Bottom line: The ATF has confirmed a cyberattack targeting a system with sensitive information on investigation targets, but the agency claims the incident has not impacted critical operations.
What's happening: Qilin, a prolific ransomware group, claimed responsibility for the attack, which occurred on May 11, 2022. The incident affected a standalone system, and no sensitive data was released. The system was maintained by the ATF's Office of Investigative Sciences.
What to do: The ATF is conducting a thorough review to determine the extent of the incident and assess potential vulnerabilities. Security teams should review their incident response plans and ensure they are equipped to handle similar scenarios.