US firearms regulator acknowledges system compromise linked to ransomware group

The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed that one of its standalone systems was breached, describing it as a major incident. The agency stated the affected system is separate from its main network and that it has terminated connections while coordinating with the Department of Justice. The Qilin ransomware gang had added the ATF to its dark web leak site earlier the same day.
The Qilin ransomware operation, active since 2022, has claimed more than 2,200 victims on its dark web leak site, including major corporations and government entities. Its addition of the ATF to that site on Wednesday preceded the agency's own confirmation of the breach, though the gang has not publicly stated whether files were exfiltrated or a ransom demanded.
This incident follows a pattern of disclosures from U.S. federal agencies this year, including an FBI breach affecting wiretap warrant systems in March and a July cyberattack on the Department of Homeland Security's information-sharing network. The ATF emphasized the compromised system is isolated from its main network and eForms, with connections terminated and forensic work underway alongside the Department of Justice.
This breach could affect public confidence in federal law enforcement's digital infrastructure, particularly given the ATF's role in regulating firearms and explosives. If sensitive data was exfiltrated, it may expose investigative methods or personal information of regulated parties. The incident also underscores how ransomware groups increasingly target government agencies, potentially disrupting operations or enabling further criminal activity, though the ATF states its core functions remain unaffected.