< Back to all clusters
[TECHNOLOGY] · United States · 5 sources

started · updated

ATF cyberattack: Qilin ransomware group leaks stolen investigation data

The Russian-speaking ransomware group Qilin has released approximately 6.3GB of data it claims to have stolen during a cyberattack on the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). The data release followed a 72-hour countdown on the group's dark web extortion site.

According to reports, the leaked files include criminal investigation target names, phone numbers, IP addresses, and forensic data such as Cellebrite phone dumps and iCloud data. The information reportedly covers various cases, including armed robbery, arson, explosives, and homicide, with some files specifically linked to the ATF's Houston Field Division.

The ATF identified the compromised system as the CALEA system, which is used for wiretaps under the Communications Assistance for Law Enforcement Act. While the agency has not confirmed the authenticity or scope of the leaked material, it stated that the affected system was separate from its enterprise network and that its ability to carry out its mission has not been impacted. The ATF is currently working with the Department of Justice and other federal partners to assess the situation.

Entities

Bureau of Alcohol, Tobacco, Firearms and Explosives · Department of Justice · Qilin · Robert Cekada