The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed on Monday that a large‑scale cyber incident has resulted in the public release of files it says were stolen by a Russian‑speaking ransomware group. The leaked material appears to contain information on targets of prior ATF investigations, including phone‑communication analyses and case details related to armed robbery, arson, explosives and homicide.
According to a review by CNN and independent cybersecurity researcher Ron Fabela, some of the documents reference specific ATF agents and high‑profile cases handled by the agency’s Houston Field Division. The data also include investigative files that the ATF says were part of a “major” cybersecurity incident, a designation that triggers mandatory notification to Congress because of potential impacts on national security, foreign policy, or economic interests.
Agency response
In a statement, ATF officials said they cannot yet confirm the authenticity, nature, or full scope of the leaked data. The bureau is working with the Department of Justice and other federal partners to assess the claims and take appropriate action. ATF emphasized that the compromised system was isolated and that the breach did not affect any other operational systems, assuring the public that the agency’s ability to carry out its mission remains intact.
Ransomware group claims responsibility
The group known as Qilin, which has previously claimed responsibility for ransomware attacks on manufacturing, retail and health‑care organizations, posted the files on its dark‑web victim site on Monday. Cyber‑intelligence firm Cisco has labeled Qilin as one of the most prolific and damaging ransomware threats worldwide. Another cybersecurity firm, Halcyon, indicated it has “high confidence” that the actors behind Qilin are Russian speakers.
Context of federal cyber threats
This breach follows a series of high‑profile cyber incidents targeting federal law‑enforcement agencies. In 2023, the U.S. Marshals Service suffered a ransomware attack that exposed personal information of subjects under investigation. That same year, hackers infiltrated a computer system used by the FBI’s New York field office for child‑exploitation investigations, including files related to the Jeffrey Epstein case.
Federal officials continue to warn that ransomware groups pose a significant threat to national security and law‑enforcement operations. The ATF’s prompt notification to Congress and ongoing coordination with the Justice Department illustrate the administration’s commitment to safeguarding critical investigative data and maintaining the integrity of federal agencies.
Original reporting: KEYT (Ventura/Santa Barbara) — read the source article.