{"id":829694,"date":"2026-05-29T08:49:33","date_gmt":"2026-05-29T08:49:33","guid":{"rendered":"https:\/\/www.europesays.com\/us\/829694\/"},"modified":"2026-05-29T08:49:33","modified_gmt":"2026-05-29T08:49:33","slug":"iranian-hackers-behind-marchs-la-transport-cyberattack-gambit-finds","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/us\/829694\/","title":{"rendered":"Iranian hackers behind March&#8217;s LA transport cyberattack, Gambit finds"},"content":{"rendered":"<p>Iranian <a href=\"https:\/\/www.jpost.com\/business-and-innovation\/all-news\/article-894559\" rel=\"nofollow noopener\" target=\"_blank\">hackers<\/a> were responsible for a disruptive computer breach in March that forced Los Angeles&#8217; transit system to shut down parts of its network, Israeli researchers found earlier this week.<\/p>\n<p>The saboteurs stole at least 700 gigabytes of emails, backups, and other files from the <a href=\"https:\/\/www.jpost.com\/diaspora\/antisemitism\/article-894792\" rel=\"nofollow noopener\" target=\"_blank\">Los Angeles<\/a> County Metropolitan Transportation Authority (LACMTA), according to Gambit Security, a Tel Aviv-based cybersecurity firm that said it discovered the misappropriated data after it was inadvertently exposed online.<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">In a report published on Tuesday, the company said a digital trail of evidence tied the server where the data was discovered to a previously known hacking operation that Israeli officials and researchers attributed to Tehran.<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">The Los Angeles transit authority didn&#8217;t respond to questions about the findings. In a statement shared last month, its officials said they were working with law enforcement and cyber specialists as they brought their systems back online. &#8220;Attribution is part of the investigation and we will not speculate,&#8221; the statement said.<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">The attack caused disruptions to digital services for passengers, including displaying arrival times and the ability to add money to digital cards. LACMTA then claimed that the transportation service itself was not affected and that no indication of harm to customers or employee data was found.<\/p>\n<p><img alt=\"An illustration of a cyber hacker and the Iranian flag.\" loading=\"lazy\" width=\"822\" height=\"829\" decoding=\"async\" data-nimg=\"1\" style=\"color:transparent\" src=\"https:\/\/www.europesays.com\/us\/wp-content\/uploads\/2026\/05\/669519.jpeg\"\/>An illustration of a cyber hacker and the Iranian flag. (credit: PX Media\/Shutterstock)<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">Gambit also noted that the attack on LACMTA&#8217;s systems did not consist solely of information theft. In some cases, the attackers also acted to destroy systems and impair the recovery capability of the affected organizations.<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">According to Gambit&#8217;s report, the attacker&#8217;s activity included deleting virtual machines, databases, and storage volumes, as well as damaging backup infrastructures &#8211; in other words, not just a breach to collect information, but an attempt to make it difficult for LACMTA to return to normal operations.<\/p>\n<p>Notably, Los Angeles is one of the host cities for the <a href=\"https:\/\/www.jpost.com\/international\/article-897295\" rel=\"nofollow noopener\" target=\"_blank\">FIFA 2026 World Cup<\/a>, which begins on June 11.<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">Digital security specialists have suspected an Iranian hand in the operation against the LACMTA ever since an obscure pro-Iran outfit calling itself Ababil of Minab claimed responsibility. The group&#8217;s name refers to the bombing of a girls&#8217; school in the Iranian city of Minab that officials there say killed more than 175 children and teachers, and its rhetoric and modus operandi are characteristic of self-styled vigilante hacker groups that US and Israeli researchers allege are cut-outs for Iranian spies.<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">The threat actor group claims to be an independent activist organization.<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">Eyal Sela, Gambit&#8217;s director of threat intelligence, said a connection between Ababil and the Iranian state &#8220;has been a working assumption.&#8221;<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">&#8220;What our research adds is the forensic evidence to support it,&#8221; he said.<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">Gambit, a security startup founded in part by veterans of Unit 8200, Israel&#8217;s equivalent of the US National Security Agency, said it had alerted relevant authorities to its findings.<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">Ababil did not return messages left via a form on its website. The FBI said it was aware of the LACMTA incident and was &#8220;coordinating with partners in response.&#8221; The FBI declined further comment.<\/p>\n<p>The US civilian cyber defense body, the Cybersecurity and Infrastructure Security Agency, did not return messages seeking comment. Iran&#8217;s mission to the United Nations and Israel&#8217;s <a href=\"https:\/\/www.jpost.com\/israel-news\/article-897341\" rel=\"nofollow noopener\" target=\"_blank\">National Cyber Directorate<\/a> also did not respond to Reuters&#8217;s request for comment.<\/p>\n<p><strong>Iranian-linked, backed hackers allegedly active since start of war<\/strong><\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">The intrusion at LACMTA was detected around March 16, its officials said in their statement. About two weeks later, Ababil materialized online and claimed to have wiped an enormous amount of data in a destructive cyberattack, publishing a video that purported to show them rampaging through the transit system&#8217;s network.<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">Ababil also has claimed credit for hacks affecting South Florida&#8217;s Tri-Rail commuter transit system, vehicle tracking company Vyncs, and Saudi infrastructure firm Unimac.<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">In a statement, Tri-Rail confirmed it had been hacked &#8220;about a month ago,&#8221; but said that none of the affected data was critical. Vyncs owner Agnik said it had detected its breach on April 2 but declined to comment on the nature of the data stolen by the hackers.<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">Both Tri-Rail and Agnik said the FBI was involved, with Agnik saying in an email that the bureau &#8220;has a pretty good understanding of who these criminals are.&#8221; Unimac did not return messages seeking comment.<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">The group behind Ababil has hacked other organizations whose identity it has not publicized, Gambit Security said, citing its analysis of other data left online by the spies. Sela said they included a media organization and educational institution in Israel and an insurance brokerage in Turkey, but he declined to identify them further.<\/p>\n<p class=\"article-paragraph-section article-body-paragraph\">Iranian hackers have allegedly carried out a drumbeat of digital operations since the US and Israel launched a war against Iran in late February, including a damaging attack on the medical device company Stryker and the leak of personal emails belonging to FBI Director Kash Patel. Iranian hackers are also suspected of having remotely tampered with fuel gauges at gas stations, CNN reported earlier this month.<\/p>\n","protected":false},"excerpt":{"rendered":"Iranian hackers were responsible for a disruptive computer breach in March that forced Los Angeles&#8217; transit system to&hellip;\n","protected":false},"author":3,"featured_media":829695,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[5123],"tags":[18393,1582,276,14460,14461,734,340512,3432,6061,36384,31307,83,340513,2961,224,5337,340514,9907,25972,522,320400],"class_list":["post-829694","post","type-post","status-publish","format-standard","has-post-thumbnail","category-los-angeles","tag-bus","tag-ca","tag-california","tag-cyber","tag-cyberattack","tag-cybersecurity","tag-cybersecurity-israel","tag-data","tag-fifa-world-cup","tag-hack","tag-hacker","tag-iran","tag-israeli-cybersecurity","tag-la","tag-los-angeles","tag-losangeles","tag-national-cyber-directorate-incd","tag-public-transportation","tag-train","tag-transportation","tag-world-cup-soccer"],"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@us\/116657008456369383","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts\/829694","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/comments?post=829694"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts\/829694\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/media\/829695"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/media?parent=829694"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/categories?post=829694"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/tags?post=829694"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}