Skip to content
News

ATF Declares ‘Major Incident’ After Ransomware Attack

The ATF ransomware incident has escalated after the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives formally classified a cyberattack on one of its systems as a "major incident" under federal law. That designation carries legal weight, triggering a mandatory notification to lawmakers in...

ATF Declares 'Major Incident' After Ransomware Attack - ATF ransomware
The ATF ransomware incident has escalated after the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives formally classified a cyberattack on one of its systems as a "major incident" under federal law. That designati

The ATF ransomware incident has escalated after the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives formally classified a cyberattack on one of its systems as a “major incident” under federal law. That designation carries legal weight, triggering a mandatory notification to lawmakers in Congress.

According to a statement from the agency, the ATF is actively responding to the breach. The affected system was a stand-alone platform kept separate from the bureau’s broader network. An ATF spokesperson told reporters that the targeted computer held sensitive material, including information on the “targets of ATF investigations.”

Ransomware Gang Claims Responsibility

The Qilin ransomware group has claimed responsibility for the attack on its leak site. However, the gang has not published any proof to back up the claim, such as a sample of the allegedly stolen data.

Qilin operates on a ransomware-as-a-service model, leasing its hacking tools to criminal affiliates in exchange for a share of any profits. The group has previously listed high-profile victims, including media company Lee Enterprises and U.K. pathology lab operator Synnovis.

What a Major Incident Means Under Federal Law

Federal law defines a major incident as a significant cyber event likely to cause demonstrable harm to U.S. national security or wider American interests. Agencies that experience such an event are required to inform Congress within one week of discovering it.

The ATF is not alone among federal agencies in reaching this threshold in recent years. A 2023 ransomware attack hit a system used by the U.S. Marshals Service, prompting a similar declaration. Earlier this year, a breach of an FBI system exposed the phone numbers of individuals under surveillance by federal agents.

As of the latest statement, the ATF continues to respond to the breach of the stand-alone system, which remained isolated from the bureau’s main network.

Source
Image: techcrunch.com

The US tech briefing

Smartphones, AI, computing and deals — the essential stories without the noise.

Mailing provider can be connected when your US list is ready.

Shop Amazon Tech Deals Shop Amazon Tech Deals