Qilin gang claims US Bureau of Alcohol, Tobacco, Firearms and Explosives
A confirmed ATF breach could expose agents, investigations, informants, and sensitive case data.

US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) Headquarters. Kevin Carter/Getty Images
- Qilin claims the ATF as its latest victim but has provided no evidence or details.
- The ATF holds potentially sensitive law enforcement, investigative, firearms, and employee information.
- Several major federal law enforcement agencies have suffered cyberattacks in 2026.
- Qilin remains one of the world's most prolific ransomware gangs, claiming thousands of victims since 2022.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The Qilin ransomware gang on Tuesday claims one of the US government's top federal law enforcement agencies – the Bureau of Alcohol, Tobacco, Firearms and Explosives, more commonly referred to as the ATF.
The notorious ransomware gang listed the ATF on its dark web leak site on Tuesday, along with five other victims primarily from the industrial and manufacturing sectors.
The ATF entry provides no details about the alleged attack, including when it took place, how much data may have been stolen, or what types of information may have been compromised.
Furthermore, the Qilin post contains no sample data files to prove its claims.
Three of the other purported victims – WireCo, Metal Conversions, and Air International Thermal Systems – show dozens of proof samples alongside their entries.
Cybernews has reached out to the ATF for confirmation and is awaiting a response.
What’s at risk in an ATF breach
Part of the US Department of Justice, the US Bureau of Alcohol, Tobacco, Firearms and Explosives is responsible for investigating and protecting the public from violent crimes involving illegal guns, bombings, weapons smuggling, and arson.
The agency is also responsible for enforcing federal laws governing firearm licenses (FFLs), regulating the commercial storage and use of explosives, and combating tobacco and alcohol bootlegging, according to the ATF website.
The ATF employs close to 5,000 personnel, including roughly 2,400 Special Agents, 700 Investigators, and partners with about 1,400 Task Force Officers across the country carrying out field operations.
If Qilin’s claims are legitimate – and depending on which ATF networks were accessed – potential risks could be enormous, compromising not just agents and case files, but ongoing ATF investigations, potentially impacting prosecutions, and exposing informants and witnesses.
US government agencies under attack
It’s also not the first hack of federal law enforcement agencies so far this year.
On July 3rd, the US Department of Homeland Security announced it was investigating a cyber breach of its own government information-sharing network used to exchange information with foreign law enforcement and other authorities.
The attack, which was reported to have taken place between late May and early June, exposed unclassified data that was categorized by lawmakers as "highly sensitive and a risk to national security.”
And in early March, the FBI revealed that hackers had infiltrated the sensitive investigative network used to manage court-authorized wiretaps and surveillance warrants.
The FBI later linked the intrusion to China and classified it as a "major incident" under federal cybersecurity law.
Last fall, a hack of the US Federal Emergency Management Agency (FEMA) exposed the personal data of an unknown number of FEMA and US Customs and Border Protection (CBP) employees.
The natoinal disaster response agency was slammed for its lack of proper security controls, leading US lawmakers to call for the resignation of then Homeland Security Secretary Kristi Noem.
The ATF claim also comes as US government networks in general continue to face a barrage of cyberattacks.
A recent Cybernews investigation found that in 2025 more than 75% of US government websites suffered a data breach, exposing everything from employee credentials to sensitive internal information.
Qilin remains a ransomware powerhouse
As for the Russian-linked Qilin gang, the ransomware operators have claimed roughly 1,900 victims in the past 18 months alone, making it one of the most active groups of 2025 and, to date, 2026.
According to Cybernews’ in-house surveillance tool Ransomlooker, the gang has listed more than 891 victims so far this year.
First observed by researchers in 2022, Qilin is known for its now-standard double-extortion tactics, stealing victims' data and then threatening to publish it unless a ransom is paid.
Since January, the ransomware-as-a-service (RaaS) affiliates have listed global food distributor Sysco Corporation and US-based commercial real estate giant Cushman & Wakefield as victims, with both also claimed by the notorious ShinyHunters extortion group.
Two New York-centric breaches were also claimed – the Shipping Association of New York & New Jersey (SANYNJ), which runs one of North America’s busiest ports, as well as New York City’s TWU Local 100 – the nation’s largest public transportation system workers’ union.
Other high-profile claims in recent months include 1800-Dentist, German political party Die Linke, and Evian water-maker Danone.
Targets in 2025 included Japan's Asahi Holdings, digital gaming giant International Game Technology (IGT), Korea’s SK Group, US newspaper group Lee Enterprises, Nissan Japan's design arm, Creative Box, and the controversial religion Scientology.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.