ATF investigates ‘major’ cybersecurity incident as ransomware group claims attack
The Qilin ransomware group has claimed ATF as a victim, though the agency has not attributed the breach to the group
{{#rendered}} {{/rendered}}The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) said Wednesday it is investigating a cybersecurity incident involving a standalone system, which senior Justice Department officials have designated a "major incident" under federal guidelines.
The disclosure comes as the Qilin ransomware group claimed ATF as a victim, according to cybersecurity outlets tracking the group's leak site. The group has not publicly provided evidence substantiating its claim, and ATF has not attributed the incident to Qilin.
ATF said the affected system operates separately from its enterprise network and that there is no indication the incident affected the agency's broader network, its eForms system or any other ATF system.
{{#rendered}} {{/rendered}}The agency disconnected the affected environment after discovering the incident and launched forensic and incident-response efforts. ATF is coordinating with the Justice Department as it investigates what happened.
FBI WRAPS UP CYBERCRIME OPERATION TARGETING GLOBAL NETWORKS PREYING ON AMERICANS
The Bureau of Alcohol, Tobacco, Firearms and Explosives national headquarters in Washington, D.C. ATF said Wednesday it is investigating a cybersecurity incident involving a standalone system. (Rich Clement/Bloomberg via Getty Images)
The agency did not identify the affected system, say when the incident was discovered or disclose whether any data was accessed or stolen.
{{#rendered}} {{/rendered}}Cybernews reported Wednesday that Qilin claimed ATF as its latest victim but had provided no evidence or details supporting the claim.
GalaxyWarden, a breach-monitoring service, separately reported that ATF appeared on Qilin's leak site and that the group claimed it obtained files from the agency. GalaxyWarden said it had not independently verified the group's assertions.
Fox News Digital reached out to ATF and the Justice Department for additional information, including whether officials believe Qilin was responsible for the incident, whether any data was accessed or stolen and what prompted officials to designate the event a "major incident."
{{#rendered}} {{/rendered}}ATF said senior Justice Department officials designated the cybersecurity event a "major incident" under applicable federal guidelines and that required notifications have been completed.
DOJ CHARGES 3 RUSSIANS IN ALLEGED $63M CYBERCRIME SCHEME TARGETING AMERICANS
The U.S. Department of Justice building in Washington, D.C., on Aug. 17, 2026. ATF said it is coordinating with the Justice Department as it investigates a cybersecurity incident involving a standalone system. (Anna Moneymaker/Getty Images)
The incident has not disrupted ATF operations or affected the agency's ability to carry out its missions, according to the agency.
{{#rendered}} {{/rendered}}A security official walks in front of the entrance to the national headquarters of the Bureau of Alcohol, Tobacco, Firearms and Explosives on Jan. 23, 2014, in Washington.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
The agency asked anyone with information related to the incident to contact the ATF Tipline at 1-888-ATF-TIPS, or 1-888-283-8477.