Hackers stole at least 700 gigabytes of emails, backups, and other files from the Los Angeles transit authority, with the intrusion detected around March 16, 2026, according to i24NEWS. This massive data exfiltration from a major metropolitan system points to an intelligence-gathering objective beyond simple disruption.
A major US city's public transit system, a critical piece of infrastructure, proved vulnerable to a state-sponsored cyberattack. The breach of the Los Angeles County Metropolitan Transportation Authority (LACMTA) reveals a growing threat to public services.
Based on this successful breach and attribution, state-sponsored cyberattacks targeting US critical infrastructure will likely increase in frequency and sophistication, posing a significant national security challenge.
The Attackers and Their Methods
- Pro-Iranian hacking group Ababil of Minab claimed responsibility for a March 2026 hack on the Los Angeles County Metropolitan Transportation Authority, according to Defense One.
- A March 2026 breach of the Los Angeles transit system (LACMTA) was the work of Iranian-backed hackers, according to Israeli startup Gambit Security.
- 700 gigabytes of data was stolen during the breach of the Los Angeles transit system, according to WION.
The rapid claim of responsibility by a known pro-Iranian group, combined with security firm analysis, quickly confirmed a state-backed operation. Dual attribution underscores the complex nature of state-sponsored cyber warfare, where front groups often obscure the true perpetrators while executing significant data exfiltration.










