ATF confirms cyberattack hit system containing info on its investigation targets

ATF Hit by Cyberattack on Investigation System, But Agency Insists Operations Remain Unaffected

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed that its systems were breached in a cyberattack, but insists that only one isolated system containing information about targets of ATF investigations was compromised. The attack is attributed to the Qilin ransomware group, although the agency’s involvement hasn’t been independently verified.

The incident occurred on an unconnected standalone computer system used by the ATF for investigation purposes. According to Tanya Roman, the agency’s public affairs chief, this system was quickly shut down as soon as the breach was discovered, preventing any potential damage or disruption to other critical systems. The ATF has assured that its ability to perform its missions remains unaffected.

Qilin is a financially motivated threat group known for its affiliate-based ransomware model and high activity level. With hundreds of victims across 60 countries since 2022, Qilin has become one of the most prominent ransomware threats globally. Its claimed attack on the ATF marks an escalation in targeting government sectors, but it’s unclear what the objectives are behind this specific breach.

The FBI has previously reported that Qilin was among the top five most reported ransomware variants last year. Google also noted that the group was one of the most active ransomware brands in 2025. The majority of Qilin’s victims are based in the United States, with nearly a quarter being from the manufacturing industry.

While it’s uncertain whether the attack on the ATF is an isolated incident or part of a larger campaign, one thing is clear: government agencies and organizations worldwide need to remain vigilant against ransomware threats like Qilin. This latest incident serves as a reminder that even the most secure systems can be vulnerable to targeted attacks.

So what can you do? To mitigate the risk of a similar breach happening in your organization, make sure to regularly update your software, use strong passwords and implement robust cybersecurity measures. Stay informed about emerging threats like Qilin, and be prepared to respond quickly in case of an attack. By taking these steps, you can help protect your systems and stay one step ahead of the cyber threat landscape.


Source: CyberScoop — 2026-08-28