Government security

ATF investigating cybersecurity incident designated a major incident

Plain code with the word "cyberattack" in red.

The Bureau of Alcohol, Tobacco, Firearms and Explosives is investigating a cybersecurity event affecting one of its systems, which Justice Department officials have designated a “major incident” under federal guidelines. The disclosure came after the ransomware group Qilin listed ATF on its dark-web leak site and claimed to have compromised the agency, as reported by Nextgov.

The ATF has not attributed the incident to Qilin or confirmed if ransomware was involved. The affected system operates separately from the bureau's main computer network, and officials stated there is no indication it spread to other ATF systems, including the electronic firearms application platform known as eForms.

The "major incident" designation, likely under FISMA, signifies potential significant harm and triggers reporting requirements to Congress. Qilin, a ransomware-as-a-service operation, typically steals data before demanding ransom. This incident follows other recent breaches of sensitive federal law enforcement systems, including those at the Department of Homeland Security and the FBI.

Source: Nextgov

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds