· via TechCrunch
ATF declares 'major incident' after Qilin ransomware gang claims federal system breach
The ATF has classified a cyberattack on a standalone system holding data on its investigation targets as a "major incident", a formal status requiring congressional notification, after the Qilin ransomware gang claimed the breach.

ATF classifies cyberattack as a formal major incident
The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives has declared a cyberattack on one of its systems a "major incident," a legally defined designation that compels the agency to formally notify Congress, TechCrunch has reported.
In a statement, the ATF said it was responding to an attack on a standalone system kept separate from the bureau's wider network. A spokesperson told reporters that the affected computer held information including the "targets of ATF investigations" — data that is sensitive by nature because it concerns active federal law enforcement work.
Qilin ransomware gang claims the breach
According to TechCrunch, the Qilin ransomware gang has claimed responsibility for the attack on its leak site, though the group did not back the claim with evidence such as a sample of stolen data.
Qilin runs a ransomware-as-a-service operation, licensing its hacking tools to affiliated criminal crews in exchange for a cut of any ransom payments. The gang's past victims include Lee Enterprises, a large U.S. newspaper publisher, and Synnovis, a U.K. pathology laboratory provider.
What the designation requires
U.S. federal law defines major incidents as significant cyber incidents likely to cause demonstrable harm to national security or broader American interests. Agencies that make the declaration must report the incident to Congress within a week of discovering it, which puts the breach on a formal record rather than leaving it in internal incident-response channels.
Part of a wider pattern
The ATF is the latest federal agency to invoke the designation in recent years. TechCrunch notes that the U.S. Marshals Service declared a major incident after a 2023 ransomware attack on one of its systems, and that an FBI breach earlier this year — which exposed phone numbers of people under surveillance by federal agents — received the same classification.
Why it matters
The designation is reserved for incidents judged likely to cause demonstrable harm, so the ATF's own classification signals the bureau treats this as potentially serious, even though the compromised system was described as standalone. The data involved reportedly includes identities of investigation targets, meaning a leak could disrupt ongoing cases and endanger individuals if the gang follows the common ransomware playbook of publishing stolen files.
The episode also illustrates how ransomware crews increasingly treat government agencies as viable targets, and it puts pressure on the ATF to establish whether Qilin's claim is genuine — either through its congressional notification or as more details surface. Until evidence appears on the gang's leak site, the claim remains unverified, and the true scope of the breach, including whether any data was actually taken, is not yet established.
- #ransomware
- #cybersecurity
- #atf
- #us-government
- #data-breach