Claim details
Ababil of Minab claimed in a June 9 post that it compromised IT Curves, affected 20 “critical machines,” wiped about 20 terabytes of data and exfiltrated roughly 2 terabytes of sensitive information. Confidence in those figures is low because they come solely from the group’s post and have not been independently verified. A review of the group’s claim site appear to show IT Curves-branded systems and files, which provides limited visual support for possible access, but the images do not establish when the access occurred, whether the material is authentic or whether the claimed scale of destruction and theft is accurate.
There is moderate confidence that a real service disruption occurred because Allegany County publicly told Transit riders to reconfirm certain paratransit trips after a cybersecurity incident involving an unnamed third-party scheduling vendor. However, there is low confidence in directly linking that disruption to IT Curves because the county did not identify the vendor, and neither the county nor IT Curves confirmed that IT Curves was involved. There is also low confidence in attributing the incident to Ababil of Minab because no affected entity or law enforcement agency publicly confirmed the group’s involvement.
The group’s broader transportation-sector activity adds context but does not verify this claim. Security researchers have linked the Ababil of Minab persona to other transportation-related intrusions and Iran-aligned infrastructure, giving the allegation some contextual credibility. Still, confidence remains low to moderate overall until IT Curves, Allegany County, law enforcement or another authoritative source confirms the compromise, affected systems, data theft, data wiping or threat actor.

