Gambit links Iranian MOIS to LA Metro breach

Get the Geopolitics newsletter
Daily geopolitics — wars, elections, sanctions, the diplomatic moves that move markets. Free.
- Gambit Security linked the March LACMTA breach to Iran’s Ministry of Intelligence and State Security (MOIS) using forensic evidence.
- Ababil of Minab claimed it stole and deleted LACMTA data, but Gambit says the group is a front for MOIS rather than an independent hacktivist crew.
- LACMTA's systems were disrupted for weeks, with recovery extending well beyond the initial attack.
- U.S. agencies warned in April that Iranian‑backed hackers were stepping up attacks on American critical infrastructure after recent U.S. and Israeli strikes on Iran.
- The Hacker News reported that Iranian actors are deploying tools like MiniFast and MiniJunk V2 via phishing and SEO poisoning, indicating a broader campaign beyond the LACMTA hack.
Why it matters: The Los Angeles transit authority suffers weeks‑long service disruption and costly recovery, while U.S. critical infrastructure faces elevated cyber risk, pushing agencies to tighten defenses and allocate extra security budgets.


