The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed that one of its standalone systems was compromised in a cybersecurity incident allegedly linked to the Qilin ransomware gang.
Qilin added the ATF to its dark web data leak site on Wednesday. The ransomware group did not disclose whether it stole files from the agency’s systems or demanded a ransom.
That same day, the ATF issued a statement confirming that a standalone system had been compromised in what it described as a “serious incident.” The investigation is being conducted in coordination with the U.S. Department of Justice.
“The affected systems operate separately from the ATF Enterprise Network, and there is no evidence that this incident impacted the ATF Enterprise Network, the ATF eForms system, or any other ATF systems,” the federal law enforcement agency said.
“Upon discovering the incident, ATF immediately terminated connectivity to the affected environment and began incident response and forensic operations. ATF is working closely with the Department of Justice on the investigation.”
The ATF said the cybersecurity incident has not disrupted the agency’s operations. It also asked anyone with information about the attack to contact the agency through its official information lines.
BleepingComputer contacted an ATF spokesperson for additional details about the alleged Qilin ransomware attack but had not received a response at the time of publication.

Qilin is a ransomware-as-a-service (RaaS) operation first identified in August 2022 under the name “Agenda.” Since then, the group has claimed responsibility for attacks against more than 2,200 victims on dark web leak sites.
Qilin’s alleged victims include several high-profile organizations, such as automakers Nissan and Yang Feng, pathology services provider Shinobis, Japanese beer company Asahi, publisher Lee Enterprises, and Australia’s Court Services Victoria.
The alleged ATF breach comes as several U.S. federal agencies have disclosed cybersecurity incidents following attacks against their networks and systems.
In early March, the Federal Bureau of Investigation (FBI) confirmed that it was investigating a breach involving systems used to manage wiretaps and surveillance warrants.
More recently, in July, the U.S. Department of Homeland Security disclosed a cyberattack that compromised the Homeland Security Information Network (HSIN). The platform is used to share sensitive information among federal, state, and local governments, as well as private-sector partners.
The overall prevention score can hide what happens after an attacker gains initial access. When threat actors use valid credentials, the effectiveness of security defenses can decline sharply.
Blue Report 2026 evaluates defense techniques across technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com




