The Qilin ransomware group has published data it claims to have stolen from the US Bureau of Alcohol, Tobacco, Firearms and Explosives, potentially exposing sensitive investigation files, phone records and forensic evidence.
The ATF confirmed that attackers breached a standalone system used in connection with federally authorised electronic surveillance. However, it has not confirmed the authenticity, nature or full scope of the published material.
ATF identifies breached standalone system
Qilin claimed the ATF attack on August 26 and later set a 72-hour deadline before threatening to release the data.
The group published an alleged 6.3GB archive on its leak site after the deadline expired. The links have since disappeared, but the files were publicly accessible for much of Monday and may already have been copied or redistributed.
In an updated statement, the ATF identified the affected system as its CALEA system. The system supports information connected to the Communications Assistance for Law Enforcement Act, including records related to authorised electronic surveillance.
The agency said the incident did not affect its enterprise network, eForms system or other ATF systems.
Leaked files appear tied to investigations
An initial review of the alleged ATF data leak suggests that it includes files associated with active or past criminal investigations.
The material appears to contain mobile-device extractions, account information, IP addresses, registration data and digital forensic evidence. Some directories reportedly refer to ATF field offices and individual investigations.
Researchers also found apparent references to iPhones, Samsung devices, SIM cards, cloud data and Cellebrite forensic phone dumps.
If genuine, the files could reveal sensitive details about investigative targets, witnesses, informants and law-enforcement operations.
Investigation exposure creates wider risks
The ATF investigates firearms trafficking, violent crime, explosives, arson and organised criminal activity. Information connected to these cases may create serious security and safety risks if exposed.
Personal information within the alleged files could also enable targeted scams or other attempts to interfere with investigations.
The ATF is working with the Department of Justice and other federal partners to assess Qilin’s claims. The agency has not publicly attributed the breach to a specific threat actor.


0 responses to “Qilin Leak Claims to Expose ATF Investigation and Phone Records”