
The Bureau of Alcohol, Tobacco, Firearms and Explosives has confirmed that hackers breached one of its computer systems, just after a Russian-linked ransomware gang called Qilin claimed the attack and listed the federal agency on its dark web leak site. The compromised system reportedly held information on targets of ATF criminal investigations, though the bureau says it was an isolated environment cut off from the agency's main enterprise network.
Senior Justice Department officials have classified the breach as a major incident under federal guidelines, according to Tampa Free Press. That designation is not a minor bureaucratic label — under Office of Management and Budget guidance and the Federal Information Security Modernization Act, a major incident classification legally requires agencies to notify Congress within seven days and triggers centralized interagency oversight of the investigation, according to Covington & Burling LLP. An ATF spokesperson told Recorded Future News that the affected standalone system was shut down quickly once the intrusion was discovered and was never connected to the agency's case management, laboratory, or eForms platforms, according to The Record.
ATF has not disclosed when the breach occurred or how the network was penetrated, and federal authorities have not said whether hackers actually managed to steal data. The bureau severed access to the impacted environment and launched incident response and forensic procedures, with federal investigators continuing their review of the extent of the intrusion. In its own statement, ATF said this is an ongoing investigation and no further details can be shared at this time, adding that its ability to perform its missions has not been impacted.
Qilin's Claim Comes Without Proof
Qilin added ATF to its leak site on Wednesday, listing the bureau alongside five other targets, but the group did not provide timestamps, data size estimates, or proof files to back up its claim, per the reporting from Tampa Free Press. That is notably different from how the gang handled other listings around the same time — Qilin posted sample files tied to Wireco, Metal Conversions, and Air International Thermal Systems, suggesting the ATF claim may still be unverified even as the bureau treats it seriously enough to trigger a formal incident response.
Qilin describes itself as a Russian-linked ransomware syndicate that was first detected in 2022 and operates on a double-extortion model, encrypting files while also stealing data to pressure victims into paying. The group claims roughly 1,900 victims over the past 18 months and says it has hit more than 891 targets so far in 2026 alone. Cybersecurity research from Flashpoint found that Qilin's operators deploy custom Rust-written loaders and kernel-level evasion toolkits specifically engineered to blind and disable endpoint detection software before encrypting a target's network, according to Flashpoint.
Threat intelligence tracking from Proven Data describes Qilin as a ransomware-as-a-service syndicate that offers affiliates an 80% to 85% cut of extortion payments and has claimed more than 2,200 victim organizations worldwide, per Proven Data. Industry tracking from Cybersecurity Insiders in August found the group has sharply escalated its U.S. targeting this year, claiming attacks against roughly 40 American businesses in 2026, including four Fortune 500 corporations, and other listed targets have reportedly included Sysco Corporation, Cushman & Wakefield, and the Shipping Association of New York & New Jersey.
A Group With a History of High-Stakes Targets
Qilin's most consequential known attack came in June 2024, when it hit London-based pathology provider Synnovis, disrupting blood testing across south-east London hospitals and forcing the cancellation of more than 10,000 medical appointments. An NHS trust investigation later cited that attack as a contributing factor in a patient's unexpected death, according to reporting from the HIPAA Journal. That history has fueled concern among analysts that compromised ATF investigative files could endanger active operations, informants, and law enforcement witnesses if the breach proves more extensive than the bureau has acknowledged.
The stakes are heightened by the sheer scale of what ATF stores. The bureau's National Tracing Center receives an average of 5 million out-of-business firearms records every month from licensed dealers and holds at least 866 million digitized records from closed federally licensed firearms dealers at its West Virginia repository, per the bureau's own documentation. ATF investigations target illegal firearms traffickers, violent gangs, illicit weapons manufacturers, bomb makers, and arsonists, and the bureau employs roughly 2,400 special agents and 700 investigators who launch between 25,000 and 38,000 criminal investigations every year.
Not the First DOJ Agency Hit This Way
This is not the first time a standalone Justice Department system has been targeted. In February 2023, the U.S. Marshals Service suffered a ransomware attack on a standalone system containing sensitive law enforcement files, employee personal data, and fugitive investigation details, which DOJ also classified as a major incident, according to CBS News. That breach took months to fully remediate before the Marshals Service stood up a reconstituted system with upgraded security controls.
The ATF breach also lands amid a broader wave of intrusions targeting federal law enforcement and homeland security infrastructure in 2026. In March, the FBI disclosed that hackers linked to China had infiltrated its Digital Collection System Network, the infrastructure used to manage court-authorized wiretaps and FISA surveillance warrants, in what investigators attributed to a vendor supply-chain compromise. In July, the Department of Homeland Security opened an inquiry into a breach of the Homeland Security Information Network, an unclassified platform federal, state, and local agencies use to share security planning and emergency response intelligence. FEMA has also experienced a breach that exposed employee information, and the Justice Department separately announced the seizure of domains run by the Chinese state-sponsored group Qtfy, which had targeted NASA, the Department of Energy, and the U.S. Senate.
Gun Rights Groups Watching Closely
Gun Owners of America highlighted the Qilin leak claim on social media, reflecting the intense interest gun rights advocates have long held in ATF data security given the volume of firearm transaction records the bureau retains. Federal law bars ATF from building a centralized searchable gun registry, though out-of-business dealer records are kept in a central repository specifically for tracing crime guns.
For now, ATF is asking anyone with information about the breach to contact its tipline at 1-888-ATF-TIPS. The bureau maintains that its core mission has not been disrupted, even as federal investigators continue their forensic review to determine just how far the intrusion into its systems actually went.









-4.webp?w=1000&h=1000&fit=crop&crop:edges)