Cybersecurity2 mins read

ATF Declares “Major Incident” After Cyberattack as Ransomware Gang Claims Hack

The ATF says a cyberattack on a stand-alone system has been classified as a “major incident,” triggering formal notification to Congress as Qilin ransomware claims responsibility without public evidence.

What Happened

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives said a cyberattack on one of its systems has been declared a “major incident.” That classification is a formal, legally defined designation that prompts notification to lawmakers in Congress. The affected system was described by ATF as a stand-alone system separate from the bureau’s network.

What Was Targeted

According to the report, an ATF spokesperson told reporters the targeted computer system contained information such as the “targets of ATF investigations.” The available details do not say whether data was stolen, leaked, or otherwise accessed beyond the system being targeted. The separation from the bureau’s broader network is a key detail for understanding the potential scope, but the full impact remains unclear from the information provided.

Ransomware Claim Remains Unproven Publicly

TechCrunch reported seeing a claim of responsibility by the Qilin ransomware gang on its leak site. The gang did not provide evidence for the claim, such as a sample of leaked data. Qilin is described as operating a “ransomware-as-a-service” model, leasing hacking tools to criminal affiliates for a cut of profits.

Why the “Major Incident” Label Matters

Under federal law, “major incidents” include significant cyber incidents likely to cause demonstrable harm to U.S. national security or broader U.S. interests. Agencies are required to disclose major incidents to Congress within a week of discovery. The ATF joins other federal agencies that have declared major incidents after breaches in recent years, including incidents involving the U.S. Marshals Service and an FBI system.

Discover More

    OpenAI cyber defense warning and steps people can take to protect themselves
    OpenAI Cyber Warning

    AI is making scams harder to spot. Here are the practical defenses experts recommend.

    CybersecurityAI
    Illustration for a report on AI-powered cyberattacks and critical infrastructure defense
    OpenAI Warns on AI Cyberattacks

    OpenAI and 100+ companies say AI-enabled cyberattacks are becoming more sophisticated and critical infrastructure is at highest risk.

    CybersecurityAI Safety