HomeUSATF Probes Significant Cybersecurity Breach Amid Ransomware Group's Attack Claim

ATF Probes Significant Cybersecurity Breach Amid Ransomware Group’s Attack Claim

Meanwhile, the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) announced on Wednesday that it is probing a cybersecurity breach involving a standalone system. Distinguished as a “major incident” under federal standards, this development has captured the attention of senior Justice Department officials.

This revelation surfaces as the Qilin ransomware group claims responsibility for targeting the ATF, according to cybersecurity analysts monitoring the group’s online activity. Although Qilin has yet to furnish evidence to back up its assertion, the ATF has not attributed the breach to this particular group.

The ATF has clarified that the compromised system functions independently of its main network. Investigations suggest that neither the agency’s broader network, its eForms system, nor any other ATF platforms have been impacted by this breach.

Upon uncovering the incident, the ATF swiftly isolated the affected environment and initiated thorough forensic and incident-response procedures. The bureau is working in conjunction with the Justice Department to dissect the details of this security lapse.

Bureau of Alcohol, Tobacco, Firearms and Explosives national headquarters in Washington, D.C.

The Bureau of Alcohol, Tobacco, Firearms and Explosives national headquarters in Washington, D.C. ATF said Wednesday it is investigating a cybersecurity incident involving a standalone system. (Rich Clement/Bloomberg via Getty Images)

The agency did not identify the affected system, say when the incident was discovered or disclose whether any data was accessed or stolen.

Cybernews reported Wednesday that Qilin claimed ATF as its latest victim but had provided no evidence or details supporting the claim. 

GalaxyWarden, a breach-monitoring service, separately reported that ATF appeared on Qilin’s leak site and that the group claimed it obtained files from the agency. GalaxyWarden said it had not independently verified the group’s assertions.

News Media reached out to ATF and the Justice Department for additional information, including whether officials believe Qilin was responsible for the incident, whether any data was accessed or stolen and what prompted officials to designate the event a “major incident.”

ATF said senior Justice Department officials designated the cybersecurity event a “major incident” under applicable federal guidelines and that required notifications have been completed.

DOJ CHARGES 3 RUSSIANS IN ALLEGED $63M CYBERCRIME SCHEME TARGETING AMERICANS

U.S. Department of Justice building in Washington, D.C., on Aug. 17, 2026

The U.S. Department of Justice building in Washington, D.C., on Aug. 17, 2026. ATF said it is coordinating with the Justice Department as it investigates a cybersecurity incident involving a standalone system. (Anna Moneymaker/Getty Images)

The incident has not disrupted ATF operations or affected the agency’s ability to carry out its missions, according to the agency.

Firearm-Trafficking

A security official walks in front of the entrance to the national headquarters of the Bureau of Alcohol, Tobacco, Firearms and Explosives on Jan. 23, 2014, in Washington.

The agency asked anyone with information related to the incident to contact the ATF Tipline at 1-888-ATF-TIPS, or 1-888-283-8477.