The ATF, which enforces federal firearms and explosives laws, disclosed the breach after the Qilin ransomware gang began publishing alleged internal documents on their leak site. While the agency has not detailed the scope of the compromise, sources familiar with the matter said the incident was serious enough to trigger a “major incident” declaration—a designation that obligates the agency to brief congressional oversight committees.
Federal agencies are required under the Federal Information Security Modernization Act (FISMA) and recent White House cybersecurity directives to report breaches that pose a substantial risk to agency operations or assets. The ATF’s notification suggests that the attackers accessed sensitive data, possibly including personnel records, investigative files, or firearm tracing information.
Qilin, a ransomware group that first emerged in 2022, claimed responsibility on its dark web leak site, stating it had exfiltrated over 2 terabytes of data from the agency’s network. The gang has posted screenshots showing what appears to be internal documents, spreadsheets, and emails. Security researchers have noted that Qilin typically operates as a ransomware-as-a-service (RaaS) operation, targeting critical infrastructure and government entities.
The ATF incident follows a string of breaches at other federal agencies, including the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Justice, underscoring persistent vulnerabilities in government networks. The agency has not said whether it paid a ransom, nor has it confirmed Qilin’s specific data theft claims.
The full extent of the breach remains under investigation, and the ATF is working with CISA and the FBI to determine the impact. The agency has urged employees to remain vigilant for signs of identity theft or phishing attempts.