ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Qilin claims ATF breach, releases over 6 GB of data after ransom talks fail

The Bureau of Alcohol, Tobacco, Firearms and Explosives recently disclosed a data security incident that compromised sensitive personal information belonging to individuals associated with the agency.

Linked InXFacebook
bookmark_borderSave to Library

The Bureau of Alcohol, Tobacco, Firearms and Explosives has disclosed a data security incident earlier this year that compromised sensitive personal information belonging to individuals associated with the agency.

 

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) is a U.S. Department of Justice law enforcement agency that combats violent crime and enforces federal laws involving firearms, explosives, alcohol and tobacco. Its responsibilities include investigating gun trafficking, bombings and arson, targeting violent offenders, combating smuggling and tax evasion, and regulating licensed firearms and explosives businesses.

 

In a data security incident notice published on its website, the ATF said it is responding to a cybersecurity incident in which threat actors breached its internal network and compromised a standalone system. The agency promptly initiated an investigation, supported by external cyber security specialists, to assess the nature and extent of the breach.

 

It also took steps to secure the affected system and contain the incident, including terminating connections to the compromised environment. The ATF said it is continuing to work with the U.S. Department of Justice to investigate the incident, determine the scope of the breach, and assess whether any sensitive information was accessed or compromised.

 

“The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system,” ATF said.

 

“Senior Department officials have designated the event a “major incident” under applicable federal guidelines, and required notifications have been completed. 

 

“The incident has not impacted ATF’s ability to perform its missions,” the agency added.

 

 

 

The Qilin ransomware group claimed responsibility for the cyber attack on ATF, listing it as a victim of its cyber attack on the group’s data leak site. The group claimed to be in possession of confidential data stolen from the agency and threatened to release the data publicly if its ransom demands were not fulfilled within 72 hours.

 

Following an unsuccessful ransom negotiation, the ransomware group published 6.3 GB of stolen data. The leaked information included the names of criminal investigation targets, phone numbers, IP addresses, iCloud data, Cellebrite phone extractions, and other sensitive data.

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543