LA Freeway Sign Hacked to Display Website Targeting Iranian Dissidents
The incident illustrates how foreign influence operations can exploit domestic infrastructure to reach diaspora communities on American soil, raising questions about federal jurisdiction and...
A digital traffic display on the 405 Freeway in Los Angeles was hacked to show the web address of a site that described itself as a campaign to identify and punish individuals it labeled traitors to Iran's Islamic regime, according to reporting by the New York Post on September 20, 2026. The sign appeared near Persian Square in the Westwood neighborhood, an area with a large Iranian diaspora population.
The website displayed on the sign, identified in the report as goorkan.info, described its purpose as a collective and patriotic effort to identify individuals the site's operators consider enemies of Iran's government. The site's content and framing are consistent with tactics the U.S. Intelligence community has previously attributed to Iranian state-affiliated actors seeking to intimidate dissidents abroad, though no U.S. Government agency has been publicly identified as having confirmed attribution in this specific incident as of the date of this report.
The 405 Freeway is one of the highest-traffic corridors in the United States. The California Department of Transportation, known as Caltrans, manages the digital variable message signs along the freeway. Caltrans has not issued a public statement specifically addressing this incident as of September 20, 2026. What document would clarify the timeline of the breach is a Caltrans incident report or a communication log from the agency's traffic management center.
Federal jurisdiction over this type of incident is shared across several agencies. The FBI's Cyber Division handles foreign cyber intrusions on domestic infrastructure. The Department of Homeland Security's Cybersecurity and Infrastructure Security Agency, known as CISA, oversees protection of critical infrastructure including transportation management systems. Neither agency had issued a public statement on this specific incident as of the publication of this article.
Iran-linked harassment and surveillance of diaspora communities in the United States has been a documented federal concern for several years. The Department of Justice has brought multiple criminal cases related to alleged Iranian government plots to monitor or harm dissidents and journalists on U.S. Soil. In 2022, the DOJ unsealed an indictment alleging an Iranian operative had sought to arrange the assassination of former National Security Advisor John Bolton, according to DOJ public records. In 2024, the DOJ charged Iranian nationals in connection with a plot targeting the 2024 presidential election, per DOJ press releases.
The targeting of transportation infrastructure message systems is not a new vulnerability class. In 2014, researchers demonstrated that variable message signs used on highways across multiple states used default passwords and unencrypted radio communications, as documented in a Trend Micro security research report published that year. Whether the 405 Freeway sign exploited a similar vulnerability or involved a more sophisticated intrusion is unknown. A CISA advisory or law enforcement filing would be the public record most likely to address the technical method used.
Iranian dissidents and community organizations in Los Angeles told the New York Post the incident created concern within the local Iranian diaspora. Los Angeles is home to one of the largest Iranian communities outside Iran, a population that includes many individuals who fled the Islamic Republic after 1979 and in subsequent years.
Congress has addressed Iranian influence operations in the United States through several legislative vehicles. The Countering America's Adversaries Through Sanctions Act, passed in 2017, included provisions targeting Iranian entities involved in human rights abuses and destabilizing activities, according to the text of Public Law 115-44. Oversight of foreign influence operations on domestic soil falls partly under the Senate Select Committee on Intelligence and the House Permanent Select Committee on Intelligence. Neither committee had issued a statement on this specific incident as of September 20, 2026.
The State Department's designation list under Executive Order 13224 and the Iran-related sanctions programs administered by the Treasury Department's Office of Foreign Assets Control are the primary federal tools for restricting Iranian government-linked actors. Whether any entity connected to the goorkan.info website appears on those lists is unknown as of this report. A search of OFAC's publicly available Specially Designated Nationals list by the relevant domain or associated organizational name would be the record to consult.
What remains unknown is who specifically orchestrated the hack, how long the message was displayed before it was removed, whether Caltrans has filed a report with law enforcement, and whether federal agencies have opened a formal investigation. A FOIA request to CISA, the FBI Los Angeles field office, or Caltrans would be the appropriate mechanism to obtain those records. This story will be updated when agency responses become available.