Intelligence. Accountability. Analysis.
Est. 2022 · Washington, D.C.
The Congressional Times
We follow the data, not the narrative
◆ Live Intelligence
Loading...
Analysis Loading today's analysis...
Federal Policy

LA Freeway Sign Hacked to Display Website Targeting Iranian Dissidents

LA Freeway Sign Hacked to Display Website Targeting Iranian Dissidents

The incident illustrates how foreign influence operations can exploit domestic infrastructure to reach diaspora communities on American soil, raising questions about federal jurisdiction and...

Gab-E Intelligence Platform · September 20, 2026

A digital traffic display on the 405 Freeway in Los Angeles was hacked to show the web address of a site that described itself as a campaign to identify and punish individuals it labeled traitors to Iran's Islamic regime, according to reporting by the New York Post on September 20, 2026. The sign appeared near Persian Square in the Westwood neighborhood, an area with a large Iranian diaspora population.

The website displayed on the sign, identified in the report as goorkan.info, described its purpose as a collective and patriotic effort to identify individuals the site's operators consider enemies of Iran's government. The site's content and framing are consistent with tactics the U.S. Intelligence community has previously attributed to Iranian state-affiliated actors seeking to intimidate dissidents abroad, though no U.S. Government agency has been publicly identified as having confirmed attribution in this specific incident as of the date of this report.

The 405 Freeway is one of the highest-traffic corridors in the United States. The California Department of Transportation, known as Caltrans, manages the digital variable message signs along the freeway. Caltrans has not issued a public statement specifically addressing this incident as of September 20, 2026. What document would clarify the timeline of the breach is a Caltrans incident report or a communication log from the agency's traffic management center.

Federal jurisdiction over this type of incident is shared across several agencies. The FBI's Cyber Division handles foreign cyber intrusions on domestic infrastructure. The Department of Homeland Security's Cybersecurity and Infrastructure Security Agency, known as CISA, oversees protection of critical infrastructure including transportation management systems. Neither agency had issued a public statement on this specific incident as of the publication of this article.

Iran-linked harassment and surveillance of diaspora communities in the United States has been a documented federal concern for several years. The Department of Justice has brought multiple criminal cases related to alleged Iranian government plots to monitor or harm dissidents and journalists on U.S. Soil. In 2022, the DOJ unsealed an indictment alleging an Iranian operative had sought to arrange the assassination of former National Security Advisor John Bolton, according to DOJ public records. In 2024, the DOJ charged Iranian nationals in connection with a plot targeting the 2024 presidential election, per DOJ press releases.

The targeting of transportation infrastructure message systems is not a new vulnerability class. In 2014, researchers demonstrated that variable message signs used on highways across multiple states used default passwords and unencrypted radio communications, as documented in a Trend Micro security research report published that year. Whether the 405 Freeway sign exploited a similar vulnerability or involved a more sophisticated intrusion is unknown. A CISA advisory or law enforcement filing would be the public record most likely to address the technical method used.

Iranian dissidents and community organizations in Los Angeles told the New York Post the incident created concern within the local Iranian diaspora. Los Angeles is home to one of the largest Iranian communities outside Iran, a population that includes many individuals who fled the Islamic Republic after 1979 and in subsequent years.

Congress has addressed Iranian influence operations in the United States through several legislative vehicles. The Countering America's Adversaries Through Sanctions Act, passed in 2017, included provisions targeting Iranian entities involved in human rights abuses and destabilizing activities, according to the text of Public Law 115-44. Oversight of foreign influence operations on domestic soil falls partly under the Senate Select Committee on Intelligence and the House Permanent Select Committee on Intelligence. Neither committee had issued a statement on this specific incident as of September 20, 2026.

The State Department's designation list under Executive Order 13224 and the Iran-related sanctions programs administered by the Treasury Department's Office of Foreign Assets Control are the primary federal tools for restricting Iranian government-linked actors. Whether any entity connected to the goorkan.info website appears on those lists is unknown as of this report. A search of OFAC's publicly available Specially Designated Nationals list by the relevant domain or associated organizational name would be the record to consult.

What remains unknown is who specifically orchestrated the hack, how long the message was displayed before it was removed, whether Caltrans has filed a report with law enforcement, and whether federal agencies have opened a formal investigation. A FOIA request to CISA, the FBI Los Angeles field office, or Caltrans would be the appropriate mechanism to obtain those records. This story will be updated when agency responses become available.

Today's Analysis
Loading...
Latest Intelligence
Congressional Intelligence
Loading...
Financial Intelligence
Loading...
Geopolitical Intelligence
Loading...
Follow the MoneyGab-E Political Intelligence Investigation
Loading...
Opinion & Analysis
Loading...
Archive
Loading...
About
Our Mission

We Follow the Data, Not the Narrative

The Congressional Times exists because public records are public — and the analysis built from them should not be exclusive to those who can afford $60,000-a-year intelligence subscriptions.

Every story published in The Congressional Times is sourced to a verifiable public record: a court filing, a Senate lobbying disclosure, an FEC contribution record, a USASpending contract, or a verified news report. We state our sources inline. We show our math. When we are wrong, we say so publicly.

We do not editorialize in news coverage. We do not use loaded language. Both political parties are held to identical standards.

The Follow the Money investigations are the heart of this publication. Each begins with Gab-E Political Intelligence running against 10+ million government records before a single word of editorial is written.

Powered by Gab-E, an elite global intelligence platform built to democratize political and financial intelligence.

Editorial Policy
Editorial Standards & Corrections Policy

How We Source, Verify, and Correct Our Work

Every factual claim in a Congressional Times story is checked against a primary source: a government filing, a court record, a direct quote, before publication. When a claim can't be verified or doesn't hold up as originally reported, we drop it or reframe it. We do not publish disputed claims as settled fact.

When we get it wrong: we correct the story directly, note the correction and date at the bottom of the piece, and update the record. We do not quietly edit and move on.

Bylines: stories with a named byline are written and fact-checked by that person. Stories without a byline are sourced from Gab-E Political Intelligence, our automated research platform, and are labeled as such.

Ownership: The Congressional Times is published by Gab-E Holdings LLC. Gab-E, our intelligence platform, powers our sourcing and research pipeline.

Corrections or concerns: support@gab-e.com