Gambit links Iranian MOIS to LA Metro breach — SkimNews

Get the Geopolitics newsletter
Daily geopolitics — wars, elections, sanctions, the diplomatic moves that move markets. Free.
- Gambit Security linked the March LACMTA breach to Iran’s Ministry of Intelligence and State Security (MOIS) using forensic evidence.
- Ababil of Minab claimed it stole and deleted LACMTA data, but Gambit says the group is a front for MOIS rather than an independent hacktivist crew.
- LACMTA's systems were disrupted for weeks, with recovery extending well beyond the initial attack.
- U.S. agencies warned in April that Iranian‑backed hackers were stepping up attacks on American critical infrastructure after recent U.S. and Israeli strikes on Iran.
- The Hacker News reported that Iranian actors are deploying tools like MiniFast and MiniJunk V2 via phishing and SEO poisoning, indicating a broader campaign beyond the LACMTA hack.
Why it matters: The Los Angeles transit authority suffers weeks‑long service disruption and costly recovery, while U.S. critical infrastructure faces elevated cyber risk, pushing agencies to tighten defenses and allocate extra security budgets.
Ask SkimNews



