The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed on Monday that a large‑scale cyber‑incident has resulted in the public release of files it says were stolen by a Russian‑speaking ransomware group. The leaked material appears to include information on targets of prior ATF investigations, phone‑communication analyses, and references to specific agents and high‑profile cases.
What was leaked
According to a review by CNN and independent cybersecurity researcher Ron Fabela, the dump contains data related to investigations of armed robbery, arson, explosives and homicide. A notable portion of the cases originates from the ATF’s Houston Field Division, suggesting the breach may have affected regional investigative work.
Agency response
ATF issued a statement saying it cannot yet confirm the authenticity, nature, or full scope of the leaked files. The bureau is working with the Department of Justice and other federal partners to assess the claims and take appropriate action. Importantly, ATF emphasized that the compromised system was isolated and did not affect any other operational systems, so the agency’s ability to carry out its mission remains unchanged.
Legal and security context
The agency originally disclosed the hack last week, noting that it met the threshold for a “major” cybersecurity incident under federal law—an incident that could potentially harm U.S. national security, foreign policy, or economic interests. Such a designation requires notification to Congress.
Who is behind the breach
The ransomware group known as Qilin, which has previously claimed responsibility for attacks on manufacturing, retail and healthcare sectors, began leaking the files from its dark‑web victim site on Monday. Cyber‑intelligence firm Cisco has labeled Qilin one of the most prolific and damaging ransomware threats worldwide. Another security firm, Halcyon, says it has “high confidence” that Qilin’s operators are Russian speakers.
Broader pattern of federal cyber threats
This incident follows other recent attacks on federal law‑enforcement entities. In 2023, the U.S. Marshals Service suffered a ransomware attack that exposed personal information of subjects under investigation. That same year, hackers breached a computer system used by the FBI’s New York field office for child‑exploitation investigations, including data tied to the Jeffrey Epstein case.
Looking ahead
Federal officials continue to urge agencies to strengthen cyber defenses and to share threat intelligence across departments. While the ATF assures the public that its core operations remain unaffected, the leak underscores the persistent risk posed by sophisticated ransomware groups targeting critical government infrastructure.
Original reporting: El Paso News (HLL/CB) — read the source article.