← BACK TO FEED
ransomwareQilinATFfederal securitydata breach

Qilin Ransomware Gang Claims ATF Scalp as Feds Confirm 'Major' Breach

The US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) is responding to a "major" cybersecurity incident after the Russia-linked Qilin ransomware gang claimed responsibility, posting the agency on its leak site. ATF states that the breach was limited to a standalone computer system containing investigation target information, with no impact on its broader network or operations. The Department of Justice has designated the compromise a "major incident," and an investigation is ongoing, with ATF declining to provide further details.

The Bureau of Alcohol, Tobacco, Firearms and Explosives has confirmed it is dealing with a 'major' cybersecurity incident, coming clean shortly after the Qilin ransomware gang listed the agency on its dark web leak site.

According to an ATF spokesperson, the attackers got into a standalone computer system holding information about targets of active ATF investigations. The agency was quick to stress this system had no connections to its main enterprise network, its eForms platform, or anything else. Whether that's reassuring or just damage limitation framing, you can decide.

Beyond that, ATF isn't saying much. Questions about Qilin's specific claims, the size of any ransom demand, and what data actually walked out the door were all met with the standard 'ongoing investigation' deflection. The agency said it cut off connections to the affected environment immediately upon discovering the breach and is coordinating with the Department of Justice, which oversees ATF.

Senior DOJ officials formally designated the compromise a 'major incident' under federal guidelines, which triggers specific reporting and response obligations. ATF insists its operations haven't been disrupted.

Qilin's leak site post, spotted by The Register, gave nothing away in terms of evidence. No data samples, no file counts, just the agency's name on a list. That's fairly typical posturing during the extortion phase, designed to pressure victims into paying before proof becomes necessary.

If the name Qilin rings a bell, it should. This is the same crew responsible for the 2024 attack on NHS pathology supplier Synnovis, which caused widespread disruption to blood transfusions and test results across London hospitals. They have not mellowed since. Comparitech tracked 799 ransomware incidents globally last month, up from 668 in June, with Qilin claiming credit for 125 of them. That's a busy month by anyone's standards.

Having a federal law enforcement agency with investigative files on its systems end up on a ransomware gang's hit list is not a great look, regardless of how isolated that system supposedly was.

READ NEXT
Ransomware Surges While Everyone's Busy Watching the AI ShowLockBit Claims US Bank Scalp With September Leak DeadlineShinyHunters Turns Up the Heat on Ernst & Young After Tax Data Breach