Skip to main content
Emerging ThreatsData Breaches

ATF Breach Exposes Investigation Targets in Ransomware Attack

Dimly lit government office workstation with blank terminal screen.

"The incident involved a standalone computer system containing information about targets of ATF investigations," Tanya Roman, the Bureau of Alcohol, Tobacco, Firearms and Explosives’ public affairs chief, told CyberScoop.

ATF's account of the breach

ATF acknowledged a cyberattack publicly on Wednesday and told CyberScoop that the intrusion "was limited to investigation targets" held on a single, standalone system. According to Roman, that system "was not connected to any other ATF systems, including any case management systems, laboratory systems, or eForms systems, and it was quickly shut down when the breach was discovered."

Senior officials at the agency, which sits under the Justice Department, designated the event a "major incident" and completed notifications, ATF said. The agency also stated, without elaboration, that "the incident has not impacted ATF’s ability to perform its missions."

ATF declined to comment further to CyberScoop on whether the ransomware group Qilin was responsible, the root cause of the breach, or when the intrusion occurred, saying: "This is an ongoing investigation, and no further details can be shared at this time."

Qilin's claim and profile

The extortion group Qilin claimed responsibility for the attack in an online post, though the agency and outside researchers have not independently confirmed Qilin’s involvement. Qilin is described in public reporting as a financially motivated, Russian-speaking affiliate-based ransomware operation that has claimed hundreds of victims in more than 60 countries since 2022.

Researchers cited by the reporting said Qilin became one of the most active ransomware threats globally by mid-2025. The group operates an affiliate model, claims dozens of new victims monthly, and lists targets across manufacturing, health care, financial services, education and government sectors.

How law enforcement and researchers characterize Qilin

Multiple independent groups and federal entities have flagged Qilin’s high activity. The FBI told reporters Qilin ranked among the five most-reported ransomware variants to the Internet Crime Complaint Center last year. Google likewise identified Qilin as one of the most active ransomware brands in 2025. Intelligence firm Halcyon said the majority of Qilin’s alleged victims are based in the United States and that nearly one in four reported targets are in the manufacturing industry.

Halcyon’s analysis also notes Qilin’s strategic partnerships and infrastructure overlaps: the extortion group has formed alliances with actors named Scattered Spider and Moonstone Sleet and uses infrastructure that overlaps with an actor called BianLian. Those relationships are cited as part of Qilin’s apparent operational scale and reach.

Technical and operational scope reported by ATF

ATF described the compromised asset as a standalone computer system containing information about targets of investigations and stressed that it "was not connected to any other ATF systems." The agency said the system was quickly taken offline once the breach was discovered. Beyond that, ATF would not provide a public timeline, technical root cause, or specifics about the data accessed, citing an ongoing investigation.

Although Qilin’s public claim suggests the group accessed ATF systems, the agency declined to confirm that attribution. The reporting emphasizes that, even when ransomware groups publicly claim a breach, independent confirmation and forensic details are critical and were not provided in ATF’s statements.

What this means for the Bureau of Alcohol, Tobacco, Firearms and Explosives, the FBI, and security teams

  • For the Bureau of Alcohol, Tobacco, Firearms and Explosives: ATF has framed the event as contained to a single system and says its core mission capability is unaffected; the agency named the incident a "major incident" and completed internal notifications while limiting public technical detail as investigators work.
  • For the FBI and federal responders: the FBI’s prior characterization of Qilin as among the most-reported ransomware variants underscores why the agency and other federal partners track and publicize these actors, even when attribution to a specific claim remains unconfirmed.
  • For security teams and investigators: the incident highlights how threat actors that use affiliate-based ransomware models publicly claim victims and form partnerships with other illicit groups, complicating attribution and response. Public reporting cited in the coverage identifies patterns of activity, sector targeting (notably manufacturing), and infrastructure overlap that defenders will monitor.

ATF’s brief, measured public statements leave several practical facts in plain view: a law enforcement agency reported a breach, said it was limited to a standalone investigation-targets system, and took that system offline while treating the event as a major incident. At the same time, Qilin’s claim and external assessments portray a highly active extortion group with a history of broad targeting—but direct attribution in this case remains unconfirmed. How investigators reconcile the group’s public claim with ATF’s containment assertions will be the central detail to emerge as the ongoing probe proceeds.

Original reporting: https://cyberscoop.com/atf-doj-cyberattack-qilin-ransomware/