1 of 1
Story summary
- Gambit Security said forensic evidence links the Los Angeles County Metropolitan Transportation Authority breach to the Iran-aligned hacking group Ababil.
- Iranian-linked hackers accessed the LACMTA network in March, stole 700 GB of data, disabled screens and reloads, while the intrusion detected around March 16 did not halt train or bus service.
- Gambit alerted U.S. and Israeli authorities, prompting agencies to probe if the attack is part of an Iranian campaign after February 2026 escalation.
