ATF confirms major breach after Qilin posts agency on leak site

The US firearms bureau says intruders hit a standalone system tied to its investigations.

CSBadmin
2 Min Read

The Bureau of Alcohol, Tobacco, Firearms and Explosives said it is responding to a major cybersecurity incident, hours after the Qilin ransomware gang listed the US federal law enforcement agency on its leak site. An ATF spokesperson told The Register that intruders accessed a standalone computer system containing information about targets of ATF investigations, which was not connected to any other ATF systems.

“There is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system,” the agency said in a statement. ATF, which sits under the US Department of Justice, said it is coordinating closely with the DOJ, immediately blocked connections to the affected environment, and designated the compromise a major incident under federal guidelines.

The agency declined to answer questions about Qilin’s claims, the ransom demand, or what data was stolen, citing the ongoing investigation. The leak site post, seen by The Register and shared on social media, offered no data samples to substantiate the claim.

Qilin, the crew behind the 2024 attack on UK pathology provider Synnovis that disrupted NHS services, was one of the most prolific ransomware gangs in July, claiming 125 of the 799 incidents counted by Comparitech. ATF said its operations have not been affected.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.