Iranian-backed hackers were responsible for a March 2026 breach of the Los Angeles County Metropolitan Transportation Authority (LACMTA) that took weeks to recover from, according to a report released Tuesday by Israeli cybersecurity firm Gambit Security.
Gambit identified the attackers as employees of Iran’s Ministry of Intelligence and State Security (MOIS), operating under the guise of a hacktivist group called Ababil of Minab. The group had claimed responsibility for the hack, saying it stole and then deleted data from LACMTA’s systems. Reuters first reported on the Gambit findings.
“They are not a new, standalone hacktivist crew as they claim,” Gambit said in its report. The firm said its conclusions are based on forensic evidence linking the group to a previous Iran-connected campaign, as well as activity attributed to MOIS by Israel’s National Cyber Directorate. Gambit said it also investigated attacks tied to the group against organizations in Israel, Saudi Arabia, and Turkey.
The group’s name references a U.S. air strike on an Iranian school in the city of Minab that killed more than 175 people, mostly children. Ababil of Minab did not respond to a request for comment from TechCrunch.
If Gambit’s assessment is accurate, Ababil of Minab would be the latest in a series of fake hacktivist fronts linked to the Iranian government. A comparable group, Handala, hacked U.S. medical technology company Stryker earlier in 2026, wiping thousands of company systems and employee devices. Following that breach, the FBI seized two Handala websites and the U.S. Justice Department formally accused Iran’s government of directing the group.
The LACMTA breach fits a broader pattern: Iranian-linked hacking activity has increased since the U.S. and Israel began bombing Iran in 2026. In April, a coalition of U.S. agencies warned that Iranian hackers were actively targeting American critical infrastructure.
Source: TechCrunch