VYPR
breachPublished Aug 27, 2026· 1 source

Qilin Ransomware Gang Claims Major Breach at US Bureau of Alcohol, Tobacco, Firearms and Explosives

The Qilin ransomware gang claims to have breached the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), prompting a federal investigation into a major cybersecurity incident.

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) is currently responding to a significant cybersecurity incident after the Qilin ransomware gang asserted it had successfully breached the agency's systems. The intrusion reportedly affected a standalone IT system, distinct from the ATF's primary enterprise network and its eForms system.

In a statement, the ATF confirmed that it is "coordinating closely" with the Department of Justice (DOJ) to investigate the breach. Upon discovery of the incident, the agency "immediately" blocked all connections to the compromised IT environment. The ATF emphasized that there is currently no indication that the incident has impacted its main enterprise network, the eForms system, or any other operational systems.

Senior Justice Department officials have officially designated the compromise as a "major incident" according to federal guidelines, underscoring the severity of the breach. Despite the incident, the ATF stated that its day-to-day operations have not been affected. The agency is actively working to determine the full scope and impact of the intrusion.

The Qilin ransomware gang listed the ATF on its dark web leak site shortly before the agency released its public statement. While the gang's post, observed by The Register, did not specify the type or volume of data allegedly stolen, nor did it provide substantiating samples, the claim itself has triggered a high-level response.

Qilin is a ransomware group known for its significant attacks, including a high-profile incident targeting the UK's National Health Service (NHS) through pathology provider Synnovis in 2024. This latest claim places the ATF, a key federal law enforcement agency, in the crosshairs of a prolific cybercriminal organization.

Comparitech, a firm specializing in cybersecurity product reviews and data analysis, identified Qilin as one of the most active ransomware gangs in July, accounting for 125 of the 799 ransomware incidents recorded that month. The gang's continued activity highlights the persistent threat posed by ransomware operators to government agencies and critical infrastructure.

The ATF has not yet provided further details regarding the specific vulnerability exploited or the nature of the data potentially compromised. The investigation is ongoing, with the agency expected to provide updates as more information becomes available. The incident serves as a stark reminder of the ongoing cyber threats facing US federal agencies.

Synthesized by Vypr AI