speaking hackers have crossed a dangerous line. U.S. investigates major hacking of federal agency

Depov

Moderator
Staff member
MODERATOR
ULTIMATE
SUPREME
PREMIUM
MEMBER
Joined
Feb 18, 2025
Messages
506
Reaction score
873
Deposit
0$
extortion group Qilin briefly opened access to about 6.3 GB of files, which he calls stolen from the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF). The Office itself confirmed the hacking of a separate system related to investigations, but has not yet confirmed the authenticity of the published materials, so the extent of the possible leakage remains unknown.

According to the materials that the researchers have studied, the archive contained folders of individual investigations, names and contact details of people who came into the field of view of ATF, IP addresses, account information and the results of forensic analysis of mobile devices. Among the files were Cellebrite unloading, iCloud data and content of several smartphones. Qilin removed the links shortly after publication, so it is not yet possible to independently check the entire declared array.

ATF acknowledged that the attackers gained access to the outdated autonomous CALEA system. The Bureau is aware of the allegations regarding the publication of investigative material, but "cannot confirm the authenticity, nature or extent" of the published data. The Department of Justice and other federal departments continue to review.

The affected system operated separately from the main corporate ATF network. After the discovery of the invasion, the specialists disabled the connections to the affected environment and began forensic analysis. According to the bureau, the attack did not affect eForms and other operating systems, and the staff continued to carry out their normal tasks.


The name CALEA is associated with the American Communications Assistance for Law Enforcement Act. The law requires telecom operators to maintain the technical possibility of legally intercepting electronic communications after obtaining the appropriate permission. Therefore, the compromise of the system associated with CALEA and investigative materials is potentially more sensitive than the usual leakage of official documents. The contents of the archive published by Qilin may reveal people and digital traces that investigators were interested in, although the ATF has not yet established how much the claimed array corresponds to the real data of the bureau.

The U.S. Department of Justice assigned the status of a “major incident” to the accident. Federal rules use this category for events that can cause noticeable damage to national security, economy, civil liberties, public safety or trust in state institutions. Such status also triggers mandatory procedures for notifying federal bodies and Congress.

Qilin operates on the Ransomware-as-a-Service model, in which operators support the extortion platform and infrastructure, and immediate attacks can be carried out by independent partners. Therefore, even confirming the use of Qilin tools does not necessarily reveal specific ATF hacking performers. The agency has not yet publicly attributed the invasion to the group and has not disclosed the method of initial penetration.

Qilin has long been among the most active extortional operations. In the FBI statistics for 2025, the family ranked second among ransomware programs, which were most often reported by the victims. One of the most famous episodes was the attack on the British laboratory company Synnovis in 2024, after which London hospitals canceled thousands of receptions and medical procedures.

The hacking of the ATF gained additional importance due to the sharp change in American policy to combat foreign cybercriminal groups. President Donald Trump signed a memorandum in August that calls for the involvement of verified private American companies in offensive cyber operations against transnational criminal organizations outside the United States.

The document allows such contractors to conduct intelligence operations and influence the infrastructure of criminals, up to disruption, blocking, altering or destroying information systems. However, it is not about the free permission of American companies to “hack hackers” on their own. Each operation should be approved in advance by representatives of the Ministry of Justice and the Ministry of Internal Security, and the private company operates under the control of the federal government.

The program is still in the deployment stage. The memorandum gave officials 60 days to prepare procedures, requirements for participants and a mechanism for harmonizing goals, and without approved rules it is impossible to carry out such operations. Therefore, the assumption that Qilin will be the goal of American private specialists immediately after the attack on the ATF remains only a possible scenario.

Formally, Qilin corresponds well to the type of threats against which a new program is created. The memorandum covers foreign non-state criminal structures that attack the U.S. government, American citizens or the interests of the country. If the investigation confirms Qilin's responsibility for hacking the ATF, the federal authorities will get a particularly clear reason to consider the group's infrastructure as a potential target of future operations. There are no public reports about the preparation of such an attack against Qilin.
 
Top Bottom