ATF confirms “major incident” after recent Qilin breach claims

ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang.
This follows Qilin adding the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives to its dark web data leak portal on Wednesday, without saying whether it had stolen files from ATF's systems or demanded a ransom.
The same day, the ATF published a press release saying that a standalone system was breached in what it described as a "major incident," which is now being investigated in collaboration with the Department of Justice.
"The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system," the federal law enforcement agency said.
"Upon discovery of the incident, ATF immediately terminated connections to the affected environment and initiated incident‑response and forensic activities. ATF is coordinating closely with the Department of Justice to investigate."
ATF added that the incident did not affect the agency's operations and asked the public to share any information on the attack via its official tipline.
BleepingComputer reached out to an ATF spokesperson with further questions about the incident, but a response was not immediately available.
ATF entry on Qilin leak site (BleepingComputer)Qilin is a Ransomware-as-a-Service (RaaS) operation first spotted in August 2022 under the "Agenda" name that has since claimed responsibility for more than 2,200 victims on its dark web leak site.
The list of victims includes many high-profile organizations such as automotive giants Nissan and Yangfeng, pathology services provider Synnovis, Japanese beer giant Asahi, publishing giant Lee Enterprises, and Australia's Court Services Victoria.
Several other U.S. federal agencies have disclosed cybersecurity incidents since the start of the year after their networks were infiltrated in cyberattacks.
For instance, the U.S. Federal Bureau of Investigation (FBI) confirmed in early March that it was investigating a breach affecting systems used to manage wiretap and surveillance warrants.
More recently, in July, the U.S. Department of Homeland Security also disclosed a cyberattack that compromised the Homeland Security Information Network (HSIN), a sensitive information-sharing platform used by federal, state, local, and private-sector partners.
References in this story
- The AI Security Starter Pack (Free Download) | Wiz wiz.io Wiz is the unified cloud security platform with prevention and response capabilities, enabling security and development teams to build faster and more securely.
- Nissan confirms design studio data breach claimed by Qilin ransomware www.bleepingcomputer.com Nissan Japan has confirmed to BleepingComputer that it suffered a data breach following unauthorized access to a server of one of its subsidiaries, Creative Box Inc. (CBI).
- Qilin ransomware claims attack on automotive giant Yanfeng www.bleepingcomputer.com The Qilin ransomware group has claimed responsibility for a cyber attack on Yanfeng Automotive Interiors (Yanfeng), one of the world's largest automotive parts suppliers.
- Qilin ransomware gang linked to attack on London hospitals www.bleepingcomputer.com A ransomware attack that hit pathology services provider Synnovis on Monday and impacted several major NHS hospitals in London has now been linked to the Qilin ransomware operation.
- Qilin ransomware claims Asahi brewery attack, leaks data www.bleepingcomputer.com The Qilin ransomware group has claimed responsibility for the attack at Japanese beer maker Asahi, adding the company to its extortion page on the dark web yesterday.
- Qilin ransomware claims attack at Lee Enterprises, leaks stolen data www.bleepingcomputer.com The Qilin ransomware gang has claimed responsibility for the attack at Lee Enterprises that disrupted operations on February 3, leaking samples of data they claim was stolen from the company.
- Victoria court recordings exposed in reported ransomware attack www.bleepingcomputer.com Australia's Court Services Victoria (CSV) is warning that video recordings of court hearings were exposed after suffering a reported Qilin ransomware attack.
- FBI investigates breach of surveillance and wiretap systems www.bleepingcomputer.com The U.S. Federal Bureau of Investigation (FBI) confirmed on Thursday that it's investigating a breach that affected systems used to manage surveillance and wiretap warrants.
- DHS confirms hackers breached HSIN info-sharing platform www.bleepingcomputer.com The Department of Homeland Security is investigating a cyberattack that compromised the Homeland Security Information Network (HSIN), a sensitive information-sharing platform used by federal, state, local, and…



