Iranian Hackers Linked to March Breach of Los Angeles Transit System
Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover

Image: Tech Crunch
A March cyberattack on the Los Angeles County Metropolitan Transportation Authority (LACMTA) has been attributed to Iranian-backed hackers, specifically a group named Ababil of Minab. The attack involved data theft and deletion, with ties to Iran’s Ministry of Intelligence and State Security (MOIS).
- 01The breach of LACMTA was attributed to Iranian-backed hackers by Gambit Security.
- 02The group Ababil of Minab claimed responsibility, referencing a historical U.S. airstrike in Iran.
- 03Gambit's report links Ababil of Minab to previous Iran-linked cyberattacks, including those against companies in Israel and Saudi Arabia.
- 04Iranian hackers have intensified their activities following U.S. and Israeli military actions against Iran earlier this year.
- 05The FBI has previously linked other Iranian hacktivist groups, like Handala, to significant cyberattacks on U.S. companies.
Advertisement
In-Article Ad
Security researchers have identified the March breach of the Los Angeles County Metropolitan Transportation Authority (LACMTA) as the work of Iranian-backed hackers, specifically a group named Ababil of Minab. This group claimed responsibility for the attack, stating they stole and deleted sensitive data from LACMTA's systems. Gambit Security, an Israeli startup, reported that the hackers are affiliated with Iran’s Ministry of Intelligence and State Security (MOIS). The group's name references a tragic U.S. airstrike in Iran that killed many civilians. Gambit's analysis suggests that Ababil of Minab is not an independent hacktivist group as they claim but part of a broader pattern of Iranian cyber operations. The report also highlights a surge in Iranian hacker activity targeting U.S. critical infrastructure following military actions by the U.S. and Israel against Iran earlier this year. This incident follows previous attacks attributed to Iranian-linked groups, including the Handala group, which targeted U.S. medical technology firm Stryker.
Advertisement
In-Article Ad
The breach of the LACMTA could affect public transportation security and operations in Los Angeles.
Advertisement
In-Article Ad
Reader Poll
How concerned are you about cybersecurity threats to public infrastructure?
Connecting to poll...
Read the original article
Visit the source for the complete story.


![Apple Seeds First Betas of watchOS 26.6, tvOS 26.6, and visionOS 26.6 to Developers [Download]](/_next/image?url=https%3A%2F%2Fwww.iclarified.com%2Fimages%2Fnews%2F100966%2F100966%2F100966-1280.jpg&w=1200&q=75)
