ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site
The breached system reportedly held information on criminal investigation targets, but was isolated from the bureau's main network. DOJ has classified it a major incident.
The Bureau of Alcohol, Tobacco, Firearms and Explosives has confirmed hackers breached one of its computer systems, after the Russian-linked ransomware group Qilin claimed the attack and added the agency to its dark web leak site.
The compromised system reportedly held information tied to targets of ATF criminal investigations. The bureau says it was an isolated environment, cut off from the agency's main enterprise network, and states there is no indication the incident touched the ATF enterprise network, the ATF eForms system, or any other agency system. The bureau's ability to carry out its mission, it says, has not been affected.
Senior Justice Department officials have classified the breach as a major incident under federal guidelines. That classification is not a formality: it legally requires notifying Congress within seven days and it triggers centralized interagency oversight of the resulting investigation, which is a meaningfully higher bar than most breach disclosures ever reach.
The compromised system reportedly held information tied to targets of ATF criminal investigations.
Qilin's own claim is thinner than usual for the group. It added ATF to its leak site alongside five other targets on Wednesday, but, unlike its handling of other listings around the same time, provided no timestamps, no data size estimate and no proof files to back the claim up. That gap between assertion and evidence matters here specifically, because a breach touching active federal investigation targets carries real safety implications for informants and case subjects if the claim turns out to be accurate, and real reputational cost to Qilin if it turns out to be an empty listing.
Federal law enforcement agencies remain an unusual target class. They hold data valuable enough to attract serious ransomware crews, but they also tend to segment sensitive investigative systems away from general IT infrastructure specifically because of scenarios like this one. Whether that segmentation held here as cleanly as ATF's statement suggests will likely become clearer as the DOJ's mandated oversight process plays out.
Qilin itself has had an active year. The group, believed to operate a ransomware-as-a-service model that leases its tooling to affiliate crews, has claimed a wide spread of victims across healthcare, manufacturing and now, apparently, federal law enforcement, a target list broad enough that some researchers question whether every listing on its leak site represents a genuine intrusion of the scale claimed. That skepticism cuts both ways here. It is exactly why ATF's own confirmation, thin on detail as it is, carries more weight than Qilin's claim alone would.
Based on reporting by CyberScoop.




