THE US Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) has confirmed a cybersecurity incident involving the Qilin ransomware group. The ATF stated that the affected system was standalone and disconnected after the incident, with no impact reported on the main enterprise network. An investigation is underway, and the situation has been classified as a 'major incident' by federal guidelines.
Qilin, which operates on a double-extortion model, claims to have targeted the ATF but has yet to release details about any stolen information. The group has a history of exploiting vulnerabilities, including a recent Check Point VPN zero-day.