BTC$84,744-0.06% LTC$70.31+4.13% XMR$539.16-1.74%
TorPortal TorPortalMarkets, mirrors, dark web news
The Record · Aug 27, 2026 · 2 min read · Original story

DOJ firearms agency says hackers breached system containing investigation targets

DOJ firearms agency says hackers breached system containing investigation targets
DOJ firearms agency says hackers breached system containing investigation targets

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed that it recently experienced a cyberattack, calling the breach a “major incident.”

The agency, housed within the Department of Justice, appeared on the leak site of the Qilin ransomware gang on Wednesday.

An ATF spokesperson told Recorded Future News the issue “involved a standalone computer system containing information about targets of ATF investigations.”

“The standalone system was not connected to any other ATF systems, including any case management systems, laboratory systems, or eForms systems, and it was quickly shut down when the breach was discovered,” the spokesperson said. “This is an ongoing investigation, and no further details can be shared at this time.”

The agency later released a public statement on Wednesday evening reiterating that the attack had no impact on any other internal system.

ATF officials “immediately terminated connections to the affected environment and initiated incident‑response and forensic activities,” they said.

The attack did not impact ATF’s “ability to perform its missions,” the statement added, though senior officials have designated it a “major incident” based on federal guidelines. The Justice Department is investigating the cyberattack.

The cyber incident is the latest to impact the Justice Department after multiple incidents involving the U.S. Marshals Service and the FBI. The Justice Department itself suffered a breach of the federal courts docketing system in early 2020.

In a post on its leak site, the Qilin ransomware gang did not provide any samples of stolen data, only adding the ATF’s name to the site.

Qilin was one of the most active ransomware operations in 2025, targeting Kuala Lumpur International Airport, Japanese beverage giant Asahi, the Texas city of Sugar Land, a county government in North Carolina and multiple power companies in Texas.

The group faced increased law enforcement scrutiny in 2024 after a devastating attack on a British healthcare company that prompted major disruptions to medical services.

But it quickly returned with attacks on the government of Palau and one of the largest newspaper chains in the United States.

The group has continued to launch damaging attacks in 2026, with researchers saying it was the second most active ransomware gang in July with 127 reported attacks. Earlier this month, French rugby club Stade Français Paris confirmed it had been attacked after being added to Qilin’s leak site.

References in this story

  1. Dark Web Informer (@DarkWebInformer) on X x.com ‼️🚨🇺🇸 Big Claim... Qilin is claiming the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) 🇺🇸 Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) - A U.S. federal law enforcement agency within the…
  2. US Marshals say data posted by ransomware gang not from 'new or undisclosed incident' therecord.media Cybercriminals posted 386 GB of data that they said was stolen from the U.S. Marshals Service. The agency said it evaluated the claims and found nothing that it hadn't seen before.
  3. www.cnn.com
  4. Researchers warn of Qilin ransomware gang after group hit hundreds of orgs this year therecord.media In October alone, the suspected Russia-based group added more than 185 victims to its leak site — claiming to be behind recent cybersecurity incidents at Japanese beverage giant Asahi, the Texas city of Sugar Land, a…
  5. Malaysia PM says country rejected $10 million ransom demand after airport outages therecord.media Computer outages at Malaysia’s Kuala Lumpur International Airport (KLIA) this weekend were attributed to a recent cyberattack, according to the country’s cybersecurity agency and aviation authority.
  6. Cybercrime crew claims attack on Japanese brewer as it restarts operations therecord.media As Asahi said it had restarted production of Super Dry beer in Japan, the Qilin ransomware gang posted screenshots of documents it said were from the company's internal networks.
  7. Houston suburb says some online services taken down by cyberattack therecord.media Officials in Sugar Land, Texas, said a cyberattack has impacted some online services.
  8. Darknet site for Qilin gang, suspected in London hospitals ransomware attack, goes down therecord.media The ransomware group Qilin is drawing extra scrutiny as London-area healthcare services respond to a disruptive cyberattack. It was unclear why the gang's extortion site was down.
  9. Ransomware attack continues to disrupt healthcare in London nearly two years later therecord.media More than 18 months after a ransomware attack disrupted care at hospitals in South East London, documents show at least one NHS trust is still working without fully restored systems and managing large backlogs of…
  10. Palau health ministry on the mend after Qilin ransomware attack therecord.media A U.S. Cyber Command “defend forward” team is now on-site conducting forensics collection and analysis, according to Palau officials.
  11. Newspaper giant Lee Enterprises says nearly 40,000 Social Security numbers leaked in ransomware attack therecord.media Lee Enterprises notified regulators in Maine of the impact on customer data after a ransomware attack in February that caused significant disruptions.
  12. Hackers threaten to leak data after cyberattack on German party Die Linke therecord.media Die Linke confirmed in late March that its IT infrastructure had been hit by what it described as a “serious cyberattack.”
  13. Romania’s oil pipeline operator confirms cyberattack as hackers claim data theft therecord.media Romania’s national oil pipeline operator Conpet said a cyberattack disrupted parts of its technology infrastructure and knocked its website offline earlier this week, adding that oil transport operations were not…
  14. French rugby club Stade Français restores systems after cyberattack, probes data leak therecord.media The club said Thursday that it had already restored its IT environment from clean backups, allowing operations to continue normally. It added that its ticketing platform and online store were not affected and remain…
  15. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  16. Advanced Cyber Threat Intelligence | Recorded Future www.recordedfuture.com Get real-time, actionable cyber threat intelligence with Recorded Future. Mitigate cyber risks, prioritize threats, and proactively secure your organization.
  17. jon greig (@jgreigj) on X twitter.com @TheRecord_Media cybersecurity reporter. formerly @zdnet @cambodiadaily @haitiantimes_ — send tips to [email protected] or signal: jgreig.51
  18. jon greig (@jgreig.bsky.social) bsky.app cybersecurity reporter for The Record. formerly: zdnet, techrepublic, blavity, haitian times, cambodia daily — send tips to [email protected] or signal: jgreig.51

Guides related to this story

← Back to all news