Image credit: Bureau of Alcohol, Tobacco, Firearms and Explosives
On Monday, the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed that a ransomware gang broke into one of its computer systems and published stolen files, including material from open criminal investigations. The Qilin ransomware group, a Russian-speaking operation, claimed the attack and posted roughly 6.3GB of data to its dark web leak site after ATF missed a 72-hour ransom deadline.
The leaked files reportedly include case files, mobile device extractions pulled from iPhones and Samsung Galaxy phones, and forensic data dumps generated by Cellebrite, the tool law enforcement uses to crack open phones during investigations. One of the named cases is an armored truck robbery series worked out of ATF’s Houston and Laredo field offices. Security researcher John Bruggeman told Cybernews that the danger with investigative data isn’t the records themselves so much as what they reveal about open cases and the people connected to them, potentially exposing informants, witnesses, and details of the roughly 1,400 local task force officers who work ATF cases nationwide.
Previously, the ATF said the breach hit a legacy, standalone system tied to its CALEA function, the Communications Assistance for Law Enforcement Act infrastructure federal agencies use to support lawful wiretaps and other communications surveillance. The agency said that system was never connected to its other operational networks, including the eForms system agents and firearms dealers use for licensing and reporting. ATF said its ability to carry out its mission hasn’t been affected. However, it designated the incident as a major incident under federal reporting guidelines, a classification that requires notifying Congress.
As for the data that was leaked today, the agency says it “cannot confirm the authenticity, nature, or scope of the material at issue,” and is working with the Justice Department and other federal partners to sort out what’s real.
If you’ve had any contact with an ATF investigation, whether as a witness, a licensed dealer, or someone whose device was seized as evidence, treat this the same way you would any government data breach: watch for unexpected contact claiming to be from the ATF or federal investigators, and don’t hand over personal information to anyone who reaches out without clear confirmation of their identity.
Read next: China spied on the US Senate and NASA for years, FBI says
