ATF Confirms Breach After Qilin Ransomware Claim
ATF confirms a cyber incident on a standalone system after the Qilin ransomware group claimed an attack.
Ransomware group Qilin has claimed an attack on the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives, and the agency has now confirmed the incident. In a statement posted to its website, ATF said the intrusion affected a standalone system, which was disconnected after discovery.
ATF Statement and Response
ATF said the impacted system operates separately from the ATF enterprise network. The agency stated that there is no indication the incident has affected the enterprise network, the ATF eForms system, or any other ATF system. The incident has not impacted ATF's ability to perform its missions.
An investigation is being conducted in coordination with the Justice Department. ATF noted that senior Department officials have designated the event a 'major incident' under applicable federal guidelines, and required notifications have been completed.
“The impacted system operates separately from the ATF enterprise network, and there is no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system,”
— ATF, in a statement on its website
Qilin's Leak Site Post
The Qilin ransomware group added ATF to its leak website on August 26. As of the report, the group has not made any specific claims about the breach. Typically, the hackers post screenshots to demonstrate that certain types of documents have been stolen from victims, but that has not yet happened in ATF's case.
Qilin's post does not specify when any stolen files might be leaked. Some victim announcements include a timer indicating when files will be published.
Agenda to Qilin
Active since at least 2022, initially under the name Agenda, Qilin operates on a double-extortion model. It encrypts files and exfiltrates sensitive information from victims' systems.
Qilin recently made headlines after exploiting a Check Point VPN zero-day vulnerability in its attacks.
Track Record of Victims
The cybercrime group has listed more than 2,000 victims on its leak website to date. The actual number is likely much higher, given that many victims pay a ransom and are not named.
- More than 2,000 victims listed on Qilin's leak website
- ATF confirmed incident on a standalone system
- Qilin added ATF to leak website on August 26
- Active since at least 2022
Implications for Federal Agencies
This incident highlights the persistent threat ransomware groups pose to government agencies. Even when systems are isolated, attackers target less-protected components. Federal agencies should review their own standalone systems for similar risks, as attackers may pivot to less-protected components.
Organizations must ensure that all systems, even those not on the main network, are adequately secured and monitored. The designation of a 'major incident' underscores the severity of the event.
Sources
- SecurityWeek Original source
Continue Reading
Berlin's Ransom Standoff Tests State Resilience
Berlin refuses to pay Rhysida after data theft from its state network, saying it won't yield to blackmail.
AI Coding Assistant Now a Ransomware Weapon
Aurora ransomware actors use Cursor Agent AI to automate post-exploitation tasks, per Gambit Security research.
TeamPCP arrests expose supply chain risk
Alleged masterminds of TeamPCP, tied to Shai-Hulud worm, arrested in Perth with FBI help.