ThinkPatternGet the app
Story
TECHNOLOGY · MAY 26, 2026

Israeli Researchers Link LA Metro Cyberattack to Iranian State

Gambit Security attributed a March cyberattack on the Los Angeles County Metropolitan Transportation Authority to Iranian state hackers who stole 700 gigabytes of data.

Israeli cybersecurity firm Gambit Security attributed a March cyberattack on the Los Angeles County Metropolitan Transportation Authority (LACMTA) to the Iranian government. The breach, detected around March 16, involved the theft of approximately 700 gigabytes of emails and backups. While a pro-Iran group called Ababil of Minab claimed the attack was an act of hacktivism, Gambit Security linked the operation to infrastructure used by MuddyWater, a group associated with Iran's Ministry of Intelligence and Security.

Attackers used ChatGPT to refine Python scripts used to wipe disks and delete virtual machines. The breach disrupted the LA Metro mobile app's contactless payment system and affected arrival screens, forcing the agency to inspect 1,400 servers before restoring services. LACMTA officials stated that essential rail and bus circulation remained uninterrupted. The broader campaign also targeted the Tri-Rail commuter system in South Florida, the vehicle tracking company Vyncs, and the construction firm UNIMAC in Saudi Arabia.

These incidents align with a wider Iranian espionage campaign conducted between February and April 2026 by the group Screening Serpens, also known as Nimbus Manticore. This broader effort targeted aerospace, defense, and telecommunications sectors across the U.S., Israel, Europe, and the United Arab Emirates using AI-assisted backdoors and SEO poisoning. The FBI is currently coordinating a response to the LACMTA incident.


Reported across 31 outlets
Actors
Government of IranFederal Bureau of InvestigationEyal Sela

Keep reading in the app

The full story and every source, free in the app.

Download on the App StoreComing soonGoogle Play