ATF DECLARES CYBERATTACK A MAJOR INCIDENT AFTER RANSOMWARE GANG CLAIMS BREACH
The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives has declared a cyberattack on one of its systems a "major incident," a formal classification that triggers mandatory notification to Congress. The targeted system was standalone and separate from the ATF's main network, containing information about targets of ATF investigations. An ATF spokesperson confirmed that intruders accessed the compromised computer but said there was no indication the breach had affected the ATF enterprise network, the eForms system, or any other ATF systems. The agency said it immediately blocked connections to the affected IT environment upon discovery.
The Qilin ransomware gang posted the ATF on its leak site shortly before the agency announced the breach publicly. The ransomware group did not disclose what data it claimed to have stolen, how much data was taken, or provide samples to substantiate its claims. The ATF declined to comment on Qilin's specific assertions, the ransom demand, or details of what information was compromised, citing an ongoing investigation. The agency said it was coordinating closely with the U.S. Department of Justice, which designated the compromise as a major incident under federal guidelines.
Qilin has been identified as responsible for a 2024 attack on NHS pathology provider Synnovis that disrupted services across the UK. According to cybersecurity firm Comparitech, Qilin was among the most prolific ransomware gangs in July, with 799 ransomware incidents recorded that month across all tracked groups, up from 668 in June. The ATF said the security breach had not affected its operations.