securityaffairs.com 5/27/2026, 2:32:02 PM · external

Iran-linked group wipes LA Metro data, sparks espionage fears

Iran-linked group wipes LA Metro data, sparks espionage fears
CyberSIXT Evidence Panel
Threat Actor

THE article discusses a cyber attack on the LA Metro attributed to an Iranian group called Ababil of Minab, linked to Iran's intelligence service (MOIS). In March 2026, this group claimed responsibility for breaching LA Metro, wiping out terabytes of data and stealing sensitive information. Researchers from Gambit Security analyzed the attack, confirming it was executed using sophisticated methods, including automation and manual commands for data destruction.

The report suggests that this operation masked itself under the guise of hacktivism, but evidence indicates it was a state-sponsored intelligence operation. The attackers also targeted other organizations, implementing custom tools for exfiltration while presenting their actions as hacktivist activities.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline