Advertisement

Iranian hackers blamed for Los Angeles transit system breach that took weeks to recover

Iran-linked hackers reportedly stole large amounts of data from the Los Angeles transit system in a March cyberattack, alongside a series of other global intrusions.

Advertisement
hacker
hacker
FP Tech Desk|May 26, 2026, 23:51:01 IST

Iranian hackers were responsible for a disruptive cyber breach in March that led to a shutdown of the Los Angeles County Metropolitan Transportation Authority (LACMTA) systems, stealing at least 700 GB of emails, backups and other files, according to Gambit Security, a Tel Aviv–based cybersecurity firm that discovered the compromised data after it was inadvertently exposed online.

Advertisement

Security experts had long suspected Iranian involvement in the attack after responsibility was claimed by a pro-Iran outfit called Ababil of Minab. The name is reportedly linked to a girls’ school attack, and the rhetoric has become characteristic of the vigilante hacker group, which, according to US and Israeli researchers, is believed to operate as a front for Iranian intelligence. Gambit Security, a firm partly founded by veterans of Unit 8200, said a connection between Ababil and the Iranian state has been a “working assumption.”

techMore from Tech

The cybercriminals claimed to have wiped large volumes of data in a destructive attack, even publishing a video allegedly showing them wreaking havoc on the system’s network.

Los Angeles transit officials said the breach did not disrupt train or bus operations. At most, it affected a few arrival screens and temporarily prevented customers from adding money to transit cards. Ababil has also claimed responsibility for attacks on South Florida’s Tri-Rail commuter system, vehicle tracking company Vyncs, and Saudi infrastructure firm Unimac. Reuters reported that Tri-Rail confirmed it was hacked about a month ago, though it said none of the affected data was critical.

Advertisement

Vyncs owner Agnik said it detected the breach on April 2 but declined to comment on the nature of the data stolen. Gambit Security also said the Ababil-linked group has targeted other unnamed organizations, including a media outlet and educational institution in Israel and an insurance brokerage in Turkey, though further details were not disclosed.

Iranian hackers have reportedly carried out several digital operations since the escalation of tensions between the US and Israel and Iran in late February, including an attack on medical device company Stryker and leaks of personal emails belonging to Kash Patel.

(With inputs from Reuters)

Handpicked stories, in your inbox
Global stories. Indian perspective. Zero noise.
No Spam. Unsubscribe Any Time.
First Published:May 26, 2026, 23:31:30 IST
Advertisement
Advertisement
Advertisement
Advertisement
Up Next