The ATF got hit by ransomware, and this time it's the agency chasing gun traffickers that's on defense.
The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a "major incident" after Russia-linked ransomware group Qilin listed it on a dark-web leak site alongside four other victims: Northern Leasing Systems, Metal Conversions, California Truck Equipment, and WireCo. Qilin hasn't published stolen files or said what it took. ATF says the breach hit only a standalone system separate from its main enterprise network, its eForms system, and other core infrastructure. The agency disconnected the affected system, brought in outside cybersecurity help, and notified the Department of Justice, which designated the incident a major one under federal guidelines.
ATF hasn't named the compromised system, but it has been described elsewhere as one holding information on targets of ATF investigations, a detail the agency's own statement stops short of confirming. If accurate, that is a far more sensitive exposure than a typical corporate breach: identities tied to open investigations into gun trafficking, arson, and organized crime. It also fits a pattern of ransomware crews using the threat of leaked sensitive files, not just locked systems, to pressure targets who would otherwise refuse to pay.
Qilin has form here. It's the same group blamed for the 2024 attack on pathology provider Synnovis, which disrupted blood testing across UK hospitals for months. A federal law enforcement agency joining that victim list says less about ATF's specific defenses than about how routine hitting government targets has become for ransomware operators.