ATF confirms breach hours after Qilin ransomware gang claims US firearms agency
The breach involved information about ATF targets under criminal investigation.

US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) Headquarters. Kevin Carter/Getty Images
- ATF confirms a breach after Qilin names the agency as its latest ransomware victim.
- The compromised system contained information tied to ATF investigations, the agency told Cybernews.
- Several major federal law enforcement agencies have suffered cyberattacks in 2026.
- Qilin remains one of the world's most prolific ransomware gangs, claiming thousands of victims since 2022.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The Qilin ransomware gang on Wednesday claims one of the US government's top federal law enforcement agencies – the Bureau of Alcohol, Tobacco, Firearms and Explosives, more commonly referred to as the ATF.
An ATF official has now confirmed to Cybernews that the US Bureau of Alcohol, Tobacco, Firearms and Explosives has suffered a system breach.
Tanya J. Roman, Chief of the ATF’s Public Affairs Division told Cybernews late Wednesday:
The standalone system was not connected to any other ATF systems, including any case management systems, laboratory systems, or eForms systems, and it was quickly shut down when the breach was discovered.
The ATF did not comment about the Qilin ransomware claims, nor provide any other information about the attacker.
The agency also did not say when the breach took place, how it happened, or whether any data was stolen by the unnamed hackers.
"This is an ongoing investigation, and no further details can be shared at this time,” it said.
In a separate statement posted on the ATF website, the agency made clear that the "ATF’s ability to perform its missions has not been impacted."
Immediately after discovering the incident, the ATF said it cut off access to the affected system and initiated incident‑response and forensic activities.
Senior Department of Justice officials have designated the event a “major incident” under federal guidelines, leading to the DoJ’s involvement in the investigation.
The ATF is asking for the public’s help, urging anyone with information about the breach to call its tipline at 1-888-ATF-TIPS.
Qilin claims ATF hours before confirmation
Meanwhile, the confirmation comes just hours after the Qilin ransomware gang claimed the US government's top federal law enforcement agency as its latest victim.
The notorious ransomware gang listed the ATF on its dark web leak site early Wednesday morning along with five other victims primarily from the industrial and manufacturing sectors.
The ATF entry provides no details about the alleged attack, including when it took place, how much data may have been stolen, or what types of information may have been compromised.
Furthermore, the Qilin post contains no sample data files to prove its claims.
Three of the other purported victims – WireCo, Metal Conversions, and Air International Thermal Systems – show dozens of proof samples alongside their entries.
What’s at risk in an ATF breach
Part of the US Department of Justice, the US Bureau of Alcohol, Tobacco, Firearms and Explosives is responsible for investigating and protecting the public from violent crimes involving illegal guns, bombings, weapons smuggling, and arson.
The agency is also responsible for enforcing federal laws governing firearm licenses (FFLs), regulating the commercial storage and use of explosives, and combating tobacco and alcohol bootlegging, according to the ATF website.
The ATF employs close to 5,000 personnel, including roughly 2,400 Special Agents, 700 Investigators, and partners with about 1,400 Task Force Officers across the country carrying out field operations.
The Bureau stressed that the impacted system operates separately from the ATF enterprise network, but that doesn't change the fact that leaked information about ATF investigations could pose a serious national security risk.
ATF investigations can target a wide range of serious criminal activity – from illegal firearms trafficking and violent gangs to bomb makers, terror suspects, and even domestic violence offenders.
Here is a roundup of typical targets according to the ATF website:
- Firearms traffickers, illegal gun makers, and straw purchasers
- Street/prison gangs and transnational criminal groups
- Felons and domestic abusers illegally possessing firearms
- Arsonists, bomb makers, and explosives thieves
- Rogue firearms dealers and other regulated offenders
If Qilin’s claims are legitimate – and data was stolen from the isolated ATF system – the potential fallout could be enormous.
Ongoing ATF investigations could be compromised, potentially undermining prosecutions and exposing hundreds, if not thousands, of informants, witnesses, and other law enforcement activities across the country.
According to annual ATF Facts and Figures Reports, the agency initiates anywhere from 25,000 to 38,000 new criminal investigations every year.
US government agencies under attack
It’s also not the first hack of federal law enforcement agencies so far this year.
On July 3rd, the US Department of Homeland Security announced it was investigating a cyber breach of its own government information-sharing network used to exchange information with foreign law enforcement and other authorities.
The attack, which was reported to have taken place between late May and early June, exposed unclassified data that was categorized by lawmakers as "highly sensitive and a risk to national security.”
And in early March, the FBI revealed that hackers had infiltrated the sensitive investigative network used to manage court-authorized wiretaps and surveillance warrants.
The FBI later linked the intrusion to China and classified it as a "major incident" under federal cybersecurity law.
Last fall, a hack of the US Federal Emergency Management Agency (FEMA) exposed the personal data of an unknown number of FEMA and US Customs and Border Protection (CBP) employees.
The national disaster response agency was slammed for its lack of proper security controls, leading US lawmakers to call for the resignation of then Homeland Security Secretary Kristi Noem.
The ATF breach also comes as US government networks in general continue to face a barrage of cyberattacks.
A recent Cybernews investigation found that in 2025 more than 75% of US government websites suffered a data breach, exposing everything from employee credentials to sensitive internal information.
Qilin remains a ransomware powerhouse
As for the Russian-linked Qilin gang, the ransomware operators have claimed roughly 1,900 victims in the past 18 months alone, making it one of the most active groups of 2025 and, to date, 2026.
According to Cybernews’ in-house surveillance tool Ransomlooker, the gang has listed more than 891 victims so far this year.
First observed by researchers in 2022, Qilin is known for its now-standard double-extortion tactics, stealing victims' data and then threatening to publish it unless a ransom is paid.
Since January, the ransomware-as-a-service (RaaS) affiliates have listed global food distributor Sysco Corporation and US-based commercial real estate giant Cushman & Wakefield as victims, with both also claimed by the notorious ShinyHunters extortion group.
Two New York-centric breaches were also claimed – the Shipping Association of New York & New Jersey (SANYNJ), which runs one of North America’s busiest ports, as well as New York City’s TWU Local 100 – the nation’s largest public transportation system workers’ union.
Other high-profile claims in recent months include 1800-Dentist, German political party Die Linke, and Evian water-maker Danone.
Targets in 2025 included Japan's Asahi Holdings, digital gaming giant International Game Technology (IGT), Korea’s SK Group, US newspaper group Lee Enterprises, Nissan Japan's design arm, Creative Box, and the controversial religion Scientology.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.