ATF Confirms Cyberattack Hit System with Investigation Target Data; Qilin Ransomware Group Claims Responsibility
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a cyberattack impacted a standalone system containing information on investigation targets, with the ransomware group Qilin claiming responsibility.

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed that a cyberattack compromised a standalone system containing sensitive information about its investigation targets. The agency stated that the affected system was isolated and promptly shut down upon discovery, with no impact on other ATF operations or missions. This confirmation comes after the prolific ransomware group Qilin claimed responsibility for the breach, although the ATF has not independently verified the group's involvement.
The ATF's public affairs chief, Tanya Roman, clarified that the compromised system was not connected to any other agency networks, including case management, laboratory, or eForms systems. This isolation was crucial in preventing the breach from spreading to more critical infrastructure. The agency has designated the incident a "major incident" and has completed necessary notifications to senior officials.
Qilin, a financially-motivated ransomware group known for its Russian-speaking operators, has been highly active since 2022, claiming hundreds of victims globally across various sectors such as manufacturing, healthcare, financial services, education, and government. According to reports, Qilin was among the most active ransomware threats by mid-2025 and was frequently reported to the FBI's Internet Crime Complaint Center.
While Qilin has a history of targeting government entities, its alleged involvement in an attack against a federal law enforcement agency like the ATF could represent an escalation in their targeting strategy. However, the specific objectives behind this potential attack remain unclear, especially given the unlikelihood of a ransom payment from a federal agency.
The ATF declined to comment on the specifics of Qilin's alleged involvement, the root cause of the attack, or the timeline of its occurrence. The agency disclosed the attack shortly after Qilin made its claim public, emphasizing that the investigation is ongoing and further details cannot be shared at this time.
Despite the breach, the ATF reiterated that it has not impacted the agency's ability to perform its core missions. The FBI has previously identified Qilin as one of the top five most reported ransomware variants, and Google also noted its significant activity in 2025. The group operates on an affiliate-based model, consistently claiming new victims each month.
Qilin's operational tactics include forming strategic partnerships with other threat actors and utilizing overlapping infrastructure with groups like BianLian. The majority of its victims are based in the United States, with a notable concentration in the manufacturing industry. The potential targeting of a federal law enforcement agency by such a group raises concerns about the evolving threat landscape and the increasing boldness of ransomware operations.
The incident underscores the persistent threat posed by ransomware groups to government agencies and the critical importance of maintaining isolated systems and robust incident response protocols. The ATF's swift action to shut down the affected system highlights a key defense mechanism against the lateral movement of attackers within a network.