incident-responsetrade-pressNewsThe Broadside1 min read

Qilin ransomware breaches ATF investigation target system

ATF calls the breached system "standalone" and says missions weren't affected, but investigation target data is exactly what you don't want a ransomware gang holding.


TL;DR

The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a ransomware breach of a standalone system containing information about investigation targets, after the Qilin gang listed ATF on its leak site. ATF designated the incident "major" under federal guidelines but said the system wasn't connected to case management systems or any other ATF operational platform and that mission capability was unaffected. Qilin posted no sample data. The DOJ is investigating.

ATF confirmed Wednesday that a standalone system containing information about investigation targets was breached, after the Qilin ransomware gang added the bureau to its leak site. The agency designated the incident "major" under federal guidelines, then immediately emphasized that the system wasn't connected to case management systems or any other ATF operational platform and that mission capability was unaffected. Both things can be true: a system can be architecturally isolated while still holding data whose exposure matters. Investigation-target information in the hands of a ransomware gang is the kind of disclosure that isn't measured by uptime metrics.

ATF's security posture has been a mixed bag. The DOJ Office of the Inspector General's July 2022 cyber supply chain risk management audit found ATF was one of only two non-FBI DOJ components fully compliant with the Justice Management Division's C-SCRM requirements, ahead of peers at a department where JMD's program was described as resource-starved and plagued by "widespread noncompliance." But a subsequent FY2023 FISMA audit identified weaknesses in four of nine security domain areas at ATF, suggesting the earlier compliance win didn't translate to comprehensive protection.

Qilin didn't post any sample data on its leak site, which could mean the gang is still negotiating or that the breach yielded less than it hoped. Either way, the ATF joins a growing list of DOJ components hit by cyber incidents, the US Marshals Service, the FBI, and the federal courts docketing system have all suffered breaches in recent years. For an agency whose systems hold firearm trace data, federal firearms licensee records, and criminal investigation targets, the "standalone" descriptor is cold comfort.


Published ·Deep Fathom

Qilin ransomware breaches ATF investigation target system — The Broadside