Russian-Linked Ransomware Gang Leaks Purported ATF Files After Major Cyber Breach

A cybercriminal gang with apparent Russian ties on Monday released what appear to be sensitive law enforcement files stolen from the U.S. Justice Department's Bureau of Alcohol, Tobacco, Firearms and Explosives, according to a review of the leaked material.
The dumped records include what look like details on past ATF investigation targets and analyses of their phone communications, according to CNN's review and an independent cybersecurity researcher. Some of the files appear to be tied to specific ATF agents and high-profile cases they had worked on, the researcher said.
The data spans investigations involving armed robbery, arson, explosives and homicide, said Ron Fabela, the independent researcher who examined the files. A significant portion of the cases referenced appear to fall under the ATF's Houston Field Division, he added.
In a statement Monday, the ATF said it “cannot confirm the authenticity, nature, or scope” of the leaked data at this time. The agency said it was coordinating with the Department of Justice and other federal agencies to “assess the claims and take appropriate actions.”
The ATF also reiterated that the affected system was not connected to its broader operational systems, and that the incident had not affected the agency’s ability to carry out its mission.
The agency first disclosed the breach last week, saying it met the threshold for a “major” cybersecurity incident requiring congressional notification. Under federal law, a major cyber incident is generally one that could harm U.S. national security, foreign policy or economic interests.
A prolific ransomware operation known as Qilin has claimed responsibility for the breach. On Monday, the group began posting the stolen files on its dark-web victim site. Qilin has previously claimed victims across manufacturing, retail and healthcare sectors, prompting Cisco’s cyber-intelligence unit to call it one of the “most prolific and damaging ransomware threats on a global scale.”
Another cybersecurity firm, Halcyon, which tracks ransomware groups, said it has “high-confidence” that Qilin operatives are Russian speakers.
The ATF hack adds to a troubling pattern of federal agencies being hit by the very kinds of cybercriminals they investigate. In 2023, a ransomware attack on the U.S. Marshals Service compromised personal information of individuals tied to its investigations. That same year, hackers breached a computer system used by the FBI’s New York field office in cases involving images of child sexual exploitation — including a system tied to the Jeffrey Epstein investigation, according to people briefed on the matter.
The latest leak underscores the escalating risk that sensitive law enforcement data can be exposed, and it raises new questions about how federal agencies are protecting investigative records from increasingly sophisticated criminal hacking groups.
