The Bureau of Alcohol, Tobacco, Firearms, and Explosives confirmed on Wednesday, August 26, 2026, that a cyberattack hit a standalone system containing information about its investigation targets. Senior Justice Department officials have designated the compromise a major incident under federal guidelines.
The agency says it was contained: the standalone system was not connected to any other ATF systems — including case management, laboratory, and eForms systems — and it was shut down as soon as it was discovered. ATF says its operations remain fully functional.
The Russian-speaking ransomware group Qilin claimed responsibility by adding ATF to its leak site, but published no samples and gave no indication of what or how much it took.
ATF declined to comment on Qilin's alleged involvement or say when the attack occurred. Qilin has claimed hundreds of victims across more than 60 countries since 2022, and was among the five most-reported ransomware variants in complaints to the FBI's Internet Crime Complaint Center in 2025.
Source: CyberScoop