Israeli cybersecurity firm Gambit Security says it discovered at least 700 GB of Los Angeles County Metropolitan Transportation Authority data exposed online and traced the server to a Tehran‑linked hacking operation. A pro‑Iran group calling itself Ababil of Minab claimed the March attack, which disabled some arrival screens and temporarily prevented transit card top‑ups. Gambit alerted authorities; the FBI and CISA have been notified while LACMTA and other officials continue investigations.
Israeli Firm Says Iranian-Linked Hackers Behind March Los Angeles Transit Breach, Exposing 700GB of Data

May 26 (Reuters) - Israeli cybersecurity firm Gambit Security says Iranian-linked hackers were behind a disruptive March intrusion that forced parts of the Los Angeles County Metropolitan Transportation Authority's (LACMTA) network offline and exposed at least 700 gigabytes of emails, backups and other files.
Gambit, a Tel Aviv–based cyber startup founded in part by veterans of Israel's Unit 8200, reported finding the misappropriated archive after it was inadvertently exposed on a server. In a report published Tuesday, the company said a digital trail of forensic evidence tied the hosting server to a previously identified hacking operation that Israeli officials and researchers have traced to Tehran.
Attribution And Response
“A connection between Ababil and the Iranian state has been a working assumption. What our research adds is the forensic evidence to support it,” said Eyal Sela, Gambit’s director of threat intelligence.
Gambit said it alerted relevant authorities after discovering the exposed archive. The FBI said it was aware of the LACMTA incident and was "coordinating with partners in response," but declined further comment. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) did not respond to requests for comment. Iran's mission to the United Nations and Israel's National Cyber Directorate also did not reply to requests for comment.
LACMTA officials told Reuters the intrusion was first detected around March 16 and that they worked with law enforcement and cybersecurity specialists while restoring systems. The transit authority has said attribution is part of the investigation and it would not speculate.
Claims, Impact And Wider Context
An obscure pro‑Iran group calling itself Ababil of Minab claimed responsibility roughly two weeks after the breach, publishing a video that purported to show intruders moving through the transit system's network. Local reporting said the breach disabled some arrival screens and temporarily prevented customers from adding funds to transit cards, though officials said train and bus circulation was not interrupted.
Ababil has also claimed responsibility for hacks affecting South Florida's Tri‑Rail commuter system, vehicle‑tracking company Vyncs and Saudi firm Unimac. Tri‑Rail confirmed it was hacked and said none of the affected data was critical. Vyncs said it detected a breach on April 2 but declined to describe the stolen data. Gambit said its analysis suggests Ababil targeted additional organizations, including a media outlet and educational institution in Israel and an insurance brokerage in Turkey, though it declined to name them.
Israeli and U.S. cyber specialists say Iranian‑linked hackers have maintained a steady tempo of operations since hostilities escalated in the region earlier this year. Reported incidents attributed to Iranian actors include a damaging intrusion at medical device maker Stryker and the publication of personal emails claimed to belong to Kash Patel, a former U.S. defense official. Some reports have also alleged suspected tampering with fuel gauges at gas stations.
What Remains Unclear
Gambit's findings reinforce suspicions about the attackers' links to Tehran, but LACMTA and other authorities continue formal investigations. Attribution in cyber incidents is complex, and officials have emphasized they will not publicly assign blame until probes are complete.
Help us improve.




























