The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed a federal major cybersecurity incident after the Qilin ransomware group listed the agency on its dark-web leak site. The compromised asset was a standalone system containing information on targets of ATF investigations; Qilin has not published samples or other evidence that data was stolen, nor disclosed whether it sought a ransom.
ATF said the affected system was isolated from its enterprise environment and was promptly shut down, with connections to the environment terminated. The agency and Department of Justice have launched incident-response, forensic, and investigative work. ATF reported no evidence that its enterprise network, case-management, laboratory, eForms, or other systems were affected, and said mission operations remain uninterrupted.

TTPs, infrastructure, and targeting history in one profile.
5 events from the most recent confirmed update back to the earliest known activity.
Agenda, also known as Qilin or Water Galura, saw increased activity beginning in December 2023. Trend Micro reported a Rust-based variant that propagates to VMware vCenter and ESXi hosts through a custom in-memory PowerShell script and can alter ESXi root passwords and terminate VM clusters.
After ransom negotiations reportedly failed, Qilin published 6.3 GB of data it claimed to have stolen from ATF. The purported leak included investigation-target names, phone numbers, IP addresses, iCloud data, and Cellebrite phone extractions.
After discovering the compromise, ATF terminated connections to the affected environment, shut down the system, and initiated incident-response and forensic activities. The Department of Justice began investigating the incident.
ATF confirmed that a standalone system containing information about targets of ATF investigations was compromised and classified the breach as a federal major incident. The agency said the system was isolated from its enterprise, case-management, laboratory, and eForms systems, with no impact to mission operations.
The Qilin ransomware gang added the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives to its leak portal. The group did not provide data samples or state whether it had exfiltrated files or demanded a ransom.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
19 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcesecuritymagazine.com
Open sourcecyberveille.ch
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourceatf.gov
Open sourcetrendmicro.com
Open sourcetrendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.