The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) confirms it is responding to a “major” cybersecurity incident following claims by the Qilin ransomware group. Multiple outlets report that Justice Department officials designate the incident as “major,” and the ATF is investigating the breach.

ATF says the impact appears limited to a standalone system that operates separately from the agency’s broader network. Sources also state that ATF indicates the incident does not appear to affect its enterprise network or key systems, including its eForms platform, though investigations are ongoing.

Across coverage, the core points are consistent: Qilin claims responsibility, ATF acknowledges the incident and moves to investigate it, and the matter is treated as significant enough to align with federal reporting practices for major cybersecurity events. Outlets differ mainly in emphasis—some focus on ATF’s confirmation of system compromise, others on the “major incident” designation by Justice Department officials, and others on the scope assessment described by ATF.