Skip to content
Tech News
← Back to articles

ATF declares ‘major incident’ as ransomware gang claims hack

read original more articles
Why This Matters

The ATF's declaration of a 'major incident' following a ransomware attack highlights the increasing threat of cyberattacks on critical government agencies, emphasizing the need for enhanced cybersecurity measures across the public sector. This incident underscores the growing sophistication and reach of ransomware gangs, which can compromise sensitive national security information, impacting both government operations and public trust.

Key Takeaways

In Brief

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives, or ATF, says a cyberattack on one of its systems has been declared a “major incident,” a formal, legally defined classification that prompts a formal notification to lawmakers in Congress.

ATF said in a statement that it’s responding to the cyberattack on a standalone system that’s separate from the bureau’s network. An ATF spokesperson told reporters that the targeted computer system contained information such as the “targets of ATF investigations.”

TechCrunch has seen a claim of responsibility by the Qilin ransomware gang on its leak site, but it did not provide evidence for its claim, such as a sample of leaked data. Qilin is known for running a “ransomware-as-a-service” operation, in which it leases its hacking tools to other criminal affiliates for a cut of the profits. The gang has listed media giant Lee Enterprises and U.K. pathology lab giant Synnovis.

Under federal law, “major incidents” include significant cyber incidents that are likely to cause demonstrable harm to U.S. national security or broader U.S. interests. Agencies are required to disclose major incidents to Congress within a week of their discovery.

The ATF joins several government agencies in recent years that have declared major incidents following a breach, including a 2023 ransomware attack on a system used by the U.S. Marshals Service, and a breach of an FBI system earlier this year that exposed phone numbers of targets under surveillance by federal agents.