ATF Investigates Major Cybersecurity Incident Amid Ransomware Group's Claims
The Bureau of Alcohol, Tobacco, Firearms and Explosives is probing a cybersecurity breach on a standalone system, deemed a 'major incident' by Justice Department officials.
U.S.·

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed on Wednesday it is probing a cybersecurity breach involving an isolated system. Senior officials within the Justice Department have classified this event as a "major incident" in accordance with federal protocols.
This revelation emerges as the Qilin ransomware collective has reportedly identified the ATF as a recent target, according to various cybersecurity news outlets monitoring the group's data leak platforms. As of now, the group has not publicly presented any proof to substantiate its assertions, and the ATF has not officially linked the incident to Qilin.
Incident Details and Response
The ATF stated that the compromised system operates independently from its primary enterprise network. The agency has indicated there is currently no evidence suggesting the incident has impacted its wider network infrastructure, its eForms application, or any other operational ATF systems.
Upon discovering the breach, the agency promptly isolated the affected environment. It has since initiated comprehensive forensic analyses and incident-response measures, working in conjunction with the Justice Department to investigate the full scope of the event.
The agency has not yet disclosed specifics regarding the identity of the affected system, the precise date of incident discovery, or whether any data was accessed or exfiltrated during the event.
Ransomware Group's Claims and Verification
Reports from Cybernews on Wednesday corroborated that Qilin asserted the ATF as its newest victim, although it provided no supporting evidence or further specifics for this claim.
Independently, GalaxyWarden, a service dedicated to monitoring data breaches, noted the ATF's appearance on Qilin's leak site. GalaxyWarden reported that the group claimed to have acquired files from the agency but emphasized that these assertions had not been independently verified.
The ATF reiterated that senior Justice Department officials formally designated the cybersecurity event as a "major incident" under relevant federal guidelines, confirming that all required notifications have been completed.
According to the agency, the incident has not caused any disruption to the ATF's ongoing operations or impeded its capacity to fulfill its core missions.
The agency has urged anyone possessing information pertinent to the incident to contact the ATF Tipline at 1-888-ATF-TIPS, which is 1-888-283-8477.
Related Stories

New 911 Recordings Detail Chaos of Deadly Seattle Festival Shooting
New 911 calls reveal the frantic moments following a deadly shooting at Seattle's Bite of Seattle festival. Multiple individuals were reported down, as dispatchers worked to guide first responders and reassure the
Aug 27

Jury Composition Under Scrutiny in Lindsay Clancy Murder Trial as Postpartum Psychosis Defense Emerges
The Lindsay Clancy murder trial is nearing its conclusion, with legal experts speculating on jury dynamics. A prosecutor from the Susan Smith case suggests women jurors might be less sympathetic to a postpartum
Aug 26

NYC Authorities Pursue Suspect in Double Fatal Shootings Across Bronx and Brooklyn
New York City law enforcement is conducting a manhunt for Jesus Acosta, a suspect wanted in connection with two fatal shootings. One involved a deli robbery in the Bronx, and the other a shooting at a Brooklyn
Aug 26

Critically Ill Newborn at Center of Surrogacy Custody Battle After Heart Surgery Complications
A newborn, critically ill after heart surgery complications, is at the center of a tense legal battle. Intended parents Nausheen Gilkar and Omar Ahmed and surrogate McKenna West are clashing in a Dallas courtroom over
Aug 26