Motorists traveling along one of the most congested arteries in Los Angeles were recently confronted with a jarring anomaly: instead of customary traffic advisories, an electronic marquee displayed the URL of a website dedicated to doxing critics of the Iranian regime. Unidentified malicious actors successfully breached a temporary electronic sign on the I-405 freeway, chillingly transforming routine public infrastructure into an instrument of profound intimidation.
This peculiar message materialized on September 8 near the Santa Monica Boulevard exit, in close proximity to Westwood and Persian Square, an enclave sheltering a substantial Iranian diaspora. The glaring screen explicitly broadcast the address Goorkan[.]info. The California Department of Transportation (Caltrans) was alerted to this rogue transmission on September 15, prompting the contractor to swiftly restore the device to its standard operational state. The agency is currently conducting a rigorous forensic review of the equipment’s access logs.
Doxing and the Real-World Threat
Translated from Farsi, the moniker “Goorkan” ominously translates to “gravedigger.” The architects of this digital platform explicitly branded it as an intelligence-gathering network engineered to expose individuals accused of treason and complicity in hostile maneuvers against Iran. The website featured a menacing “Burn List” detailing names, photographs, and highly sensitive personal information. This aggressive deployment of doxing deliberately seeks to transplant online harassment directly into the physical realm, creating tangible threats to safety.
One Los Angeles resident of Iranian descent reported the terrifying discovery of her own identity, complete with photographs and private data, plastered on the site; following a deluge of explicit threats, she immediately sought refuge with the FBI. An affiliated Telegram channel associated with Goorkan actively solicited its followers to submit intelligence regarding expatriates deemed subversive by the channel’s administrators. Iranian intelligence operatives have historically weaponized Telegram in preceding campaigns targeting outspoken dissidents and journalists. Such incidents serve as a stark reminder that intimate secrets are actively traded in the darknet; vigilant concealment is paramount.
Global Espionage and Digital Harassment
The precise identity of the perpetrators who compromised the highway marquee remains publicly shrouded in mystery. Caltrans has merely confirmed the manifestation of the unauthorized broadcast and the initiation of an ongoing inquiry. Furthermore, a definitive link connecting this specific intrusion to official Iranian state apparatuses remains unverified. As highlighted in coverage detailing how a Los Angeles 405 freeway sign hacked with threats targeting Iranian dissidents caused public alarm, the Goorkan URL lingered on the marquee for approximately a week before highway authorities received formal notification.
Against the backdrop of this local disruption, a chilling global advisory emerged on September 15 regarding the CHOSEN BRICK malware. British, American, and Dutch intelligence agencies jointly declared that state-sponsored Iranian actors are aggressively deploying this sophisticated espionage tool. You can read the official joint alert regarding Iranian cyber targeting of dissidents, activists, and journalists to understand the full scope of the looming threat.
The CHOSEN BRICK Campaign Connection
CHOSEN BRICK empowers its operators to silently plunder private communications, contact lists, and email archives, while simultaneously capturing covert screenshots and stealthily activating device microphones. The authors of the intelligence brief specifically noted that the compromised data of several victims subsequently surfaced on pro-Iranian leak portals. Mere days preceding the freeway incident, cybersecurity analysts published an exhaustive dissection of the CHOSEN BRICK campaign. The malicious actors methodically cultivated trust via encrypted messaging applications before stealthily feeding their victims malignant files, occasionally going so far as to disguise the payloads as highly sensitive medical examination results.
Yet another alarming precedent demonstrates that these digital incursions are frequently woven into a much broader tapestry of relentless geopolitical pressure. Security researchers have linked the Iran-affiliated Handala syndicate not solely to destructive network breaches and data publication, but also to persistent surveillance, overt threats, and calculated efforts to terrorize and manipulate individuals residing beyond their national borders. However, there is currently no publicly available forensic evidence explicitly tethering Handala directly to the Los Angeles marquee sabotage.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.