The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed Wednesday that it is investigating a significant cybersecurity incident, with the Qilin ransomware group publicly claiming responsibility. The agency released a statement saying the affected system operated separately from its main network and that there was no evidence the breach impacted its enterprise network, the eForms system, or other critical databases.
The ATF’s eForms system is widely used by licensed firearm dealers and individuals for background checks and transactions, making any potential compromise a matter of national security and public safety. The agency has not disclosed what data, if any, was accessed or exfiltrated from the standalone system, nor has it provided a timeline for when the incident was discovered.
The Qilin ransomware group, which has been active since at least 2022, is known for targeting government and corporate entities in the United States and abroad. The group often operates a “ransomware-as-a-service” model, providing tools to affiliates in exchange for a cut of ransom payments. Their claim of responsibility for the ATF breach has not been independently verified, and the full extent of the intrusion remains under investigation.
The ATF has directed all questions regarding the incident to its Office of Public and Governmental Affairs, which declined to comment further on the ongoing investigation. Law enforcement and cybersecurity experts are collaborating to assess damages and secure the affected systems. The agency emphasized that its law enforcement operations and regulatory functions have not been disrupted.