OTHER

ATF Declares ‘Major Incident’ Following Ransomware Group’s Cyberattack Assertion

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has labeled a cyberattack on one of its systems as a “major incident.” This classification carries specific legal implications and necessitates formal communication to Congress.

In its statement, the ATF indicated that it is working to resolve the cyberattack on a dedicated system that functions separately from the bureau’s primary network. An ATF representative explained to reporters that the compromised system contained data related to the “targets of ATF investigations.”

TechCrunch has reported that the Qilin ransomware group has taken responsibility on its leak website, although there is no substantiated evidence, such as leaked data samples, to corroborate this assertion. Qilin employs a “ransomware-as-a-service” approach, offering its hacking tools to criminal partners in exchange for a portion of the profits. The group has also targeted prominent organizations, including the media company Lee Enterprises and the U.K.-based pathology lab Synnovis.

Federal law defines “major incidents” as substantial cyber events that could pose a threat to U.S. national security or interests. Agencies are required to notify Congress of such incidents within a week of their detection.

With this incident, the ATF joins the ranks of government agencies that have reported major incidents stemming from security breaches in recent years. This includes a ransomware attack on a system utilized by the U.S. Marshals Service in 2023 and a breach of an FBI system earlier this year that exposed the phone numbers of surveillance targets.