A ransomware group called Qilin has claimed responsibility for stealing files from the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), a Justice Department agency. The group began posting files on its dark-web site Monday, claiming the theft occurred last week.
The stolen records reportedly come from the ATF's CALEA system, which collects phone and other communications records for criminal investigations. According to security researchers and media reports who reviewed the leaked files, the material appears to include information on old investigation targets, phone-record analysis, named agents, and cases involving armed robbery, arson, explosives, and homicide. A significant portion of the leaked data appears to relate to the Houston Field Division.
The Justice Department has designated the incident a "major" cyber event, a classification that requires notification to Congress.
The ATF said it is aware of claims that records from the CALEA system are online. The agency stated it cannot yet confirm the authenticity, nature, or scope of the material and is working with the Department of Justice and other federal partners to assess the claims.
According to the ATF, the affected system was standalone and not connected to other agency networks. The agency said the incident has not disrupted its operational systems or ability to carry out its mission.


