California city reports ransomware attack as LA transit agency finds ‘unauthorized activity’
2026-03-22T02:51:55Z•768d66ea42eb6fcdd3ee3690b6b2d2a0347595ab816823ac1e6f32c83291291a
AI-fraudAisuruDDoSFBI-seizureHandalaIran-MOISJackSkidKimWolfMossad-botnetSection-702account-fraudbotnet-takedowndata-exposuredomain-seizurelaw-enforcementleak-siteslegislationmunicipal-breachpassword-resetransomwarestreaming-fraudunauthorized-activity
What happened
A batch of US cyber and legal news: Foster City reported a ransomware attack that may have exposed public information and urged residents to change passwords; LA Metro detected unspecified “unauthorized activity.” The FBI executed seizures of leak websites tied to Iran’s Ministry of Intelligence and Security (MOIS), including sites using the ‘Handala’ moniker, per a detailed seizure warrant. The DOJ also announced takedowns/seizures of infrastructure for multiple botnets (Aisuru, KimWolf, JackSkid, Mossad) used for large-scale DDoS campaigns. Separately, Rep. Darin LaHood commented on the need
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- 768d66ea42eb6fcdd3ee3690b6b2d2a0347595ab816823ac1e6f32c83291291a
- Enrichment time
- 2026-03-22T02:51:55Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.