US firearms agency ATF confirms 'major incident' as Qilin ransomware gang lists it as a victim

The Bureau of Alcohol, Tobacco, Firearms and Explosives says a standalone system was breached. The Qilin ransomware crew added ATF to its dark web leak site the same day.

ThreatVectr Newsdesk· 4 min read
A dim server room bathed in cold blue light, rows of rack-mounted servers with faint red status LEDs, one open cabinet showing tangled fibre cables, shallow dep
Share

Key points

  • The US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed on Wednesday that one of its systems was broken into, calling it a "major incident".
  • The Qilin ransomware gang, a criminal group that locks victims' files and demands payment, added ATF to its dark web leak site the same day.
  • ATF says the affected system runs separately from its main network and its eForms system for firearms paperwork was not touched.
  • Qilin has claimed more than 2,200 victims since it appeared in August 2022, including Nissan, Asahi and UK pathology firm Synnovis.
  • The US Department of Justice is investigating alongside ATF.

The US Bureau of Alcohol, Tobacco, Firearms and Explosives, the federal agency that polices gun and explosives laws, has confirmed one of its systems was broken into. It described the intrusion as a "major incident" in a public notice this week.

The confirmation came the same day the Qilin ransomware group added ATF to its dark web leak portal, where criminals name victims to pressure them into paying. Qilin did not say what, if anything, it stole. It also did not publicly state a ransom demand.

What actually happened?

Attackers got into a single ATF system that sits apart from the agency's main network. ATF says it cut the connection to that system as soon as staff spotted the problem and called in forensic investigators. The Department of Justice is now helping run the inquiry.

"The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system," the agency said in its statement. The eForms system is the online portal Americans use to file firearms paperwork, so its status matters to dealers and buyers.

ATF says day-to-day operations were not disrupted. The agency has asked anyone with information about the attack to contact its official tipline. Questions sent to an ATF spokesperson, first reported by BleepingComputer, had not been answered at time of writing.

Who is Qilin?

Qilin is a ransomware-as-a-service operation, meaning the core gang builds the file-locking malware and rents it out to other criminals who split any ransom paid. Researchers first spotted the group in August 2022 under the name "Agenda".

The crew has become one of the busiest extortion outfits online. Its leak site lists more than 2,200 named victims to date.

Notable Qilin victims Sector
Nissan Automotive
Yangfeng Auto parts
Synnovis UK pathology
Asahi Japanese beverages
Lee Enterprises US publishing
Court Services Victoria Australian courts

Should the public be worried?

Probably not directly, based on what ATF has said so far. The agency insists the eForms system and its main network are untouched, so background checks and firearms paperwork should keep working normally. If that changes, expect dealers to hear about it first.

What is still unknown is whether Qilin walked out with sensitive files from the standalone system, and if so, what kind. Investigators typically take weeks to work that out. Anyone whose data might sit on ATF systems (licensed dealers, informants, applicants) should watch for unusual mail or phishing attempts, where criminals send fake messages trying to trick people into handing over passwords or money.

A pattern at US federal agencies

ATF is the third US federal body to disclose a breach this year. In March, the Federal Bureau of Investigation confirmed an intrusion affecting systems tied to wiretap and surveillance warrants. In July, the Department of Homeland Security said attackers hit the Homeland Security Information Network, a platform used to share sensitive tips with state and local partners.

Three serious federal incidents in nine months suggests attackers are finding gaps at the edges of government networks, in the smaller systems that get less attention than the crown jewels. Qilin's claim, if it holds up, fits that pattern neatly.

© 2026 Threat Vectr