passed its normal test, but whether the complete railway system remains safe under credible operating conditions.
ONRSR reported in Jul 25 that more than 30 train-detection failures had been reported during the preceding three years. The reported consequences included short level-crossing warnings, non-operation of level-crossing equipment, derailments and wrong-side signalling failures, demonstrating that train-detection reliability remains a current rail safety issue rather than a peculiarity of steam-era operations.
The ATSB has also identified the continuing tension between sanding for adhesion and maintaining reliable track-circuit operation. Its investigation into the 2020 Ballarat level-crossing collision noted that sand accumulation can increase the risk of a train failing to activate a track circuit, with consequences for signalling and level-crossing protection.
Brooklyn’s central lesson therefore survives the retirement of particular locomotives and signalling equipment. Safety-critical interfaces must be assessed under actual and foreseeable operating conditions, not merely under the clean assumptions used when individual components were designed.
Operational Changes Require Engineering Analysis
Heritage trains, special movements and unusual rolling stock can introduce operating characteristics that differ from the regular fleet. Differences may include braking performance, sanding arrangements, axle configuration, electrical shunting characteristics, train length, communication equipment and performance on steep gradients.
These differences require more than administrative approval for the train to enter the network. They require an engineering assessment of how the rolling stock will interact with signalling, train detection, track geometry, safeworking rules and emergency arrangements.
The current Rail Safety National Law National Regulations require accredited rail transport operators’ safety management systems to address risk management, human factors, corrective action, auditing and management of change. The management-of-change requirements include identifying the change in its operational context, consulting affected parties, assigning responsibilities, training workers and reviewing whether the change has been managed effectively.
For a sanding system or special train movement, that assessment should examine normal operation, maximum credible sand discharge, prolonged wheel slip, stalling in a signalled section, railhead contamination and the performance of train detection after sanding. Testing must represent the actual gradient, rolling stock and signalling interface where the risk exists, because a desk-based assurance that each component is individually compliant does not prove that the combined system is safe.
Hazard analysis also needs to examine common dependencies. If several purported protection layers rely on the same track-circuit indication, the organisation may have three displays of the same incorrect information rather than three independent controls.
Detect The Wrong-Side Failure Before It Becomes Authority
Train-detection integrity should be monitored for intermittent occupation, unexplained signal changes, abnormal shunt values and discrepancies between detection systems. Locations with known contamination risks, steep gradients, regular sanding activity or low-frequency traffic require monitoring and maintenance arrangements proportionate to their collision potential.
ONRSR identifies failure to recognise high-risk contamination locations, deterioration in detection-system performance and inadequate inspection, testing or calibration as contributors to train-detection incidents. It also notes that contamination and poor wheel-to-rail contact can prevent a system from accurately detecting rolling stock.
Where the potential consequence is a high-speed passenger-train collision, the safety case should consider independent or diverse methods of confirming train occupancy. Depending on the network and technical architecture, this could include axle-counting technology, independent positional information, train integrity monitoring or logic that identifies an implausible disappearance of an occupied section.
Diversity matters because a second system is not independent merely because it has a different name or display. It must be capable of detecting the hazardous condition without relying on the same failed input, power supply, communication path or software assumption.
Disagreement between safety-critical inputs should produce the restrictive state. The system should not select whichever input keeps trains moving, because rail passengers are not the appropriate medium for resolving an engineering argument.
Automatic Train Protection Is A Layer, Not A Magic Wand
ONRSR identifies automatic train protection, braking systems, vigilance controls and deadman systems as rolling-stock controls that can reduce train-to-train collision risk. It also identifies signalling and safeworking systems as the primary means of maintaining safe train separation.
Automatic train protection can supervise speed, braking curves and compliance with movement authorities. It is a substantial control against overspeed and certain signal-passed-at-danger events, but it cannot automatically be assumed to protect against every wrong-side signalling failure.
Where ATP receives its movement authority from the same signalling system that has incorrectly determined the block to be clear, it may enforce an incorrect authority rather than detect the stationary train. This is an engineering inference from the system dependency, and it is why the safety analysis must establish whether protection layers are genuinely independent, sufficiently diverse and capable of detecting loss of train occupancy.
The answer is therefore not simply to install ATP and declare the risk closed. The operator must demonstrate which accident sequences ATP controls, which failures remain possible and what additional protection is provided where the underlying train-detection information may be wrong.
Degraded Mode Must Be Genuinely Conservative
When the integrity of train detection is uncertain, the railway must enter a clearly defined degraded mode. That mode should treat the affected section as occupied until its status has been positively established, rather than allowing normal operations to continue while workers attempt to determine whether the indication is probably correct.
Triggers should include unexplained signal fluctuations, abnormal track-circuit readings, substantial sanding in a detection section, a stalled train, loss of communications or any discrepancy between the known train location and the signalling display. The response may require signals to be maintained at stop, blocking facilities applied, the following movement held, train control confirmation obtained and any permitted movement conducted under restrictive authority and speed.
Procedures must also specify who has the authority to impose and remove the degraded condition. A system in which drivers, signallers, maintainers and operations controllers each assume someone else has confirmed the track is clear is merely distributed optimism with a roster attached.
Training drivers to recognise unusual indications has value, but it cannot compensate for a system presenting a credible green signal. A driver approaching a proceed aspect has limited information about rail contamination, track-circuit status or a stationary train concealed beyond a tunnel or curve.
The stronger control is to prevent the false authority from being generated. The next strongest control is to detect the inconsistency and force a restrictive condition before the following train is committed.
Investigate The Interface, Not Just The Failed Component
An investigation into a signalling event should not stop after identifying contaminated rail or a track circuit that failed to shunt. It should examine why the contamination was foreseeable, how sanding was controlled, what assumptions existed about wheel-to-rail contact, what monitoring could detect deteriorating performance and whether previous anomalies had been recorded and acted upon.
It should also test the organisation’s assurance process. The critical issue is whether the operator knew why the control worked, understood the conditions under which it could fail and had evidence that the remaining protection layers would still prevent a collision.
The current National Regulations require operators to assess the effectiveness of their safety management systems, examine notifiable occurrences and system breaches, identify deficiencies and establish plans to remedy them. Corrective actions must be registered, assigned, implemented and reviewed, with priority given to matters representing the greatest safety risk.
That is materially different from replacing a component, issuing a briefing and closing the action. A wrong-side failure is evidence that one of the system’s core safety assumptions may be invalid, and the response must be proportionate to that significance.
The Lesson From Brooklyn
The driver of the following interurban train was given a proceed indication. Expecting that driver to somehow recognise that the green signal was lying would transfer responsibility from the failed system to the person least able to identify the hidden condition.
Brooklyn demonstrates that safety-critical controls must remain conservative when exposed to foreseeable contaminants and unusual operations. Sanding systems, track circuits, heritage rolling stock, steep gradients, communications and operating rules were not separate matters that happened to meet on 06 May 90; they were one railway system, and their interaction produced the collision.
Six people died and 93 were injured because an occupied section was presented as clear. The enduring requirement is straightforward, where the system cannot reliably prove that the track is clear, it must not authorise another train to proceed.




Comments