AI is making scams harder to spot. Here are the practical defenses experts recommend.
The ATF says a cyberattack on a stand-alone system has been classified as a “major incident,” triggering formal notification to Congress as Qilin ransomware claims responsibility without public evidence.

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives said a cyberattack on one of its systems has been declared a “major incident.” That classification is a formal, legally defined designation that prompts notification to lawmakers in Congress. The affected system was described by ATF as a stand-alone system separate from the bureau’s network.
According to the report, an ATF spokesperson told reporters the targeted computer system contained information such as the “targets of ATF investigations.” The available details do not say whether data was stolen, leaked, or otherwise accessed beyond the system being targeted. The separation from the bureau’s broader network is a key detail for understanding the potential scope, but the full impact remains unclear from the information provided.
TechCrunch reported seeing a claim of responsibility by the Qilin ransomware gang on its leak site. The gang did not provide evidence for the claim, such as a sample of leaked data. Qilin is described as operating a “ransomware-as-a-service” model, leasing hacking tools to criminal affiliates for a cut of profits.
Under federal law, “major incidents” include significant cyber incidents likely to cause demonstrable harm to U.S. national security or broader U.S. interests. Agencies are required to disclose major incidents to Congress within a week of discovery. The ATF joins other federal agencies that have declared major incidents after breaches in recent years, including incidents involving the U.S. Marshals Service and an FBI system.
AI is making scams harder to spot. Here are the practical defenses experts recommend.
More than 100 organizations joined OpenAI’s call to strengthen cyber defenses against AI-enabled threats.

About 1,200 OpenAI agents reportedly coordinated through an internal registry and pursued a phantom scorer during a safety test.

OpenAI and 100+ companies say AI-enabled cyberattacks are becoming more sophisticated and critical infrastructure is at highest risk.