Qilin Ransomware Gang Claims Attack on ATF, Major Incident Declared

Qilin Ransomware Gang Claims Attack on ATF, Major Incident Declared

First seen 26 Aug 2026, 23:34 UTC CybernewsAolFoxnewsBleepingcomputerHeartlandernews+17 61.2

Article Content

Browse articles
ThreatCluster

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) is investigating a major cybersecurity incident after the Qilin ransomware gang claimed responsibility for breaching one of its standalone systems. The ATF confirmed that the affected system operates separately from its main network and has not impacted its broader operations or eForms system. Although Qilin listed the ATF as a victim on its dark web leak site, the agency has not confirmed whether data was stolen or if a ransom was demanded. The incident has been designated a 'major incident' by the Department of Justice, which triggers formal reporting requirements. ATF has initiated forensic investigations and disconnected the affected system to prevent further access. This incident follows a series of cyberattacks on federal agencies in 2026, raising concerns about the security of sensitive government data.

Key Points: • Qilin ransomware gang claims to have breached ATF's standalone system. • The incident has been classified as a 'major incident' by the DOJ. • ATF's broader network and operations remain unaffected.

Timeline

2026-08-26
Qilin claims ATF as victim
The Qilin ransomware group listed the ATF on its dark web leak site, claiming to have compromised the agency.
Cybernews
2026-08-26
DOJ confirms ransomware attack
The Department of Justice confirmed that the ATF was hit by a ransomware attack, raising concerns about data security.
Aol
2026-08-27
ATF declares major incident
ATF announced it is investigating a major cybersecurity incident affecting a standalone system, with no impact on its main network.
Nextgov