IT Curves attack claim followed paratransit disruption
Summary
Allegany County Transit said a cybersecurity incident involving a third-party scheduling vendor required riders with May 6–7, 2026, pickups to call and confirm their trips. Public evidence points to IT Curves as the likely vendor, while Ababil of Minab separately claimed it compromised IT Curves and wiped and stole data; neither the vendor link nor the actor’s technical claims were confirmed.
Key facts
Timeline
-
Incident start:
?
Earliest known or assessed start of malicious activity or incident activity. -
First public signal:
?
Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity. -
First public cyber evidence:
?
Earliest credible public information connecting the incident or disruption to malicious cyber activity. -
Official cyber disclosure:
?
First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related. -
Last impact seen:
?
Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
Primary victim organization
DysruptionHub coverage
Impacted locations
Organization types
Critical infrastructure sector
Incident characteristics
Assessments
- Status:
- Presumed Resolved
- Incident confidence:
- Medium
- Ransomware:
- Not Ransomware
- Attribution:
- Low
DD-CIT classification
Only external sources publicly identify the event as cyber-related. Credible external sources document the disruption, but the organization does not clearly do so.
Attack mechanisms
-
Unknown cyber mechanism
The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.
Data impacts
-
Unknown data impact
The incident is cyber-related, but available evidence does not establish whether or how data was affected.
Operational impacts
-
Scheduling disruption
Appointment, booking, reservation, dispatch, staffing, or other scheduling functions were unavailable or impaired.
-
Manual workaround required
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
-
Transportation operations disrupted
Transit, aviation, rail, maritime, logistics, fleet, traffic, ticketing, or related transportation operations were materially affected.
-
Third-party service disruption
The incident materially affected services delivered by or through a vendor, managed service provider, contractor, partner, or other third party.
Extortion indicators
-
No known extortion indicator
Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.
Incident narrative
Analyst assessment
DysruptionHub assesses with medium confidence that a cyber incident affecting an unnamed third-party paratransit scheduling vendor disrupted Allegany County Transit trip confirmations in May 2026. DysruptionHub’s published report documents a May 6 county notice directing riders with pickups on May 6 and May 7 to call Transit and confirm their trips. The county did not identify the vendor.
Publicly visible IT Curves-hosted systems and transit-industry listings support a possible connection to IT Curves, but neither Allegany County nor IT Curves has confirmed that relationship. The available evidence therefore establishes a vendor-related cyber disruption and only a medium-confidence association with IT Curves.
Operational significance
The confirmed effect was a two-day loss of confidence in near-term paratransit scheduling records. Riders had to use a telephone workaround to verify trips, creating additional work for riders and transit staff. The public record does not establish that any trip was missed or delayed, that later reservations were affected, or that another customer experienced disruption.
IT Curves describes products supporting scheduling, reservations, dispatch, rider communications and vehicle management. Those functions make a vendor incident potentially consequential for transit continuity, but the reviewed evidence supports only the limited Allegany County impact and does not establish broader platform disruption.
Disclosure posture
Allegany County disclosed the vendor-related cybersecurity incident in a May 6 Facebook notice. The notice was no longer public after DysruptionHub sent questions in June, and the county did not explain whether it was deleted, restricted, edited or replaced. IT Curves has not publicly confirmed a compromise, operational disruption, data theft or data destruction in the reviewed sources.
Current status
May 7 is the latest supported operational-impact date because it was the final pickup date covered by the county’s confirmation workaround. No later impact evidence or authoritative restoration notice was found by July 26. The known operational impact is presumed resolved after 80 days without a newer observation; that lifecycle assessment is not an authoritative all-clear for the underlying vendor incident.
Confidence and uncertainty
A persona calling itself Ababil of Minab claimed on June 9 that it compromised 20 critical IT Curves machines, wiped about 20 TB of data and exfiltrated about 2 TB. Those figures remain unverified. Gambit Security’s research connects the persona to a broader Iran-linked destructive campaign, but it predates and does not verify the IT Curves claim.
Confidence is high that Allegany County used a manual trip-confirmation workaround because the county documented it. Confidence that IT Curves was the affected vendor is medium, and confidence in Ababil of Minab attribution remains low. The actor’s claim does not establish a specific access method, confirmed data theft, data destruction or extortion.
Analytic gaps
The public record does not conclusively identify the vendor, initial access vector, affected systems, attack duration, restoration method, number of affected customers or responsible actor. It also does not establish whether rider information was accessed, whether any trips were missed, or whether the claimed wiping and exfiltration occurred.
Threat actor and claim
Claim details
Ababil of Minab claimed in a June 9 post that it compromised IT Curves, affected 20 “critical machines,” wiped about 20 terabytes of data and exfiltrated roughly 2 terabytes of sensitive information. Confidence in those figures is low because they come solely from the group’s post and have not been independently verified. A review of the group’s claim site appear to show IT Curves-branded systems and files, which provides limited visual support for possible access, but the images do not establish when the access occurred, whether the material is authentic or whether the claimed scale of destruction and theft is accurate.
There is moderate confidence that a real service disruption occurred because Allegany County publicly told Transit riders to reconfirm certain paratransit trips after a cybersecurity incident involving an unnamed third-party scheduling vendor. However, there is low confidence in directly linking that disruption to IT Curves because the county did not identify the vendor, and neither the county nor IT Curves confirmed that IT Curves was involved. There is also low confidence in attributing the incident to Ababil of Minab because no affected entity or law enforcement agency publicly confirmed the group’s involvement.
The group’s broader transportation-sector activity adds context but does not verify this claim. Security researchers have linked the Ababil of Minab persona to other transportation-related intrusions and Iran-aligned infrastructure, giving the allegation some contextual credibility. Still, confidence remains low to moderate overall until IT Curves, Allegany County, law enforcement or another authoritative source confirms the compromise, affected systems, data theft, data wiping or threat actor.

Organizations involved
IT Curves

Locations
Organization type
Critical infrastructure
Allegany County Transit

Locations
Organization type
Critical infrastructure
Impacted locations
Sources
- Type: News Report
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
DysruptionHub reported that Allegany County riders with May 6 and May 7 pickups had to call Transit to confirm trips because of a cybersecurity incident involving a third-party scheduling vendor. Public infrastructure pointed to IT Curves as the likely vendor, while Ababil of Minab separately claimed data wiping and theft that neither the company nor county confirmed.
- Type: Research Threat Intelligence
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
Gambit Security said Ababil of Minab was unlikely to be a new standalone hacktivist group and linked the persona through forensic evidence to infrastructure associated with an Iran-aligned campaign. The research described destructive operations against IT, applications, virtualization, storage and backups but did not verify the later IT Curves claim.
- Type: Public Record
- Stance: Report
- Platform: Website
- Medium: Web Page
- Confidence: High
IT Curves describes transportation-management software covering scheduling, reservations, dispatch, communications, vehicle management and related operations for public transit, paratransit and other transportation providers.