Press play to start listening
The US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a cyber incident affecting one of its standalone systems. The Qilin ransomware group separately claimed responsibility for the breach.
Qilin ransomware listed ATF on its dark web site on August 26 and added a 72-hour publication countdown two days later. After the countdown expired on August 31, the group published links to at least 6.3 GB of files it claimed were stolen from the agency.
As seen by Hackread.com, on September 1, the links had been removed after remaining accessible for most of Monday. ATF has not attributed the breach to Qilin and says it cannot confirm the authenticity, nature, or extent of the published material.
“ATF immediately terminated connections to the affected environment and initiated incident-response and forensic activities,” the agency said, adding that it was investigating with the Justice Department.
Exposed Investigative Data and Forensic Details
A review of the published files found material connected to ATF investigations involving armed robbery, arson, homicide and explosives. A separate analysis identified directories labelled “LAREDO Field Office,” “atf-houston” and “ARMORED TRUCK ROBBERY SERIES 22-23.”
The dump also appears to contain digital forensic evidence, including phone and device extractions, SIM card data, Apple iPhone and Samsung Galaxy records, iCloud data, Cellebrite phone dumps, account identifiers and XML files.
The files also reveal the ATF’s use of Cellebrite, a digital forensics platform used to extract and analyze data from mobile devices. The material also referenced Symantec Endpoint Protection version 14.3, although it is unclear whether that version was still deployed when the breach occurred.
Attack and System Impact
In its August 31 update, ATF identified the affected environment as a legacy, standalone CALEA system used in connection with the federal Communications Assistance for Law Enforcement Act. Tanya J. Roman, chief of ATF’s Public Affairs Division, separately said the system contained information about targets of ATF investigations.
The agency said it terminated connections to the affected environment after discovering the incident and that there was no indication the breach affected its enterprise network, eForms system or other ATF systems. ATF also said its ability to carry out its mission was not affected. The Department of Justice is assisting with the investigation, and senior DOJ officials designated the incident a “major incident” under federal guidelines.
Qilin’s Recent Activity
Qilin has operated since at least 2022, initially under the name Agenda, and uses a double-extortion model that combines data theft with file encryption. Hackread.com previously reported on the group’s 2024 attack on NHS pathology provider Synnovis, where Qilin claimed to have stolen 400GB of hospital and patient data. In 2025, Qilin claimed a 4TB data breach at Nissan’s Creative Box subsidiary, including design and other internal files.
The ATF incident is another breach involving US law enforcement data, following the 2023 ransomware attack on the US Marshals Service and a breach of an FBI New York field office system linked to the Jeffrey Epstein investigation. In the ATF case, the files Qilin claims to have stolen include information from criminal investigations, which could expose witnesses, informants, and people connected to those cases.
