The Bureau of Alcohol, Tobacco, Firearms and Explosives ( ATF ) stated that an independent system separated from its main network suffered a cyberattack, and the incident has been classified as a "major event." According to U.S. federal regulations, cybersecurity incidents of this level must be officially reported to Congress within one week of discovery.
The attacked system contains investigation information.
ATF stated in the declaration that the affected system is an independently operating one and does not form part of the institution's main network. ATF A spokesperson told the media that the information stored within this system includes ATF data related to the subjects of the investigation.
At present, ATF has not disclosed the specific time of the attack, the scope of its impact, or whether any data has been confirmed to have been leaked.
Qilin claims responsibility
According to TechCrunch, it has been observed that the ransomware group Qilin has published claiming information on their leaked website. However, this group has not provided sample data or other verifiable materials, so it is currently impossible to independently confirm their claims.
Qilin is one of the more active ransomware gangs in recent years, adopting a "ransomware as a service" model by providing tools to other attackers and splitting profits from the ransoms. Reports mention that this organization has previously included media company Lee Enterprises and a British pathology testing institution Synnovis on its list of targets for data breaches.
To be reported to Congress within one week.
According to U.S. federal law, a "major incident" typically refers to a significant cybersecurity event that could cause proven damage to U.S. national security or broader national interests. Once a federal agency makes such a determination, it is required to report it to Congress within seven days of discovery.
In recent years, several U.S. government agencies have made similar assessments after experiencing intrusions. Reports mention that in 2023, a system of the U.S. Marshals Service was attacked by ransomware; earlier this year, a data breach occurred in a system of the Federal Bureau of Investigation (FBI), involving phone numbers of targets monitored by federal agents.











