Mastodon Skip to content
LIVE - NYSE/-/- CRYPTO/OPEN/24/7
BTC$80,496▼ 0.91%ETH$2,579▼ 2.15%SOL$108.21▼ 2.91%TOTAL CRYPTO$2.74T▼ 4.81%S&P 5007,650.50▼ 0.54%NASDAQ26,522.55▲ 0.89%DOW51,682.64▼ 3.11%GOLD4,424.90▼ 3.20%WTI96.08▲ 9.39%BRENT99.29▲ 5.88%EUR/USD1.1490▼ 0.80%USD/JPY156.86▼ 1.56%DXY100.22▲ 1.33%
Cyber

Qilin Leak Exposes ATF Criminal Investigation Files

Ransomware group publishes 6.3GB of federal law enforcement data including case files, phone records, and forensic evidence after 72-hour deadline

Pexels – Ann H

The Qilin ransomware gang has published a massive trove of stolen data from the US Bureau of Alcohol, Tobacco, Firearms and Explosives, exposing criminal investigation files, phone records, and digital forensic evidence just days after issuing a 72-hour ransom deadline.

The data dump appeared on Qilin dark web leak site on Monday, marking the end of a countdown timer the group set on Friday after claiming the ATF as a victim on August 26. An initial review by Cybernews researchers found at least 6.3 gigabytes of confidential internal files organized around individual investigations and field operations.

The ATF confirmed in an updated statement on Monday that the compromised system was its CALEA server – a standalone system used in connection with the federal Communications Assistance for Law Enforcement Act. CALEA systems process highly sensitive information tied to wiretaps, communications monitoring, and ongoing criminal investigations.

ATF is aware of claims concerning the publication of data obtained from an ATF standalone system, the bureau said. The agency added that it cannot confirm the authenticity, nature, or scope of the material at issue and is working with the Justice Department and other federal partners to assess the claims.

What the Leaked Files Contain

Directories reviewed by researchers show dozens of folders organized around individual investigations and ATF field operations, including directories labeled LAREDO Field Office and atf-houston. Many folders appear to be named after specific individuals of interest, while others identify the exact mobile devices or accounts tied to those individuals.

The leaked files also appear to include phone and device extractions, identifying Apple iPhones, Samsung Galaxy models, SIM cards, iCloud data, and Cellebrite phone dumps. Cellebrite is a widely used digital forensics platform that allows law enforcement to extract and analyze data from mobile devices. Its presence in the leak is particularly alarming because it suggests the stolen data includes raw forensic evidence collected during active investigations.

Additional records contain account identifiers, IP addresses, registration information, and verified phone numbers. Some file names reportedly expose actual phone numbers alongside named individuals, raising immediate concerns about the safety of witnesses, informants, and undercover operatives connected to ongoing cases.

Cybernews researchers noted that the sheer volume and organization of the data suggest the attackers had persistent access to the CALEA system for some time before the exfiltration was detected. The folder structures mirror how ATF field offices organize their digital evidence, indicating the breach may have captured entire investigative directories rather than isolated files.

This is the agency investigating firearms trafficking, illegal explosives, arson, and organized crime tied to the illicit alcohol and tobacco trade. When attackers reach investigative data, the real risk is not exposed records – it is what those records could reveal about open cases, targets, and the people tied to them, said John Bruggeman, vCISO at CBTS.

The Breach Timeline

Qilin first listed the ATF on its leak site on August 26, the same day the bureau confirmed to Cybernews that it had suffered a breach of a standalone server. At the time, the group provided no sample proof files or details about the scope of stolen data, leaving the severity of the incident unclear.

On Friday, Qilin posted the 72-hour countdown clock, clearly seeking a ransom payout to keep the sensitive law enforcement data private. When the deadline expired Monday without a reported payment, the full dataset was published in what security researchers described as one of the most significant law enforcement data breaches in recent memory.

The ATF said the compromised CALEA system contained information about targets of ATF investigations but emphasized that there was no indication that the incident has affected the ATF enterprise network, the ATF eForms system, or any other ATF system. The bureau mission was not impacted, according to officials.

Tanya J. Roman, Chief of the ATF Public Affairs Division, told Cybernews on Wednesday that the compromised system contained information about targets of ATF investigations. The agency noted in a public statement that there was no indication the incident affected the ATF enterprise network, the eForms system, or any other ATF system.

National Security Implications

ATF investigations can target a wide range of serious criminal activity, from illegal firearms trafficking and violent gangs to bomb makers and terror suspects. The exposure of case files could compromise active operations, put confidential informants at risk, and reveal the inner workings of federal law enforcement to criminal networks.

The leaked data also reportedly includes references to roughly 1,400 local task force officers who work with the ATF across the country on thousands of investigations. These officers, drawn from local and state police departments, could be exposed through the breach, potentially compromising ongoing joint operations.

John Bruggeman, vCISO at CBTS, highlighted that the Department of Justice immediately designated the event a major incident under federal guidelines, suggesting the response procedures were established and practiced. He noted that the ATF was able to quickly identify the compromised system as standalone and separate from the enterprise network, then terminate connections to the affected environment while broader systems remained operational.

The breach underscores the persistent vulnerability of standalone legacy systems that operate outside an organization main security perimeter. While the ATF enterprise network remained untouched, the CALEA system stored some of the most sensitive data the bureau handles, including wiretap orders and surveillance records tied to active criminal cases.

Qilin is a Russian-speaking ransomware group that operates a double extortion model, encrypting victim data and threatening to publish it unless a ransom is paid. The group has previously targeted organizations across healthcare, government, and critical infrastructure sectors. The ATF breach represents one of its most high-profile government targets to date.

SourcesCybernews; CISA advisory AA26-237A; ATF official statements; CBTS security analysis; BleepingComputer
Share: X