California city reports ransomware attack as LA transit agency finds ‘unauthorized activity’
2026-03-21T14:52:01Z•b877470336277d4f91559a3d62f8aa97fc913106ff4945147fe5d7277aaeb0ad
AI-generated fraudAisuruDDoSFBIFoster CityHandalaIran MOISJackSkidKimWolfLA MetroMossadSection 702botnetdata exposuredomain seizurelaw enforcementleak sitesransomwarestreaming fraudsurveillance policytransit agency
What happened
Collection of security and policy incidents: Foster City reported a ransomware attack that may have exposed public information and advised affected individuals to reset passwords and protect personal data; LA Metro reported unspecified unauthorized activity. The FBI seized leak sites tied to Iran’s Ministry of Intelligence and Security (MOIS), operating under names including “Handala.” The U.S. DOJ also seized infrastructure and domains for multiple botnets (Aisuru, KimWolf, JackSkid, Mossad) used in large-scale DDoS campaigns. Separately, an individual pleaded guilty to an $8M scheme inflatng
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- b877470336277d4f91559a3d62f8aa97fc913106ff4945147fe5d7277aaeb0ad
- Enrichment time
- 2026-03-21T14:52:01Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.