A Russian-speaking ransomware group published a cache of files it says it stole from the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), the Justice Department agency that investigates gun trafficking, bombings, and arson. The trove appears to expose targets of past ATF investigations and forensic data pulled from their phones.
The group, known as Qilin, began releasing the files from its dark web extortion site on Monday after a 72-hour countdown expired. The initial dump runs to at least 6.3GB, according to Cybernews researchers who reviewed it.
🚨 BREAKING: Qilin has briefly published 6.3GB of data the ransomware group says it stole from the ATF, after a 72-hour countdown expired.
Files include Cellebrite extractions, dumps from an iPhone 6 and a Samsung Galaxy J3, and case folders naming investigation targets, phone… pic.twitter.com/B9K9Ni9Obk
— International Cyber Digest (@IntCyberDigest) August 31, 2026
ATF said it could not verify the material. The agency “cannot confirm the authenticity, nature, or scope” of the leaked data and is working with the Justice Department and other federal partners to assess the claims, ATF said in a statement Monday. It added that the affected system was not connected to its other operational networks and that its mission had not been affected.
The compromised system was ATF’s CALEA system, tied to the federal Communications Assistance for Law Enforcement Act, a 1994 law that requires telecom carriers to build wiretap access into their networks. That detail explains the phone records in the leak. A review of the files by CNN and independent cybersecurity researcher Ron Fabela found information on investigation targets and analyses of their phone communications.
The cases cover armed robbery, arson, explosives, and homicide, Fabela said. Many trace to ATF’s Houston Field Division, and directories carry labels including “LAREDO Field Office” and one marked “ARMORED TRUCK ROBBERY SERIES 22-23,” according to the Cybernews review.
The leak also names the tools ATF investigators used. Files identify extractions from Apple iPhones, Samsung Galaxy handsets, and SIM cards, along with data processed through Cellebrite, an Israeli-made forensics platform that pulls information off locked mobile devices.
Separate files expose part of ATF’s security stack, including Symantec Endpoint Protection version 14.3, giving attackers a map of the agency’s defenses.
ATF first disclosed the breach on August 26, the same day Qilin listed the agency. The Justice Department classified it a “major incident,” a designation under federal law that requires notifying Congress and generally applies when a breach could harm national security.
The exposure carries risk beyond the named targets. ATF investigations rely on witnesses, informants, and roughly 1,400 local task force officers, and leaked case data could reveal how open investigations are built.
The ATF breach extends a pattern inside the Justice Department. A 2023 ransomware attack on the U.S. Marshals Service exposed personal data on the subjects of its investigations. The same year, hackers breached an FBI New York field office system used to store images tied to child exploitation cases, including material from the Jeffrey Epstein investigation.
Qilin has operated since 2022 and ranks among the most active ransomware groups tracked this year, with more than 891 victims listed in 2026, according to Cybernews.
Researchers are still reviewing the ATF files to determine the full scope of what was exposed.
Click Here For The Original Source.
