The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives said a separate standalone system was compromised in a "major incident" after the Qilin ransomware gang claimed ATF on its dark-web leak site. ATF said the affected environment was isolated from its main enterprise network and that there was no indication the enterprise network, eForms system, or other ATF systems were affected. The agency says it cut connections to the breached environment and is investigating with the Department of Justice.
Why it matters: This is a significant breach at a U.S. federal law-enforcement agency and could involve stolen sensitive government data even if core ATF systems were not impacted. Federal defenders and partner organizations should watch for follow-on disclosures, while anyone interacting with ATF should be alert for phishing or fraud using potentially stolen information.
Eduard Kovacs
2026.08.28
99% relevant
This source appears to be the same underlying event: ATF confirms a cyber incident affecting a standalone system, says DOJ is investigating, and notes the event was designated a major incident after Qilin listed the agency on its leak site.
2026.08.27
98% relevant
This source directly updates the same incident, adding that ATF called it a "major" cybersecurity incident under federal guidelines, said the affected environment was a standalone system separate from the enterprise network, and said DOJ is investigating.
2026.08.27
99% relevant
This article is the core report confirming the ATF breach, adding that the compromised standalone system contained information about targets of ATF investigations, was isolated from other ATF systems, and was designated a federal 'major incident.'
Sergiu Gatlan
2026.08.27
100% relevant
This article appears to be the first confirmed disclosure that ATF suffered a system compromise linked to Qilin's leak-site claim, establishing the underlying breach event.
← Back to all stories