ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

US federal agency confirms data breach in wake of claims by ransomware group

A ransomware group gained access to a computer system containing information about targets of investigations by the Bureau of Alcohol, Tobacco, Firearms and Explosives, a spokesperson for the U.S. agency said after a hacking group publicized a claimed breach on Wednesday.

 

Linked InXFacebook
bookmark_borderSave to Library

By AJ Vicens

 

(Reuters) - A ransomware group gained access to a computer system containing information about targets of investigations by the Bureau of Alcohol, Tobacco, Firearms and Explosives, a spokesperson for the U.S. agency said after a hacking group publicized a claimed breach on Wednesday.

 

Tanya Roman, a spokesperson for the agency, said in an email that the standalone system was not connected to any other ATF systems, including case management, laboratory or eForms systems, which are used by the agency to manage form submissions from the public. 

Roman said the affected system was “quickly shut down when the breach was discovered,” and that an investigation is ongoing. A separate statement posted to the agency’s website said the ATF is coordinating closely with the Department of Justice and that the episode has been designated a “major incident.”

 

Neither Roman nor the statement identified a possible culprit for the breach.

The breach raises concerns because ATF systems can contain sensitive law enforcement data, including details on ongoing investigations. The "major incident" designation means the breach could result in harm to national security or civil liberties and triggers congressional reporting requirements.

 

The ATF is a federal law enforcement agency under the U.S. Department of Justice. A Department of Justice spokesperson referred Reuters to the statement by the ATF. The Cybersecurity and Infrastructure Security Agency also referred questions to the ATF.

Qilin, a prolific ransomware operation thought to be Russian-based or Russian-speaking, posted a message on its website on Wednesday, in which it claimed responsibility for the compromise. The message included no description of what was stolen or how much, and did not include any samples. 

Qilin has listed nearly 2,400 claimed attacks across more than 100 countries since it emerged in October 2022, according to data compiled by cybercrime research and tracking platform eCrime.ch.  

 

(Reporting by AJ Vicens in Detroit; Editing by Matthew Lewis)

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543