Qilin Ransomware Gang Claims ATF Scalp as Feds Confirm 'Major' Breach
The Bureau of Alcohol, Tobacco, Firearms and Explosives has confirmed it is dealing with a 'major' cybersecurity incident, coming clean shortly after the Qilin ransomware gang listed the agency on its dark web leak site.
According to an ATF spokesperson, the attackers got into a standalone computer system holding information about targets of active ATF investigations. The agency was quick to stress this system had no connections to its main enterprise network, its eForms platform, or anything else. Whether that's reassuring or just damage limitation framing, you can decide.
Beyond that, ATF isn't saying much. Questions about Qilin's specific claims, the size of any ransom demand, and what data actually walked out the door were all met with the standard 'ongoing investigation' deflection. The agency said it cut off connections to the affected environment immediately upon discovering the breach and is coordinating with the Department of Justice, which oversees ATF.
Senior DOJ officials formally designated the compromise a 'major incident' under federal guidelines, which triggers specific reporting and response obligations. ATF insists its operations haven't been disrupted.
Qilin's leak site post, spotted by The Register, gave nothing away in terms of evidence. No data samples, no file counts, just the agency's name on a list. That's fairly typical posturing during the extortion phase, designed to pressure victims into paying before proof becomes necessary.
If the name Qilin rings a bell, it should. This is the same crew responsible for the 2024 attack on NHS pathology supplier Synnovis, which caused widespread disruption to blood transfusions and test results across London hospitals. They have not mellowed since. Comparitech tracked 799 ransomware incidents globally last month, up from 668 in June, with Qilin claiming credit for 125 of them. That's a busy month by anyone's standards.
Having a federal law enforcement agency with investigative files on its systems end up on a ransomware gang's hit list is not a great look, regardless of how isolated that system supposedly was.