Qilin Ransomware Claims Breach of ATF System, Agency Confirms Isolated Incident
The **Qilin** ransomware gang has asserted responsibility for a breach impacting a system belonging to the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (**ATF**). The federal agency has confirmed the compromise of an isolated system, emphasizing that its enterprise network and critical operations remain unaffected.
The **ATF**, the federal regulatory body overseeing firearms and explosives in the United States, has confirmed a system compromise following claims made by the **Qilin** ransomware group.
**Qilin** added the **ATF** to its dark web data leak portal, though it did not specify whether data was exfiltrated or if a ransom demand was issued.
On the same day, the **ATF** released a press statement acknowledging a "major incident" involving a standalone system. The agency is now investigating the breach in collaboration with the Department of Justice.
"The impacted system operates separately from the **ATF** enterprise network, and there is no indication that the incident has affected the **ATF** enterprise network, the **ATF** eForms system, or any other **ATF** system," the agency stated in its press release.
"Upon discovery of the incident, **ATF** immediately terminated connections to the affected environment and initiated incident-response and forensic activities. **ATF** is coordinating closely with the Department of Justice to investigate."
The **ATF** further noted that the incident has not impacted its operations and encouraged the public to submit any relevant information via its official tip line.

## Understanding Qilin Ransomware
**Qilin** is a Ransomware-as-a-Service (**RaaS**) operation, first identified in August 2022 under the moniker "Agenda." The group has since claimed over 2,200 victims on its dark web leak site.
Notable organizations reportedly targeted by **Qilin** include automotive giants **Nissan** and **Yanfeng**, pathology services provider **Synnovis**, Japanese brewery **Asahi**, publishing company **Lee Enterprises**, and **Australia's Court Services Victoria**.
## Broader Federal Agency Breaches
This incident is part of a series of cybersecurity breaches affecting U.S. federal agencies this year.
In early March, the U.S. Federal Bureau of Investigation (**FBI**) confirmed an investigation into a breach impacting systems used for managing wiretap and surveillance warrants.
More recently, in July, the U.S. Department of Homeland Security (**DHS**) disclosed a cyberattack that compromised the Homeland Security Information Network (**HSIN**), a critical information-sharing platform utilized by federal, state, local, and private-sector partners.