-
Qilin posted about 6.3GB of files from the Bureau of Alcohol, Tobacco, Firearms and Explosives. It says the files came after a 72-hour countdown ended.
-
Researchers found ATF case files and phone extractions. They also found account details, IP addresses and digital forensic data.
-
ATF confirms a cyber incident on a legacy CALEA system. It cannot yet check the leaked files or their full size.

Qilin Ransomware has posted 6.3GB of data they allegedly stole from the Bureau of Alcohol, Tobacco, Firearms and Explosives, ATF. The post followed a 72-hour countdown on Qilin’s leak site. The group first listed ATF on August 26. That was the same day ATF disclosed a cyber incident involving a separate system.
Analysts who reviewed the posted files found files that appear linked to ATF cases. The analysts are still examining the data and have not established the full size of the leak.
The data appeared on Qilin’s site on August 31. Reports said the files were briefly available before the group removed them.
While the ATF acknowledged a cybersecurity incident, it hasn’t confirmed that Qilin carried out the break-in. It also has not confirmed that every file posted by the group came from its systems.
Files Appear Linked to Crime Cases
An early review found folders tied to ATF field work and cases. Some directories are labeled “LAREDO Field Office” and “atf-houston.” Another folder carries the name “ARMORED TRUCK ROBBERY SERIES 22-23.”
The files appear linked to armed robbery, arson, explosives and other major crimes. Some folders seem to name people of interest in ATF cases.
Researchers also found phone and device data. The files reportedly include Apple iPhone and Samsung Galaxy extractions, SIM card data and iCloud data.
Some files have Cellebrite forensic data. Cellebrite develops software that police agencies use to investigate and gather evidence from phones.
Reports on the files specifically mention an iPhone 6 and a Samsung Galaxy J3. The files also appear to have account identifiers, phone numbers, IP addresses and registration details. If the files prove real, they could expose data about people linked to federal cases.
Researchers also found files that appear to show parts of ATF’s security setup. Symantec Endpoint Protection 14.3 is one such reference. Such information could help the hackers to determine how secure ATF is. They do not show that the main network was breached.
ATF Says the Breach Hit a Separate System
ATF first confirmed the cyber incident on August 26. The ATF said the hit system had data about targets of ATF cases. The ATF also said the system was separate from its main network. It was not linked to the ATF case management, laboratory, or eForms systems, per the ATF.
ATF quickly shut down the system after finding the breach. It began working with the Justice Department and other federal partners. The Justice Department designated the incident a “major incident” under federal guidelines. That label can trigger formal reporting and other response steps.
ATF has stressed that its wider work remains available. The ATF says the incident has not hit its ability to carry out its mission. The hit system was the ATF’s CALEA system, per the ATF’s August 31 update.
CALEA, which stands for the Communications Assistance for Law Enforcement Act, is a law that sets rules for phone firms that support lawful wiretaps.
ATF Still Cannot Check the Leak
ATF’s latest statement adds an important warning about the posted files. ATF says it is aware of claims that Qilin posted data from its separate CALEA system. But ATF cannot confirm the “authenticity, nature, or scope” of the files.
The 6.3GB figure remains a claim linked to the posted files. ATF has not confirmed that amount. The same applies to the contents of the data. Researchers have identified files that appear linked to ATF work, but the ATF has not checked them.
ATF is working with the Justice Department and other federal agencies. They are analyzing the files and taking appropriate measures.
Qilin’s been active since 2022 and is notorious for pressuring their targets by threatening to publish stolen data online. According to Reuters, Qilin had claimed thousands of attacks in over 100 nations by August 2026.
ATF Has No Ties to Qilin to the Breach
Qilin claimed the ATF break-in. It listed the agency on its leak site on August 26. The later post adds weight to the claim. Analysts found files that appear related to ATF cases. Still, the ATF has not publicly blamed Qilin for the break-in.
For now, investigators are trying to learn what happened. They also want to know what data the attackers got.
Why the Incident Matters
The ATF case highlights the risks of a breach involving police files. Even when a hit system sits apart from ATF’s main network, its data can remain highly private. Case files can have personal details, evidence, and data about federal work.
The incident also shows why ransomware groups use data leaks as pressure. Hackers can demand payment while threatening to publish private data if victims refuse.
Qilin’s targeting extends well beyond government agencies. In June 2026, the group claimed a breach of Sivatel Bangkok, a hotel in Thailand, listing the hospitality business on its leak site and adding it to a victimology that spans multiple countries and industries.
ATF has confirmed the cyber incident and identified the hit CALEA system. It has not confirmed the authenticity or full size of the files Qilin claims to have posted. The case will show if the files are genuine. It will also show how much data attackers exposed and whether anyone outside ATF has it.