Cronkite

Bulletin of October 11, 2026

3 minNews

ATF investigates cybersecurity incident after ransomware group claims attack

The Bureau of Alcohol, Tobacco, Firearms and Explosives is investigating a cybersecurity incident involving a standalone system, which senior Justice Department officials have designated a "major incident." The Qilin ransomware group has claimed responsibility, though the agency has not confirmed the attribution.

The Bureau of Alcohol, Tobacco, Firearms and Explosives said Wednesday it is investigating a cybersecurity incident involving a standalone system, which senior Justice Department officials have designated a "major incident" under federal guidelines. The disclosure comes as the Qilin ransomware group claimed the ATF as a victim, according to cybersecurity outlets tracking the group's leak site.

The group has not publicly provided evidence substantiating its claim, and the ATF has not attributed the incident to Qilin. The agency said the affected system operates separately from its enterprise network and that there is no indication the incident affected its broader network, its eForms system or any other ATF system. The ATF disconnected the affected environment after discovering the incident and launched forensic and incident-response efforts.

The agency is coordinating with the Justice Department as it investigates what happened. The ATF did not identify the affected system, say when the incident was discovered or disclose whether any data was accessed or stolen. Cybernews reported Wednesday that Qilin claimed the ATF as its latest victim but had provided no evidence or details supporting the claim.

GalaxyWarden, a breach-monitoring service, separately reported that the ATF appeared on Qilin's leak site and that the group claimed it obtained files from the agency. GalaxyWarden said it had not independently verified the group's assertions. The ATF said senior Justice Department officials designated the cybersecurity event a "major incident" under applicable federal guidelines and that required notifications have been completed.

The incident has not disrupted ATF operations or affected the agency's ability to carry out its missions, according to the agency. The agency asked anyone with information related to the incident to contact the ATF Tipline at 1-888-ATF-TIPS, or 1-888-283-8477.

The development follows a series of federal cybercrime actions. The FBI recently wrapped up a cybercrime operation targeting global networks preying on Americans, and the Justice Department charged three Russians in an alleged $63 million cybercrime scheme targeting Americans. The ATF's disclosure adds to a growing list of federal agencies reporting cyber intrusions as ransomware groups continue to target government systems.

64Views

Gavin Kendall

Author

Business Analyst

Gavin Kendall covers public affairs, politics, business, culture and daily news for Cronkite. The role focuses on verification, context, and clear explanations for readers.

Tail slate

Reporter
Gavin Kendall
Filed
Runs
3 min
Source
fox - U.S.
Block
News

Next in the News block

  1. ——:—— Oct 10 DeSantis Deploys 16,000 Utility Workers as Florida Clears Roads and Restores Power After Isaias 4 min
  2. ——:—— Oct 10 ABC News Republishes Corrected Report on Trump Sons' Pentagon-Linked Investments After Quiet Removal 4 min
  3. ——:—— Oct 10 Media Coverage of Oct. 7 Anniversary Overlooks Mamdani's Genocide Remark, Critics Say 6 min
  4. ——:—— Oct 9 Clarkstown Launches Workplace Investigation After Heated Exchange Between Highway Supervisor and Town Official 5 min