The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has declared a cyberattack on one of its systems a “major incident.” This classification requires formal notification to lawmakers in Congress.
The ATF stated it is responding to the cyberattack on a standalone system, separate from the bureau’s main network. An ATF spokesperson told reporters that the targeted computer system held information including “targets of ATF investigations.”
The Qilin ransomware gang has claimed responsibility for the attack on its leak site, but has not provided evidence such as a sample of leaked data. Qilin is known for operating a “ransomware-as-a-service” model and has previously listed media giant Lee Enterprises and U.K. pathology lab giant Synnovis.
Under federal law, “major incidents” are significant cyber incidents that could cause demonstrable harm to U.S. national security or broader U.S. interests. Agencies are required to disclose such incidents to Congress within a week of discovery.