The Qilin ransomware group has released data it claims was stolen from the US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), exposing files that appear to contain information connected to federal criminal investigations and digital forensic examinations.
The publication follows an earlier threat from Qilin, which gave the agency 72 hours before releasing the stolen material. After the countdown expired, the ransomware operation posted what appears to be at least 6.3GB of internal ATF files on its dark web leak site.
ATF has confirmed that a legacy standalone system was compromised. The affected environment has been identified as the agency’s CALEA system, which is used in connection with federally authorized electronic surveillance under the Communications Assistance for Law Enforcement Act.
The agency acknowledged that Qilin is claiming to have published material obtained from that system but said it has not verified the authenticity, exact nature, or complete scope of the released files. ATF is working with the Department of Justice and other federal partners to investigate the incident.
The bureau previously confirmed that the compromised system contained information concerning targets of ATF investigations. However, officials said there was no indication that attackers reached the agency’s main enterprise network, its eForms platform, or other ATF systems. The incident also did not disrupt the agency’s operations.
An initial examination of the published material indicates that the leak may contain considerably more than routine administrative information.
Directories within the data appear to correspond to individual investigations and field operations, including folders associated with ATF offices in Houston and Laredo. Other directories appear to identify individuals, specific mobile devices and online accounts connected to investigative work.
The files also appear to contain information extracted from smartphones and other devices. The exposed material reportedly includes references to iPhones, Samsung Galaxy devices, SIM cards, iCloud information and Cellebrite forensic extractions.
Additional records contain what appear to be account identifiers, IP addresses, registration information and verified telephone numbers. Some directories also seem to correspond directly to criminal cases, including records associated with an armored truck robbery investigation.
The leak may additionally reveal information about parts of ATF’s technology environment, including security software used by the agency.
Qilin first listed ATF on its leak site on August 26th, the same day the agency confirmed that one of its standalone systems had been breached. At that point, the ransomware group had provided little evidence about what it had obtained.
The subsequent publication provides substantially more material, but the full impact remains under investigation. ATF has not officially attributed the intrusion to Qilin, and authorities have not confirmed that every file published by the ransomware group is authentic.
The sensitivity of the affected system makes the incident particularly serious. ATF investigations can involve firearms trafficking, explosives, arson, violent crime and other federal cases, meaning exposed investigative records could potentially contain information about suspects, evidence and people connected to ongoing or previous investigations.