The Bureau of Alcohol, Tobacco, Firearms and Explosives recently disclosed a data security incident that compromised sensitive personal information belonging to individuals associated with the agency.

The Bureau of Alcohol, Tobacco, Firearms and Explosives has disclosed a data security incident earlier this year that compromised sensitive personal information belonging to individuals associated with the agency.
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) is a U.S. Department of Justice law enforcement agency that combats violent crime and enforces federal laws involving firearms, explosives, alcohol and tobacco. Its responsibilities include investigating gun trafficking, bombings and arson, targeting violent offenders, combating smuggling and tax evasion, and regulating licensed firearms and explosives businesses.
In a data security incident notice published on its website, the ATF said it is responding to a cybersecurity incident in which threat actors breached its internal network and compromised a standalone system. The agency promptly initiated an investigation, supported by external cyber security specialists, to assess the nature and extent of the breach.
It also took steps to secure the affected system and contain the incident, including terminating connections to the compromised environment. The ATF said it is continuing to work with the U.S. Department of Justice to investigate the incident, determine the scope of the breach, and assess whether any sensitive information was accessed or compromised.
“The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system,” ATF said.
“Senior Department officials have designated the event a “major incident” under applicable federal guidelines, and required notifications have been completed.
“The incident has not impacted ATF’s ability to perform its missions,” the agency added.
🚨BREAKING🚨
— Gun Owners of America (@GunOwners) August 31, 2026
After a 72 hour countdown expired, Russian ransomware gang Qilin briefly published 6.3GB of data it hacked from ATF.
The data includes criminal investigation target names, phone numbers, IP addresses, iCloud data, Cellebrite phone dumps, and more. https://t.co/pq63X4DvPx pic.twitter.com/2FjqOEoqNw
The Qilin ransomware group claimed responsibility for the cyber attack on ATF, listing it as a victim of its cyber attack on the group’s data leak site. The group claimed to be in possession of confidential data stolen from the agency and threatened to release the data publicly if its ransom demands were not fulfilled within 72 hours.
Following an unsuccessful ransom negotiation, the ransomware group published 6.3 GB of stolen data. The leaked information included the names of criminal investigation targets, phone numbers, IP addresses, iCloud data, Cellebrite phone extractions, and other sensitive data.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543