Iranian Hackers Strengthen Ties to Cyberattack on Los Angeles Transit Network
A significant cyberattack that disrupted the Los Angeles public transit network earlier this year has been linked to a hacking group believed to be associated with Iran’s intelligence services. This revelation comes from a recent report by Gambit Security, a cybersecurity firm based in Tel Aviv, which has provided new insights into the incident that occurred in March 2023.
Details of the Cyberattack
The cyberattack targeted the Los Angeles County Metropolitan Transportation Authority (LACMTA) and was executed by a group known as “Ababil of Minab.” According to Gambit Security, the hackers not only stole sensitive data but also attempted to damage systems and hinder recovery efforts. This attack forced LACMTA to temporarily shut down parts of its network, disrupting various digital services utilized by passengers throughout Los Angeles.
Gambit Security reported that at least 700 gigabytes of data were compromised during the breach. The stolen information included emails, backups, databases, and other internal documents belonging to LACMTA. This data was later found to be accidentally exposed online, raising concerns about the security measures in place.
Forensic Evidence and Attribution
Researchers from Gambit Security have presented forensic evidence linking the exposed server to a previously identified hacking campaign attributed to Tehran. While the Los Angeles transit authority did not respond to inquiries regarding these findings, LACMTA officials stated they were collaborating with law enforcement and cybersecurity specialists to restore the affected systems.
In a statement, LACMTA emphasized that “attribution is part of the investigation, and we will not speculate” on the origins of the attack. However, the implications of this incident are significant, particularly given the increasing sophistication of cyber threats targeting critical infrastructure.
Impact on Passenger Services
The cyberattack severely disrupted several passenger-facing digital systems in Los Angeles, including services that display train and bus arrival times and functions allowing riders to add funds to digital transit cards. Despite these interruptions, LACMTA maintained that transportation operations were not directly affected and claimed there was “no indication” that customer or employee data had been compromised.
However, Gambit’s report suggests that the Iranian hackers executed a far more destructive operation than initially perceived. The attackers deleted virtual machines, databases, and storage volumes, damaging backup infrastructure in the process. This indicates that the goal of the attack extended beyond mere data theft; it aimed to disrupt and destroy systems critical to the operation of LACMTA.
Broader Implications and Future Risks
The attack on LACMTA has garnered heightened attention, especially as Los Angeles prepares to host the FIFA 2026 World Cup, commencing on June 11, 2026. Cybersecurity experts have warned that transportation infrastructure may become increasingly attractive targets for cybercriminals, particularly in the lead-up to major international events. The potential for disruption in such critical sectors raises concerns about the resilience of public services against cyber threats.
Ababil of Minab: The Claim of Responsibility
Shortly after the cyberattack, a group identifying itself as “Ababil of Minab” publicly claimed responsibility. Approximately two weeks post-intrusion, the group announced online that it had wiped substantial amounts of data during the operation. They even released a video purportedly showing their navigation through the Los Angeles transit agency’s network during the attack.
The name “Ababil of Minab” references a tragic bombing incident at a girls’ school in the Iranian city of Minab, where over 175 children and teachers lost their lives. Researchers have noted that the group’s rhetoric and tactics closely resemble those employed by vigilante hacking groups that are believed to operate as fronts for Iranian intelligence services.
Despite these allegations, Ababil of Minab has asserted that it functions as an independent activist organization. Eyal Sela, Gambit’s director of threat intelligence, indicated that experts had long suspected a connection between Ababil and the Iranian government prior to the emergence of the forensic evidence. He stated, “A connection between Ababil and the Iranian state has been a working assumption,” adding that the research provides forensic evidence to support this claim.
The implications of this cyberattack extend beyond the immediate disruption of services. It highlights the vulnerabilities of critical infrastructure to sophisticated cyber threats and raises questions about the preparedness of organizations to defend against such attacks. As cyber threats continue to evolve, the need for robust cybersecurity measures becomes increasingly paramount.
For more detailed insights into the implications of this incident and ongoing developments in cybersecurity, visit thecyberexpress.com.
Keep reading for the latest cybersecurity developments, threat intelligence and breaking updates from across the Middle East.


