Circuit Wire — a daily news update from the Circuit.

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed on August 26 that a cyberattack on one of its computer systems has been designated a “major incident,” a formal classification under federal law that requires notification to Congress within a week. An ATF spokesperson said the affected machine was a standalone system that held information about the targets of ATF investigations.

The agency said the system was not connected to any other ATF network, including its case management, laboratory, and eForms systems. Staff terminated connections to the environment as soon as the breach was found and began incident response and forensic work. In a public statement issued Wednesday evening, the ATF said the attack did not affect its ability to carry out its missions. Officials added that the investigation is ongoing and that no further details could be shared. The Justice Department, which houses the bureau, is leading the inquiry.

The Qilin ransomware gang added the ATF to its leak site on Wednesday. The group offered no proof of its claim and posted no sample of stolen data. Qilin runs a ransomware-as-a-service operation that leases its tools to affiliates in exchange for a share of any payments. Researchers ranked it the second most active ransomware operation in July, with 127 reported attacks. Its 2026 victims include a Romanian oil pipeline operator and a French rugby club. The group drew heavy law enforcement scrutiny in 2024 after an attack on a British healthcare provider disrupted medical services, then resumed operations.

Under federal guidelines, a major incident is one likely to cause demonstrable harm to national security or broader U.S. interests. The breach follows a run of cyberattacks across the Justice Department. A 2023 ransomware attack hit a U.S. Marshals Service system, and an FBI system was breached earlier this year in a case that exposed phone numbers of people under federal surveillance. Qilin’s earlier targets include Kuala Lumpur International Airport, the U.S. newspaper chain Lee Enterprises, and a pathology provider whose attack disrupted hospitals in London.

Want a weekly roundup of the major stories shaping the security industry? The On The Circuit newsletter is read by more than 12,000 protection professionals.

Spotted something we should cover? Send tips and feedback via circuit-magazine.com.