ATF reports major cybersecurity incident after ransomware gang claims hack
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has become the latest federal agency to formally notify Congress of a “major incident” involving its cybersecurity. In a brief briefing to congressional committees, ATF officials confirmed that a breach of its information systems had been detected and contained, but that the event met the agency’s threshold for a major incident under the Cybersecurity Information Sharing Act.
According to the briefing, the breach involved unauthorized access to a segment of the ATF’s internal network that houses sensitive data related to firearms licensing and enforcement. While the agency has not disclosed the full scope of the compromised data, it stated that the incident was isolated and that no evidence of data exfiltration or use by third parties has been found. The ATF’s cybersecurity team, in coordination with the Department of Homeland Security’s Cybersecurity and Infrastructure Security Agency, has implemented containment and remediation measures and is conducting a full forensic investigation.
The notification underscores the growing frequency of cyber incidents across federal agencies and highlights the importance of rapid disclosure to Congress under current cybersecurity reporting mandates. As the investigation continues, the ATF will provide updates on any additional findings and the steps it will take to prevent future incidents.