Powered by MOMENTUMMEDIA
For breaking news and daily updates, subscribe to our newsletter

Exclusive: US ATF confirms ‘critical’ cyber incident following Qilin dark web claims

The US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has issued a statement responding to claims of a cyber incident impacting its network by an infamous threat actor.

Thu, 27 Aug 2026
Exclusive: US ATF confirms ‘critical’ cyber incident following Qilin dark web claims

The ATF was listed on the dark web leak site of the Qilin ransomware gang, which provided no details of the incident, as is common practice for the group.

In a statement released on its website today (26 August), the ATF confirmed it was aware of the incident, confirming that a standalone system has been impacted.

“The Bureau of Alcohol, Tobacco, Firearms and Explosives is responding to a cyber security incident affecting a standalone system,” it said in a statement on its site.

 
 

“The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system.

“Upon discovery of the incident, ATF immediately terminated connections to the affected environment and initiated incident‑response and forensic activities. ATF is coordinating closely with the Department of Justice to investigate.”

Despite the statement suggesting that the incident is well under control, the ATF said senior department officials have flagged the cyber attack as a “major incident.” As a result, relevant authorities have been notified.

The incident has not impacted ATF’s ability to perform its missions.

Who is Qilin?

Qilin has claimed 2,223 victims since it was first observed in 2022, spread across 99 countries. It is currently the most active ransomware operation in existence, averaging about 100 victim listings per month so far in 2026.

The group operates under a ransomware-as-a-service model, with affiliates gaining access to its ransomware infrastructure in return for a cut of any ransom payments.

While some affiliates will publish complete details of their activities, including the volume of data stolen and screenshots of evidence, others post minimal information, often not going into detail about the data or its contents.

Cyber DailyWant to see more stories from trusted news sources?
Make Cyber Daily a preferred news source on Google.
Tags: