The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has announced that a cyberattack on one of its systems has been classified as a “major incident.” This designation requires the agency to formally notify Congress.
In a statement, the ATF confirmed it is addressing the cyberattack, which targeted a standalone system separate from its main network. An ATF spokesperson reported to the media that the compromised system contained sensitive information, including details about “targets of ATF investigations.”
JS has identified a claim by the Qilin ransomware group on its leak site, though no evidence, such as leaked data samples, was provided. Known for its “ransomware-as-a-service” model, Qilin leases hacking tools to other criminals in exchange for a share of the profits. The group has previously listed major companies like Lee Enterprises and Synnovis, a U.K. pathology lab giant, among its targets.
According to federal law, “major incidents” encompass significant cyber events with the potential to harm U.S. national security or other key interests. Agencies are required to report such incidents to Congress within one week of discovery.
The ATF is the latest in a series of government agencies to declare major incidents following security breaches. This includes a 2023 ransomware attack on the U.S. Marshals Service system and a breach of an FBI system earlier this year, which exposed phone numbers of individuals under federal surveillance.Â

