ATF declares ‘major incident’ after ransomware gang claims cyberattack
What happened
- The US government’s Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) suffered a “major incident” after a ransomware gang claimed a cyberattack.
- Ransomware group Qilin listed the ATF among new victims on their data leak site.
- The attackers reportedly accessed a standalone system that held information about targets of ATF investigations.
- The ATF disconnected the affected systems and notified relevant authorities, including the Department of Justice (DOJ).
Why it matters for me
The ATF investigates serious federal crimes like illegal firearms trafficking, organized crime, and explosives. This incident highlights the critical need for cybersecurity, especially for agencies handling sensitive investigation data.
What to remember
- The breach affected a standalone system, not the core ATF enterprise network.
- The attackers did not specify what data was stolen or how much they took.
- Qilin is a known ransomware threat actor linked to Russia and previously attacked Synnovis in 2024.
Source: Original article
Source: www.techradar.com
