The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has classified a cyberattack on one of its systems as a major incident, a formal designation that triggers notification to Congress.
According to the bureau, the affected system was separate from its main network. An ATF spokesperson said the targeted computer held information related to investigative priorities, including potential case targets.
A ransomware group known as Qilin has claimed responsibility, though no proof of the breach has been publicly presented. Qilin operates a ransomware-as-a-service model, offering its tools to criminal affiliates in exchange for a share of profits.
In federal cybersecurity rules, major incidents are reserved for cases that may significantly affect national security or broader U.S. interests. Agencies must report such events to lawmakers within seven days of discovery.
The ATF now joins a growing list of public institutions that have elevated cyber incidents to this level, underscoring how digital resilience is becoming central to modern governance. This shift may shape stronger security standards across public systems in the years ahead.