The Bureau of Alcohol, Tobacco, Firearms, and Explosives (ATF) said Wednesday that it is investigating a cybersecurity incident for which a ransomware group has claimed responsibility.
Senior ATF officials have deemed the event a “major incident” under federal guidelines, although it stressed the hack did not impact the bureau’s ability to perform its operations, according to a statement published Wednesday.
The hackers targeted what the ATF said is a “standalone system,” which it did not describe.
“The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system,” it added.
“Upon discovery of the incident, ATF immediately terminated connections to the affected environment and initiated incident‑response and forensic activities. ATF is coordinating closely with the Department of Justice to investigate.”
The ATF did not confirm or mention what group or country may have been responsible. It also did not say when the incident occurred, whether any data was stolen, or whether the attack involved ransomware.
A Russia-linked ransomware group, Qilin, took responsibility for the ATF hack, according to breach-monitoring service GalaxyWarden. The ransomware group listed the ATF on its website, but GalaxyWarden noted that it did not provide any evidence to substantiate its claims.
“Qilin claims to have stolen internal data. This is the group’s claim, not a confirmed finding,” GalaxyWarden said in a blog post on Wednesday.
Ransomware is a form of software that locks a computer or encrypts files, with purveyors demanding that the victims submit a payment to regain access.
The incident comes as U.S. officials on Wednesday said federal authorities had disrupted a Chinese regime-linked hacking operation responsible for break-ins and attempts on the Department of Justice (DOJ), NASA, the Federal Reserve, the Senate, and other government agencies.
In a statement, the DOJ revealed it had seized domains used by two hacking platforms, called QScan and QTRouter, which the department said were used as part of the campaign.
“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted,” Attorney General Todd Blanche said in a statement.
“We are here to ensure security for the American people and will use every tool we have to keep that promise. Federal law enforcement investigated and disabled the [Chinese regime’s] malicious software, the latest in a series of technical operations to dismantle indiscriminate hacking activities sponsored by the People’s Republic of China.”
The ATF is a subdivision of the DOJ, although the DOJ’s statement did not say whether the firearms bureau was targeted by the Chinese hackers.
In July and August, federal officials sent out warnings about hacks targeting water facilities in multiple U.S. states. Officials said in one warning this month that Iranian regime-linked hackers targeted logic controllers at various facilities made by Siemens, Rockwell Automation, and Schneider Electric.
For years, the FBI and other U.S. agencies have warned that China, Russia, and Iran have been seeking to hack and target U.S. infrastructure systems, companies, and government entities.






















