US federal agency confirms data breach in wake of claims by ransomware group


The breach raises concerns as ATF systems hold sensitive data; a “major incident” triggers Congress reporting

The ransomware group breached the data. PHOTO: PEXELS

 A ransomware group gained access to a computer system containing information about targets of investigations by the Bureau of Alcohol, Tobacco, ​Firearms and Explosives, a spokesperson for the U.S. agency said ‌after a hacking group publicized a claimed breach on Wednesday.

Tanya Roman, a spokesperson for the agency, said in an email that the standalone system was not connected to ​any other ATF systems, including case management, laboratory or eForms systems, ​which are used by the agency to manage form submissions ⁠from the public.

Roman said the affected system was “quickly shut down when ​the breach was discovered,” and that an investigation is ongoing. A separate statement ​posted to the agency’s website said the ATF is coordinating closely with the Department of Justice and that the episode has been designated a “major incident.”

Neither Roman nor the statement ​identified a possible culprit for the breach.

Read More: Major tech companies call for defensive surge to defeat AI-driven hacks

The breach raises concerns because ​ATF systems can contain sensitive law enforcement data, including details on ongoing investigations. The “major incident” ‌designation ⁠means the breach could result in harm to national security or civil liberties and triggers congressional reporting requirements.

The ATF is a federal law enforcement agency under the US Department of Justice. A Department of Justice spokesperson referred ​Reuters to the ​statement by the ⁠ATF. The Cybersecurity and Infrastructure Security Agency also referred questions to the ATF.

Qilin, a prolific ransomware operation thought to ​be Russian-based or Russian-speaking, posted a message on its website ​on ⁠Wednesday, in which it claimed responsibility for the compromise. The message included no description of what was stolen or how much, and did not include any ⁠samples.

Qilin ​has listed nearly 2,400 claimed attacks across more ​than 100 countries since it emerged in October 2022, according to data compiled by cybercrime ​research and tracking platform eCrime.ch.

 



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *