International Edition
Latest News
Business

ATF Declares ‘Major Incident’ After Qilin Ransomware Gang Claims Hack

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives declared a major cybersecurity incident after the Qilin ransomware gang listed the federal law enforcement agency on its public leak site. ATF Responds to Standalone System Breach Senior Justice…

ATF Declares ‘Major Incident’ After Qilin Ransomware Gang Claims Hack

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives declared a major cybersecurity incident after the Qilin ransomware gang listed the federal law enforcement agency on its public leak site.

ATF Responds to Standalone System Breach

Senior Justice Department officials formally designated the intrusion as a “major incident” under federal guidelines. Under U.S. law, this legal classification applies to significant cyber events likely to cause demonstrable harm to national security or broader federal interests, requiring agencies to notify Congress within one week of discovery.

In a public statement, the ATF confirmed that the breach did not affect its enterprise network, the eForms system, or any other operational infrastructure. Upon discovering the intrusion, agency staff immediately blocked connections to the affected environment.

Qilin Ransomware Gang Claims Responsibility

The Russia-linked Qilin cybercrime crew claimed responsibility for the breach by listing the firearms agency on its extortion leak site. However, the group did not provide concrete evidence, such as data samples or specific figures detailing the volume of stolen files, according to TechCrunch reporting. The ATF spokesperson declined to answer additional questions concerning Qilin’s claims, the ransom demands, or the exact nature of the stolen data.

Qilin operates a ransomware-as-a-service model, leasing its malicious encryption tools to criminal affiliates in exchange for a percentage of profits. The gang previously targeted high-profile organizations, including media enterprise Lee Enterprises and U.K. pathology lab giant Synnovis, an attack that severely disrupted National Health Service operations in Britain. Data from Comparitech shows Qilin ranked among the most active ransomware operations, claiming 125 incidents out of 799 total global ransomware attacks recorded in July.

Precedents in Federal Agency Breaches

The ATF now joins several other federal organizations that have declared major cyber incidents in recent years. Marshals Service.

ATF Declares 'Major Incident' After Qilin Ransomware Gang Claims Hack
Photo: techcrunch.com

Federal law mandates strict reporting timelines following these designations to ensure congressional oversight. Investigations into the extent of the ATF data exposure remain ongoing as the Department of Justice assists with technical remediation and forensic analysis.

ATF investigating 'major' cybersecurity incident
About the author: Marcus Liu - Business Editor

MBA and ex‑B bureau chief specializing in global finance and fintech. Marcus speaks Mandarin, Japanese, and English, and has interviewed CEOs from the Fortune 50 to Y‑Combinator unicorns. Marcus Liu delivers sharp analysis on markets, startups, and corporate strategy for investors and entrepreneurs alike.