ATF Declares 'Major Incident' as Ransomware Gang Claims Responsibility for Cyberattack

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has classified a cyberattack on one of its systems as a "major incident," a formal legal designation that triggers a mandatory notification to Congress. The bureau said in a statement that it is responding to the attack, which targeted a standalone system separate from its main network. An ATF spokesperson told reporters that the compromised system contained sensitive information, including the "targets of ATF investigations." TechCrunch has observed a claim of responsibility posted by the Qilin ransomware gang on its leak site, though the group has not provided evidence, such as a sample of stolen data. Qilin operates a "ransomware-as-a-service" model, leasing its hacking tools to affiliates in exchange for a share of any profits. The gang has previously claimed attacks on media giant Lee Enterprises and U.K. pathology lab Synnovis. Under federal law, a "major incident" is defined as a significant cyber event likely to cause demonstrable harm to U.S. national security or broader national interests. Federal agencies are required to disclose such incidents to Congress within seven days of discovery. The ATF's declaration adds to a growing list of U.S. government agencies that have experienced major cyber incidents in recent years. Notable examples include a 2023 ransomware attack on the U.S. Marshals Service and a breach of an FBI system earlier this year that exposed phone numbers of surveillance targets. In 2026, federal agencies continue to face escalating cyber threats, prompting increased scrutiny and calls for stronger cybersecurity measures across the government.

via TechCrunch

Related