ATF Confirms Cyber Incident After Ransomware Group Claims Attack
ATF confirms cyber incident after Qilin ransomware group claims attack.
Summary
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a cybersecurity incident involving a standalone system, which was disconnected after discovery. The Qilin ransomware group claimed responsibility and added the ATF to its leak site, though no specific claims or evidence of exfiltrated data have been released. The incident is being investigated by the Justice Department as a 'major incident' under federal guidelines.
Full text
The US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed suffering a cybersecurity incident after the Qilin ransomware group claimed to have targeted the agency. In a statement on its website, ATF said the incident affected a standalone system, which was disconnected after the intrusion was discovered. “The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system,” ATF said, adding, “The incident has not impacted ATF’s ability to perform its missions.” An investigation is being conducted in coordination with the Justice Department. “Senior Department officials have designated the event a ‘major incident’ under applicable federal guidelines, and required notifications have been completed,” ATF noted.Advertisement. Scroll to continue reading. The Qilin ransomware group added ATF to its leak website on August 26, but it has not made any specific claims about the breach. The hackers often post screenshots to demonstrate that certain types of documents have been stolen from victims, but that has yet to happen in ATF’s case. Qilin ransomware attack on ATF Qilin’s post also does not specify when any stolen files might be leaked; some victim announcements include a timer indicating when files will be published. Active since at least 2022 — initially under the name Agenda — Qilin operates on a double-extortion model, encrypting files and exfiltrating sensitive information from victims’ systems. Qilin made headlines recently after it exploited a Check Point VPN zero-day vulnerability in its attacks. The cybercrime group has listed more than 2,000 victims on its leak website to date, and the actual number is likely much higher, given that many pay a ransom and are not named. Related: Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign Related: Sensitive Information Exposed in Nutex Health Data Breach Related: ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Eduard Kovacs Cyberattack Causes Global Disruption at Boston ScientificUS Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure AttacksRecent Citrix NetScaler Vulnerability Exploited in the WildAI Speeds Up Malware Development, Not Its Success Rate: AnalysisAdobe and Nvidia Patch Dozens of VulnerabilitiesCISA: Over 100 Internet-Exposed Water Systems Targeted in July CyberattacksChrome 152 Patches Over 300 VulnerabilitiesSensitive Information Exposed in Nutex Health Data Breach Latest News OpenAI Agents Exploited Linux Kernel Flaw on Company’s Own SystemsTech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense PledgeThink You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco SaysPaperCut Releases Emergency Patch for Exploited Zero-DayTrump Order Aims to Block Foreign Backdoors in US Power Grid GearAustralia Arrests 2 Alleged TeamPCP HackersOpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face HackOkta Shares Surge on Strong Earnings, Growing Demand for AI Identity Security Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Scaling AI Security August 26, 2026 Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveSocial engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.Naveen Bhateja has been appointed Chief People Officer at HackerOne.The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.More People On The MoveExpert Insights The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Rethinking Application Security for the AI Era As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. (Joshua Goldfarb) Flipboard Reddit Whatsapp Whatsapp Email
Indicators of Compromise
- malware — Qilin