The US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has declared a major incident after a cyberattack on one of its systems, a formal legal classification requiring Congress to be notified. The attack hit a stand-alone computer system that held information such as the targets of ATF investigations. The Qilin ransomware gang has claimed responsibility on its leak site, though it offered no leaked samples as evidence. Under federal law, agencies must disclose a major incident to Congress within a week.
Major incident is a legal term for the significant cyber harm that could affect US national security or interests. The ATF joins a recent run of federal agencies that declared such an event, including a 2023 ransomware attack on a US Marshals system and a breach earlier this year on an FBI system exposing phone numbers of surveillance targets. Qilin runs a ransomware-as-a-service operation, leasing its tools to criminal affiliates, and has listed media giant Lee Enterprises and UK pathology lab Synnovis among its previous victims. Breaching a law-enforcement system that walks information about targets raises worry that it could expose active sources or operations.
The attack shows that sensitive federal enforcement systems remain a favorite target for criminal gangs, and that a breach touching investigation subjects is high stakes for insider safety and operations. Because suspected data could include the targets of ATF investigations, its exfiltration could jeopardize active cases or informants. Declaring a major incident signals that agencies are now obligated to flag these breaches to Congress and to take them seriously. For national-security observers, it is a reminder that the seams of everyday government data are under constant assault.

The US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has declared a major incident after a cyberattack on one of its systems, a formal legal classification requiring Congress to be notified. The attack hit a stand-alone computer system that held information such as the targets of ATF investigations. The Qilin ransomware gang has claimed responsibility on its leak site, though it offered no leaked samples as evidence. Under federal law, agencies must disclose a major incident to Congress within a week.

Major incident is a legal term for the significant cyber harm that could affect US national security or interests. The ATF joins a recent run of federal agencies that declared such an event, including a 2023 ransomware attack on a US Marshals system and a breach earlier this year on an FBI system exposing phone numbers of surveillance targets. Qilin runs a ransomware-as-a-service operation, leasing its tools to criminal affiliates, and has listed media giant Lee Enterprises and UK pathology lab Synnovis among its previous victims. Breaching a law-enforcement system that walks information about targets raises worry that it could expose active sources or operations.

The attack shows that sensitive federal enforcement systems remain a favorite target for criminal gangs, and that a breach touching investigation subjects is high stakes for insider safety and operations. Because suspected data could include the targets of ATF investigations, its exfiltration could jeopardize active cases or informants. Declaring a major incident signals that agencies are now obligated to flag these breaches to Congress and to take them seriously. For national-security observers, it is a reminder that the seams of everyday government data are under constant assault.

πŸ“° Source: TechCrunch
techcrunch.com β†—
Was this article useful?