ATF confirms ransomware breach of system holding investigation data
The US ATF confirmed a ransomware group accessed a system containing investigation target information, prompting a major incident response.
The US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed that a ransomware group gained access to a computer system containing information about targets of its investigations. The disclosure came after a hacking group publicised a claimed breach on Wednesday.
Tanya Roman, an ATF spokesperson, said the affected system was standalone and not connected to other agency networks, including those used for case management, laboratory work, or eForms submissions from the public. She added that the system was quickly shut down once the breach was discovered, and that an investigation is currently underway.
The agency has designated the episode as a "major incident," which signals the breach could potentially harm national security or civil liberties and triggers congressional reporting requirements. The ATF is coordinating closely with the Department of Justice on the matter.
Neither the agency spokesperson nor the official statement identified a suspected culprit. However, Qilin, a prolific ransomware operation believed to be Russian-based or Russian-speaking, posted a claim of responsibility on its website on Wednesday. The post did not include details about what data was stolen or any sample files.
According to data from cybercrime tracking platform eCrime.ch, Qilin has listed nearly 2,400 claimed attacks across more than 100 countries since it emerged in October 2022. The breach raises concerns due to the sensitive nature of ATF data, which can include details on ongoing federal investigations.