For a brief period on Monday, the Russian-linked ransomware group Qilin posted over 6GB of files it claimed were stolen from the Bureau of Alcohol, Tobacco, Firearms and Explosives.
The dump followed last week’s public listing of the ATF on Qilin’s leak site, first reported by AmmoLand News. Although the files have not been officially authenticated by the bureau, AmmoLand News sources inside the ATF have said the material is genuine.
Qilin is a Russia-based cybercrime syndicate that sells ransomware-as-a-service. Affiliates use its tools to break into target networks, steal data, and then post a countdown on Qilin’s dark-web blog. If the ransom is not paid by the deadline, the group publishes the stolen files. The ATF timer hit zero on Monday. Qilin then released more than six gigabytes of data for a short window before taking the files down. When Qilin pulls a dump, it often means a ransom was paid. There is no public evidence that the ATF paid.
Even after the files disappeared, enough of the package was recovered to identify the compromised environment. The breached system was the ATF’s Communications Assistance for Law Enforcement Act (CALEA) system.
Click the link to read the whole article: Hackers Leak ATF Investigation Files
No comments:
Post a Comment