The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has declared a cyberattack a “major incident,” triggering a formal notification to Congress. The attack targeted a standalone system containing sensitive investigative data, separate from the bureau’s main network. An ATF spokesperson confirmed the breach but did not detail the scope of compromised information.
The Qilin ransomware gang claimed responsibility via its leak site, though no evidence—such as leaked data samples—was provided to substantiate the claim. Qilin operates a ransomware-as-a-service model, leasing tools to affiliates for profit-sharing. The gang has previously targeted high-profile entities, including media giant Lee Enterprises and a U.K. pathology lab.

Under federal law, major incidents require disclosure to lawmakers within a week of discovery. The ATF joins other agencies, including the U.S. Marshals Service and FBI, that have recently classified breaches as major incidents. The FBI breach earlier this year exposed phone numbers of surveillance targets.



