California city reports ransomware attack as LA transit agency finds ‘unauthorized activity’

2026-03-21T20:52:00Z0555222b858a0e51c1e48d8b495e8bb50b52a23ed7207c4807536d5fe4e6aa1d
AisuruDDoSFBI-takedownJackSkidKimWolfMossadai-fraudbotnet-seizurecity-breachdata-exposuredomain-seizurehandalairan-moislaw-enforcementleak-siteslegal-policypublic-sectorransomwaresection-702streaming-fraudtransit-securityunauthorized-activity

What happened

Multiple cybersecurity and cybercrime developments: Foster City reported a ransomware incident that may have exposed public information and advised residents to change passwords; LA Metro detected unspecified unauthorized activity. The FBI executed a seizure of leak sites tied to Iran’s Ministry of Intelligence and Security (MOIS), operating under aliases including “Handala.” The U.S. Justice Department also seized infrastructure for four large botnets (Aisuru, KimWolf, JackSkid, Mossad) used in DDoS campaigns. Separately, an individual pleaded guilty to an $8M scheme using thousands of fake账号

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
0555222b858a0e51c1e48d8b495e8bb50b52a23ed7207c4807536d5fe4e6aa1d
Enrichment time
2026-03-21T20:52:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.