Iranian hackers blamed for Los Angeles transit system breach that took weeks to recover
Iran-linked hackers reportedly stole large amounts of data from the Los Angeles transit system in a March cyberattack, alongside a series of other global intrusions.

Iranian hackers were responsible for a disruptive cyber breach in March that led to a shutdown of the Los Angeles County Metropolitan Transportation Authority (LACMTA) systems, stealing at least 700 GB of emails, backups and other files, according to Gambit Security, a Tel Aviv–based cybersecurity firm that discovered the compromised data after it was inadvertently exposed online.
Security experts had long suspected Iranian involvement in the attack after responsibility was claimed by a pro-Iran outfit called Ababil of Minab. The name is reportedly linked to a girls’ school attack, and the rhetoric has become characteristic of the vigilante hacker group, which, according to US and Israeli researchers, is believed to operate as a front for Iranian intelligence. Gambit Security, a firm partly founded by veterans of Unit 8200, said a connection between Ababil and the Iranian state has been a “working assumption.”
The cybercriminals claimed to have wiped large volumes of data in a destructive attack, even publishing a video allegedly showing them wreaking havoc on the system’s network.
Los Angeles transit officials said the breach did not disrupt train or bus operations. At most, it affected a few arrival screens and temporarily prevented customers from adding money to transit cards. Ababil has also claimed responsibility for attacks on South Florida’s Tri-Rail commuter system, vehicle tracking company Vyncs, and Saudi infrastructure firm Unimac. Reuters reported that Tri-Rail confirmed it was hacked about a month ago, though it said none of the affected data was critical.
Vyncs owner Agnik said it detected the breach on April 2 but declined to comment on the nature of the data stolen. Gambit Security also said the Ababil-linked group has targeted other unnamed organizations, including a media outlet and educational institution in Israel and an insurance brokerage in Turkey, though further details were not disclosed.
Iranian hackers have reportedly carried out several digital operations since the escalation of tensions between the US and Israel and Iran in late February, including an attack on medical device company Stryker and leaks of personal emails belonging to Kash Patel.
(With inputs from Reuters)

OpenAI launches Presence to bring AI agents into customer support and enterprise workflows
Samsung Galaxy Fold 8 Ultra, Fold 8, Flip 8 launched: Here is how much it costs in India with discounts
Florida pastor sues OpenAI, says ChatGPT's medical advice delayed emergency treatment: Report
US accuses China's Moonshot AI of using Anthropic's Fable to build K3 model
Apple's biggest Mac refresh in years could bring 11 new models: Report
