黑客泄露从美国司法部窃取的敏感执法文件


2026-08-31T17:11:15.798Z / 美国有线电视新闻网(CNN)

作者:肖恩·林加斯(Sean Lyngaas)

更新于31分钟前
更新于美国东部时间2026年8月31日下午3:37
发布于美国东部时间2026年8月31日下午1:11

数字安全 联邦机构 俄罗斯

image

2022年7月,华盛顿特区烟酒火器与爆炸物管理局(ATF)总部讲台上的该局标识。

塞缪尔·科鲁姆 摄 / 盖蒂图片社 资料图

一个疑似操俄语的网络犯罪团伙于周一泄露了其从美国司法部烟酒火器与爆炸物管理局窃取的疑似敏感执法文件。

据美国有线电视新闻网和一名独立网络安全研究人员对数据的审查,此次泄露的文件似乎包含过往烟酒火器与爆炸物管理局调查目标的信息,以及对他们手机通讯的分析内容。部分文件涉及特定烟酒火器与爆炸物管理局探员以及他们参与的知名案件。

该研究人员罗恩·法贝拉(Ron Fabela)表示,这批数据涵盖与武装抢劫、纵火、爆炸物案件和凶杀案相关的调查。他还提到,文件中提及的案件有很大一部分属于该局休斯顿外勤分局的工作范畴。

烟酒火器与爆炸物管理局周一在一份声明中称,目前“无法证实泄露数据的真实性、性质或范围”,该机构正与司法部及其他联邦机构合作,“评估相关情况并采取适当行动”。

“正如烟酒火器与爆炸物管理局此前所言,受影响的系统并未连接至——且此次事件也未波及——该局其他业务系统。该局履行职责的能力未受影响,”该机构的声明补充道。

烟酒火器与爆炸物管理局上周首次披露此次黑客攻击事件,称其达到了需要通知国会的“重大”网络安全事件标准。根据联邦法律,“重大”网络事件通常指可能损害美国国家安全、外交政策或经济利益的事件。

一个名为麒麟(Qilin)的活跃勒索软件团伙此前已宣称对此次入侵负责;周一,该团伙开始在其暗网受害者网站上泄露文件。近年来,该团伙以制造业、零售业和医疗行业为攻击目标,思科公司的网络情报部门因此将其列为“全球范围内最活跃、破坏性最强的勒索软件威胁之一”。

另一家追踪勒索软件团伙的网络安全公司哈尔西恩(Halcyon)表示,该公司“有高度把握”认定麒麟团伙为俄语使用者。

此次烟酒火器与爆炸物管理局遭黑客攻击,是联邦机构面临的又一困扰——这些机构本就时常追捕网络犯罪分子。2023年,美国法警局遭遇勒索软件攻击,导致该局调查对象的个人信息泄露。同年,据知情人士透露,黑客入侵了联邦调查局纽约外勤办公室用于调查儿童色情制品图像的计算机系统,其中包括用于存储与杰弗里·爱泼斯坦案相关图像的系统。

数字安全 联邦机构 俄罗斯

Hackers leak sensitive law enforcement files stolen from the DOJ

2026-08-31T17:11:15.798Z / CNN

By Sean Lyngaas

Updated 31 min ago

Updated Aug 31, 2026, 3:37 PM ET

PUBLISHED Aug 31, 2026, 1:11 PM ET

Digital security Federal agencies Russia

The Bureau of Alcohol, Tobacco, Firearms, and Explosives logo is seen on a podium at the ATF headquarters in Washington, DC, in July 2022.

Samuel Corum/Getty Images/File

A likely Russian-speaking cybercriminal gang on Monday leaked what appear to be sensitive law enforcement files it stole from the Justice Department’s Bureau of Alcohol, Tobacco, Firearms and Explosives.

The dumped files appear to include information on targets of past ATF investigations and analyses of their phone communications, according to a review of the data by CNN and an independent cybersecurity researcher. Some of the files correspond to specific ATF agents and high-profile cases they apparently worked on.

The data cover investigations related to armed robbery, arson, explosives and homicide, according to the researcher, Ron Fabela. A chunk of the cases mentioned in the files fall under the work the ATF’s Houston Field Division, Fabela said.

In a statement on Monday, ATF said it “cannot confirm the authenticity, nature, or scope” of the leaked data at this time and that the agency was working with the Department of Justice and other federal agencies to “assess the claims and take appropriate actions.”

“As ATF previously stated, the affected system was not connected to – and the incident did not affect – ATF’s other operational systems. ATF’s ability to carry out its mission has not been impacted,” the agency’s statement continued.

ATF originally disclosed the hack last week, saying it met the threshold for a “major” cybersecurity incident that requires notifying Congress. Under federal law, a “major” cyber incident is generally one that could harm US national security, foreign policy or economic interests.

A prolific ransomware group called Qilin previously claimed responsibility for the breach; on Monday, the group began leaking the files from its dark -web victim site. The group has claimed victims in the manufacturing, retail and healthcare sectors in recent years, leading Cisco’s cyber-intelligence unit to brand it one of the “most prolific and damaging ransomware threats on a global scale.”

Halcyon, another cybersecurity firm that tracks ransomware groups, has said it has “high-confidence” that Qilin are Russian speakers.

The ATF hack is the latest headache for federal agencies involving the cybercriminals they often pursue. A 2023 ransomware attack on the US Marshals Service affected personal information of the subjects of the service’s investigations. That same year, hackers breached a computer system the FBI’s New York field office used in investigations of images of child sexual exploitation, including a system used to store images related to the investigation of Jeffrey Epstein, according to people briefed on the matter.

Digital security Federal agencies Russia

评论

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注

湘ICP备2026001899号-2