← All stories
● Covered by 4 sources · 4 reportsMedium impact2 negative2 neutral

ATF confirms "major incident" after Qilin ransomware group claims breach

🔄 Updated 34d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • ATF confirmed a breach of a standalone system.
  • Qilin ransomware group claimed responsibility for the breach.
  • The main ATF enterprise network was not affected.
  • ATF is investigating with the Department of Justice.
  • The breached system contained information about targets of ATF investigations.
  • ATF shut down the standalone system when the breach was discovered.
  • ATF released a public statement on Wednesday evening.
  • ATF officials terminated connections to the affected environment and initiated incident-response and forensic activities.
  • The attack did not impact ATF's ability to perform its missions.
  • ATF classified the cyberattack as a "major incident."
  • The "major incident" classification triggers formal notification to Congress.
  • Agencies must disclose major incidents to Congress within one week.
  • Qilin ransomware group operates a "ransomware-as-a-service" model.
  • Qilin previously listed Lee Enterprises and Synnovis on its leak site.
  • ATF added to Qilin's leak website on August 26.
  • Qilin has not made specific claims about the breach.
  • Qilin has not posted screenshots of stolen documents from ATF.

ATF System Compromised

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed that one of its standalone systems was compromised. This confirmation follows claims made by the Qilin ransomware group, which added the ATF to its dark web data leak portal.

Incident Details and Response

The ATF described the event as a "major incident" and is investigating it in collaboration with the Department of Justice. Upon discovery, the agency immediately terminated connections to the affected environment and initiated incident-response and forensic activities. The impacted system operates separately from the main ATF enterprise network, and there is no indication that the incident affected the ATF eForms system or any other core ATF system.

Operational Impact and Public Appeal

The ATF stated that the incident did not affect the agency's operations. The agency has asked the public to share any information regarding the attack through its official tipline.

About Qilin Ransomware

Qilin is a Ransomware-as-a-Service (RaaS) operation, first identified in August 2022 under the name "Agenda." The group has claimed responsibility for over 2,200 victims on its dark web leak site, including organizations such as Nissan, Yangfeng, Synnovis, Asahi, Lee Enterprises, and Australia's Court Services Victoria.

Broader Context of Government Breaches

This incident follows other cybersecurity breaches disclosed by U.S. federal agencies this year. The FBI confirmed in March it was investigating a breach affecting systems for wiretap and surveillance warrants. In July, the Department of Homeland Security disclosed a cyberattack that compromised the Homeland Security Information Network (HSIN).

Updates

🕒 2026-08-28 · new reporting from SecurityWeek
  • ATF added to Qilin's leak website on August 26.
  • Qilin has not made specific claims about the breach.
  • Qilin has not posted screenshots of stolen documents from ATF.
🕒 2026-08-27 · new reporting from TechCrunch
  • ATF classified the cyberattack as a "major incident."
  • The "major incident" classification triggers formal notification to Congress.
  • Agencies must disclose major incidents to Congress within one week.
  • Qilin ransomware group operates a "ransomware-as-a-service" model.
  • Qilin previously listed Lee Enterprises and Synnovis on its leak site.
🕒 2026-08-27 · new reporting from The Record
  • The breached system contained information about targets of ATF investigations.
  • ATF shut down the standalone system when the breach was discovered.
  • ATF released a public statement on Wednesday evening.
  • ATF officials terminated connections to the affected environment and initiated incident-response and forensic activities.
  • The attack did not impact ATF's ability to perform its missions.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

The US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a cybersecurity incident on a standalone system after the Qilin ransomware group claimed an attack. The incident did not affect the ATF enterprise network or its ability to perform missions, but the Justice Department has designated it a "major incident."

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has classified a cyberattack on one of its standalone systems as a "major incident," triggering a formal notification to Congress. The Qilin ransomware gang has claimed responsibility for the attack, which targeted a system containing information related to ATF investigations. This incident highlights ongoing cybersecurity vulnerabilities within government agencies, following similar breaches at the U.S. Marshals Service and the FBI.

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a cyberattack on a standalone system holding information about investigation targets. The Qilin ransomware gang claimed responsibility, listing the ATF on its leak site, marking another incident for the Justice Department.

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a "major incident" involving a breach of one of its standalone systems, following claims by the Qilin ransomware group. The agency stated that its main enterprise network, eForms system, and other ATF systems were not affected, and operations remain uninterrupted.