Cronkite

Bulletin of August 27, 2026

3 minNews

ATF investigates cybersecurity incident after ransomware group claims attack

The Bureau of Alcohol, Tobacco, Firearms and Explosives is investigating a cybersecurity incident involving a standalone system, which senior Justice Department officials have designated a "major incident." The Qilin ransomware group has claimed responsibility, though the agency has not confirmed the attribution.

The Bureau of Alcohol, Tobacco, Firearms and Explosives said Wednesday it is investigating a cybersecurity incident involving a standalone system, which senior Justice Department officials have designated a "major incident" under federal guidelines. The disclosure comes as the Qilin ransomware group claimed the ATF as a victim, according to cybersecurity outlets tracking the group's leak site.

The group has not publicly provided evidence substantiating its claim, and the ATF has not attributed the incident to Qilin. The agency said the affected system operates separately from its enterprise network and that there is no indication the incident affected its broader network, its eForms system or any other ATF system. The ATF disconnected the affected environment after discovering the incident and launched forensic and incident-response efforts.

The agency is coordinating with the Justice Department as it investigates what happened. The ATF did not identify the affected system, say when the incident was discovered or disclose whether any data was accessed or stolen. Cybernews reported Wednesday that Qilin claimed the ATF as its latest victim but had provided no evidence or details supporting the claim.

GalaxyWarden, a breach-monitoring service, separately reported that the ATF appeared on Qilin's leak site and that the group claimed it obtained files from the agency. GalaxyWarden said it had not independently verified the group's assertions. The ATF said senior Justice Department officials designated the cybersecurity event a "major incident" under applicable federal guidelines and that required notifications have been completed.

The incident has not disrupted ATF operations or affected the agency's ability to carry out its missions, according to the agency. The agency asked anyone with information related to the incident to contact the ATF Tipline at 1-888-ATF-TIPS, or 1-888-283-8477.

The development follows a series of federal cybercrime actions. The FBI recently wrapped up a cybercrime operation targeting global networks preying on Americans, and the Justice Department charged three Russians in an alleged $63 million cybercrime scheme targeting Americans. The ATF's disclosure adds to a growing list of federal agencies reporting cyber intrusions as ransomware groups continue to target government systems.

Gavin Kendall

Author

Business Analyst

Gavin Kendall covers public affairs, politics, business, culture and daily news for Cronkite. The role focuses on verification, context, and clear explanations for readers.

Tail slate

Reporter
Gavin Kendall
Filed
Runs
3 min
Source
fox - U.S.
Block
News

Next in the News block

  1. ——:—— Aug 26 Airport worker killed after being struck by passenger jet in Montreal 3 min
  2. ——:—— Aug 26 FDA approves once-daily pill for pancreatic cancer after trial shows survival nearly doubles 4 min
  3. ——:—— Aug 26 Dolly Parton’s Career Was Built on Songs, Control and Reach 5 min
  4. ——:—— Aug 26 Vitruvias Recalls One U.S. Lot of 30 mg Thyroid Tablets 4 min