The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has declared a cyberattack on one of its systems a “major incident,” a formal, legally defined classification that mandates a notification to Congress. According to an ATF statement, the attack targeted a stand-alone computer system separate from the bureau’s main network, which contained information such as “targets of ATF investigations” (TechCrunch, 2026).
The Qilin ransomware gang has claimed responsibility for the hack on its leak site, although it did not provide evidence to substantiate the claim, such as a sample of leaked data. Qilin operates a “ransomware-as-a-service” model, leasing its hacking tools to other criminal affiliates for a share of the profits. The gang has previously targeted media giant Lee Enterprises and U.K. pathology lab company Synnovis (TechCrunch, 2026). Under federal law, “major incidents” are significant cyber incidents likely to cause demonstrable harm to U.S. national security or broader U.S. interests, requiring agencies to disclose them to Congress within a week of discovery (TechCrunch, 2026).
Source: TechCrunch. (2026, August 27). ATF declares ‘major incident’ as ransomware gang claims hack. https://techcrunch.com/2026/08/27/atf-declares-major-incident-as-ransomware-gang-claims-hack/