The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives declared a major cybersecurity incident after the Qilin ransomware gang listed the federal law enforcement agency on its public leak site.
ATF Responds to Standalone System Breach
Senior Justice Department officials formally designated the intrusion as a “major incident” under federal guidelines. Under U.S. law, this legal classification applies to significant cyber events likely to cause demonstrable harm to national security or broader federal interests, requiring agencies to notify Congress within one week of discovery.
https://x.com/AlvieriD/status/2092913665661907101
In a public statement, the ATF confirmed that the breach did not affect its enterprise network, the eForms system, or any other operational infrastructure. Upon discovering the intrusion, agency staff immediately blocked connections to the affected environment.
Qilin Ransomware Gang Claims Responsibility
The Russia-linked Qilin cybercrime crew claimed responsibility for the breach by listing the firearms agency on its extortion leak site. However, the group did not provide concrete evidence, such as data samples or specific figures detailing the volume of stolen files, according to TechCrunch reporting. The ATF spokesperson declined to answer additional questions concerning Qilin’s claims, the ransom demands, or the exact nature of the stolen data.
Qilin operates a ransomware-as-a-service model, leasing its malicious encryption tools to criminal affiliates in exchange for a percentage of profits. The gang previously targeted high-profile organizations, including media enterprise Lee Enterprises and U.K. pathology lab giant Synnovis, an attack that severely disrupted National Health Service operations in Britain. Data from Comparitech shows Qilin ranked among the most active ransomware operations, claiming 125 incidents out of 799 total global ransomware attacks recorded in July.
Precedents in Federal Agency Breaches
The ATF now joins several other federal organizations that have declared major cyber incidents in recent years. Marshals Service.

Federal law mandates strict reporting timelines following these designations to ensure congressional oversight. Investigations into the extent of the ATF data exposure remain ongoing as the Department of Justice assists with technical remediation and forensic analysis.
Keep reading