The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has declared a “major incident” following a cyberattack on one of its systems, with the Qilin ransomware gang claiming responsibility. The declaration, reported on August 27, 2026, triggers a formal legal requirement to notify Congress within a week of the incident’s discovery.
According to an ATF statement, the attack targeted a standalone computer system separate from the bureau’s main network. An ATF spokesperson confirmed the compromised system contained sensitive information, including data on “targets of ATF investigations.”
The Qilin ransomware gang posted a claim of responsibility on its leak site, though it did not provide supporting evidence such as a sample of stolen data. Qilin operates a “ransomware-as-a-service” model, leasing its hacking tools to criminal affiliates in exchange for a share of the profits. The gang has previously listed media company Lee Enterprises and U.K. pathology provider Synnovis among its targets.
Under federal law, a “major incident” designation applies to significant cyber incidents likely to cause demonstrable harm to U.S. national security or broader U.S. interests. Affected agencies must disclose such incidents to Congress within seven days of discovery.
The ATF is not the first federal agency to reach this threshold in recent years. A 2023 ransomware attack struck a system used by the U.S. Marshals Service, and earlier in 2026 a breach of an FBI system exposed phone numbers of individuals under federal surveillance. The pattern of major incident declarations across multiple agencies suggests ongoing vulnerability within federal government cybersecurity infrastructure.
Source: TechCrunch