ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang.
This follows Qilin adding the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives to its dark web data leak portal on Wednesday, without saying whether it had stolen files from ATF’s systems or demanded a ransom.
The same day, the ATF published a press release saying that a standalone system was breached in what it described as a “major incident,” which is now being investigated in collaboration with the Department of Justice.
“The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system,” the federal law enforcement agency said.
“Upon discovery of the incident, ATF immediately terminated connections to the affected environment and initiated incident‑response and forensic activities. ATF is coordinating closely with the Department of Justice to investigate.”
ATF added that the incident did not affect the agency’s operations and asked the public to share any information on the attack via its official tipline.
BleepingComputer reached out to an ATF spokesperson with further questions about the incident, but a response was not immediately available.
Qilin is a Ransomware-as-a-Service (RaaS) operation first spotted in August 2022 under the “Agenda” name that has since claimed responsibility for more than 2,200 victims on its dark web leak site.
The list of victims includes many high-profile organizations such as automotive giants Nissan and Yangfeng, pathology services provider Synnovis, Japanese beer giant Asahi, publishing giant Lee Enterprises, and Australia’s Court Services Victoria.
Several other U.S. federal agencies have disclosed cybersecurity incidents since the start of the year after their networks were infiltrated in cyberattacks.
For instance, the U.S. Federal Bureau of Investigation (FBI) confirmed in early March that it was investigating a breach affecting systems used to manage wiretap and surveillance warrants.
More recently, in July, the U.S. Department of Homeland Security also disclosed a cyberattack that compromised the Homeland Security Information Network (HSIN), a sensitive information-sharing platform used by federal, state, local, and private-sector partners.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Chick-fil-A data breach affects more than 13,000 customers
AssuranceAmerica data breach exposes records of 6.9 million drivers
CISA: Medusa ransomware hit over 500 critical infrastructure orgs
French tax authority data breach affects 678,000 individuals
France fines unemployment agency €5 million over data breach
Ubiquiti patches three max severity security vulnerabilities
Police arrests dozens of suspects in global cybercrime crackdown
Microsoft Teams now lets admins block external bots from meetings
Discover how least agency keeps your AI tools capable, controlled, and secure.
Discover why encryption and key management are critical for modern business.
Protect yourself from data brokers, scammers, and the next data breach with digital identities.
See how AI is reshaping email attacks. Download the 2026 Kaseya Email Security Report.
Overdue a password health-check? Audit your Active Directory for free
Pixellot discovered and secured hundreds of unmanaged AI agent identities in weeks, not months. Download the case study for how.
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.


