U.S. ATF Confirms Cyberattack May Have Exposed Investigative Data; Ransomware Group “Qilin” Claims Responsibility — BigGo Finance | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) announced on the 27th that it had confirmed a breach by a ransomware hacking group into a standalone system that stored information related to the agency’s investigative targets. The U.S. Department of Justice has designated the matter as a “major incident” under federal guidelines and is conducting a joint investigation.

According to the ATF’s statement, the affected system was a standalone unit separated from the corporate network, and it was immediately disconnected upon detection of the intrusion. No impact has been confirmed on the agency’s core network or other systems such as “eForms,” the electronic firearms application system. The agency said there has been no disruption to normal operations.

The “major incident” designation applies to matters that could potentially harm national security or civil liberties, and triggers a mandatory reporting obligation to Congress. ATF systems may contain highly sensitive law enforcement data, including details of ongoing investigations, making the scale and content of any information leak a key focus.

Meanwhile, Qilin, a ransomware group believed to be based in Russia or comprised of Russian-speaking actors, posted ATF on its leak site on the 26th, claiming involvement in the breach. However, the group has not provided the contents or volume of the stolen data, nor any samples to substantiate its claim. The ATF also did not reference specifics about the hacking group in its statement.

Qilin is known for attacking Synnovis, a major British pathology services provider, in 2024, disrupting services across the UK’s National Health Service (NHS). According to data compiled by eCrime.ch, a cybercrime investigation and tracking platform, the group has executed approximately 2,400 attacks across more than 100 countries since its emergence in October 2022.

According to Comparitech, a company specializing in cybersecurity product reviews and data analysis, 799 ransomware incidents were confirmed in July, up from 668 in June. Qilin claimed responsibility for 125 of these, making it one of the most active groups.

Ransomware attacks targeting law enforcement agencies can lead to the exposure of investigative techniques and confidential informant information, carrying more severe consequences than attacks on ordinary businesses. The ATF is responsible for regulating firearms transactions and investigating explosives-related cases, and if classified information were to leak, the safety of active investigators and informants could be threatened.

The U.S. Department of Justice has in recent years strengthened its response to cyberattacks targeting government agencies, establishing an investigative framework in coordination with the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA). In this case as well, identifying the intrusion vector and determining the scope of the damage are urgent priorities.

——————————————————–


Click Here For The Original Source.

.........................