5 days ago
ATF Investigates Standalone System Hack, Says Missions Unaffected
The ATF says someone hacked one of its computer systems.
That system was separate from the agency’s main computer network.
ATF says its work has not been disrupted.
It also says its online firearms forms and other systems were not affected.
A ransomware group called Qilin says it carried out the attack.
However, Qilin has not shown proof that it was responsible.
Cybersecurity companies describe Qilin as an active and serious threat.
The ATF is still investigating what happened.
The Bureau of Alcohol, Tobacco, Firearms and Explosives is investigating a hack affecting a standalone system.
The agency said the incident has not impaired its law-enforcement missions.
ATF said the affected system is separate from its main network, online firearms forms and other systems.
Ransomware group Qilin claimed responsibility but provided no evidence supporting the claim.
The disclosure followed a Justice Department announcement about disrupted infrastructure used by Chinese state-sponsored hackers.
- Who
- The Bureau of Alcohol, Tobacco, Firearms and Explosives is investigating; ransomware group Qilin claims responsibility.
- What
- A cybersecurity incident affected an ATF standalone computer system.
- Where
- The incident involved an ATF system, but the agency did not identify its physical location.
- When
- The ATF announced the incident on Wednesday; no specific date was provided.
- Why
- The reason for the intrusion remains under investigation; Qilin claims it was a ransomware attack.
ATF’s assessment
Qilin’s claim
Impact of the incident
ATF’s assessment
ATF said the hack was limited to a standalone system and did not affect its missions or broader systems.
Qilin’s claim
Qilin claimed responsibility for the hack, but it did not provide evidence showing the extent of any impact.
Responsibility
ATF’s assessment
ATF has said it is investigating the cybersecurity incident and has not publicly confirmed who was responsible.
Qilin’s claim
Qilin claimed to have carried out the attack, although the claim remains unverified.
Key facts
- Affected agency
- Bureau of Alcohol, Tobacco, Firearms and Explosives
- Affected system
- A standalone system separate from ATF’s main computer network
- Reported impact
- ATF said its missions were not affected
- Other systems
- ATF reported no sign of impact to its broader network, online firearms forms or other systems
- Claimed attacker
- Ransomware group Qilin
- Evidence
- Qilin provided no evidence supporting its claim
- Threat assessment
- Check Point Software Technologies and Halcyon describe Qilin as increasingly active and a major ransomware threat




