Home Technology Cyber Hackers Turned a Freeway Sign Into a Tool for Digital Intimidation

Hackers Turned a Freeway Sign Into a Tool for Digital Intimidation

Representational image of a protest against the Iranian regime

This post is also available in: עברית (Hebrew)

Digital road signs are designed to deliver simple information to thousands of drivers, but unauthorized access can turn that public infrastructure into something very different. A recent incident in Los Angeles showed how a compromised traffic display can be used to amplify an online intimidation campaign beyond the internet.

A digital sign along the I-405 freeway was hijacked to display the address of Goorkan, a website that publishes names, photographs and personal information belonging to Iranian dissidents around the world.

The unauthorized message was spotted on September 8th, 2026, near the Santa Monica Boulevard exit, close to Westwood, an area with a substantial Iranian community. According to Cyber News, the altered display remained unreported for approximately one week before the California Department of Transportation (CALTRANS) was notified.

CALTRANS said it addressed the incident and is examining the sign’s access history. Details about exactly how the display was compromised have not been disclosed.

The incident is notable because the message did not simply contain graffiti or a political slogan. Instead, it directed passing motorists toward an existing doxxing platform.

Goorkan, whose name translates from Farsi as “Grave Digger,” maintains what it calls a “Burn List” containing profiles of people it accuses of opposing Iran or acting on behalf of Israel. At least one member of the Los Angeles Iranian community reportedly found her name, photograph and personal information published on the site after receiving threats through social media.

A Telegram channel apparently connected to the website adds another layer to the operation. It encourages followers to provide information about people accused of treason, while publishing allegations and profiles of identifiable individuals living abroad.

The combination illustrates how cyber-enabled intimidation can move between digital and physical environments. A website provides the database, messaging platforms can solicit additional information, and compromised public infrastructure can expose the campaign to people who would otherwise never encounter it online.

The incident also follows warnings about other Iran-linked cyber operations targeting dissidents, activists and journalists abroad. Authorities recently described Chosen Brick, Windows spyware that uses Telegram infrastructure and can collect messages, files, screenshots and microphone audio after attackers trick a target into installing it.

For homeland-security organizations, the freeway incident highlights a different part of the same problem. Connected public infrastructure, including road signs and other remotely managed displays, can become useful targets even when compromising them provides no access to sensitive government data.

In this case, the value of the hacked sign was its visibility. Taking control of one roadside display gave an online doxxing campaign a physical presence in the middle of a community containing some of the very people it targets.