
A digital highway sign near Westwood’s Persian Square was briefly used to display a message directing drivers to a website that threatened perceived opponents of Iran’s Islamic regime. The incident placed a piece of public infrastructure near a symbolic center of Los Angeles’ Iranian-American community in the broader context of reported Iranian state-linked intimidation and cyber activity.
A Warning Spotted at the Santa Monica Boulevard Exit
Payam Shiravi, a 59-year-old Iranian-born real estate broker, told the New York Post that he spotted the hacked sign near the Santa Monica Boulevard exit of the 405 on September 8. The sign directed onlookers to goorkan.info, a site the Post reports has been linked to Iran’s Islamic Revolutionary Guard Corps, which the United States government designated a foreign terrorist organization in 2019. According to the Post, goorkan means gravedigger in Farsi, and the site promoted what it described as a national campaign to identify and punish alleged traitors to Iran.
The California Department of Transportation, which operates the sign, acknowledged the unauthorized message, according to the Post. Caltrans said its project team was alerted on September 15 and directed a contractor to restore normal operations. The agency said the message was not part of normal operations, and that a review and field investigation were ongoing.
Dissidents Say They Found Their Own Names on the Site
Emel Karsaz, a 48-year-old Iranian-born critic of the regime, filed a report with the FBI's Los Angeles field office on September 9 after finding her name, photo, and personal details posted on goorkan.info, the station's report notes. She said she was shocked to discover her information on the site and has since received threats on social media. Karsaz said she now fears being attacked with acid while walking around Los Angeles.
Shiravi said he recognized people he knew among those targeted on the site. The site added a section this month called The Burn List, which claimed its operators had amassed sensitive information about targets, the report states. Despite the threats, Iranian dissidents in the area remain defiant, according to the same account.
A Broader Pattern of Iranian State Cyber Activity
The freeway sign hack came one week before the FBI, alongside the UK's National Cyber Security Centre and the Netherlands' General Intelligence and Security Service, issued a joint advisory on September 15 exposing Chosen Brick, a Windows spyware strain deployed by Iranian state cyber actors against dissidents, activists, and journalists across the United States, United Kingdom, and Europe, according to Help Net Security. The advisories detailed how Iranian operators distribute the spyware via WhatsApp and Telegram using social engineering tactics, such as sending fake medical MRI results or impersonating trusted acquaintances, to gain access to a target's microphone, inbox, and location data, per Gblock. The FBI also warned on September 15 that Iranian state cyber actors were targeting dissidents, activists, and journalists around the world, the Post reported, though the bureau would not confirm whether it was investigating the freeway sign hack.
Shiravi alleged that the IRGC already has operatives inside the United States, claiming undercover agents attend protests with long-lens cameras and Chinese-supplied facial-recognition technology, according to his account to the Post. The Justice Department and FBI have repeatedly warned of escalating transnational repression tactics by Iranian intelligence services, including previously disrupted plots to kidnap or assassinate Iranian-American dissidents and journalists on U.S. soil, according to the U.S. Department of Justice.
Persian Square's Deep Roots in Westwood
The Los Angeles City Council officially designated the intersection of Westwood Boulevard and Wilkins Avenue as Persian Square in 2010 to honor the local Iranian-American community, which built its commercial hub there after the 1979 Islamic Revolution, according to Pars Times. Los Angeles County is home to an estimated 141,000 Iranian Americans, per the Post, making it a natural target for a campaign designed to intimidate the diaspora at its symbolic front door.
Documented Cases and Community Roots
The Justice Department has documented more direct alleged efforts to target Iranian dissidents and activists in the United States. A federal jury found two men guilty in March 2025 in an IRGC-directed murder-for-hire plot targeting Iranian-American journalist and activist Masih Alinejad, according to the U.S. Department of Justice. In January 2024, the Justice Department’s National Security Division announced charges against three men in an alleged plot to murder two Maryland residents who had fled Iran, a case involving alleged recruitment for killings on U.S. soil. Those cases differ from the Westwood incident, which involved an unauthorized digital sign message and an online targeting campaign rather than a publicly documented murder-for-hire prosecution. Many Iranian migrants arrived in Los Angeles in the late 1970s and early 1980s after fleeing the Iranian Revolution, helping establish the Iranian-American community rooted in Westwood and surrounding areas. That history helps explain why Persian Square functions as a significant symbolic setting for an incident aimed at people perceived as opponents of Iran’s government.
Roadside digital signs like the one on the 405 can be vulnerable to unauthorized access. The incident also raised questions about possible legal consequences.
Part of a Wider Wave of Iran-Linked Cyber Incidents
The Westwood sign hack comes amid other cyber incidents in recent months. Foreign cyber actors briefly breached operational technology at two tiny Colorado water systems in late August, and an Iranian hacker group claimed in June that it had infiltrated water systems serving several California cities. In March, L.A. Metro suffered a cyberattack that disrupted passenger-information and payment systems and resulted in the theft of at least 700 gigabytes of data, an intrusion Israeli researchers attributed to Iranian state-linked hackers.
Taken together, the incidents involve cyber activity affecting U.S. infrastructure and Iranian dissidents.









