The Bureau of Alcohol, Tobacco, Firearms and Explosives has confirmed that one of its systems was breached, following claims made by the Qilin ransomware gang. The federal agency, which regulates firearms and explosives, added the incident to its list of security events after Qilin posted the ATF on its dark web leak portal. The ATF did not state whether files were stolen or a ransom was demanded, but it described the breach as a “major incident” that is now under investigation with the Department of Justice.
The compromised system is standalone and operates separately from the ATF’s main enterprise network, according to the agency’s press release. The ATF said there is no indication that the breach affected its enterprise network, its eForms system, or any other internal systems. After discovering the incident, the ATF immediately cut connections to the affected environment and launched incident response and forensic activities. The agency said the attack did not disrupt its operations and asked the public to report any related information through its official tipline.
A spokesperson for the ATF did not immediately respond to questions from BleepingComputer about the incident. Qilin is a Ransomware-as-a-Service operation that first appeared in August 2022 under the name “Agenda” and has since claimed more than 2,200 victims on its dark web leak site. The group’s known targets include automotive companies Nissan and Yangfeng, pathology services provider Synnovis, Japanese beer maker Asahi, publishing firm Lee Enterprises, and Australia’s Court Services Victoria.
This attack is part of a broader pattern of cyber incidents affecting U.S. federal agencies this year. The Federal Bureau of Investigation confirmed in early March that it was investigating a breach of systems used to manage wiretap and surveillance warrants. In July, the Department of Homeland Security disclosed a cyberattack that compromised the Homeland Security Information Network, a platform used to share sensitive information across federal, state, local, and private-sector partners.
The ATF’s confirmation comes as agencies face scrutiny over how they protect sensitive data after initial access is gained. Security experts note that prevention scores can mask weaknesses that emerge once attackers use valid credentials, with defenses dropping sharply after that point. A recent industry report, the Blue Report 2026, measured defenses across 338 million simulations in customer production environments, highlighting technique-by-technique vulnerabilities. The full scope of the ATF breach, including whether any data was exfiltrated, remains unclear as the investigation with the Justice Department continues.
More cybersecurity news from TechManNews.








