ATF Confirms Cyber Incident After Qilin Ransomware Claim
The ATF confirmed a cybersecurity incident after Qilin listed the agency. ATF reported the intrusion affected one standalone system that was isolated and did not reach its enterprise network.
The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a cybersecurity incident after the Qilin ransomware group added the agency to its online leak site on Aug. 26. ATF reported the intrusion affected a single standalone system that was discovered and disconnected from other networks. The agency reported no indication the ATF enterprise network, the ATF eForms system or other systems were affected, and the agency added that the incident has not impacted its ability to perform its missions. An investigation is underway in coordination with the Department of Justice.
An ATF statement read: “The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system. The incident has not impacted ATF’s ability to perform its missions.”
The bureau declined to disclose the type of standalone system involved, how the intruder gained access, or whether data were taken. Officials provided no estimate of data loss, did not say whether law enforcement or national security information was involved, and gave no timetable for the probe’s completion.
Senior Justice Department officials designated the event a “major incident” under federal guidelines and the ATF completed the required notifications, the agency reported.
Qilin has operated since at least 2022 and initially called itself Agenda. The group uses a double-extortion model, combining file encryption with data theft and threats to publish stolen information. Qilin added ATF to its leak site without posting screenshots, naming files or setting a timeline for publishing data. The group has exploited a zero-day vulnerability in a Check Point VPN product in recent campaigns and has listed more than 2,000 victims on its leak site; security researchers say the actual number is likely higher because many victims pay ransoms and are not publicly named.








