Drooid Logo
Back to story perspectives

Full Breakdown

Iranian-linked Hackers Disrupt Los Angeles Transit System, Steal 700 GB of Data

5/26/2026, 10:36:41 PM

Incident Overview

In March 2026, the Los Angeles County Metropolitan Transportation Authority (LACMTA) detected a cyber intrusion that exfiltrated at least 700 GB of emails, backups and internal files. The breach forced parts of the transit system’s digital infrastructure offline, prompting a coordinated response with law-enforcement.

Attribution & Context

Tel Aviv-based Gambit Security linked the compromised server to a known operation previously attributed by Israeli officials to Tehran. The attackers identified themselves as “Ababil of Minab,” a pro-Iran group whose name references a 2022 school bombing in Minab. Gambit’s threat-intelligence director Eyal Sela said the forensic evidence now supports the long-standing assumption of Iranian state involvement. Ababil has also claimed responsibility for hacks of South Florida’s Tri-Rail commuter system, vehicle-tracking company Vyncs and Saudi infrastructure firm Unimac.

Timeline

  • March 16, 2026: LACMTA discovers unauthorized network access.
  • Late March: Ababil posts a video claiming to have wiped transit data.
  • Early April: Gambit alerts U.S. and Israeli authorities after the stolen files appear online.
  • May 26, 2026: Reuters reports Gambit’s attribution.

Data Stolen and Impact

The exfiltrated 700 GB included internal communications and system backups. LACMTA officials said train and bus services continued, but local media reported that arrival-display screens at several stations went dark and fare-card reload kiosks were temporarily offline, highlighting vulnerabilities in transit digital systems.

Official Statements & Responses

LACMTA said attribution remains part of the ongoing investigation and that it would not speculate on the perpetrators. The FBI confirmed awareness of the breach and indicated it was working with partner agencies, but declined further comment on who was responsible. Neither the U.S. Cybersecurity and Infrastructure Security Agency nor Iran’s UN mission responded to inquiries, and Israel’s National Cyber Directorate also declined comment.

Criticism & Opposition

Observers note that the FBI and Iranian officials have not confirmed state sponsorship, leaving the attribution claim unverified. The absence of comments from Iran’s UN mission and Israel’s cyber authority underscores the difficulty of assigning responsibility in cyber incidents.

Conflicting Reports & Gaps

LACMTA maintains passenger service was unaffected, yet media accounts describe disabled arrival screens and payment kiosks. Gambit’s forensic link to Iran remains unendorsed by U.S. agencies, creating a gap between technical attribution and official confirmation.

Verbatim Quotes

  • “Attribution is part of the investigation and we will not speculate,” — LACMTA spokesperson
  • “What our research adds is the forensic evidence to support it.” — Eyal Sela, Gambit Security
  • “A connection between Ababil and the Iranian state has been a working assumption,” — Eyal Sela, Gambit Security
  • “The FBI confirmed it was “coordinating with partners in response”.” — Federal Bureau of Investigation
  • “has a pretty good understanding of who these criminals are.” — Agnik, owner of Vyncs

What’s Next

U.S. and Israeli cyber agencies will continue forensic analysis to verify the group’s ties to Tehran, while transit operators nationwide review security measures to guard against similar attacks.