AI News Feed
Market watch
Cybersecurity

ATF confirms 'major incident' after Qilin ransomware gang lists agency on leak site

ATF confirmed a ransomware incident on a standalone system after Qilin listed the agency on its leak site, with investigation target data at risk.

According to TechRadar, Qilin added several names to its leak site, including Northern Leasing Systems, Metal Conversions, California Truck Equipment, ATF, and WireCo. The attackers did not disclose what kind of data they stole, how much data they have, or post samples of the stolen files.

In a press release, ATF said the incident affected a “standalone system” that operates separately from the ATF enterprise network. “There is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system,” the agency said. A spokesperson told The Register the system contains information about targets of ATF investigations.

The ATF investigates federal crimes such as illegal firearms trafficking, violent crime and gangs, explosives, arson and bombings, organized crime, illegal alcohol and tobacco trafficking, and firearms dealers and manufacturers. After detecting the attack, ATF disconnected the affected systems, engaged cybersecurity experts, and notified relevant authorities, including the Department of Justice. “Senior Department officials have designated the event a ‘major incident’ under applicable federal guidelines, and required notifications have been completed,” ATF added.

TechRadar reported that Qilin is a relatively old ransomware threat actor tied to Russia, best known for its 2024 attack on the pathology provider Synnovis.