The Bureau of Alcohol, Tobacco, Firearms and Explosives announced Wednesday that it is responding to a cybersecurity incident affecting a standalone system.
The impacted system operates separately from the ATF enterprise network, and officials said there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system.
Upon discovery of the incident, the ATF immediately terminated connections to the affected environment and initiated incident-response and forensic activities. The agency is coordinating closely with the Department of Justice to investigate.
Senior Department of Justice officials have designated the event a “major incident” under applicable federal guidelines, and required notifications have been completed.
The incident has not impacted the ATF’s ability to perform its missions, according to the agency.
The disclosure follows claims by the Qilin ransomware group, which listed the ATF among victims on its dark web leak site earlier this week. Qilin is a Russian-linked ransomware-as-a-service operation that has claimed responsibility for thousands of attacks since 2022. The ATF has not confirmed the group’s involvement or provided details on any data that may have been accessed or stolen.
The agency encouraged anyone with information related to the incident to submit a tip through the ATF Tipline at 1-888-ATF-TIPS (1-888-283-8477).
Cybersecurity reporting indicates that Qilin added the ATF to its leak portal without immediately publishing files or demanding a ransom. The breach involves a system described by an ATF official as disconnected from case management, laboratory, and eForms systems, and it was quickly isolated.
Comments
No comments yet. Be the first to share your thoughts.