WASHINGTON (TNND) — The Bureau of Alcohol, Tobacco, Firearms and Explosives announced an investigation into a “major” cybersecurity incident that affected a standalone system.
The ATF said Wednesday that the “impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system.”
The bureau added that when the incident was discovered, it “immediately terminated connections to the affected environment and initiated incidentresponse and forensic activities.”
The ATF is working with the Justice Department on the investigation, which has designated the event as a “major incident.”
The Russia-linked Qilin ransomware group claimed the ATF as a victim, but the bureau did not confirm or mention that they were responsible, The Hill reported.
Qilin listed the ATF along with five other victims in the manufacturing and industrial sectors on its dark web site early Wednesday, according to Cybernews.
The cybersecurity incident investigation was announced the same day the DOJ said that it seized the hacking platforms QScan and QTRouter, which were operated by a state-run group employed by the Chinese-based firm Nanjing Xinjiuwei Network Technology Co.
The hacking platforms targeted the DOJ, NASA, Federal Reserve, Department of Energy, Senate, Department of Health and Human Services, and National Institutes of Health, according to a court affidavit.
“State-sponsored malicious hackers preying on America’s critical infrastructure will be stopped and prosecuted. We are here to ensure security for the American people and will use every tool we have to keep that promise,” Attorney General Todd Blanche said in a statement.
