ATF launches probe after major cyber breach linked to Russian ransomware group
The Bureau of Alcohol, Tobacco, Firearms and Explosives announced a investigation into a significant cyber intrusion, which it says was isolated from its main networks. A Russian-affiliated ransomware gang, Qilin, claimed responsibility, though the agency has not verified the allegation.
The Bureau of Alcohol, Tobacco, Firearms and Explosives reported a major cybersecurity incident affecting a system that operates independently of its primary networks, including the ATF eForms platform. Upon detection, the agency immediately terminated connections to the compromised environment and launched incident-response and forensic procedures. The investigation is being conducted jointly with the Justice Department.
A Russian-linked ransomware collective known as Qilin posted the ATF on a dark-web leak page alongside five other manufacturing and industrial victims. While the ATF has not validated the group’s claim or detailed any stolen data, experts note that even limited exposure of agency information could have far-reaching consequences. The case underscores growing threats to U.S. law-enforcement infrastructure from foreign-based cybercriminals.
Why it matters
A breach of a federal law-enforcement agency could expose sensitive data and highlight vulnerabilities to foreign ransomware groups.
In this story
