ATF investigating ‘major’ cyber incident after ransomware group claim

Kevin Carter/Getty Images

The agency says the affected system was isolated from its broader network and eForms platform but has not disclosed whether data was stolen.

The Bureau of Alcohol, Tobacco, Firearms and Explosives is investigating a cybersecurity event affecting one of its systems, which Justice Department officials have designated a “major incident” under federal guidelines.

The disclosure came after the ransomware group Qilin listed ATF on its dark-web leak site and claimed to have compromised the agency. ATF has not attributed the incident to Qilin or said whether ransomware was involved.

The bureau, housed within the Justice Department, said the affected system operates separately from its main computer network. The agency found no indication that the incident spread to its broader network, its electronic firearms application platform or any other ATF system.

The eForms platform allows members of the firearms industry and the public to electronically submit applications involving weapons regulated under the National Firearms Act, including silencers, short-barreled rifles and machine guns.

The Record reported the intrusion before ATF acknowledged it Wednesday. The agency said it disconnected the affected system and began examining it for evidence about how the intrusion occurred.

ATF did not identify the affected system, say when the incident was discovered or disclose whether the intruders accessed or stole information. The agency did say the incident has not disrupted its operations or affected its ability to carry out its law enforcement and regulatory missions.

The “major incident” designation is likely a formal classification under the Federal Information Security Modernization Act, or FISMA. Federal guidelines generally apply the label to incidents likely to cause significant harm to national security, public confidence, civil liberties, public health or safety, or government operations. The designation also triggers reporting requirements to Congress.

ATF said the required notifications have been completed but did not explain what prompted Justice Department officials to classify the incident as major.

The hack could be significant because ATF investigates firearms trafficking, violent criminal organizations, bombings, arson and illegal explosives. It also operates systems used to trace guns recovered by law enforcement and administers licensing and regulatory programs for firearms and explosives businesses.

Qilin is generally deemed a ransomware-as-a-service operation, meaning its developers provide malware and supporting infrastructure to affiliates who conduct individual attacks, typically in exchange for a portion of any ransom. The group commonly attempts to steal data before threatening to publish it unless a victim pays.

Cisco researchers last year described the group as one of the world’s most active ransomware operations, with victims spanning companies, hospitals and government organizations. 

The ATF incident follows several other breaches involving sensitive federal law enforcement systems this year. Hackers breached the Homeland Security Information Network, a Department of Homeland Security platform used to exchange sensitive information with federal, state, local and private-sector partners. Investigators later determined that intruders had remained inside the environment for weeks after suspicious activity was twice dismissed as harmless.

A suspected China-linked group also accessed an FBI system used to manage information about court-authorized surveillance operations earlier this year.