California city reports ransomware attack as LA transit agency finds ‘unauthorized activity’

2026-03-22T14:52:00Zde90c4078b95097c26de32c8ecb50a92f969367a1a0a47824d6860915a6c6bc1
AI-fraudAisuruDDoSDOJFBIFoster-CityHandalaIran-MOISJackSkidKimWolfLA-MetroMossadSection-702account-fraudbotnetdata-exposuredomain-seizureinfrastructure-takedownleak-siteslegallocal-governmentransomwarestreaming-fraud

What happened

Multiple significant cyber incidents reported: Foster City disclosed a ransomware attack that may have exposed public-facing information and advised residents and vendors to change passwords (LA Metro also reported “unauthorized activity”). The FBI executed seizures against online leak sites tied to Iran’s Ministry of Intelligence and Security (MOIS/“Handala”), and the DOJ seized infrastructure and domains used by large botnets—Aisuru, KimWolf, JackSkid and Mossad—used in widespread DDoS campaigns. Separately, an individual pleaded guilty to an $8M scheme using thousands of fake accounts to la

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
de90c4078b95097c26de32c8ecb50a92f969367a1a0a47824d6860915a6c6bc1
Enrichment time
2026-03-22T14:52:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.