Security researchers have attributed the March breach of the Los Angeles County Metropolitan Transportation Authority to an Iran-linked operation masquerading as the hacktivist group Ababil of Minab. Gambit Security said forensic evidence and infrastructure overlaps connect the activity to actors associated with Iran’s Ministry of Intelligence and Security, including clusters tracked as MuddyWater, Black Shadow, and Static Kitten. The attackers reportedly disrupted LA Metro’s payment environment, preventing riders from loading funds onto the agency’s mobile contactless payment app, while claiming they had stolen and deleted transit-system data.
According to the report, the intrusion combined automation, hands-on-keyboard activity, and ChatGPT-assisted scripting to target IT, application, virtualization, and backup systems. Researchers said the attackers deleted virtual machines, wiped disks, and exfiltrated at least 700 GB of emails and backups, forcing Metro to inspect roughly 1,400 servers during recovery. Gambit linked the same actor to destructive incidents affecting Tri-Rail, UNIMAC, and Vyncs, reinforcing warnings that Iranian state-linked operators are using fake hacktivist branding to conduct disruptive attacks against critical infrastructure.

TTPs, infrastructure, and targeting history in one profile.
8 events from the most recent confirmed update back to the earliest known activity.
By 2026-05-27, Gambit Security said the operators linked to the LA Metro breach had also targeted additional victims in Israel, Turkey, Saudi Arabia, and other sectors. This expanded the known scope of the destructive campaign beyond the previously reported organizations.
Gambit Security said the same actor behind the LA Metro attack was also connected to destructive incidents affecting Tri-Rail, UNIMAC, and Vyncs, where backups were similarly deleted. The finding positioned the breach as part of a broader Iranian campaign using fake hacktivist branding.
On or before May 26, 2026, Gambit Security assessed that the LA Metro breach was conducted by Iranian government-linked operators tied to Iran's Ministry of Intelligence and Security rather than an independent hacktivist collective. The firm linked Ababil of Minab to infrastructure and tradecraft associated with clusters tracked as MuddyWater, Black Shadow, and Static Kitten.
On 2026-04-09, Ababil of Minab publicly claimed the LA Metro attack on Telegram and its website, posting screenshots, video, and statements alleging access to VMware vCenter, Microsoft IIS servers, and a rail yard management and train control display system. The group also claimed large-scale data wiping and exfiltration, though those figures were not independently verified.
In April 2026, U.S. government agencies warned that Iranian hackers were targeting American critical infrastructure. The warning provided broader context for the LA Metro incident and related activity.
After the attack, LA Metro reportedly had to inspect about 1,400 servers before restoring affected systems. Recovery took weeks as the agency worked to bring disrupted services back online.
Following the March 2026 breach, the group calling itself Ababil of Minab publicly claimed responsibility and said it had stolen and deleted data from LA Metro transit systems. The claim framed the incident as a hacktivist operation before later attribution shifted.
In March 2026, Los Angeles County Metropolitan Transportation Authority was hit by a cyberattack that disrupted its payment network and prevented riders from loading money onto the mobile contactless payment app. The attackers reportedly targeted IT, application, virtualization, and backup infrastructure, deleting virtual machines, wiping disks, and stealing at least 700 GB of emails and backups.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
10 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcetherecord.media
Open sourcescworld.com
Open sourcetechcrunch.com
Open sourcebankinfosecurity.com
Open sourcedataminr.com
Open sourceababilofminab.io
Open sourcecdn.prod.website-files.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.