The Department of Justice and the Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a cybersecurity breach of an agency system, following dark web claims made by the Russian-linked ransomware syndicate Qilin, according to a report from CyberNews.
ATF officials released a statement on August 26, 2026, confirming that an isolated system had been breached. The agency said it immediately severed access to the impacted environment and launched incident response and forensic procedures.
Senior Justice Department officials have officially classified the breach as a “major incident” under federal guidelines, prompting direct DOJ involvement in the investigation.
Federal authorities have not disclosed when the breach occurred, how the network was penetrated, or whether any data was successfully exfiltrated by the hackers.
“This is an ongoing investigation, and no further details can be shared at this time,” the ATF said in a statement. In a separate release on its website, the bureau stressed that the affected environment functions separately from its main enterprise network and that “ATF’s ability to perform its missions has not been impacted”. The bureau has asked anyone with information to contact its tipline at 1-888-ATF-TIPS.
The agency’s acknowledgment came hours after Qilin added the ATF to its dark web leak site early Wednesday morning alongside five other targets, primarily from the industrial and manufacturing sectors. While Qilin posted sample files to substantiate claims against three other victims—WireCo, Metal Conversions, and Air International Thermal Systems—its listing for the ATF contained no proof files, timestamps, or data size estimates.
The potential compromise of ATF systems has drawn scrutiny from gun rights advocacy groups over the safety of federal firearms records. Gun Owners of America first highlighted the leak claim on social media, noting the agency’s extensive records on firearms and owners.
The ATF holds at least 866 million digitized records from closed federally licensed firearms dealers, a repository Second Amendment groups have long argued functions as a backdoor gun registry.
Beyond firearms licensing and regulatory registries, the ATF employs roughly 2,400 Special Agents and 700 Investigators who launch between 25,000 and 38,000 criminal investigations annually.
These cases target illegal firearms traffickers, violent gangs, illicit weapons manufacturers, bomb makers, and arsonists. Cybersecurity analysts have noted that any compromised investigative files could potentially endanger active operations, informants, and law enforcement witnesses.
The incident follows a pattern of recent cyber intrusions across federal law enforcement and government infrastructure. In March, the FBI disclosed that hackers linked to China infiltrated a network handling wiretaps and surveillance warrants.
In July, the Department of Homeland Security opened an inquiry into a breach of the Homeland Security Information Network, and an earlier breach at FEMA exposed employee information. On Wednesday, the DOJ also announced the seizure of domains run by the Chinese state-sponsored group QTFY, which targeted agencies including NASA, the Department of Energy, and the U.S. Senate.
The Russian-linked Qilin group, first detected in 2022, operates on a double-extortion ransomware model. The gang has claimed roughly 1,900 victims over the past 18 months, including over 891 targets so far this year such as Sysco Corporation, Cushman & Wakefield, and the Shipping Association of New York & New Jersey.
Federal investigators continue their forensic review into the extent of the ATF system breach.
READ: Tropical System Could Form Today In Atlantic Before Facing Hostile Conditions
Please make a small donation to the Tampa Free Press to help sustain independent journalism. Your contribution enables us to continue delivering high-quality, local, and national news coverage.
Sign up: Subscribe to our free newsletter for a curated selection of top stories delivered straight to your inbox.

