CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

ATF responds to 'major' cybersecurity incident after ransomware gang's claims

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5891

As cited

Copy frozen at (site build).

ransomware

ATF responds to 'major' cybersecurity incident after ransomware gang's claims

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) disclosed a major cybersecurity incident involving a standalone computer system containing information on ATF investigation targets after the Qilin ransomware gang posted the agency on its leak site. The affected system was not connected to other ATF networks, and the agency stated there was no impact to its enterprise network, eForms system, or operations. ATF is investigating the breach in coordination with the Department of Justice, which designated it as a major incident under federal guidelines.

Why it matters: Federal law enforcement and cybersecurity teams tracking Qilin's activity should assess exposure to ATF investigation data and monitor for related targeting; organizations should review their own isolation of sensitive systems from enterprise networks.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

ATF responds to 'major' cybersecurity incident after ransomware gang's claims

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) disclosed a major cybersecurity incident involving a standalone computer system containing information on ATF investigation targets after the Qilin ransomware gang posted the agency on its leak site. The affected system was not connected to other ATF networks, and the agency stated there was no impact to its enterprise network, eForms system, or operations. ATF is investigating the breach in coordination with the Department of Justice, which designated it as a major incident under federal guidelines.

Why it matters: Federal law enforcement and cybersecurity teams tracking Qilin's activity should assess exposure to ATF investigation data and monitor for related targeting; organizations should review their own isolation of sensitive systems from enterprise networks.

Actorsqilin
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary