Skip to content

Thursday, August 27, 2026

Gigantum.net
Software & security

ATF declares ‘major incident’ as ransomware gang claims hack

The ATF is the latest federal government agency in recent years to notify Congress of a "major incident" involving its cybersecurity.

· 246 words· updated August 27, 2026 at 02:57 PM

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives, or ATF, says a cyberattack on one of its systems has been declared a “major incident,” a formal, legally defined classification that prompts a formal notification to lawmakers in Congress.

ATF said in a statement that it’s responding to the cyberattack on a stand-alone system that’s separate from the bureau’s network. An ATF spokesperson told reporters that the targeted computer system contained information such as the “targets of ATF investigations.”

TechCrunch has seen a claim of responsibility by the Qilin ransomware gang on its leak site, but it did not provide evidence for its claim, such as a sample of leaked data. Qilin is known for running a “ransomware-as-a-service” operation, in which it leases its hacking tools to other criminal affiliates for a cut of the profits. The gang has listed media giant Lee Enterprises and U.K. pathology lab giant Synnovis as targets.

Under federal law, “major incidents” include significant cyber incidents that are likely to cause demonstrable harm to U.S. national security or broader U.S. interests. Agencies are requi r ed to disclose major incidents to Congress within a week of their discovery.

The ATF joins several government agencies in recent years that have declared major incidents following a breach, including a 2023 ransomware attack on a system used by the U.S. Marshals Service , and a breach of an FBI system earlier this year that exposed phone numbers of targets under surveillance by federal agents.

Gathered from external sources. Rights to this text belong to whoever originally published it.