EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/ransomware-attack/2026-atf-qilin-ransomware
010/430

File EL-0421CriticalOngoingRansomware Attack / Government Data Theft

ATF Ransomware Attack

Also filed as ATF Major Incident · Qilin ATF Hack

A standalone ATF system holding information on targets of ATF investigations was breached. The Justice Department declared a "major incident" and the Qilin ransomware gang claimed responsibility.

  • #government
  • #law-enforcement
  • #atf
  • #qilin
  • #major-incident
  • #united-states
Notoriety9/10
Event
26 Aug 2026
Disclosed
26 Aug 2026
Target
Bureau of Alcohol, Tobacco, Firearms and Explosives
Actor
Qilin (claimed)
Status
Ongoing

01Summary

ATF confirmed the breach on 26 August 2026 and notified Congress on 27 August after senior Justice Department officials designated it a "major incident". The affected system held information on targets of ATF investigations. ATF says it was not connected to case management, laboratory or eForms systems, and was shut down when the breach was found. The Russian-speaking Qilin gang claimed the attack. Cybernews later reported that Qilin had leaked files it said exposed ATF criminal investigations.

02Threat actor

Qilin is a Russian-speaking ransomware-as-a-service operation active since 2022, with hundreds of victims in more than 60 countries.

03Victims and impact

Countries affected

  • United States

04Data exposed

Data types

  • Information on investigation targets

05Timeline

  1. 2026-08-26ATF confirms the breach.
  2. 2026-08-27Congress notified of a "major incident".

06On the record

The standalone system was not connected to any other ATF systems, including any case management systems, laboratory systems, or eForms systems, and it was quickly shut down when the breach was discovered.

Tanya Roman (ATF Public Affairs Chief), Statement to CyberScoop

07Reaction and fallout

Political impact

Mandatory congressional notification under the "major incident" rules.

08Significance and legacy

Significance

Exposure of federal investigation targets to a criminal gang.

09Disclosure and media

Publishing organisations

  • TechCrunch
  • CyberScoop
  • Cybernews
  • SecurityWeek

10Related files

Related events

  • 2026-shinyhunters-fbijobs-breach-claim

11Sources

References

  1. [1]TechCrunch: https://techcrunch.com/2026/08/27/atf-declares-major-incident-as-ransomware-gang-claims-hack/
  2. [2]CyberScoop: https://cyberscoop.com/atf-doj-cyberattack-qilin-ransomware/
  3. [3]Cybernews: https://cybernews.com/cybercrime/atf-qilin-ransomware-cyberattack-data-leak-investigations/
Fact sheetEL-0421

Dates

Event
26 Aug 2026
Disclosed
26 Aug 2026
Ongoing
Yes

Target

Organisation
US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF)
Type
Federal Law Enforcement Agency
Sector
Government / Law Enforcement
Country
United States
Gov. level
Federal

Actor

Name
Qilin (claimed)
Type
Ransomware Gang
Motivation
Extortion
Attribution
Medium
Arrested
No
Convicted
No

Data

Sensitivity
Highly Sensitive
Published
Yes

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.