ATF Declares Major Cyber Incident After Ransomware Gang Claims Hack
ATF declares a major cyber incident after a ransomware group claims to have hacked a standalone system containing sensitive investigative data.
The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has classified a recent cyberattack against one of its systems as a “major incident,” triggering formal reporting requirements to Congress under federal cybersecurity rules.
The agency said it is responding to a cyberattack affecting a standalone system separate from the ATF network. The bureau said it is investigating the incident and working to determine the scope of the attack.
An ATF spokesperson told reporters that the affected computer system contained information related to the targets of ATF investigations. The agency has not publicly disclosed additional details about the information involved or whether attackers removed any data.
The ransomware group Qilin has claimed responsibility for the attack. The group operates a ransomware-as-a-service model, where it provides hacking tools and infrastructure to criminal affiliates in exchange for a share of ransom payments.
Qilin has previously been linked to attacks targeting organisations such as the media company Lee Enterprises and the U.K. pathology provider Synnovis. Security researchers have identified the group as a ransomware operation involved in double-extortion campaigns, where attackers threaten to release stolen information if ransom demands are not met.
Under federal cybersecurity guidelines, a “major incident” is a significant cyber event likely to cause demonstrable harm to U.S. national security, foreign relations, the economy, public confidence, civil liberties, or public health and safety.
The designation also activates federal reporting requirements. Agencies are required to notify Congress about major cybersecurity incidents within a week of discovery.
The ATF joins other U.S. government agencies that have declared major cybersecurity incidents after breaches. Previous examples include a ransomware attack affecting a system used by the U.S. Marshals Service in 2023 and a breach involving an FBI system that exposed phone numbers connected to surveillance targets.
The ATF has not released further public details about how attackers gained access, the full impact of the incident, or whether additional systems were affected. The investigation is ongoing.
What's Your Reaction?
Like
0
Dislike
0
Love
0
Funny
0
Angry
0
Sad
0
Wow
0