HomeSecurityIran-Linked Hackers Blamed for Los Angeles Transit System Breach

Iran-Linked Hackers Blamed for Los Angeles Transit System Breach

Security researchers say a March breach of the Los Angeles County Metropolitan Transportation Authority was likely carried out by hackers tied to Iran’s intelligence services, adding another case to a growing list of cyberattacks aimed at public agencies and critical infrastructure.

The Los Angeles transit agency, commonly known as LACMTA or LA Metro, took weeks to recover from the incident. A group calling itself Ababil of Minab claimed responsibility at the time, saying it had stolen and then deleted data from the agency’s systems.

Researchers Point to an Iran-Linked Persona

Israeli cybersecurity firm Gambit Security said in a report that Ababil of Minab is not the independent hacktivist group it claims to be. Instead, Gambit assessed that the operators work for Iran’s Ministry of Intelligence and State Security.

The firm said its assessment is based on forensic evidence connecting the group to earlier Iran-linked activity, along with overlaps with activity previously attributed to Iranian intelligence by Israel’s national cyber authority. Gambit also said it investigated related attacks against organizations in Israel, Saudi Arabia, and Turkey.

The group’s name has been described as a reference to a reported U.S. airstrike on a school in the Iranian city of Minab that killed more than 175 people, mostly children. That framing, and the group’s claim to be a standalone hacktivist operation, has not been independently verified.

Why the Attribution Matters

If Gambit’s assessment is accurate, Ababil of Minab would fit a pattern seen in other suspected Iranian cyber operations: state-backed hackers using activist-style branding to claim attacks, shape public messaging, and obscure the government connection.

That model gives attackers a way to present disruptive operations as political retaliation or grassroots action, even when researchers believe the activity is directed or supported by a government agency.

The Los Angeles transit breach also stands out because it affected a large public transportation system. Transit agencies hold sensitive operational and administrative data, and even when service continues, recovery from a cyber incident can consume weeks of staff time and technical resources.

A Broader Wave of Iran-Linked Activity

Iran-linked hackers have become more active in the wake of U.S. and Israeli strikes on Iran earlier this year, according to warnings from U.S. agencies. In April, a coalition of American government agencies warned that Iranian hackers were targeting U.S. critical infrastructure.

Another group, Handala, has also been described by U.S. authorities as an Iranian-backed hacktivist persona. Earlier this year, Handala was accused of hacking medical technology company Stryker and wiping thousands of company systems and employee devices, though the full scope and technical details of that incident have not been independently verified.

After the Stryker attack, U.S. authorities seized two Handala websites, and the Justice Department accused Iran’s government of being behind the group and its operations.

The pattern matters for defenders because the label on a breach claim may not tell the whole story. A group presenting itself as a new political hacking collective can still be part of a longer-running state-backed campaign.

For public agencies and infrastructure operators, the lesson is practical: attacks that look like data theft or website defacement can carry broader operational risk, especially when the suspected actor is tied to a foreign intelligence service.

RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular

POPULAR TAGS

- Advertisment -