ATF confirms cyberattack hit system containing info on its investigation targets

Wait 5 sec.

The Bureau of Alcohol, Tobacco, Firearms and Explosives insists the cyberattack that it publicly disclosed Wednesday was limited to investigation targets, and has not impacted other agency systems.ATF said it is responding to the breach, which first became public after a prolific ransomware group claimed it accessed the federal agency’s network “The incident involved a standalone computer system containing information about targets of ATF investigations,” Tanya Roman, ATF’s public affairs chief, told CyberScoop in an email.“The standalone system was not connected to any other ATF systems, including any case management systems, laboratory systems, or eForms systems, and it was quickly shut down when the breach was discovered,” Roman added. Qilin, a financially-motivated threat group composed of Russian-speaking operators, claimed responsibility for the attack, but its involvement hasn’t been independently confirmed. The group has claimed hundreds of victims from more than 60 countries since 2022 and became one of the most active ransomware threats globally by mid-2025, according to Halcyon. ATF declined to comment on Qilin’s alleged involvement, the root cause of the attack or when it occurred. Yet, the agency disclosed the attack hours after Qilin claimed it breached ATF’s systems.“This is an ongoing investigation, and no further details can be shared at this time,” Roman said. The federal law enforcement agency, which is under the Justice Department, said senior officials designated the event a “major incident” and completed notifications. “The incident has not impacted ATF’s ability to perform its missions,” ATF said in a statement.Qilin operates an affiliate-based ransomware model and remains highly active, claiming dozens of new victims monthly across manufacturing, health care, financial services, education and government sectors.The FBI said Qilin was among the five-most reported ransomware variants reported to Internet Crime Complaint Center last year. Google also said the group was one of the most active ransomware brands in 2025.The majority of Qilin’s victims are based in the United States and nearly 1 in 4 alleged targets are in the manufacturing industry, according to Halcyon. The extortion group has formed strategic partnerships with Scattered Spider and Moonstone Sleet, and uses infrastructure overlapping with BianLian. While Qilin has targeted organizations in the government sector before, its claimed attack against a federal law enforcement agency could mark an escalation in targeting. Yet, its objectives in this case are unclear as any ransom payment is very unlikely.The post ATF confirms cyberattack hit system containing info on its investigation targets appeared first on CyberScoop.