Tech
Iranian hackers blamed for breach of Los Angeles transit system that took weeks to recover
Security researchers say a March breach of the Los Angeles transit system (Los Angeles County Metropolitan Transportation Authority, or LACMTA) was the work of Iranian-backed hackers. Israeli startup Gambit Security said in a report on Tuesday that the hackers work for Iran’s Ministry of Intelligence and State Security (MOIS).
Reuters first wrote about the Gambit report.
A hacktivist group calling itself Ababil of Minab claimed responsibility for the earlier hack, saying they stole, then deleted data from the LACMTA’s systems. The group’s name is a reference to the U.S. air strike on an Iranian school in the city of Minab that killed more than 175 people, mostly children.
“They are not a new, standalone hacktivist crew as they claim,” said Gambit.
Ababil of Minab did not respond to a request for comment when contacted by TechCrunch.
Gambit said its claims are based on forensic evidence that ties the group to a previous Iran-linked campaign, as well as activity attributed to the MOIS by Israel National Cyber Directorate. Gambit said it investigated other attacks against companies in Israel, Saudi Arabia, and Turkey.
Contact Us
Do you have more information about Ababil of Minab or other Iran-linked hackers and their cyberattacks? From a non-work device, you can contact Lorenzo Franceschi-Bicchierai securely on Signal at +1 917 257 1382, or via Telegram and Keybase @lorenzofb, or email.
If Gambit’s assessment is correct, Ababil of Minab would be the latest in a series of fake hacktivist groups that are working for the Iranian government. The most recent example is Handala, which earlier this year hacked U.S. medical tech giant Stryker, wiping thousands of company systems and employee devices.
Following the Stryker breach, the FBI seized two Handala websites, and the U.S. Justice Department accused Iran’s government of being behind the hacktivist group and its attacks.
Iranian-linked hackers have increased their activities and their claimed hacks after the U.S. and Israel started bombing Iran earlier this year. In April, a coalition of U.S. agencies warned that Iranian hackers were targeting American critical infrastructure.
Tech
Sam Altman isn’t the only one who wants to pump the brakes on AI
After years of pushing full speed ahead on AI, OpenAI CEO Sam Altman says maybe it’s time for the AI industry to “pace” itself. The comments came just days after one of OpenAI’s own models broke out of its test environment and got tangled up in a breach at Hugging Face — though as Equity’s hosts point out, sloppy security seems to have been just as much to blame as the model itself. And Altman’s not alone in this stance: both OpenAI and Anthropic have come out in support of a petition echoing that same message.
Watch TechCrunch’s Equity podcast hosts Kirsten Korosec, Anthony Ha, and Sean O’Kane dig into whether the industry is ready to pump the brakes or just temporarily spooked, and who’s on the hook when a model goes rogue.
Subscribe to Equity on YouTube, Apple Podcasts, Overcast, Spotify and all the casts. You also can follow Equity on X and Threads, at @EquityPod.
Tech
VC-backed startups commit more fraud, and researchers think they know why
A new report from the U.K.’s Imperial College and France’s Emlyon Business School has mapped out the ways Silicon Valley’s VC-backed founders commit fraud — and the role investors play.
For the report, published online in June, researchers built a database of tech founders and companies who faced civil and criminal securities fraud prosecutions from the SEC and DOJ between 2000 and 2023.
Some famous cases of tech founders being convicted of fraud over the past few years include Frank’s Charlie Javice, Kalder’s Gökçe Güven, Terraform Labs’ Do Kwon, and GameOn’s Alexander and Valerie Lau Beckman.
All over X, the tech industry’s social network of choice, the topic of fraud and its gentler word “scam” are discussed, as people debate the limits of ambition and success. “Fraud is much more common and normalized in the startup world than we are ready to admit and accept,” Tim Weiss, one of the authors of the report, told TechCrunch.
He pointed to another report from the University of Toronto (UT), also published in June, that looked at 654 fraud cases against U.S. VC-backed startups from 2000 to 2023. It found that fraud is rare overall but that companies with venture funding were more likely to face fraud charges compared to companies that didn’t take venture funding. It found that startups launched during overheated markets with weak oversight and investor due diligence are 19% more likely to later commit fraud.
“The problem here is not just the founders but also those that set and reinforce, at times unreasonable, expectations of high growth,” Weiss said. He added that the current frothy AI startup environment is exactly the kind of conditions that tempt founders into fraud.
Weiss’ paper, co-authored with Emlyon researcher Nevena Radoynovska, discusses what may happen when founders face a gap between how investors want their startups to perform and how they are actually performing. They may turn to “façading,” as the paper calls it, in three increasingly dishonest stages: surface, reinforced, and deep.
Surface façading is when founders lie about how successful the company is or is becoming. It’s common during the early stages of a company when it’s pitching its vision to investors. It’s a level of dishonesty higher than just pitching an aspirational vision or an astronomical total addressable market.
After the surface façade, the founder may move into “reinforced façading,” according to the paper, which involves creating fake evidence to back up the lies told.
The paper gave the example of a mobile testing app that created fake customer contracts and invoices, recorded fake revenue, and used those fake documents to convince VCs to back it at a unicorn valuation.
From there founders may enter “deep façading,” where they extend their lies to areas like making their tech seem more capable than it is, complete with fake demos. This involves entire “parallel realities” built on lies, Weiss said.
But investors aren’t always hapless victims, the researchers found. Beyond the outsized growth expectations that push founders toward fraud in the first place, some investors unwittingly “co-create fraud,” Weiss said, by continuing to back founders—sometimes the very same ones— who’ve previously been accused of fraud, thereby normalizing it to a certain extent.
In fact, the UT report found little evidence that alleged fraud prevents founders from raising funding for new startups, even when those fraud cases received major media attention.
“New investors and the broader VC market do not penalize past misconduct,” the UT report said, which is “also consistent with the Silicon Valley culture that embraces failure regardless of the cause.”
The study also found that startups whose boards were controlled by the founders were twice as likely to commit fraud compared to those with investor-controlled or shared-controlled boards.
Even more interesting, it reported that after VC-backed startups go public, they are more likely to face securities class-action lawsuits within two years compared with private equity-backed companies that go public.
The fact that companies are staying private longer also contributes. Public companies undergo more scrutiny than private ones. “Founders do not have a professional body or association that could govern or enforce rules of entrepreneurial and investor conduct on how to be a good founder and what reasonable growth expectations are,” Weiss said.
Weiss proposes that the SEC routinely investigate and conduct formal audits on startups after they hit a large “investment threshold.” Currently, the SEC typically waits for something like a whistleblower complaint or a lawsuit from investors or former employees to trigger an investigation.
Weiss’ paper also suggests that investors should take more accountability when pushing founders to hit extreme growth metrics.
“Investors should be held liable for corporate governance failures and violating their fiduciary duties,” he said. He wants to see more research into “entrepreneur-investor dynamics” that could help prevent fraud and also “balance the overemphasis on the entrepreneur as the sole perpetrator of wrongdoing.”
Fraud is rarely a solo act, in other words, and until investors are held to account for the pressure they exert, founders will likely keep facing the temptation to fake it until they make it.
This piece was updated.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Tech
Fresh off its Wiz payout, Index Ventures raises $2B across three funds
Index Ventures has raised $2 billion in fresh capital across three funds, the firm announced on Friday.
The 30-year-old firm raised $400 million for its new seed-focused fund and $900 million for its venture fund. Index also added $700 million to a $1.5 billion growth fund raised in 2024, bringing its total available capital to $3.5 billion.
The fresh capital haul comes two years after Index raised $2.3 billion across two funds, including $800 million toward a predecessor venture fund.
While Index has refrained from ballooning its fund sizes unlike several other VCs, the outfit continues to stand out for its strong recent performance.
Earlier this year, Index portfolio company Wiz completed its $32 billion sale to Alphabet. Index first invested in Wiz at the seed stage and became its largest outside shareholder with a 12% stake, a position likely worth $3.8 billion, according to Reuters’ reporting. Index was also an early investor in Figma, which went public last year.
Index’s AI bets include robotics company Physical Intelligence, inference platform Fireworks AI, and Anthropic, an investment made when the AI model maker raised capital at a $183 billion valuation last September.
