ATF Classifies Ransomware Attack on Investigative System as 'Major Incident'
The federal agency has initiated statutory notifications to Congress following a breach affecting a system that stored investigation target data.

Federal law enforcement officials at the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives have classified a recent cyberattack targeting one of its computer networks as a 'major incident.' The formal legal classification initiates mandatory reporting procedures requiring the bureau to brief members of Congress on the breach.
In a statement addressing the incident, an ATF spokesperson confirmed that the compromise affected a standalone computer system that remains isolated from the agency's primary network infrastructure. However, the targeted system held sensitive operational information, including details regarding targets of active ATF investigations.
The cybercrime syndicate known as Qilin posted a claim of responsibility for the intrusion on its dark web leak site, as first reported by TechCrunch. At the time of publication, the extortion group had not uploaded proof of data exfiltration or released sample files from the federal agency.
Qilin operates using a ransomware-as-a-service model, leasing its custom hacking tools and malware to criminal affiliates in exchange for a share of extortion payments. The syndicate's dark web registry of previous targets includes American publishing firm Lee Enterprises and British medical diagnostic provider Synnovis.
Under federal statute, government entities must classify a compromise as a major incident if it poses a threat of significant harm to American national security or core governmental interests. The designation legally requires the affected agency to inform congressional committees within seven days of identifying the intrusion.
The breach at the ATF adds to a series of major cyber incidents reported across federal law enforcement in recent years. The U.S. Marshals Service declared a major incident following a ransomware breach in 2023, while an intrusion into an FBI network earlier this year exposed phone numbers belonging to individuals under active federal surveillance.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.


