news.mlab.sh
Back to the feed
threat-intel

ATF Confirms Cyber Incident After Ransomware Group Claims Attack

Medium
Summary

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) suffered a cybersecurity incident, confirmed by the agency itself, and attributed to the Qilin ransomware group. While the incident didn't impact the agency's core systems, it led to a ‘major incident’ designation and an ongoing investigation. The Qilin group, known for double-extortion tactics and exploiting zero-day vulnerabilities, has added ATF to its leak site, though specific details about stolen data remain unclear.

The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a cybersecurity incident, with the agency stating that the event was linked to the Qilin ransomware group. The incident affected a standalone system, operating independently of the ATF enterprise network and the ATF eForms system. According to the ATF’s statement on its website, the agency disconnected the impacted system after discovering the intrusion.

“The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system,” ATF stated. “The incident has not impacted ATF’s ability to perform its missions.”

The Qilin ransomware group announced on August 26th that it had targeted ATF, adding the agency to its leak website. The group, which has been active since at least 2022 and initially operated under the name Agenda, employs a double-extortion model, encrypting files and exfiltrating sensitive data.

Qilin has previously exploited a Check Point VPN zero-day vulnerability in its attacks. The group has listed over 2,000 victims on its leak site, and the actual number is likely significantly higher, as many victims pay a ransom and are not publicly named.

Related: Cl0p Ransomware Group Names Over 40 Victims of PTC Windchill Campaign

Related: Sensitive Information Exposed in Nutex Health Data Breach

Related: ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited

Read the full article at SecurityWeek