The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) yesterday announced an investigation into a “major” cybersecurity incident that the Qilin ransomware group claimed responsibility for. Given that is is Qilin, that’s all that needs to be said really.
Commenting on this is Paul Bischoff, Consumer Privacy Advocate at Comparitech:
“We recorded a significant uptick in the number of Qilin’s claims last month. Qilin claimed responsibility for the second-most data breaches out of all ransomware gangs in July, second only to the Gentlemen. Many of Qilin’s attack claims have proven credible. Most experts believe Qilin is based in Russia, which raises further questions about national security and what data was exposed.”
If you want to see more details on the Comparitech report that is being referred to, here you go: https://www.comparitech.com/news/ransomware-roundup-july-2026/
UPDATE: The ATF has since confirmed a breach of one standalone, isolated system that was quickly disconnected, and says its enterprise network, eForms system, and core mission functions were not affected. Qilin listed the ATF on its leak site on August 26 but hasn’t posted the screenshots or stolen documents it typically shares as proof, and the DOJ has designated it a “major incident,” which triggers mandatory federal reporting.
Adrian Culley, offensive security engineer at SafeBreach had this to say:
“ATF’s claim that the compromised system “operates separately from the ATF enterprise network” is the detail worth testing rather than accepting at face value. A genuinely standalone system with no route out has no way to hand data to Qilin’s leak site — so either that isolation has a gap nobody has mapped yet, or the segmentation held and what Qilin is holding is thinner than the leak posting implies. Both are worth knowing before this gets filed as contained.
Qilin’s tradecraft favours exploiting internet-facing systems for initial access (T1190) before attempting lateral movement (T1021) toward whatever segment holds value. That a federal law enforcement agency runs a system isolated enough to survive contact with its enterprise network is good practice. Whether that isolation has actually been tested against an actor trying to break out of it is a separate question, and the more important one.
Owning a segmentation boundary and knowing it holds under a live attack path are not the same claim. Before this incident is closed out, I am sure that the ATF’s own investigators will be running the same lateral-movement techniques Qilin favours against that boundary directly, rather than relying on logs that simply show no crossing occurred.
Related
This entry was posted on August 27, 2026 at 4:35 pm and is filed under Commentary with tags Comparitech. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
ATF investigating ‘major’ cybersecurity incident
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) yesterday announced an investigation into a “major” cybersecurity incident that the Qilin ransomware group claimed responsibility for. Given that is is Qilin, that’s all that needs to be said really.
Commenting on this is Paul Bischoff, Consumer Privacy Advocate at Comparitech:
“We recorded a significant uptick in the number of Qilin’s claims last month. Qilin claimed responsibility for the second-most data breaches out of all ransomware gangs in July, second only to the Gentlemen. Many of Qilin’s attack claims have proven credible. Most experts believe Qilin is based in Russia, which raises further questions about national security and what data was exposed.”
If you want to see more details on the Comparitech report that is being referred to, here you go: https://www.comparitech.com/news/ransomware-roundup-july-2026/
UPDATE: The ATF has since confirmed a breach of one standalone, isolated system that was quickly disconnected, and says its enterprise network, eForms system, and core mission functions were not affected. Qilin listed the ATF on its leak site on August 26 but hasn’t posted the screenshots or stolen documents it typically shares as proof, and the DOJ has designated it a “major incident,” which triggers mandatory federal reporting.
Adrian Culley, offensive security engineer at SafeBreach had this to say:
“ATF’s claim that the compromised system “operates separately from the ATF enterprise network” is the detail worth testing rather than accepting at face value. A genuinely standalone system with no route out has no way to hand data to Qilin’s leak site — so either that isolation has a gap nobody has mapped yet, or the segmentation held and what Qilin is holding is thinner than the leak posting implies. Both are worth knowing before this gets filed as contained.
Qilin’s tradecraft favours exploiting internet-facing systems for initial access (T1190) before attempting lateral movement (T1021) toward whatever segment holds value. That a federal law enforcement agency runs a system isolated enough to survive contact with its enterprise network is good practice. Whether that isolation has actually been tested against an actor trying to break out of it is a separate question, and the more important one.
Owning a segmentation boundary and knowing it holds under a live attack path are not the same claim. Before this incident is closed out, I am sure that the ATF’s own investigators will be running the same lateral-movement techniques Qilin favours against that boundary directly, rather than relying on logs that simply show no crossing occurred.
Share this:
Like this:
Related
This entry was posted on August 27, 2026 at 4:35 pm and is filed under Commentary with tags Comparitech. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.