01Summary
ATF confirmed the breach on 26 August 2026 and notified Congress on 27 August after senior Justice Department officials designated it a "major incident". The affected system held information on targets of ATF investigations. ATF says it was not connected to case management, laboratory or eForms systems, and was shut down when the breach was found. The Russian-speaking Qilin gang claimed the attack. Cybernews later reported that Qilin had leaked files it said exposed ATF criminal investigations.
02Threat actor
Qilin is a Russian-speaking ransomware-as-a-service operation active since 2022, with hundreds of victims in more than 60 countries.
03Victims and impact
Countries affected
- United States
04Data exposed
Data types
- Information on investigation targets
05Timeline
- 2026-08-26ATF confirms the breach.
- 2026-08-27Congress notified of a "major incident".
06On the record
The standalone system was not connected to any other ATF systems, including any case management systems, laboratory systems, or eForms systems, and it was quickly shut down when the breach was discovered.
07Reaction and fallout
Political impact
Mandatory congressional notification under the "major incident" rules.
08Significance and legacy
Significance
Exposure of federal investigation targets to a criminal gang.
09Disclosure and media
Publishing organisations
- TechCrunch
- CyberScoop
- Cybernews
- SecurityWeek
11Sources
References
- [1]TechCrunch: https://techcrunch.com/2026/08/27/atf-declares-major-incident-as-ransomware-gang-claims-hack/
- [2]CyberScoop: https://cyberscoop.com/atf-doj-cyberattack-qilin-ransomware/
- [3]Cybernews: https://cybernews.com/cybercrime/atf-qilin-ransomware-cyberattack-data-leak-investigations/









