The ATF was listed on the dark web leak site of the Qilin ransomware gang, which provided no details of the incident, as is common practice for the group.
In a statement released on its website today (26 August), the ATF confirmed it was aware of the incident, confirming that a standalone system has been impacted.
“The Bureau of Alcohol, Tobacco, Firearms and Explosives is responding to a cyber security incident affecting a standalone system,” it said in a statement on its site.
“The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system.
“Upon discovery of the incident, ATF immediately terminated connections to the affected environment and initiated incident‑response and forensic activities. ATF is coordinating closely with the Department of Justice to investigate.”
Despite the statement suggesting that the incident is well under control, the ATF said senior department officials have flagged the cyber attack as a “major incident.” As a result, relevant authorities have been notified.
The incident has not impacted ATF’s ability to perform its missions.
Who is Qilin?
Qilin has claimed 2,223 victims since it was first observed in 2022, spread across 99 countries. It is currently the most active ransomware operation in existence, averaging about 100 victim listings per month so far in 2026.
The group operates under a ransomware-as-a-service model, with affiliates gaining access to its ransomware infrastructure in return for a cut of any ransom payments.
While some affiliates will publish complete details of their activities, including the volume of data stolen and screenshots of evidence, others post minimal information, often not going into detail about the data or its contents.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.