EXCLUSIVE: Qilin hackers leak ATF data, exposing criminal investigations and phone records
Qilin’s ransom 72-hour countdown expires – revealing leaked ATF case files, phone dumps, and forensic evidence.

ATF agents bust blackmarket gun business. Photo by Irfan Khan/Los Angeles Times via Getty Images
- Qilin’s ATF leak exposes case files tied to criminal investigations and field operations.
- The leaked files appear to include investigation records, phone data, account details, and forensic evidence.
- ATF confirmed a standalone server was breached but said its main network and eForms system were unaffected.
- Cybernews researchers are still reviewing the data to determine the full scope of exposure.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The Qilin ransomware gang has made good on its threat to publish ATF data allegedly stolen from the US Bureau of Alcohol, Tobacco, Firearms and Explosives last week – exposing what appears to be a large cache of sensitive information tied to criminal investigations, phone records, and forensic evidence.
The massive data dump was posted to the ransomware group’s dark web leak site on Monday – and at first glance the "Publicated" trove appears to contain at least 6.3GB of confidential internal files.
The Russian-speaking ransomware operators claimed the ATF on their dark web leak site on Wednesday, August 26th, the same day the ATF confirmed to Cybernews that it had suffered a breach of one of its standalone servers.
In the initial ATF cyberattack claim, Qilin provided no sample proof files or details about how much or what type of data it may have exfiltrated from ATF systems, leaving the scope of the alleged breach unknown.
To note, the ATF did not confirm to Cybernews the threat actor responsible for the attack.
On Friday, Qilin posted a countdown clock on the site giving the ATF exactly 72 hours before it threatened to publicly unleash the stolen data – clearly looking for a ransom payout to keep the sensitive law enforcement data private.
An initial review by the Cybernews research team found files that appear to contain information connected to active or previous criminal investigations, including records extracted from mobile devices, account information, and digital forensic evidence.
Cybernews researchers are continuing to analyze the leaked material to determine the scope of the breach and what information may have been exposed. Cybernews will update this report once the analysis is complete.
What ATF confirmed
Tanya J. Roman, Chief of the ATF’s Public Affairs Division, told Cybernews on Wednesday that the compromised ATF system “contained information about targets of ATF investigations.”
The agency also noted in a public statement that there was “no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system” and that the bureau’s mission was not impacted in any way.
Still, leaked information about ATF investigations could expose the inner workings of federal investigations and could create national security risks.
ATF investigations can target a wide range of serious criminal activity – from illegal firearms trafficking and violent gangs to bomb makers, terror suspects, and even domestic violence offenders.
“This is the agency investigating firearms trafficking, illegal explosives, arson, and organized crime tied to the illicit alcohol and tobacco trade. When attackers reach investigative data, the real risk isn't exposed records; it's what those records could reveal about open cases, targets, and the people tied to them,”says John Bruggeman, vCISO at CBTS.
Inside the stolen ATF files
The large number of files and directories published by Qilin suggests the gang may have obtained substantial amounts of digital evidence collected by ATF investigators.
The parent directories Cybernews reviewed show dozens of folders organized around individual investigations and ATF field operations, including directories labeled “LAREDO Field Office” and “atf-houston.”
Many of the folders appear to be named after specific individuals of interest, while others identify the exact mobile devices or accounts tied to those individuals.
The leaked files also appear to include phone and device extractions, identifying Apple iPhones, Samsung Galaxy models, SIM cards, iCloud data, and Cellebrite phone dumps.
Additionally, the alleged files reveal the use of Cellebrite, a controversial Israeli-made digital forensics software platform widely used by law enforcement and the military to extract and analyze data from mobile devices.
And although Cellebrite is used by government agencies and some private companies worldwide, the technology has faced backlash from privacy and civil-liberties advocates in recent years.
Other notable ATF finds
Cybernews found a number of records containing account identifiers, IP addresses, registration information, and verified phone numbers – with some file names exposing actual phone numbers alongside named individuals.
Other files seem to be connected to specific criminal investigations, including an “ARMORED TRUCK ROBBERY SERIES 22-23” directory, with other directories containing ZIP reports, XML files, and forensic records.
Also of importance, the leak appears to reveal details about the ATF’s IT environment, including its use of Symantec Endpoint Protection version 14.3 – potentially providing the hackers with valuable intelligence about the agency’s security infrastructure.
Cybernews reached out to the ATF for further clarification on the published data.
The ATF responded to Cybernews on Monday, saying the agency plans to release an official statement later today. Cybernews will update this report once the statement is released.
What’s at risk after the ATF leak
With a reported 25,000–38,000 new criminal investigations launched by the ATF each year, the potential fallout from the leak could extend far beyond just the exposure of sensitive records.
John Bruggeman, vCISO at CBTS, says the ATF response to the breach gives us some clues about how prepared the agency was for a major security incident, stating the quick response was a good sign.
“The ATF says they were able to quickly identify the compromised system as standalone and separate from the enterprise network, then terminate connections to the affected environment while broader systems remained operational,” Bruggeman points out.
“You want that kind of clarity during an incident. You don’t want to wonder or try to figure out what systems connect to what. You also want to know who has the authority to isolate a compromised system after an attack, when you might not be sure if the attacker is still inside,”says John Bruggeman, vCISO at CBTS.
Bruggeman also noted that the US Department of Justice, under which the ATF operates, immediately designated the event a “major incident” under federal guidelines, “suggesting those response procedures were established and probably practiced.”
The vCISO also acknowledges the sensitivity of the data allegedly accessed and what it actually implies.
“This is the agency investigating firearms trafficking, illegal explosives, arson, and organized crime tied to the illicit alcohol and tobacco trade. When attackers reach investigative data, the real risk isn't exposed records; it's what those records could reveal about open cases, targets, and the people tied to them,” Bruggeman says.
This exposure can include not only the targets themselves but also witnesses, informants, prosecutorial evidence, and the roughly 1,400 local task force officers working with the ATF across the country on thousands of investigations.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.