ATF probes cyber incident in isolated system
ATF said an isolated system was affected and reported no signs of impact to eForms, its corporate network or other systems.
ATF confirmed it is investigating a cyber incident in a standalone system separate from its enterprise network. The agency said it sees no signs of impact on its corporate network, eForms or other systems, and cut connections to the affected environment while response and forensic work continue.
ATF confirmed it is investigating a cyber incident that affected a standalone system separate from its enterprise network. The agency said there are no signs of impact on its corporate network, eForms, or other systems, and that it has already cut connections to the affected environment while incident response and forensic analysis continue.
What did ATF say about the scope of the incident?
ATF said the event was contained to an isolated system and, so far, it has found no signs of compromise in its enterprise network or in eForms. It also said there are no indications that other agency systems were affected.
The agency added that it has already separated the compromised environment from the rest of its infrastructure. According to its statement, the remaining work includes incident response and forensic analysis.
What does the "major incident" classification mean?
The "major incident" designation triggers a formal notification to members of Congress, according to TechCrunch. ATF also said it has already completed the notifications required under that classification.
Nextgov reported that, despite the label, the agency said the incident did not disrupt operations or affect its ability to carry out law enforcement and regulatory missions. ATF did not explain what factors led the Justice Department to classify the event that way.
What is known about Qilin and attribution?
TechCrunch reported that it saw a claim of responsibility from the ransomware group Qilin on its leak site, but found no public evidence of the hack. Nextgov added that ATF did not publicly confirm whether ransomware was used or formally attribute the case to Qilin.
The agency also did not say whether data was stolen. According to Nextgov, it did not publicly identify which system was affected or when the incident was discovered, and it has not said whether intruders accessed or took information.
Nextgov described Qilin as a ransomware-as-a-service group that typically steals data and threatens to publish it to pressure victims. In this case, ATF did not confirm that tactics or say the intrusion involved exfiltration.
What is known about the affected system?
Nextgov said eForms allows the firearms industry and the public to submit requests related to weapons regulated by the National Firearms Act, including suppressors, short-barreled rifles and machine guns. ATF, however, said that system was not affected.
A syndicated report from KATU/7News, citing The Hill and Cybernews, said Qilin listed ATF alongside five other manufacturing and industrial victims on its dark web site. Even so, the agency did not publicly acknowledge Qilin as the culprit.
The same report added that the investigation announcement came alongside another Justice Department operation in which the QScan and QTRouter hacking platforms, linked to a Chinese state group, were seized, amid simultaneous pressure on multiple threat actors.
Tactical Shit, citing statements from spokespeople and internal sources, said the compromised isolated system contained information on ATF investigation targets, but not NFA records or the licensing stack used by eForms.
Sources
- ATF declares 'major incident' as ransomware gang claims hacktechcrunch.com· TechCrunch
- ATF sufre vulneración de un sistema y abre investigación por posible ciberataque rusolaopinion.com· La Opinión
- US ATF confirms 'critical' cyber incident following Qilin dark web claimscyberdaily.au· Cyber Daily
- ATF investigating 'major' cyber incident after ransomware group claimnextgov.com· Nextgov
- ATF announces investigation into 'major' cybersecurity incidentkatu.com· KATU / 7News (contenido sindicado)
- The ATF Hack, Explained - Major Breach After Qilin Puts the Agency on its Leak Sitetacticalshit.com· Tactical Shit



