Ransomware

ATF Confirms Cyber Incident After Ransomware Group Claims Attack

The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.

The US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed suffering a cybersecurity incident after the Qilin ransomware group claimed to have targeted the agency.

In a statement on its website, ATF said the incident affected a standalone system, which was disconnected after the intrusion was discovered. 

“The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system,” ATF said, adding, “The incident has not impacted ATF’s ability to perform its missions.”

An investigation is being conducted in coordination with the Justice Department.

“Senior Department officials have designated the event a ‘major incident’ under applicable federal guidelines, and required notifications have been completed,” ATF noted.

Advertisement. Scroll to continue reading.

The Qilin ransomware group added ATF to its leak website on August 26, but it has not made any specific claims about the breach. 

The hackers often post screenshots to demonstrate that certain types of documents have been stolen from victims, but that has yet to happen in ATF’s case.

Qilin ransomware attack on ATF

Qilin’s post also does not specify when any stolen files might be leaked; some victim announcements include a timer indicating when files will be published.

Active since at least 2022 — initially under the name Agenda — Qilin operates on a double-extortion model, encrypting files and exfiltrating sensitive information from victims’ systems.

Qilin made headlines recently after it exploited a Check Point VPN zero-day vulnerability in its attacks. 

The cybercrime group has listed more than 2,000 victims on its leak website to date, and the actual number is likely much higher, given that many pay a ransom and are not named.

Related: Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign

Related: Sensitive Information Exposed in Nutex Health Data Breach

Related: ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

Related Content

Data Breaches

The cybercrime gang has listed major companies such as Shell, Philips, Fiserv, Zebra, Mindray, and Largan Precision.

Cybercrime

Maksim Silnikau was the creator and administrator of the ransomware group and involved in Angler EK’s distribution.

Data Breaches

An extortion group stole personal, financial, and medical information from the hospital’s network.

Data Breaches

The bank holding company was hacked in June, but the investigation into the incident continues.

Data Breaches

The physical security firm says its alarm monitoring and system functionality have not been affected.

Ransomware

The INC Ransomware gang has been targeting vulnerable SMA1000 appliances for root access and lateral movement.

Data Breaches

Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files.

Data Breaches

Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version