California city reports ransomware attack as LA transit agency finds ‘unauthorized activity’
2026-03-22T14:52:00Z•de90c4078b95097c26de32c8ecb50a92f969367a1a0a47824d6860915a6c6bc1
AI-fraudAisuruDDoSDOJFBIFoster-CityHandalaIran-MOISJackSkidKimWolfLA-MetroMossadSection-702account-fraudbotnetdata-exposuredomain-seizureinfrastructure-takedownleak-siteslegallocal-governmentransomwarestreaming-fraud
What happened
Multiple significant cyber incidents reported: Foster City disclosed a ransomware attack that may have exposed public-facing information and advised residents and vendors to change passwords (LA Metro also reported “unauthorized activity”). The FBI executed seizures against online leak sites tied to Iran’s Ministry of Intelligence and Security (MOIS/“Handala”), and the DOJ seized infrastructure and domains used by large botnets—Aisuru, KimWolf, JackSkid and Mossad—used in widespread DDoS campaigns. Separately, an individual pleaded guilty to an $8M scheme using thousands of fake accounts to la
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- therecord_media
- Record identifier
- de90c4078b95097c26de32c8ecb50a92f969367a1a0a47824d6860915a6c6bc1
- Enrichment time
- 2026-03-22T14:52:00Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.