ATF confirms “major incident” after recent Qilin breach claims

The US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a significant security incident after being added to the list of victims by the Qilin ransomware gang. The incident follows a pattern of increasingly brazen cyberattacks on high-profile targets, including several US federal agencies.

Qilin, a Ransomware-as-a-Service operation that emerged in August 2022, claims to have compromised over 2,200 organizations worldwide. These include major brands like Nissan, Asahi, and Lee Enterprises, as well as government agencies such as Australia’s Court Services Victoria. The gang has been using its dark web leak portal to publish stolen data from these victims.

In a press release, the ATF confirmed that one of its systems had been compromised in what it described as a “major incident.” However, the agency assured the public that the affected system operates separately from its main network and that there is no indication of further compromise. The ATF has also initiated an investigation into the breach, working closely with the Department of Justice.

The Qilin ransomware gang’s tactics involve using stolen credentials to gain access to a target’s systems. Once inside, attackers can move freely and carry out their malicious activities without being detected by traditional security measures. This is why prevention scores often hide what happens after initial access – once attackers have valid credentials, they are able to bypass many security controls.

The fact that Qilin has added the ATF to its list of victims suggests a growing trend of ransomware gangs targeting high-profile targets in an effort to extort large sums of money. This raises questions about the resilience of US federal agencies’ cybersecurity defenses and their ability to prevent such incidents.

In related news, several other US federal agencies have disclosed cybersecurity incidents in recent months. These include the FBI and Department of Homeland Security, which were both targeted by sophisticated cyberattacks that compromised sensitive information-sharing platforms.

For individuals and organizations looking to protect themselves against similar threats, it’s essential to focus on prevention measures that go beyond traditional security controls. This includes implementing robust incident response plans, conducting regular security audits, and providing regular training for employees to identify potential phishing attacks and other social engineering tactics used by attackers.

Ultimately, the ATF incident serves as a reminder of the ongoing threat posed by ransomware gangs like Qilin. As these groups continue to evolve and become more sophisticated in their tactics, it’s crucial that organizations take proactive steps to protect themselves against such threats. By staying vigilant and adapting to new security risks, individuals and businesses can reduce their exposure to cyberattacks and minimize the impact of a potential breach.


Source: Bleeping Computer — 2026-08-27