California city reports ransomware attack as LA transit agency finds ‘unauthorized activity’

2026-03-21T08:51:54Zbdc9c0842d2faaec8d8051bfac46f115b9b55a0763c8fd3d0a053f00fae3f075
account-fraudai-fraudaisurubotnetdata-exposureddosdojdomain-seizurefbihandalaincident-responseiran-moisjackskidkimwolflaw-enforcement-takedownleak-sitesmossadmunicipalransomwaresection-702streaming-fraudsurveillance-policy

What happened

A batch of security stories: Foster City, California reported a ransomware attack that may have exposed public information and urged residents and vendors to change passwords and protect personal data. The FBI seized leak sites tied to Iran’s Ministry of Intelligence and Security (MOIS), which operated under names including “Handala,” per a detailed seizure warrant. The DOJ also seized domains and infrastructure linked to large botnets (Aisuru, KimWolf, JackSkid and Mossad) used to mount DDoS campaigns. Separately, Rep. Darin LaHood discussed the political challenges around Section 702 re‑auth

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
bdc9c0842d2faaec8d8051bfac46f115b9b55a0763c8fd3d0a053f00fae3f075
Enrichment time
2026-03-21T08:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.