The United States Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) announced on Wednesday, August 26, that they are investigating a “major” cybersecurity incident. According to ATF’s statement, the incident affected an independent operational system that is separate from ATF’s corporate network. Currently, there are no signs that the event has spread to ATF’s corporate network, electronic forms system (eForms), or other systems. Senior officials from the Department of Justice (DOJ) have classified this incident as a “major incident” in accordance with applicable federal guidelines.
Following the discovery of the event, ATF immediately disconnected the affected environment and initiated incident response and forensic work. ATF is closely collaborating with the Department of Justice in conducting the investigation. The incident has not impacted ATF’s ability to carry out its daily law enforcement and regulatory missions.
ATF, which has belonged to the Department of Justice since 2003 and was previously under the Department of the Treasury from 1972 to 2003, stated that under U.S. federal regulations, a cyber intrusion that could cause substantial harm to national security, economic interests, or civil liberties is classified as a “major incident.” This designation requires ATF to submit a formal report to the U.S. Congress within a week.
A ransomware group affiliated with Russia called “Qilin” has claimed responsibility for the incident and has listed ATF, along with five other victims in the manufacturing and industrial sectors, on a dark web leak site. ATF has neither confirmed nor denied Qilin’s claims, nor disclosed the timing of the incident or whether any data was stolen.
Media outlets like Cybernews reported that if Qilin’s claims are true, the consequences of any data theft from ATF systems could be severe. An ATF spokesperson later mentioned that the invaded “independent system” contained information related to ATF investigative targets.
On the same day ATF announced the hack, the Department of Justice announced the successful shut down of two hacker platforms, “QScan” and “QTRouter.” According to court documents unsealed by the Southern District of California, these platforms were operated by the Chinese state-supported hacker organization “QTFY,” which is employed by Nanjing Xinjiuwei Network Technology Co., and provides services to Chinese state entities like the Ministry of State Security and military.
These platforms were used to target networks of institutions like the Department of Justice, NASA, the Federal Reserve, Department of Energy, the Senate, the Department of Health and Human Services, and the National Institutes of Health.
Attorney General Todd Blanche stated in a release, “This nation-state-supported malicious hacking targeting critical U.S. infrastructure will be stopped and prosecuted. We will use all means to combat hacking activities to ensure the safety of the American people.”
In July and August of this year, federal officials issued multiple warnings about hacker attacks on water facilities in several states in the U.S. Earlier in this month, officials pointed out in a warning that hackers associated with the Iranian regime had attacked the logic controllers of multiple water facilities produced by companies like Siemens, Rockwell Automation, and Schneider Electric.
For years, the FBI and other U.S. agencies have been warning that China, Russia, and Iran have been attempting to breach and attack U.S. infrastructure systems, companies, and government entities.
