Qilin hackers leak 6.3GB of ATF data exposing criminal investigation records
This digest was compiled by AI from multiple sources — links to the originals are below.
The Qilin ransomware gang published at least 6.3GB of data allegedly stolen from the US Bureau of Alcohol, Tobacco, Firearms and Explosives on its dark web leak site on Monday. The leaked files appear to include criminal investigation records, phone data, account details, and forensic evidence. The ATF confirmed a standalone server was breached but said its main network and eForms system were unaffected.
Key Facts
- Qilin posted the ATF data on its dark web leak site on Monday, marking it as published.
- The leaked trove appears to contain at least 6.3GB of confidential internal files.
- ATF Chief of Public Affairs Tanya J. Roman confirmed on Wednesday that the compromised system contained information about targets of ATF investigations.
- Qilin initially claimed the ATF on August 26 and later posted a 72-hour countdown before releasing the data.
The Data Leak
The Qilin ransomware gang published the stolen ATF data on its dark web leak site on Monday. The leak site marks the data as published, and the trove appears to contain at least 6.3GB of confidential internal files. An initial review by Cybernews researchers found files that appear to contain information connected to active or previous criminal investigations. The files include records extracted from mobile devices, account information, and digital forensic evidence.
ATF Response
Tanya J. Roman, Chief of the ATF’s Public Affairs Division, told Cybernews on Wednesday that the compromised ATF system contained information about targets of ATF investigations. The ATF confirmed a standalone server was breached but said its main network and eForms system were unaffected. The ATF did not confirm to Cybernews the threat actor responsible for the attack.
Ransom Timeline
Qilin initially claimed the ATF on its dark web leak site on Wednesday, August 26. On Friday, Qilin posted a countdown clock giving the ATF 72 hours before it threatened to publicly unleash the stolen data. The group provided no sample proof files or details about the amount or type of data in its initial claim.