Los Angeles transit system hack blamed on Iranian attackers - but they might not have worked alone
Date:
Wed, 27 May 2026 20:05:00 +0000
Description:
Some researchers believe the attack was the work of the Iranian government, not hacktivists.
FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Gambit Security links March
2026 breach of Los Angeles transit system to Iranian statesponsored actors, not hacktivists, citing forensic evidence tied to prior campaigns Attackers stole ~700GB of emails, backups, and internal data, with the proIranian group Ababil of Minab claiming responsibility despite indications it is a front for Tehran Analysts note this fits a broader pattern of fake hacktivist groups like Handala being used by Iran to mask statedirected cyberespionage and destructive operations The March 2026 cyberattack on the Los Angeles transit system was not the work of hacktivists, but rather Iranian state-sponsored threat actors, after experts from Gambit Security claimed to have found evidence connecting the breach to the government in Teheran.
Two months ago, the Los Angeles County Metropolitan Transportation Authority (LACMTA) detected unauthorized activity on its internal network and shut down parts of its computer systems to contain the breach. The attack disrupted
some customer-facing services, including arrival information displays and TAP card reloading systems, although trains and buses continued operating normally. Sometime later, a pro-Iranian hacking group calling itself Ababil
of Minab claimed responsibility for the breach, saying they stole hundreds of gigabytes of internal data from the transit agency. Gambit now claims that
the attackers walked away with 700GB of emails, backups , and other data, after finding the stolen files exposed online. Latest Videos From You may
like Iranian hackers launch ransomware campaign looking to steal details via Microsoft Teams Iranian "Charming Kitten" hackers used old Cold War methods
to steal tech secrets US agencies warn Iranian hackers are targeting American critical infrastructure causing 'disruptive effects within the United
States' Who are Ababil of Minab? The researchers also said they followed the trail of evidence back to a server that was previously seen being used in other Iranian state-sponsored hacking campaigns.
According to Reuters , many cybersecurity researchers suspected that the LACMTA attack was the work of the Iranians. Eyal Sela, Gambit's director of threat intelligence, said that the companys research now adds forensic evidence to support these claims.
Ababil of Minab is a lesser-known group that first emerged a few weeks after the LACMTA incident. The name references the US air strike on an Iranian school that happened at the very beginning of the latest US/Israel-Iran conflict, in which 175 people, mostly children, were killed.
In its writeup, TechCrunch said that if Gambits assumptions are correct, Ababil of Minab would be the latest in a series of fake hacktivist groups
that are working for the Iranian government. Before this group, there was Handala, which struck Stryker and wiped thousands of company systems and employee devices. Are you a pro? Subscribe to our newsletter Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners
or sponsors By submitting your information you agree to the Terms &
Conditions and Privacy Policy and are aged 16 or over.
Via TechCrunch The best antivirus for all budgets Our top picks, based on real-world testing and comparisons
Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
======================================================================
Link to news story:
https://www.techradar.com/pro/security/los-angeles-transit-system-hack-blamed- on-iranian-attackers-but-they-might-not-have-worked-alone
--- Mystic BBS v1.12 A49 (Linux/64)
* Origin: tqwNet Technology News (1337:1/100)