California city reports ransomware attack as LA transit agency finds ‘unauthorized activity’

2026-03-21T14:52:01Zb877470336277d4f91559a3d62f8aa97fc913106ff4945147fe5d7277aaeb0ad
AI-generated fraudAisuruDDoSFBIFoster CityHandalaIran MOISJackSkidKimWolfLA MetroMossadSection 702botnetdata exposuredomain seizurelaw enforcementleak sitesransomwarestreaming fraudsurveillance policytransit agency

What happened

Collection of security and policy incidents: Foster City reported a ransomware attack that may have exposed public information and advised affected individuals to reset passwords and protect personal data; LA Metro reported unspecified unauthorized activity. The FBI seized leak sites tied to Iran’s Ministry of Intelligence and Security (MOIS), operating under names including “Handala.” The U.S. DOJ also seized infrastructure and domains for multiple botnets (Aisuru, KimWolf, JackSkid, Mossad) used in large-scale DDoS campaigns. Separately, an individual pleaded guilty to an $8M scheme inflatng

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
b877470336277d4f91559a3d62f8aa97fc913106ff4945147fe5d7277aaeb0ad
Enrichment time
2026-03-21T14:52:01Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.