Bureau of Alcohol, Tobacco, Firearms and Explosives Discloses Cyber Incident

After the Qilin ransomware group claimed to have breached the Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), the bureau confirmed the incident.
John Bruggeman, vCISO, CBTS, comments, “ATF’s actions after the Qilin ransomware gang claimed that AFT had been breached gives us a few clues about how prepared the agency was before this incident occurred. They indicated that they were able to quickly identify the compromised system as standalone and separate from the enterprise network, then terminate connections to the affected environment while broader systems remained operational. Quick response like that is a good sign that they are prepared for a data breach incident. You want that kind of clarity during an incident. You don’t want to wonder or try to figure out what systems connects to what. You also want to know who has the authority to isolate a compromised system after an attack, when you might not be sure if the attacker is still inside. ATF also moved quickly to make the required federal notifications and publicly address the incident, which suggests those response procedures were established and probably practiced.”
At this time, it is unclear when the incident took place or what data was exposed.
Bruggeman explains, “Beyond this being an attack on a Federal agency, the data involved makes this incident particularly sensitive. ATF has confirmed that intruders accessed a system containing information about targets of its investigations. This is the agency investigating firearms trafficking, illegal explosives, arson, and organized crime tied to the illicit alcohol and tobacco trade. When attackers reach investigative data, the real risk isn't exposed records, it's what those records could reveal about open cases, targets, and the people tied to them. I tend to think of the risk from what that information could reveal about investigations, the targets of the investigations, and potentially worse are the people involved in those cases.
“For organizations not dealing with this, you get a very useful exercise here. If one of your most sensitive systems were compromised today, could you identify everything it connects to and isolate it without taking down the rest of your business? The questions you want to ask yourself at a minimum are: Do you have an updated network diagram, or does someone have to reconstruct it from memory? Could you quickly determine what information an attacker could reach, and who to notify if it includes regulated data?
“If the answer depends on one person being available, you don't have an answer, you have a risk, you have a single point of failure. If you can't work through these questions before an incident, you won't have time to work through them while an attacker is in your environment.”
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!








