Bureau of Alcohol Tobacco and Firearms
Credit: ajay_suresh / Wikimedia Commons

DOJ firearms agency says hackers breached system containing investigation targets

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirmed that it recently experienced a cyberattack, calling the breach a “major incident.” 

The agency, housed within the Department of Justice, appeared on the leak site of the Qilin ransomware gang on Wednesday. 

An ATF spokesperson told Recorded Future News the issue “involved a standalone computer system containing information about targets of ATF investigations.” 

“The standalone system was not connected to any other ATF systems, including any case management systems, laboratory systems, or eForms systems, and it was quickly shut down when the breach was discovered,” the spokesperson said. “This is an ongoing investigation, and no further details can be shared at this time.”

The agency later released a public statement on Wednesday evening reiterating that the attack had no impact on any other internal system. 

ATF officials “immediately terminated connections to the affected environment and initiated incident‑response and forensic activities,” they said. 

The attack did not impact ATF’s “ability to perform its missions,” the statement added, though senior officials have designated it a “major incident” based on federal guidelines. The Justice Department is investigating the cyberattack. 

The cyber incident is the latest to impact the Justice Department after multiple incidents involving the U.S. Marshals Service and the FBI. The Justice Department itself suffered a breach of the federal courts docketing system in early 2020.

In a post on its leak site, the Qilin ransomware gang did not provide any samples of stolen data, only adding the ATF’s name to the site. 

Qilin was one of the most active ransomware operations in 2025, targeting Kuala Lumpur International Airport, Japanese beverage giant Asahi, the Texas city of Sugar Land, a county government in North Carolina and multiple power companies in Texas.

The group faced increased law enforcement scrutiny in 2024 after a devastating attack on a British healthcare company that prompted major disruptions to medical services. 

But it quickly returned with attacks on the government of Palau and one of the largest newspaper chains in the United States.

The group has continued to launch damaging attacks in 2026, with researchers saying it was the second most active ransomware gang in July with 127 reported attacks. Earlier this month, French rugby club Stade Français Paris confirmed it had been attacked after being added to Qilin’s leak site. 

Recorded Future
No previous article
No new articles
Jonathan Greig

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.