The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed that a standalone system was compromised in a cybersecurity incident, shortly after the Qilin ransomware operation listed the federal agency on its dark web leak site.

 

 

Qilin added ATF to its list of alleged victims on Wednesday. The ransomware group did not provide details about what it claimed to have obtained and did not publicly state whether a ransom had been demanded.

On the same day, ATF acknowledged a cybersecurity incident involving one of its systems, describing the breach as a “major incident.” According to the agency, the affected environment is separate from its primary enterprise network.

ATF said there was no indication that its enterprise network, eForms platform, or other agency systems had been affected. After discovering the intrusion, officials disconnected the compromised environment and began forensic and incident-response work.

The Department of Justice is working with ATF on the investigation. The agency also said the incident had not disrupted its operations.

While the timing of Qilin’s claim and ATF’s disclosure connects the two developments, ATF’s announcement does not publicly attribute the intrusion to Qilin. The agency has also not disclosed whether information was stolen from the compromised system. Therefore, Qilin’s responsibility for the breach and any claims regarding stolen data remain unconfirmed.

Qilin operates a Ransomware-as-a-Service model and has been active since 2022, when the operation was initially tracked under the name Agenda. The group has subsequently claimed attacks against a wide range of organizations and publishes alleged victims through its dark web leak portal.

Its previously reported targets include Nissan, automotive supplier Yanfeng, pathology services provider Synnovis, Japanese brewer Asahi, newspaper publisher Lee Enterprises, and Court Services Victoria in Australia.

The ATF incident follows several other cybersecurity breaches disclosed by U.S. federal agencies during 2026. In March, the FBI confirmed that it was investigating an intrusion affecting systems involved in managing surveillance and wiretap warrants.

The Department of Homeland Security disclosed another incident in July involving the Homeland Security Information Network (HSIN). That platform facilitates information sharing among federal, state, and local authorities as well as private-sector partners.

For the ATF breach, several important details remain undisclosed. The agency has not identified how attackers initially gained access, when the compromise began, what information was stored in the affected environment, or whether any files were exfiltrated.

ATF said it is continuing its investigation with the Department of Justice and has requested that anyone with relevant information about the incident contact the agency through its official tipline. ATF cybersecurity incident statement

Leave a Reply