Goorkan Appears on Los Angeles Freeway Sign as Website Threatens Iranian Government Opponents
Goorkan collects information on people who oppose the Islamic Republic and publishes dossiers about them, while threatening them with “punishment.” At the same time, the website’s address appeared on a digital sign along Los Angeles’s Interstate 405. It remains unclear who posted the message or how they accessed the sign’s system.


In September 2026, the address goorkan[.]info appeared on a digital sign along Interstate 405 in Los Angeles. The sign is used for traffic messages, not website advertising. The California Department of Transportation (Caltrans) said the message was unauthorized and that it was reviewing access records. It has not said who changed the sign or whether it was hacked.
The sign is only part of the story. In its promotional material, Goorkan asks people to submit information about individuals it labels “traitors.” It claims to have opened thousands of files and seized property, and says it has access to some people’s private information. The identities of those behind the site, how they collect data, and the accuracy of many of their claims remain unclear.
The California Post reported yesterday that the domain was linked to a site publishing details about people who oppose the Islamic Republic. Caltrans said it learned of the message on September 15 and instructed the contractor responsible for the sign to remove it.

According to the same report, the sign was displaying the message near the Santa Monica Boulevard exit by September 8. One person whose information appeared on Goorkan said they reported the matter to the FBI on September 9. These dates indicate that the message was on the sign before Caltrans was officially notified, but they do not establish exactly when the alteration began or how long it remained there.
Was the Sign Hacked?
The media report described the incident as a “hack,” but the information released by officials does not yet confirm that characterization. It is not known how the person or people responsible accessed the system. Remote access, use of a contractor’s account, insider access, or exploitation of a technical vulnerability are all possible scenarios. None has been confirmed in the information made public. As of publication, the FBI had not publicly confirmed an investigation into the alteration of this particular sign.
The appearance of Goorkan’s address on the sign, by itself, is not enough to identify who was responsible. No evidence has been released showing that Goorkan’s operators accessed the traffic system, or that a particular hacking group or government agency carried out the change.
What Is Goorkan, and What Is It Asking People to Do?
Goorkan does not present itself simply as a website that publishes information. Its promotional material invites people to help identify individuals. Advertisements linked to the project use the name Goorkan alongside the domain goorkan[.]com and ask users to identify people the advertisers call “traitors.”
One slogan reads: “You identify them; Goorkan punishes the traitors.”

The slogan lays out the model Goorkan promotes: members of the public identify people and submit information, while an organization whose leadership and structure are unknown promises action against them. In this model, political opposition can become grounds for reporting someone. The use of the word “punishment” also suggests that the stated aim is not limited to recording or publishing information; Goorkan’s operators are trying to connect submissions with consequences for the people targeted.
The promotional material does not explain what happens after information is submitted. It is unclear who verifies it, what criteria determine whether someone is listed, how inaccurate information can be corrected, or who is supposed to carry out the promised “punishment.”
The “Burn List” and Claims of Access to Private Information
According to a report about Goorkan, the site has published photos and details of people described as opponents of the Islamic Republic. A section reportedly titled “Burn List” claims access to some individuals’ conversations, accommodation details, and financial transactions.

So far, no independent technical evidence has been published showing that the site’s operators actually breached these people’s accounts, devices, or private systems. That distinction matters. Information in dossiers like these can come from many sources: public records, social media, submissions by other people, leaked databases, or—if unauthorized access has occurred—accounts and devices.
Without examining where the data came from, publication alone does not establish that Goorkan stole it directly. But claims of access to private life can themselves be part of the pressure. A target may not know what the site’s operators really possess or which claims are exaggerated or fabricated. In that situation, publishing personal details alongside claims of private access and promises of “punishment” can make uncertainty part of the threat.
Claims of 2,000 Dossiers and More Than 150 Property Seizures
Goorkan’s promotional material refers not only to future action but also claims a record of past operations.
The material says the group has opened files on 2,000 people, carried out more than 150 property seizures, and caused over 1.5 trillion tomans in losses to its targets.
These figures are presented as Goorkan’s track record, but the sources reviewed for this article did not provide independent documentation to verify them.
It is also unclear what Goorkan means by a “file.” The term could refer to a page about someone on the website, a collection of data in an internal system, information sent to another party, or a case opened by an official authority.
The same uncertainty applies to the property-seizure claims. No court rulings, legal records, or independent information have been provided to verify the number of cases or the claimed financial losses. These figures should therefore be treated as claims made by Goorkan, not as established results.
Still, the way the figures are used is significant. By listing dossiers, seizures, and financial losses together, Goorkan seeks to suggest that reporting someone to the group can lead to consequences beyond having their name and photo published.
Reporting Channels: Telegram, Bale, and Eitaa
Goorkan does not rely solely on its website to collect information. Its promotional material lists @GoorkanLink as a contact on Telegram, Bale, and Eitaa. The indexed description of the Instagram account @goorkaninsta also directs users to an account with the same name on Bale and Telegram. The promotions describe these as “secure communication channels,” but that is the publishers’ claim, not an independent assessment of their security.
Using a website, social media, and several messaging apps creates multiple routes for collecting reports: a user might encounter a target on social media, send information through a messaging app, and later see a dossier or result on the website. This structure does not establish who operates the channels, but it shows that collecting information from the public is a visible part of Goorkan’s promotional model.
Goorkan Promotions on Pro-government Channels
Search-indexed results show the domain goorkan[.]info appearing in posts by the Telegram channel “Iranian Cyber Army.” The post repeats the main elements of Goorkan’s promotions: calls to identify individuals, promises of punishment, and figures about dossiers and property seizures.
The channel’s name and content are openly supportive of the Islamic Republic, but that alone does not prove an official connection to the Islamic Revolutionary Guard Corps (IRGC). Likewise, the reposting of Goorkan’s promotions by such a channel is not evidence that the IRGC or another specific government body operates the site. What can be said with greater confidence is that Goorkan’s promotional material has circulated through networks that publish pro-Islamic Republic content.
How Clear Is the Relationship Between goorkan[.]com and goorkan[.]info?
Both goorkan[.]com and goorkan[.]info appear in promotions linked to the project, and both use the Goorkan name. This is evidence of a content and promotional connection between the domains. The review for this article did not establish whether they share a registered owner, technical administrator, or hosting infrastructure.

That distinction matters. A shared name and brand may indicate a relationship, but establishing common ownership requires examining registration records, network infrastructure, certificates, website code, or other technical indicators.
There are similar limits to what can be inferred from indexed Instagram content. Text shown in search results alongside a post is not necessarily the account owner’s original caption; some of it may come from user comments. Such results can help show that promotional messages are circulating, but determining who published a specific passage—or whether it was paid advertising—requires examining the post itself and where the text appeared.
The Timing: Three Countries Warn of Operations Against Islamic Republic Opponents
The Goorkan case drew attention during the same week that officials in three countries warned about cyber operations by the Islamic Republic targeting opponents, activists, and journalists. On September 15, the UK National Cyber Security Centre, the FBI, and the Dutch General Intelligence and Security Service issued a joint advisory about cyber actors linked to the Iranian government.
The advisory describes the use of malware called CHOSEN BRICK to collect information such as victims’ contacts, emails, and messages. It also says that personal information about some targets has been published on pro-Islamic Republic websites, potentially creating further security risks for them.
The advisory shows that, in other cases examined by security officials, stolen information has been used to expose and pressure opponents. But it does not mention Goorkan. The advisory therefore does not establish that information published by Goorkan was collected using CHOSEN BRICK, that the site’s operators are part of the same operation, or that those actors accessed the California freeway sign. Similarities in tactics are not a substitute for technical or organizational evidence of attribution.
What Can Be Established About Goorkan So Far?
The identity of Goorkan’s operators remains one of the central unknowns in this case. But the anonymity of those behind the site does not mean its operating model is impossible to describe. Three elements repeatedly appear together in its published material: calls to identify people, the creation or publication of dossiers about them, and promises of consequences under the label of “punishment.”
Claims about access to private data, property seizures, and financial losses are also used to project operational capability, though many remain unverified. The appearance of Goorkan’s address on a Los Angeles traffic sign adds a separate question to the case: who accessed the freeway sign’s system, and who operates Goorkan, its information-collection channels, and its dossiers?
Proving a connection between those two matters will require evidence beyond the display of a domain name on a sign. At the same time, even if some of Goorkan’s claims about its operational capacity, property seizures, or access to private information are exaggerated, its stated model remains visible: turning user submissions into files about individuals and pairing those files with promises of consequences.
It is not yet clear how much of the threat reflects real operational capacity and how much is promotional messaging. Clarifying that boundary will require further investigation into Goorkan’s infrastructure, operators, and the sources of its data.