ATF confirms cyberattack hit system containing info on its investigation targets
Qilin ransomware group claimed breaching the ATF, exposing data on investigation targets; the agency says a standalone system was hit with no mission impact.
The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a cyberattack on a standalone system holding information about targets of ATF investigations, designated a major incident, with no impact on case management, lab, or eForms systems. Qilin, a Russian-speaking affiliate-based ransomware group, claimed responsibility, though ATF declined to confirm involvement or the root cause. Qilin has claimed hundreds of victims across 60+ countries since 2022 and partners with Scattered Spider and Moonstone Sleet.
- ATF says incident limited to a standalone investigation-targets system
- Qilin claimed responsibility shortly before ATF's disclosure
- Qilin among five most-reported ransomware variants to IC3 last year
- Group overlaps with BianLian infrastructure; allies with Scattered Spider
Full article650 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
The prolific ransomware group Qilin claimed responsibility for the attack. ATF insists the incident was limited to a standalone system and hasn’t impacted critical operations.
Listen to this article
0:00
Learn more.
The Bureau of Alcohol, Tobacco, Firearms and Explosives insists the cyberattack that it publicly disclosed Wednesday was limited to investigation targets, and has not impacted other agency systems.
ATF said it is responding to the breach, which first became public after a prolific ransomware group claimed it accessed the federal agency’s network “The incident involved a standalone computer system containing information about targets of ATF investigations,” Tanya Roman, ATF’s public affairs chief, told CyberScoop in an email.
“The standalone system was not connected to any other ATF systems, including any case management systems, laboratory systems, or eForms systems, and it was quickly shut down when the breach was discovered,” Roman added.
Qilin, a financially-motivated threat group composed of Russian-speaking operators, claimed responsibility for the attack, but its involvement hasn’t been independently confirmed. The group has claimed hundreds of victims from more than 60 countries since 2022 and became one of the most active ransomware threats globally by mid-2025, according to Halcyon.
ATF declined to comment on Qilin’s alleged involvement, the root cause of the attack or when it occurred. Yet, the agency disclosed the attack hours after Qilin claimed it breached ATF’s systems.
“This is an ongoing investigation, and no further details can be shared at this time,” Roman said.
The federal law enforcement agency, which is under the Justice Department, said senior officials designated the event a “major incident” and completed notifications. “The incident has not impacted ATF’s ability to perform its missions,” ATF said in a statement.
Qilin operates an affiliate-based ransomware model and remains highly active, claiming dozens of new victims monthly across manufacturing, health care, financial services, education and government sectors.
The FBI said Qilin was among the five-most reported ransomware variants reported to Internet Crime Complaint Center last year. Google also said the group was one of the most active ransomware brands in 2025.
The majority of Qilin’s victims are based in the United States and nearly 1 in 4 alleged targets are in the manufacturing industry, according to Halcyon. The extortion group has formed strategic partnerships with Scattered Spider and Moonstone Sleet, and uses infrastructure overlapping with BianLian.
While Qilin has targeted organizations in the government sector before, its claimed attack against a federal law enforcement agency could mark an escalation in targeting. Yet, its objectives in this case are unclear as any ransom payment is very unlikely.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Jail time for Maine child in 764 marks turning point in federal law enforcement
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/atf-doj-cyberattack-qilin-ransomware/