17 Iranians charged in cyber theft campaign
The Justice Department has charged 17 Iranian nationals in connection with an expansive cyber theft operation that allegedly targeted U.S. universities and government agencies. Reporter Alexandria Hoff explains that, according to officials, the hackers infiltrated networks beginning in 2013 to steal valuable intellectual property. Authorities stressed that even years-old cyber intrusions remain a priority, warning that time will not shield foreign hackers from U.S. prosecution.
The Bureau of Alcohol, Tobacco, Firearms and Explosives said Wednesday that it is probing a cybersecurity incident tied to a standalone system, a breach that senior Justice Department officials have classified as a “major incident” under federal guidelines.
The announcement followed claims from the Qilin ransomware gang that it had compromised ATF, according to cybersecurity publications monitoring the group’s leak site. However, Qilin has not publicly released evidence to back up the allegation, and ATF has not linked the incident to the ransomware group.
ATF said the system involved is isolated from its main enterprise network. The agency added that it has found no signs the incident reached its broader network, the eForms platform or any other ATF systems.
After identifying the issue, the agency said it took the affected environment offline and began forensic analysis and incident-response work. ATF is also working with the Justice Department as officials examine the scope and cause of the incident.
The Bureau of Alcohol, Tobacco, Firearms and Explosives national headquarters in Washington, D.C. ATF said Wednesday it is investigating a cybersecurity incident affecting a standalone system. (Rich Clement/Bloomberg via Getty Images)
Officials have not named the specific system involved, disclosed when the incident was first detected or said whether any information was viewed, removed or stolen.
Cybernews reported Wednesday that Qilin listed ATF as its newest alleged victim, though the outlet noted the group had not shared supporting evidence or additional details.
GalaxyWarden, a breach-monitoring service, separately reported that ATF appeared on Qilin’s leak site and that the group claimed it obtained files from the agency. GalaxyWarden said it had not independently verified the group’s assertions.
News Outlet reached out to ATF and the Justice Department for additional information, including whether officials believe Qilin was responsible for the incident, whether any data was accessed or stolen and what prompted officials to designate the event a “major incident.”
ATF said senior Justice Department officials designated the cybersecurity event a “major incident” under applicable federal guidelines and that required notifications have been completed.
DOJ CHARGES 3 RUSSIANS IN ALLEGED $63M CYBERCRIME SCHEME TARGETING AMERICANS
The U.S. Department of Justice building in Washington, D.C., on Aug. 17, 2026. ATF said it is coordinating with the Justice Department as it investigates a cybersecurity incident involving a standalone system. (Anna Moneymaker/Getty Images)
The incident has not disrupted ATF operations or affected the agency’s ability to carry out its missions, according to the agency.
A security official walks in front of the entrance to the national headquarters of the Bureau of Alcohol, Tobacco, Firearms and Explosives on Jan. 23, 2014, in Washington.
The agency asked anyone with information related to the incident to contact the ATF Tipline at 1-888-ATF-TIPS, or 1-888-283-8477.

