Skip to content

Los Angeles Metro cyber intrusion

Summary

Los Angeles County Metropolitan Transportation Authority logo

LA Metro restricted internal administrative systems after detecting unauthorized activity March 16, disrupting arrival information and some TAP fare-loading channels while buses and trains continued operating. Ababil of Minab claimed the intrusion; later technical research found LA Metro data on infrastructure tied to the operation, supporting high-confidence attribution and data theft but not the actor’s claimed destruction or exfiltration volumes. The incident is presumed resolved because no continuing operational impact has been documented since April 2.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

  • Malware

    Malicious software other than ransomware used to compromise or disrupt systems.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Data publication or leak

    Stolen, exposed, or otherwise compromised data was publicly released, posted, distributed, or offered for download.

  • Data deletion or destruction

    Data was intentionally deleted, wiped, destroyed, or made permanently unrecoverable.

Operational impacts

  • Degraded service

    Services remained available but with reduced performance, reliability, functionality, capacity, or responsiveness.

  • Application unavailable

    A specific application or software platform became unavailable or unusable.

  • Payment processing disruption

    The organization could not process, receive, issue, reconcile, or record payments normally.

  • Transportation operations disrupted

    Transit, aviation, rail, maritime, logistics, fleet, traffic, ticketing, or related transportation operations were materially affected.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Data sample published

    The actor published or shared a sample of allegedly stolen victim data to substantiate the extortion claim.

Incident narrative

Analyst assessment

Los Angeles Metro detected unauthorized activity March 16 and restricted employee access to internal administrative systems. The Los Angeles Times reported April 2 that restoration remained underway and that Metro was reviewing about 1,400 servers individually before returning them to service. Bus and rail service and safety systems continued operating, but the incident affected arrival information, service alerts and some TAP fare-loading channels.

Ababil of Minab claimed the intrusion March 31. The actor alleged that it wiped more than 500 terabytes and stole more than 1 terabyte of sensitive data, offered a 17.1-megabyte proof-of-concept archive and threatened more severe future action. Those figures and the full destruction claim remain unverified.

Later technical research materially strengthened the underlying claim. Gambit Security found custom exfiltration tooling and infrastructure overlap with an Iran-linked operation, while Hunt.io found more than 1 gigabyte of LA Metro database backups, operational and personnel records, SCADA configurations, yard-management material and employee email archives on an exposed staging server associated with the campaign. DysruptionHub therefore assesses with high confidence that data was stolen and that Ababil of Minab was connected to the intrusion.

Operational significance

The incident disrupted administrative and customer-information systems across LA Metro’s Los Angeles County service area. Arrival monitors stopped displaying real-time information, service alerts were delayed and riders encountered problems reloading TAP cards through some channels. Metro maintained essential bus and rail circulation and said transit safety and security systems continued operating.

The prolonged server-by-server recovery establishes material operational disruption even though the agency’s core transportation service continued. Public evidence does not establish that train-control or other operational-technology systems were manipulated. Images posted by the actor purported to show access to a rail-yard management display, but that assertion was not confirmed by Metro.

Disclosure posture

LA Metro’s public cyber wording preceded the actor claim. Metro acknowledged unauthorized activity and system restrictions in reporting published before Ababil of Minab’s March 31 website post, supporting an organization-first cyber-transparency assessment.

The actor’s post is a stable victim claim, not proof of every assertion. Gambit and Hunt.io independently linked LA Metro data and operator tooling to the broader operation, but Metro told Reuters that attribution remained under investigation and that it would not speculate. No U.S. government agency publicly attributed the incident in the reviewed sources.

Current status

The incident is presumed resolved. The latest authoritative source documenting continuing impact was the April 2 Los Angeles Times report that system restoration remained underway. No later authoritative source identified continuing service-delivery effects or a formal all-clear.

Confidence and uncertainty

Confidence is high that a cyber intrusion caused the administrative restrictions and rider-facing degradation because LA Metro directly acknowledged unauthorized activity. Confidence is also high that data was stolen because researchers found LA Metro material on infrastructure associated with the operation.

Threat-actor confidence is high, but not confirmed. The direct claim, matching victim data and campaign infrastructure support Ababil of Minab attribution; Metro did not confirm the actor, and Hunt.io did not independently verify Gambit’s further attribution to Iran’s Ministry of Intelligence and Security.

The evidence supports destructive activity but not ransomware. No reviewed source identified encryption, a ransom demand, payment instructions or a payment condition. The actor published a sample and threatened future harm, but its public messaging was ideological rather than financial.

Analytic gaps

The public record does not establish the initial-access vector, compromised account, exploited vulnerability, dwell time, full affected-system inventory, verified destruction volume, complete stolen-data volume, affected-person count, notification obligations, final restoration date or whether operational technology was directly altered. It also does not establish whether any organization besides Ababil of Minab participated in the intrusion or whether the Iranian government directed the operation.

Threat actor and claim

Listed as: LA Metro / metro.netSource: otherPublished: Discovered:

Claim details

Ababil of Minab listed LA Metro and metro.net on its website and claimed it penetrated systems, wiped more than 500 terabytes and extracted more than 1 terabyte of sensitive data. The page offered a 17.1-megabyte proof-of-concept ZIP and threatened more severe future action. LA Metro did not confirm the actor or claimed volumes. Later Gambit Security and Hunt.io research found LA Metro data on infrastructure associated with the operation, supporting the underlying compromise and data theft but not every actor assertion.

Screenshot documenting Ababil of Minab claim

Organizations involved

Impacted locations

Sources

metro.net is HACKED

Ababil of Minab listed LA Metro and claimed it penetrated systems, wiped more than 500 terabytes and extracted more than 1 terabyte. The page offered a 17.1-megabyte proof-of-concept ZIP and threatened more severe future action; the quantities remain unverified.

L.A. Metro confirms it was hacked. Weeks later, it's still getting systems back online

LA Metro said it detected unauthorized activity March 16 and restricted access to internal administrative systems. About 1,400 servers were still being reviewed individually April 2, while bus, rail, safety and security systems continued operating.

Ababil of Minab: How an Iran-Linked Crew Exfiltrated Data From Four Countries and Destroyed IT, Backups, and Recovery at a subset of victims

Gambit Security linked the Ababil of Minab campaign to prior Iran-linked infrastructure and described custom exfiltration tooling and destructive techniques across virtualization, storage and backup systems. Gambit said LA Metro systems were destroyed and data was exfiltrated, while noting it was not Metro’s incident-response provider.

Iranian hackers responsible for Los Angeles transit system breach, Israeli researchers say

Reuters reported that Gambit Security found at least 700 gigabytes of LA Metro emails, backups and other files. Metro said attribution remained under investigation and it would not speculate; the FBI said it was coordinating with partners.

Ababil of Minab Exposed: LA Metro SCADA Backups and Israeli Victim Data Left Open on an Iranian Staging Server

Hunt.io found more than 1 gigabyte of LA Metro SQL backups, operational and personnel records, SCADA configurations, yard-management data and employee email archives on an exposed staging server. It also recovered custom exfiltration tooling and operator command history.

Los Angeles County Metropolitan Transportation Authority official website

The organization’s official website describes its identity, services, operating role and public or customer-facing programs.

See something that needs correction?

Signed-in members can report an error, update, or missing source.