ATF investigating 'major' cybersecurity incident involving Russian-linked ransomware group
When the security breach was discovered, the ATF said, the agency terminated connections to the affected environment and initiated incident‑response and forensic activities.
The Bureau of Alcohol, Tobacco, Firearms and Explosives on Wednesday announced an investigation into a "major" cybersecurity incident.
The ATF said the impacted system operates separately from the ATF enterprise network, the ATF eForms system, and other ATF systems.
When the security breach was discovered, the ATF said, the agency terminated connections to the affected environment and initiated incident‑response and forensic activities. The ATF is working with the Justice Department to investigate the matter.
The Russian-linked hacker group Qilin listed the ATF along with five other victims in the manufacturing and industrial sectors on its dark web leak site on Wednesday, The Hill reported. The ATF hasn't confirmed the group's involvement, nor did the agency say what data was stolen.
CyberNews reported that, if Qilin's claim is legitimate, the impact of stealing any amount of data from the ATF "could be enormous."