Back to overview
Confidence MediumMay 27, 2026metro.net

Iranian Hackers Blamed for Los Angeles County Metropolitan Transportation Authority Breach

PatternExternal actor · Hacking · Confidentiality impact

Iranian hackers were reportedly responsible for a breach of the Los Angeles County Metropolitan Transportation Authority (LA Metro) that disrupted parts of the transit environment in California. The investigation involved exposed internal data and operational disruption. Security researchers linked the intrusion to Iran-aligned Ababil activity, with reports describing stolen emails, backups, and a video showing access inside the target network.

Signal date
May 27, 2026
Updated
Jun 24, 2026
Confidence
Medium
Sources
2 sources

Signal context

First seen: May 27, 2026

Last updated: Jun 24, 2026

Status: Public signal

Key points

  • Iranian hackers blamed for the breach.
  • Disrupted parts of the transit environment.
  • Exposed internal data and operational disruption.

Signal analysis

Beta

It helps compare this signal with other published signals without treating the labels as final determinations.

Affected organization
Metro logo
Metro

Likely country: Location not provided

Threat source
Hacking activity

Watch internet-facing systems, credential abuse and exploit activity.

  • Source type: outside the affected organization
Business impact
Potential operational disruption

Impact area: Confidentiality, Availability

Likely asset: User or customer data

Trend context
51 signals with similar action pattern
  • 1 signal in the same sector
  • 69 signals with the same likely impact area
  • 1 signal linked to this organization/domain
Mentioned entities
MetroData DisclosureIranian Hackers Blamed for LosAngeles County Metropolitan Transportation AuthorityLos Angeles County Metropolitan TransportationAuthorityLA MetroCalifornia. TheIran-aligned AbabilIranian

External sources

Related signals

Grouped by why the signal is relevant.

fluke.com logoFlukeMay 22, 2026
Same action patternSame impact area

Fluke Corporation data breach impacts over 18,000, Clop claims responsibility

Fluke Corporation notified over 18,000 people of a data breach that occurred between August 10 and October 7, 2025. The breach, resulting from an exploited vulnerability in a third-party application, compromised highly sensitive personal information including SSNs, birth dates, and disability status. The Clop ransomware group claimed responsibility.

tampabaydentalimplants.com logoTampabaydentalimplantsMay 22, 2026
Same action patternSame impact area

Tampa Bay Dental Implants & Prosthetics discloses ransomware attack and data exposure

Tampa Bay Dental discovered unauthorized access to its network on January 19, 2026, when ransomware was used to encrypt files on a legacy server containing a backup of electronic medical records. Patient data, including names, contact information, birth dates, treatment notes, clinical histories, and for some, Social Security numbers, was exposed.

lastpass.com logoLastpassJun 23, 2026
Same action patternSame impact area

LastPass confirms data breach in Klue supply chain attack

LastPass announced that hackers accessed customer data from its Salesforce environment after stealing the company's OAuth tokens in a supply chain attack targeting Klue, a third-party market intelligence platform. The unauthorized actor obtained OAuth tokens from Klue, which were then used to access LastPass customer data. Exposed information includes customer names, phone numbers, email addresses, physical addresses, support case information, and sales/CRM-related data. LastPass stated that its core products, services, and infrastructure, including customer vaults, were not affected by this incident. The Icarus extortion group claimed responsibility for the Klue attack.

snyk.io logoSnykJun 22, 2026
Same action patternSame impact area

Snyk impacted by Klue supply chain attack

Snyk, a cybersecurity firm, was affected by a supply chain attack on market intelligence platform Klue. The attack compromised Klue's integration with Salesforce, leading to the exfiltration of business information from Snyk's Salesforce CRM, including sales account data and business contact information such as names, email addresses, job titles, and phone numbers. Snyk stated the intrusion was limited to its Salesforce instance and did not involve its internal systems.

onetrust.com logoOnetrustJun 22, 2026
Same action patternSame impact area

OneTrust impacted by Klue supply chain attack

OneTrust, a cybersecurity firm, was affected by a supply chain attack on market intelligence platform Klue. The attack compromised Klue's integration with Salesforce, leading to the exfiltration of business information from OneTrust's Salesforce CRM, including sales account data and business contact information such as names, email addresses, job titles, and phone numbers. OneTrust stated the intrusion was limited to its Salesforce instance and did not involve its internal systems.

jamf.com logoJamfJun 22, 2026
Same action patternSame impact area

Jamf impacted by Klue supply chain attack

Jamf, a cybersecurity firm, was affected by a supply chain attack on market intelligence platform Klue. The attack compromised Klue's integration with Salesforce, leading to the exfiltration of business information from Jamf's Salesforce CRM, including sales account data and business contact information such as names, email addresses, job titles, and phone numbers. Jamf stated the intrusion was limited to its Salesforce instance and did not involve its internal systems.