Thursday, 27 August 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
Technology

ATF responds to 'major' cybersecurity incident after ransomware gang's claims

The Register ·
ATF responds to 'major' cybersecurity incident after ransomware gang's claims

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) said it’s responding to a “major” cybersecurity incident shortly after the Qilin ransomware gang posted the US federal law enforcement agency on its leak site.

According to ATF's statement, the intrusion affected a standalone system that operated separately from its enterprise network.

“There is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system,” the statement said.

ATF, which is housed under the US Department of Justice, said it’s “coordinating closely” with the DOJ to investigate the breach, and “immediately” blocked connections to the affected IT environment upon discovering the incident.

The statement said the security breach had not affected ATF’s operations and noted that senior Justice Department officials designated the compromise as a “major incident” under federal guidelines.

Shortly before ATF posted its security-incident notice on its website, Russia-linked Qilin ransomware criminals listed the firearms agency on its leak site.

The post, seen by The Register and shared on social media, did not say what data Qilin claimed to have stolen, how much, or provide samples to substantiate the claim.

ATF did not immediately respond to our questions, and we will update this story when we receive a response.

Qilin, the notorious crew behind the 2024 attack on pathology provider Synnovis that disrupted NHS services in the UK, was one of the most prolific ransomware gangs in July, according to Comparitech.

The firm, which reviews cybersecurity products and provides data analysis, counted 799 ransomware incidents last month, up from 668 in June.

Qilin claimed 125 of those.®

Read the full article on The Register ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.

More from The Register

See all ›

More in Technology

See all ›