Sunday, August 30, 2026
LIVEGiveWP plugin flaw let unauthenticated attackers run commands on 100,000+ WordPress sites///Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer///PaperCut ships second emergency patch after researchers break the first fix within days///ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site///McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records///Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections///Russia's drone-strike decree turns physical attacks into an ownership question///A Saudi Arabic AI model on Microsoft's platform raises the sovereignty question///Embassy warning on visa agents describes a textbook social-engineering market///Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation///Two HTTP requests were enough to hijack any Keycloak account, researchers found///Microsoft patches a maximum-severity Entra ID flaw, then walks back its exploitation claim///GiveWP plugin flaw let unauthenticated attackers run commands on 100,000+ WordPress sites///Manchester Airports Group breach was worse than first disclosed, extortion gang tells BleepingComputer///PaperCut ships second emergency patch after researchers break the first fix within days///ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site///McKesson breach tied to vishing and Okta compromise, ShinyHunters claims 284 million patient records///Berlin refuses ransom after Rhysida gang steals 5.79 terabytes weeks before city elections///Russia's drone-strike decree turns physical attacks into an ownership question///A Saudi Arabic AI model on Microsoft's platform raises the sovereignty question///Embassy warning on visa agents describes a textbook social-engineering market///Critical Zimbra flaw has already compromised 270+ mail servers, CISA confirms active exploitation///Two HTTP requests were enough to hijack any Keycloak account, researchers found///Microsoft patches a maximum-severity Entra ID flaw, then walks back its exploitation claim///
Subscribe
Cyber Security
Independent · Digital
The Hacking Post
NewsAI-assisted

ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site

The breached system reportedly held information on criminal investigation targets, but was isolated from the bureau's main network. DOJ has classified it a major incident.

ATF confirms cyberattack after Qilin ransomware gang lists the agency on its leak site

The Bureau of Alcohol, Tobacco, Firearms and Explosives has confirmed hackers breached one of its computer systems, after the Russian-linked ransomware group Qilin claimed the attack and added the agency to its dark web leak site.

The compromised system reportedly held information tied to targets of ATF criminal investigations. The bureau says it was an isolated environment, cut off from the agency's main enterprise network, and states there is no indication the incident touched the ATF enterprise network, the ATF eForms system, or any other agency system. The bureau's ability to carry out its mission, it says, has not been affected.

Senior Justice Department officials have classified the breach as a major incident under federal guidelines. That classification is not a formality: it legally requires notifying Congress within seven days and it triggers centralized interagency oversight of the resulting investigation, which is a meaningfully higher bar than most breach disclosures ever reach.

The compromised system reportedly held information tied to targets of ATF criminal investigations.
Chloe Simmons · The Hacking Post

Qilin's own claim is thinner than usual for the group. It added ATF to its leak site alongside five other targets on Wednesday, but, unlike its handling of other listings around the same time, provided no timestamps, no data size estimate and no proof files to back the claim up. That gap between assertion and evidence matters here specifically, because a breach touching active federal investigation targets carries real safety implications for informants and case subjects if the claim turns out to be accurate, and real reputational cost to Qilin if it turns out to be an empty listing.

Federal law enforcement agencies remain an unusual target class. They hold data valuable enough to attract serious ransomware crews, but they also tend to segment sensitive investigative systems away from general IT infrastructure specifically because of scenarios like this one. Whether that segmentation held here as cleanly as ATF's statement suggests will likely become clearer as the DOJ's mandated oversight process plays out.

Advertisement

Qilin itself has had an active year. The group, believed to operate a ransomware-as-a-service model that leases its tooling to affiliate crews, has claimed a wide spread of victims across healthcare, manufacturing and now, apparently, federal law enforcement, a target list broad enough that some researchers question whether every listing on its leak site represents a genuine intrusion of the scale claimed. That skepticism cuts both ways here. It is exactly why ATF's own confirmation, thin on detail as it is, carries more weight than Qilin's claim alone would.

Based on reporting by CyberScoop.

AI transparency. This article was produced with the assistance of artificial intelligence and published under human editorial oversight. AI systems can make mistakes. Read how we use AI (EU AI Act, Art. 50).
Related Stories