ATF responds to 'major' cybersecurity incident after ransomware gang's claims
US Justice Department investigating the breach
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) is responding to a "major" cybersecurity incident following claims from the Qilin ransomware gang. The intrusion targeted a standalone system that operates independently from the ATF's enterprise network. According to ATF, there is no evidence that the breach has impacted the ATF's main network, eForms system, or any other systems.
The agency has stated that it is working closely with the Department of Justice to investigate the issue and has immediately blocked connections to the affected IT environment. ATF has not disclosed any details about the data claimed to have been stolen by Qilin or provided any evidence to support the claim. The security breach did not interfere with ATF's operations, but senior DOJ officials classified the incident as a "major incident" according to federal guidelines.
Qilin, a Russian-linked ransomware group, listed the ATF on its leak site shortly before ATF's security incident notice was posted to the ATF's website. The group, known for its high-profile attacks, including the 2024 breach of pathology provider Synnovis that disrupted NHS services in the UK, was among the most active ransomware gangs in July, with 799 reported incidents, of which Qilin claimed responsibility for 125.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.