{
  "id": 3784653,
  "title": "ATF declares ‘major incident’ as ransomware gang claims hack",
  "url": "https://urgent.news/2026/08/27/atf-declares-major-incident-as-ransomware-gang-claims-hack",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-08-27T17:54:23.000Z",
  "source": {
    "name": "TechCrunch",
    "slug": "techcrunch",
    "url": "https://techcrunch.com/2026/08/27/atf-declares-major-incident-as-ransomware-gang-claims-hack/"
  },
  "original_language": "en",
  "account": "The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has classified a recent cyberattack on one of its standalone systems as a \"major incident.\" This classification, a legally defined designation, mandates a formal notification to lawmakers in Congress. In a statement, ATF emphasized that the attack targeted an isolated system, distinct from the bureau's primary network. An ATF spokesperson indicated that the affected computer system held sensitive information, including the \"targets of ATF investigations.\" However, TechCrunch has sourced a claim of responsibility by the Qilin ransomware gang, which has published the announcement on its leak site. Yet, the gang has not supplied evidence to substantiate their allegation, such as a sample of the stolen data. Qilin is notorious for operating a \"ransomware-as-a-service\" model, whereby they lease their hacking tools to other criminal affiliates in exchange for a share of the profits. The gang has previously targeted high-profile entities, including media conglomerate Lee Enterprises and U.K. pathology lab giant Synnovis.\n\nNotably, \"major incidents\" under federal law pertain to significant cyber breaches that are likely to inflict demonstrable harm to U.S. national security or broader U.S. interests. Consequently, agencies are obligated to report such incidents to Congress within a week of their detection. This recent classification of the ATF incident by the ATF follows in the footsteps of several other government entities that have declared major incidents in recent years due to cyber breaches. These include the 2023 ransomware attack on a system utilized by the U.S. Marshals Service and a breach of an FBI system earlier this year, which exposed the phone numbers of targets under surveillance by federal agents.",
  "summary": "The ATF is the latest federal government agency in recent years to notify Congress of a \"major incident\" involving its cybersecurity.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 3,
    "also_reported_by": [
      {
        "outlet": "The Hill",
        "title": "ATF investigating 'major' cybersecurity incident",
        "url": "https://urgent.news/2026/08/27/atf-investigating-major-cybersecurity-incident",
        "published": "2026-08-27T11:45:04.000Z"
      },
      {
        "outlet": "The Register",
        "title": "ATF responds to 'major' cybersecurity incident after ransomware gang's claims",
        "url": "https://urgent.news/2026/08/27/atf-responds-to-major-cybersecurity-incident-after-ransomware-gangs",
        "published": "2026-08-27T15:25:52.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}