Labor Day gun deals are live through Monday. See the deals
Home/Articles/News
News

ATF Hack: Qilin Leaks 6.3GB, Agency Says NFA Data Safe

Qilin published roughly 6.3GB of ATF material on August 31 after its ransom countdown expired: investigative case directories, Cellebrite phone dumps, and forensic records tied to field offices. ATF named the breached machine as its standalone CALEA system and says eForms, the NFA registry, and case management were never connected to it. What that means for your Form 1, your fingerprints, and the registry that lists what you own.

Author
Aditya Bawankule
Read
11 min
ATF Hack: Qilin Leaks 6.3GB, Agency Says NFA Data Safe header image

Key Takeaways

  • →Qilin published the data on August 31: after a 72-hour ransom countdown expired, the group marked its ATF entry published with a trove Cybernews puts at roughly 6.3GB, containing what appear to be investigative case directories, mobile-device extractions, and forensic records.
  • →ATF confirmed it: a press release dated Wednesday, August 26, 2026 says ATF is responding to a cybersecurity incident affecting a standalone system, and that it cut connections to that environment on discovery.
  • →Designated a major incident: senior Department of Justice officials applied the formal federal classification, which carries a seven-day congressional notification requirement. ATF says required notifications are complete.
  • →ATF named the system on August 29: Director Robert Cekada said it was the ATF CALEA system, the standalone environment the agency uses in connection with the federal wiretap-assistance law, not case management, laboratory, or eForms.
  • →eForms named as unaffected: ATF states there is no indication the incident reached the enterprise network, eForms, or any other ATF system, and the NFA portal has kept processing through the disclosure.

Qilin Published the Files on August 31

The leak-site entry that sat empty for five days is no longer empty. Qilin posted a 72-hour countdown against the Bureau on Friday, August 28, and when it expired on Monday, August 31 the group marked the ATF listing published and released the material. Cybernews, which reviewed the trove first, puts it at roughly 6.3GB of internal files. ATF told the outlet it planned to issue a statement on the published data; that statement had not appeared as of the evening of August 31, 2026, and the agency has not confirmed the material is authentic.

What Cybernews describes in the directory tree is enforcement material, not applicant paperwork. The parent directories are organized around individual investigations and field operations, including folders labeled “LAREDO Field Office” and “atf-houston,” with subfolders named after specific people of interest and the exact phones or accounts tied to them. The files include mobile-device extractions naming Apple iPhones, Samsung Galaxy models, SIM cards, and iCloud data, along with Cellebrite phone dumps, the Israeli forensics platform most US law enforcement agencies use to pull data off seized devices. Cybernews also found account identifiers, IP addresses, and verified phone numbers, some appearing in file names next to named individuals, a directory labeled “ARMORED TRUCK ROBBERY SERIES 22-23,” and enough detail about ATF's own IT environment to identify the endpoint protection software and version it runs.

That content is consistent with what ATF and its spokesperson described from the first day, a standalone system holding information about investigative targets, and consistent with the CALEA identification the Director gave on August 29. It is also the reason the major incident designation was applied. The people exposed by investigative and forensic material are not only the subjects of cases; they are witnesses, cooperators, and the roughly 1,400 local task force officers who work alongside ATF agents. For an ordinary NFA filer, nothing in the published material has been described as touching applicant records, and the practical guidance below is unchanged.

What ATF Confirmed

ATF published a press release on Wednesday, August 26, 2026 stating that it is responding to a cybersecurity incident affecting a standalone system. The agency says that system operates separately from the ATF enterprise network, and that there is no indication the incident has affected the enterprise network, the eForms system, or any other ATF system. On discovery, ATF says it immediately terminated connections to the affected environment and began incident-response and forensic work, and that it is coordinating with the Department of Justice on the investigation. Senior Department officials designated the event a major incident under federal guidelines, and ATF says required notifications have been completed. The release closes by saying the incident has not impacted ATF's ability to perform its missions, and asks anyone with information to call the ATF Tipline at 1-888-ATF-TIPS.

An ATF spokesperson told Recorded Future News the machine held information about targets of ATF investigations, a different population from the ordinary applicants whose paperwork moves through the NFA pipeline. Three days later the agency named the system outright.

Three things remain unanswered, and they are the three that determine how serious this ends up being. ATF has not said when the intrusion occurred, has not said how the system was reached, and has not said whether any data was successfully copied off it. Confirming an incident is not the same as confirming a data theft, and the agency's statement carefully stops short of the second.

ATF Names the System: Its CALEA Environment

On Saturday, August 29, 2026, ATF Director Robert Cekada said the compromised machine was the ATF CALEA system, a standalone system the agency uses in connection with the federal Communications Assistance for Law Enforcement Act. He framed the statement as a correction to claims circulating about the incident, repeated that the system was separate from ATF's other systems and networks, and said the agency would release more as the investigation allows. That is the first public identification of the system. The August 26 press release named nothing beyond “a standalone system.”

CALEA, signed into law on October 25, 1994, requires telecommunications carriers and equipment makers to build their networks so a specific subscriber's communications and call-identifying information can be isolated and handed to the government under proper legal authorization. It is the plumbing behind court-authorized wiretaps and call-record orders, and an agency-side CALEA system is the equipment and process an investigating agency uses to work that pipeline. Cekada stopped there. ATF has not said whether the system held intercept content, subscriber and call-detail records, or only the administrative workflow around authorized requests, and it has not said how many investigations or people the records touch.

The identification does two things at once. It squares the earlier spokesperson description, because court-authorized surveillance material on investigative subjects is exactly “information about targets of ATF investigations.” And it explains the gap between a single isolated machine and a major incident classification: material tied to lawful intercept is among the most sensitive a law enforcement agency generates, since it reveals who is under surveillance and, by implication, who is not. It also puts the intrusion firmly on the enforcement side of the agency, further from the applicant records than the first-day reporting could establish.

What a “Major Incident” Designation Actually Means

The phrase is a formal federal classification, not an adjective. The Federal Information Security Modernization Act directs the Office of Management and Budget to define what counts as a major incident and requires agencies to report one to Congress within seven days of identifying it. OMB guidance reserves the label for incidents involving classified or otherwise protected information, or incidents likely to cause demonstrable harm to national security interests, foreign relations, the economy, or the public confidence, civil liberties, or safety of the American people.

Read that against what ATF actually said and the designation carries real weight without resolving the open questions. The agency confined the intrusion to one isolated machine and said its mission capability is intact, yet senior DOJ officials still elevated the event to a classification that puts it in front of Congress. That combination is consistent with a small blast radius holding unusually sensitive contents, which is exactly what a system of investigative-target records would be. It is not, by itself, evidence that a large volume of data left the building.

How the Qilin Listing Developed

Qilin added the Bureau of Alcohol, Tobacco, Firearms and Explosives to its dark web leak site on the morning of August 26, hours before ATF published its statement, as one of six new victims in a batch otherwise drawn from industrial and manufacturing companies. ATF was the outlier and the only federal law enforcement agency in the group. For five days the entry carried no proof at all: no intrusion date, no claimed data volume, no description of what was taken, and no sample files, while three of the five other victims posted that same morning each carried dozens of samples. That gap is what made the claim unverifiable through the first week.

The countdown on August 28 and the publication on August 31 closed it. Whether the material is complete or authentic is still ATF's to confirm, and the agency has named no adversary at any point: its release describes an incident and an ongoing investigation without attributing either. But the sequence now reads the way a standard double-extortion negotiation reads when it fails, and the published directory names are specific enough to ATF field operations that fabrication is the harder explanation.

Qilin is a Russian-linked ransomware-as-a-service operation first observed by researchers in 2022. Operators rent its tooling, break into a target, steal data, encrypt systems, and publish the victim's name to force payment. It is among the most prolific groups currently operating, with Cybernews reporting roughly 1,900 victims claimed over the past 18 months and 891 listed so far in 2026, and recent claimed victims including Sysco, Cushman & Wakefield, Danone, and the German political party Die Linke.

Two ATF agents in ATF Police plate carriers carrying carbines and helmets during a field operation
ATF fields roughly 2,400 Special Agents and 700 Investigators, per figures cited by Cybernews. The agency says the compromised system held information about targets of its investigations. (Credit: timesunion.com)

ATF eForms Is Named as Unaffected and Still Running

ATF singled out eForms by name as a system the incident did not reach, and the portal has stayed online and kept processing NFA applications through the disclosure. On August 26, eforms.atf.gov served its standard login page reporting version 3.6.3-2026-08-18 in the footer, with the usual Form 1 notice stating that the average processing time for a Form 1 submitted through eForms was 57 days in July. That tracks with the 59-day June average ATF published on its own processing-times page, so the queue is moving at its normal pace rather than stalling. Our suppressor wait-time tracker carries the running series for both ATF averages and dealer medians.

Two independent signals now point the same direction: the agency's own scope statement and the observable behavior of the portal. That is meaningfully stronger than uptime alone, which never proved much, because double extortion frequently involves stealing data without encrypting anything and produces no visible downtime at all. The remaining caveat is that ATF is describing an investigation still in progress, and first-week scope statements do get revised once forensics finish.

ATF eForms login page on August 26, 2026 showing the Form 1 processing notice and version 3.6.3-2026-08-18
The ATF eForms login page on August 26, 2026, still posting the Form 1 notice and a 57-day July average. (Credit: eforms.atf.gov)

What ATF Holds on Gun Owners

The reason a federal firearms agency being breached lands harder than a retail breach is the material ATF holds, even though the agency says none of it sat on the compromised system. A Form 1 or Form 4 submitted through eForms carries the applicant's name, address, date of birth, a photograph, and fingerprints, and on a trust or legal-entity filing it carries that same set for every responsible person. That is a far richer identity package than a leaked email list, and it is attached to a specific firearm application. Our Form 4 walkthrough covers exactly what goes into that submission, and our breakdown of what records the government actually keeps on gun owners covers the rest of the pile.

Approved applications populate the National Firearms Registration and Transfer Record, the federal registry that ties each registered suppressor, short-barreled rifle, machine gun, and other NFA item to the person or entity that registered it. Separately, when a licensed dealer closes, its Form 4473 records go to ATF's National Tracing Center in Martinsburg, West Virginia, and are imaged into the out-of-business records system. A 4473 carries the buyer's name, address, and date of birth alongside the make, model, and serial number of the firearm.

ATF's own position this year is that it collects more of this than it needs. The July 2026 proposed rule (RIN 1140-AA63) would drop individual applicants from two fingerprint cards to one, let any applicant submit a copy of a photo ID instead of the 2x2 passport photograph, and exempt trust responsible persons from fingerprints unless the FBI specifically asks. Comments close October 5, 2026, and the rule is not in effect. A confirmed intrusion anywhere inside the agency is the sharpest available argument for the position that rule already takes: every identity artifact ATF stops holding is one that cannot be stolen.

One broader change is already live. Since October 9, 2026, ATF does not enforce the Form 4 approval and registration requirements for suppressors, SBRs, SBSs, and AOWs, as a matter of enforcement discretion. Where state and local law allow an unregistered suppressor, a buyer can take one home on a 4473 and a NICS check without filing a Form 4 at all, and that transfer creates no new NFA registration record. Buyers in states that tie possession to federal registration can still file a voluntary eForm 4. Our suppressor buying guide tracks current eForm waits and which route applies.

Federal Agencies Have Been Hit Repeatedly This Year

ATF is the third confirmed federal incident of 2026, on top of a fourth last fall, and the closest parallel is the first one. In early March the FBI disclosed that intruders had reached the network used to manage court-authorized wiretaps and surveillance warrants, an intrusion the bureau later linked to China and classified as a major incident under the same federal cybersecurity law ATF is now operating under. With ATF's system now identified as its CALEA environment, both incidents land on the same functional category of infrastructure: the agency-side apparatus for court-authorized electronic surveillance. On July 3 the Department of Homeland Security said it was investigating a breach of the information-sharing network it uses with foreign law enforcement, which lawmakers described as exposing highly sensitive unclassified data.

Last fall a hack at FEMA exposed personal data belonging to FEMA and Customs and Border Protection employees. Cybernews reported separately that more than 75 percent of US government websites suffered a data breach in 2025. The pattern across those cases is worth noting for what happens next here: initial scope statements described contained intrusions, and the fuller picture arrived weeks later.

Shop Suppressors

SilencerCo Omega 36M product image
Suppressors • $993.65

SilencerCo Omega 36M

  • 5.7x28 to 9mm / 5.56 to .338 LM / .350 Legend
  • 17-4 stainless, titanium, Inconel, Cobalt 6
$993.65 Catalog
Shop at Silencer Central
SilencerCo Omega 9K product image
Suppressors • $636.65

SilencerCo Omega 9K

  • 9mm + .300 BLK rated
  • 4.54 inches
$636.65
Shop at Classic Firearms
SilencerCo Spectre 9 product image
Suppressors • $879

SilencerCo Spectre 9

  • 9mm and .300 BLK subsonic
  • 4.76 inches
$879.00
Shop at SilencerCo
SilencerCo Velos LBP 556 product image
Suppressors • $997.9

SilencerCo Velos LBP 556

  • 5.56 NATO
  • 3D-printed Inconel 625
$997.90
Shop at KYGUNCO
SilencerCo Velos LBP 556K product image
Suppressors • $1,164

SilencerCo Velos LBP 556K

  • .223 Rem and 5.56 NATO
  • 4.76 in
$1164.00 Catalog
Shop at Silencer Central
Rugged Obsidian 45 product image
Suppressors • $709

Rugged Obsidian 45

  • .45 cal rated
  • Modular length
$709.00
Shop at Classic Firearms

Affiliate links (?)

Scroll

Stay Updated on ATF Rules and NFA Filing

We track ATF rulemaking, eForm processing times, and the court decisions reshaping suppressor and SBR paperwork. One email a week, no noise.

Free targets, drill cards, and weekly reviews by email.

What to Do Right Now

For an ordinary NFA filer there is still no protective action to take. No category of applicant record has been identified as compromised, the published files reviewed so far are investigative rather than administrative, and no individual breach notice has gone out. ATF has named eForms as unaffected and described the hit system as isolated from case management. Two habits are still worth adopting while the investigation runs.

First, treat any email, text, or phone call referencing an ATF breach as hostile until proven otherwise. A confirmed federal incident is a phishing accelerant: impersonation campaigns follow the headlines and ask people to verify their information or re-authenticate an account. Treat any unsolicited request for your password or full identifying details as fraudulent, and confirm anything that looks official through eForms or ATF's own published contact channels.

Second, if the password on your eForms account is reused anywhere else, change it now. Credential reuse is a routine entry path for ransomware crews, and this is worth doing regardless of how the scope resolves. The thing to watch from here is ATF's response to the published trove: whether the agency authenticates the material, and whether its account of the scope survives contact with what is now sitting in public.

Frequently Asked Questions

▶Was the ATF actually hacked?
Yes. ATF confirmed a cybersecurity incident in a press release dated Wednesday, August 26, 2026, and senior Department of Justice officials designated the event a major incident under federal guidelines. ATF says the intrusion hit a standalone system that operates separately from its enterprise network, that it terminated connections to the affected environment on discovery, and that required notifications have been completed. On August 31, Qilin published what it says is the stolen material, so whether data left the system is now largely settled even though ATF has not itself confirmed a data theft. What ATF still has not said is when the breach happened or how the system was reached.
▶What system did the hackers get into?
ATF's CALEA system. Director Robert Cekada said on August 29, 2026 that the system involved was the ATF CALEA system, a standalone system the agency uses in connection with the Communications Assistance for Law Enforcement Act, the federal law behind court-authorized wiretaps and call-record orders. That is consistent with what an ATF spokesperson had told Recorded Future News three days earlier, describing a standalone computer holding information about targets of ATF investigations and connected to no other ATF system, including case management, laboratory, and eForms. In plain terms, this is enforcement-side surveillance infrastructure, not the paperwork pipeline ordinary gun owners pass through. ATF has still not said what categories of records the system held or how many people appear in them.
▶What is the ATF CALEA system?
CALEA is the Communications Assistance for Law Enforcement Act, signed into law on October 25, 1994. It requires telecommunications carriers and equipment makers to build their networks so that a specific subscriber's communications and call-identifying information can be isolated and handed to the government under proper legal authorization. It is the plumbing behind court-authorized wiretaps and call-record orders. An agency-side CALEA system is the equipment and process an investigating agency uses to work that pipeline. ATF has named the system but has not said what it stored, whether intercept content, subscriber and call-detail records, or only the administrative workflow around authorized requests.
▶Is my NFA Form 1 or Form 4 information at risk?
Based on what ATF has said, no. The agency's press release states there is no indication the incident affected the ATF enterprise network, the eForms system, or any other ATF system, and a spokesperson separately said the compromised machine was not connected to eForms or to case management systems. Nothing in the material Cybernews reviewed from the August 31 leak points at applicant paperwork either; the directories it describes are investigative and forensic. That is still the agency's own account of an investigation in progress, and scope statements issued in the first days of an incident do get revised as forensics finish. The exposure would be significant if that happened, because an eForms Form 1 or Form 4 carries the applicant's name, address, date of birth, photograph, and fingerprints, plus the same set for every responsible person on a trust.
▶What does a “major incident” designation mean?
It is a formal classification under the Federal Information Security Modernization Act, not a description of how bad the damage looks. OMB guidance reserves it for incidents likely to cause demonstrable harm to national security, foreign relations, the economy, or public confidence and civil liberties, and an agency that declares one has to notify Congress within seven days of identifying it. ATF says those required notifications have been completed. The designation tells you the government is treating this seriously enough to put it in front of Congress; it does not by itself tell you how much data moved.
▶Is ATF eForms down?
No. ATF's press release explicitly names eForms as unaffected, and the portal has stayed online and continued processing NFA applications through the disclosure. On August 26 eforms.atf.gov was serving its normal login page running version 3.6.3-2026-08-18, with the standard Form 1 notice reporting an average processing time of 57 days for July, in line with the 59-day June average ATF published on its own processing-times page. Nothing in the public portal's behavior suggests the queue was disrupted.
▶Did Qilin do it?
Qilin claimed it and has now published material to back the claim, though ATF has still not confirmed the attribution. The Russian-linked ransomware-as-a-service group added the Bureau to its dark web leak site on the morning of August 26, hours before ATF published its statement, posted a 72-hour ransom countdown on August 28, and marked the entry published on August 31 with a trove Cybernews measured at roughly 6.3GB. The published directory structure names ATF field offices outright, which is difficult to fabricate. ATF's statement still describes an incident and names no adversary.
▶What should NFA applicants do right now?
Nothing urgent, but two things are worth doing. Treat any email, text, or phone call referencing an ATF breach as hostile until proven otherwise, because a confirmed federal incident reliably draws phishing that impersonates the agency and asks applicants to verify their information or re-authenticate an account. And if your eForms password is reused on any other account, change it. Neither step depends on how the scope of this incident ultimately resolves.
Share
Pass the dispatch