The ATF confirmed a breach after Qilin claimed responsibility, raising concerns over information tied to criminal investigations.

The US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed that one of its systems was breached, just hours after the Qilin ransomware group claimed the federal law enforcement agency as its latest victim.
The ATF said the compromised system contained information connected to its investigations, although the agency has not confirmed that Qilin was responsible for the intrusion.
An ATF spokesperson told Cybernews that the affected system was standalone and was not connected to other ATF systems, including case management, laboratory or eForms systems. The agency said the system was quickly taken offline after the breach was discovered.
The ATF said its ability to carry out its missions has not been impacted by the incident. Officials immediately began incident-response and forensic investigations after discovering the breach. The US Department of Justice has classified the incident as a major incident under federal cybersecurity guidelines and is involved in the investigation.
The agency has not disclosed when the intrusion occurred, how attackers gained access or whether information was stolen. The ATF is also asking anyone with information about the incident to contact its tip line. The breach confirmation came shortly after Qilin listed the ATF on its dark web leak site.
The ransomware group provided no details about the alleged attack, including when it supposedly occurred, how much information was taken or what specific data may have been compromised.
Qilin also did not initially publish sample files alongside the ATF listing, unlike several other organizations appearing on the group’s site.
As a result, the ATF’s confirmation establishes that a breach occurred, but does not independently verify Qilin’s claim that it carried out the attack.
The ATF investigates a wide range of serious crimes, including illegal firearms trafficking, weapons smuggling, violent criminal organizations, bombings and arson.
Its investigations can involve firearms traffickers, illegal gun manufacturers, straw purchasers, gangs, convicted felons illegally possessing firearms, bomb makers and other suspects.
That makes information contained in an investigative system potentially sensitive even if the affected network was isolated from the agency’s main systems.
The ATF launches tens of thousands of criminal investigations each year. If information connected to active cases were stolen, its exposure could potentially reveal investigative activity, witnesses or other sensitive law enforcement information. At this stage, however, the agency has not said whether any investigative data was actually exfiltrated.
Qilin, a Russian-linked ransomware operation first identified in 2022, has become one of the most prolific ransomware groups in the world. The group uses a double-extortion model in which attackers steal information from victims before threatening to publish it unless a ransom is paid.
Cybernews’ Ransomlooker tracking platform recorded more than 891 Qilin victims in 2026 as of August 26. The group had also claimed roughly 1,900 victims during the previous 18 months.
Its recent targets have included organizations in sectors ranging from manufacturing and healthcare to transportation and government. The ATF incident is the latest in a series of cyberattacks affecting US government agencies.
Earlier in 2026, the Department of Homeland Security disclosed a breach involving a government information-sharing network. The FBI also revealed an intrusion affecting a sensitive system used to manage court-authorized wiretaps and surveillance warrants.
The incidents highlight the continuing threat facing federal networks, particularly systems containing information connected to law enforcement and national security.
For the ATF, the investigation remains ongoing. Until forensic investigators determine what information was accessed or removed, the full impact of the breach remains unclear.
Source: CyberNews
Related articles :
- Ex-CBP Officer Sentenced Over Emoji Drug Scheme
- Google Disrupts Cyber Espionage Breaches in 42 Countries
- Weapons and fireworks discovered below A’dam police HQ
Reports are sourced from official documents, law-enforcement updates, and credible investigations.
Discover additional reports, market trends, crime analysis and Harm Reduction articles on DarkDotWeb to stay informed about the latest dark web operations.






