ATF declares ‘major incident’ as ransomware gang claims hack

ATF declares ‘major incident’ as ransomware gang claims hack

美国烟酒枪炮及爆炸物管理局(ATF)宣布发生“重大事件”,勒索软件团伙声称对此负责

The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives, or ATF, says a cyberattack on one of its systems has been declared a “major incident,” a formal, legally defined classification that prompts a formal notification to lawmakers in Congress.

美国烟酒枪炮及爆炸物管理局(ATF)表示,其系统遭受的网络攻击已被定性为“重大事件”。这是一个正式的法律定义分类,要求必须向国会议员提交正式通知。

ATF said in a statement that it’s responding to the cyberattack on a stand-alone system that’s separate from the bureau’s network. An ATF spokesperson told reporters that the targeted computer system contained information such as the “targets of ATF investigations.”

ATF 在一份声明中表示,他们正在应对针对一个独立系统的网络攻击,该系统与局内的主网络是隔离的。ATF 发言人告诉记者,被攻击的计算机系统包含诸如“ATF 调查目标”等信息。

TechCrunch has seen a claim of responsibility by the Qilin ransomware gang on its leak site, but it did not provide evidence for its claim, such as a sample of leaked data. Qilin is known for running a “ransomware-as-a-service” operation, in which it leases its hacking tools to other criminal affiliates for a cut of the profits. The gang has listed media giant Lee Enterprises and U.K. pathology lab giant Synnovis as targets.

TechCrunch 已在其泄密网站上看到 Qilin 勒索软件团伙发布的认领声明,但该团伙并未提供证据(如泄露数据样本)来支持其说法。Qilin 以运营“勒索软件即服务”(RaaS)而闻名,即通过将黑客工具出租给其他犯罪分支机构来获取利润分成。该团伙曾将媒体巨头 Lee Enterprises 和英国病理学实验室巨头 Synnovis 列为攻击目标。

Under federal law, “major incidents” include significant cyber incidents that are likely to cause demonstrable harm to U.S. national security or broader U.S. interests. Agencies are required to disclose major incidents to Congress within a week of their discovery.

根据联邦法律,“重大事件”包括可能对美国国家安全或更广泛的美国利益造成明显损害的重大网络事件。各机构必须在发现重大事件后的一周内向国会披露。

The ATF joins several government agencies in recent years that have declared major incidents following a breach, including a 2023 ransomware attack on a system used by the U.S. Marshals Service, and a breach of an FBI system earlier this year that exposed phone numbers of targets under surveillance by federal agents.

近年来,已有多个政府机构在遭遇入侵后宣布发生“重大事件”,ATF 此次也位列其中。此前案例包括 2023 年美国法警局(U.S. Marshals Service)使用的系统遭受勒索软件攻击,以及今年早些时候 FBI 系统遭入侵,导致联邦特工监控目标的相关电话号码泄露。