California city reports ransomware attack as LA transit agency finds ‘unauthorized activity’

2026-03-23T08:51:58Z8121cfed7a9c6624284c2a9a09f36be699eb1f09edf939bb17e6f9cfa44005d2
AI-generated-musicAisuruDDoSFBIFoster CityHandalaIranJackSkidKimWolfLA MetroMOISMossadSection-702botnetdata-breachdomain-seizurefraudguilty-pleaincident-responselegislationpassword-resetransomwarestreaming-fraudtakedowntransit

What happened

A batch of cybersecurity and policy stories: Foster City reported a ransomware incident and warned that public information may have been accessed, urging affected residents and businesses to change passwords; LA Metro reported ‘unauthorized activity.’ The FBI executed a 40-page seizure warrant to take down leak sites tied to Iran’s Ministry of Intelligence and Security (MOIS), operating under aliases including “Handala.” The U.S. Justice Department seized domains and infrastructure for four large botnets — Aisuru, KimWolf, JackSkid and Mossad — that were used in widespread DDoS campaigns. Law‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
8121cfed7a9c6624284c2a9a09f36be699eb1f09edf939bb17e6f9cfa44005d2
Enrichment time
2026-03-23T08:51:58Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · California city reports ransomware attack as LA transit agency finds ‘unauthorized activity’ · Baitaphish