VYPR
breachPublished Aug 27, 2026· 1 source

DOJ Firearms Agency Confirms Breach by Qilin Ransomware

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a significant cyberattack, with the Qilin ransomware gang claiming responsibility for compromising a system containing sensitive data on investigation targets.

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), a key agency within the U.S. Department of Justice, has confirmed it was the victim of a significant cyberattack. The incident, which the agency has designated a "major incident" under federal guidelines, saw the Qilin ransomware gang claim responsibility by listing the ATF on its data leak site.

According to an ATF spokesperson, the breach affected a "standalone computer system containing information about targets of ATF investigations." Crucially, the agency emphasized that this system was not connected to any other ATF networks, including case management, laboratory, or eForms systems. This isolation, the spokesperson stated, allowed the system to be "quickly shut down" upon discovery of the breach.

The ATF has initiated comprehensive incident-response and forensic activities, terminating all connections to the affected environment immediately after the breach was identified. While the agency asserts that the attack has not impacted its ability to perform its core missions, the designation of the incident as "major" underscores the potential severity and sensitivity of the compromised data.

The Qilin ransomware group has been a prolific threat actor throughout 2025 and 2026. The gang has been linked to numerous high-profile attacks, including breaches at Kuala Lumpur International Airport, Japanese beverage giant Asahi, the city of Sugar Land, Texas, and several Texas-based power companies. Their activity has drawn significant law enforcement attention, particularly after a disruptive attack on a British healthcare company.

Despite increased scrutiny, Qilin has demonstrated resilience, continuing to launch damaging attacks. Researchers noted Qilin as the second most active ransomware gang in July 2026, reporting 127 attacks. Recent victims include French rugby club Stade Français Paris, highlighting the group's persistent targeting of diverse sectors.

The Department of Justice is overseeing the investigation into the ATF breach. This incident adds to a series of cyber challenges faced by the Justice Department, which has previously experienced breaches affecting the U.S. Marshals Service, the FBI, and the federal courts' docketing system.

In their leak site post, the Qilin ransomware gang did not initially provide samples of the data allegedly stolen from the ATF, only confirming the agency's name. The full scope and nature of the compromised investigation targets remain unclear as the investigation is ongoing. The ATF has stated that no further details can be shared at this time due to the active nature of the investigation.

This breach serves as a stark reminder of the persistent threats posed by sophisticated ransomware groups to government agencies. The compromise of a system containing sensitive investigation data, even if isolated, raises significant concerns about data security and the potential for future exploitation by threat actors.

Synthesized by Vypr AI