Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Ransomware

ATF Confirms Cyber Incident After Ransomware Group Claims Attack

The Bureau of Alcohol, Tobacco, Firearms and Explosives has described it as a ‘major incident’ and it’s conducting an investigation with the DOJ.

Ransomware

The US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed suffering a cybersecurity incident after the Qilin ransomware group claimed to have targeted the agency.

In a statement on its website, ATF said the incident affected a standalone system, which was disconnected after the intrusion was discovered. 

“The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system,” ATF said, adding, “The incident has not impacted ATF’s ability to perform its missions.”

An investigation is being conducted in coordination with the Justice Department.

“Senior Department officials have designated the event a ‘major incident’ under applicable federal guidelines, and required notifications have been completed,” ATF noted.

Advertisement. Scroll to continue reading.

The Qilin ransomware group added ATF to its leak website on August 26, but it has not made any specific claims about the breach. 

The hackers often post screenshots to demonstrate that certain types of documents have been stolen from victims, but that has yet to happen in ATF’s case.

Qilin ransomware attack on ATF
Qilin ransomware attack on ATF

Qilin’s post also does not specify when any stolen files might be leaked; some victim announcements include a timer indicating when files will be published.

Active since at least 2022 — initially under the name Agenda — Qilin operates on a double-extortion model, encrypting files and exfiltrating sensitive information from victims’ systems.

Qilin made headlines recently after it exploited a Check Point VPN zero-day vulnerability in its attacks. 

The cybercrime group has listed more than 2,000 victims on its leak website to date, and the actual number is likely much higher, given that many pay a ransom and are not named.

Related: Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign

Related: Sensitive Information Exposed in Nutex Health Data Breach

Related: ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Social engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.

Naveen Bhateja has been appointed Chief People Officer at HackerOne.

The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.