DOJ firearms agency says hackers breached system containing investigation targets
ATF confirmed a cyberattack on a standalone system containing investigation target data, calling it a major incident; Qilin listed ATF on its leak site.
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a cyberattack on a standalone computer system containing information about targets of ATF investigations, with no connection to case management, laboratory, or eForms systems. The agency designated the breach a major incident and immediately terminated connections, initiating incident response and forensics. The Qilin ransomware gang added ATF to its leak site without providing stolen data samples. Qilin was the second most active ransomware gang in July 2026 with 127 reported attacks, and has previously hit Kuala Lumpur International Airport, Asahi, and Palau's government.
- ATF designates breach of standalone investigation-target system as major incident
- Qilin ransomware listed ATF on its leak site with no stolen data samples shown
- No impact on ATF mission systems including eForms and case management
- Justice Department is investigating the cyberattack
- Qilin ranked second most active ransomware gang in July 2026 with 127 attacks
Full article443 words · extracted from therecord.media · click to collapse
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed that it recently experienced a cyberattack, calling the breach a “major incident.” The agency, housed within the Department of Justice, appeared on the leak site of the Qilin ransomware gang on Wednesday. An ATF spokesperson told Recorded Future News the issue “involved a standalone computer system containing information about targets of ATF investigations.” “The standalone system was not connected to any other ATF systems, including any case management systems, laboratory systems, or eForms systems, and it was quickly shut down when the breach was discovered,” the spokesperson said. “This is an ongoing investigation, and no further details can be shared at this time.” The agency later released a public statement on Wednesday evening reiterating that the attack had no impact on any other internal system. ATF officials “immediately terminated connections to the affected environment and initiated incident‑response and forensic activities,” they said. The attack did not impact ATF’s “ability to perform its missions,” the statement added, though senior officials have designated it a “major incident” based on federal guidelines. The Justice Department is investigating the cyberattack. The cyber incident is the latest to impact the Justice Department after multiple incidents involving the U.S. Marshals Service and the FBI. The Justice Department itself suffered a breach of the federal courts docketing system in early 2020. In a post on its leak site, the Qilin ransomware gang did not provide any samples of stolen data, only adding the ATF’s name to the site. Qilin was one of the most active ransomware operations in 2025, targeting Kuala Lumpur International Airport, Japanese beverage giant Asahi, the Texas city of Sugar Land, a county government in North Carolina and multiple power companies in Texas. The group faced increased law enforcement scrutiny in 2024 after a devastating attack on a British healthcare company that prompted major disruptions to medical services. But it quickly returned with attacks on the government of Palau and one of the largest newspaper chains in the United States. The group has continued to launch damaging attacks in 2026, with researchers saying it was the second most active ransomware gang in July with 127 reported attacks. Earlier this month, French rugby club Stade Français Paris confirmed it had been attacked after being added to Qilin’s leak site.
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/doj-atf-cyberattack-qilin-ransomware