A ransomware group claims it stole data from the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), potentially exposing sensitive information connected to federal criminal investigations.
Qilin, a Russian-speaking ransomware operation, claimed responsibility for the cyberattack and posted approximately 6.3 gigabytes of data to its dark web leak site after a 72-hour countdown expired. Cybernews reported that an initial review of the published material found files associated with investigations, mobile-device extractions, account information and digital forensic evidence.
ATF said it is aware of claims involving the publication of information obtained from a standalone system and is working with the Department of Justice and other federal partners to assess the claims and take appropriate actions.
ATF Identifies Compromised System
In an updated statement Monday, ATF identified the affected system as its Communications Assistance for Law Enforcement Act (CALEA) system. ATF uses the system in connection with the federal law, and it contains information related to ATF investigative matters.
The agency said the legacy, standalone system operated separately from its other operational systems.
“ATF’s ability to carry out its mission has not been impacted,” the agency said.
On August 26, ATF said the incident did not affect its enterprise network, eForms system or any other ATF system.
The agency has not publicly attributed the breach to Qilin.
Leaked Files Appear To Include Investigation Data
Cybernews reported that an initial review of the leaked files found directories associated with ATF field offices and individual investigations. Some directories were labeled “LAREDO Field Office” and “atf-houston.”
Cybernews said the material appears to include mobile-device extractions involving Apple iPhones and Samsung Galaxy phones, as well as SIM-card information, iCloud data and forensic dumps from Cellebrite software.
Law enforcement uses Cellebrite technology to extract and analyze information from mobile devices during investigations.
Cybernews also reported that the published files contain account identifiers, IP addresses, registration information and phone numbers. Researchers identified one directory labeled “ARMORED TRUCK ROBBERY SERIES 22-23.”
The leak may also reveal details about ATF’s technology environment, including endpoint-protection software, according to Cybernews.
ATF cautioned that it has not independently verified the material.
“ATF cannot confirm the authenticity, nature, or scope of the material at issue at this time,” the agency said.
Leak Could Expose Investigations And Sensitive Sources
Cybernews reported that the apparent leak could expose information beyond individual files because investigative records may identify suspects, witnesses, informants, evidence and law enforcement operations.
Security researcher John Bruggeman, vCISO at CBTS, told Cybernews that the primary concern is what investigative records could reveal about active cases and the people connected to them.
ATF investigations can involve firearms trafficking, illegal explosives, arson, organized crime and other serious offenses. Cybernews also reported that ATF works with approximately 1,400 local task force officers nationwide.
Bruggeman said the risk is what investigative data could reveal about open cases, targets and people tied to them.
Cybernews said its researchers were continuing to examine the leaked material to determine the full scope of the exposure.
ATF Says Core Systems Remain Operational
ATF said the incident did not affect its enterprise network, eForms system or other ATF systems. The bureau also said the incident did not affect its ability to carry out its mission.
Senior Justice Department officials designated the event a “major incident” under applicable federal guidelines, and ATF said officials completed the required notifications.
Bruggeman described ATF’s ability to identify and isolate the affected environment as an important part of its response. He also said the Justice Department’s major-incident designation suggested federal response procedures were established and probably practiced.
What the Leak Could Mean for People Connected to ATF Cases
The reported publication of investigative information could affect more than people directly targeted in ATF investigations. If ATF authenticates the material, its publication could increase privacy or security risks for witnesses, informants, law enforcement personnel and others named in investigative records.
ATF has not publicly confirmed which, if any, portions of the published material are authentic, leaving the extent of any exposure unclear.
Cybernews reported Tuesday that the dataset links no longer appeared on Qilin’s leak site. The files had been publicly accessible for most of Monday, and Cybernews said copies could have been downloaded or circulated during that period.
ATF said it cannot provide additional details while its review and investigation continue.
Click Here For The Original Source.
