The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has declared a cyberattack on one of its systems a 'major incident', a legally defined classification that mandates a formal notification to lawmakers in Congress. The targeted computer system contained sensitive information related to ATF investigations. TechCrunch reports that a ransomware gang, Qilin, has claimed responsibility for the breach, though no evidence has been provided to back up the claim.
Qilin is known for its 'ransomware-as-a-service' operation, where it leases its hacking tools to other criminal affiliates for a cut of the profits. The gang has previously targeted major media and healthcare organisations. This latest incident has prompted the ATF to join a growing list of government agencies that have declared major incidents following breaches, including the U.S. Marshals Service and the FBI.
Under federal law, 'major incidents' are defined as significant cyber incidents that are likely to cause demonstrable harm to U.S. national security or broader U.S. interests. Agencies are required to disclose such incidents to Congress within a week of their discovery.
The incident highlights the ongoing threat of cybercrime and the importance of robust cybersecurity measures. As the digital landscape evolves, so too do the challenges faced by government agencies in protecting sensitive information.







