Congress Must Rein In ATF’s Billion-Record Gun Archive After Qilin Breach

For thirty years, the same story has repeated itself inside the Bureau of Alcohol, Tobacco, Firearms and Explosives: Congress bars the agency from building anything that looks like a national gun registry, ATF quietly builds something that comes close anyway, and it takes an outside audit, sometimes a decade or more later, to catch it. A review of a Government Accountability Office (GAO) audit, ATF’s own internal technical manuals released under the Freedom of Information Act, and a 2022 report from Gun Owners of America lays out just how close, and just how poorly secured, ATF’s records empire has become. To be fair to the agency, most of the specific security holes exposed over the years have since been fixed. But several still exist, and the ones that remain go to the heart of whether ATF’s records can be trusted at all.
The numbers alone should stop every gun owner in their tracks. ATF’s Out-of-Business Records Imaging System, known as OBRIS, held roughly 297 million images as of 2016. By November 2021, according to ATF’s own letter to Congress, that number had ballooned to 920,664,765 records, with 865,787,086 already digitized. It has since grown past a billion records, according to new figures detailed in a separate report. That is not a filing cabinet. That is one of the largest repositories of firearm-owner-linked personal data anywhere in the federal government, and it keeps growing.
Then, The ATF Got Hacked
This report was largely finished when the story took an unplanned turn. On August 26, 2026, the Russian-speaking ransomware gang Qilin, a rebrand of the older Agenda ransomware operation with more than 2,200 claimed victims, posted ATF to its dark-web leak site, claiming to have broken into the agency’s systems. ATF confirmed the breach within hours. The Department of Justice designated it a “major incident,” the classification that triggers mandatory notification to Congress.
ATF’s line, delivered through Chief of Public Affairs Tanya Roman, was reassuring on its face. The compromised system was standalone and tied to the agency’s CALEA infrastructure, used to handle court-authorized communications intercepts in criminal cases. According to ATF, it was not connected to any other ATF systems, including case management, laboratory, or eForms systems, and there was no indication the incident had affected the ATF enterprise network or any other ATF system. In plain terms: not the same database at the center of this report. As of late September, ATF has not said it has any indication that gun-purchase records, Forms 4473, or the OBRIS out-of-business repository were touched.
That reassurance held for five days. On August 31, Qilin’s ransom countdown expired, and the gang briefly posted roughly 6.3 gigabytes of files before pulling them back down, plenty of time for reporters to see what was inside. According to CNN and other outlets, the trove included the names of criminal investigation targets, phone numbers, IP addresses, iCloud data, and Cellebrite phone-extraction dumps. It was drawn from cases involving armed robbery, arson, explosives, and homicide, with a heavy concentration of files traced to ATF’s Houston Field Division. By Monday, September 1, ATF’s public posture had softened from denial to agnosticism: the agency said it “cannot confirm the authenticity, nature, or scope” of what Qilin published. Nearly a month later, it has offered no fuller accounting.
No one has yet produced evidence that OBRIS itself, the over-a-billion-record repository at the center of this report, was part of what Qilin took, and this report won’t claim otherwise. But watch the shape of ATF’s defense: a “standalone” system, walled off, nothing to see here. That is the identical assurance ATF has given gun owners for a decade about OBRIS’s disabled name-search feature, a policy promise, not a demonstrated architectural fact.
Texas Gun Rights president Chris McNutt said in the days after the breach that gun owners are entitled to a full accounting, both of what was compromised and of what the federal government keeps on them in the first place. His group put the broader principle more bluntly: “The government cannot lose information it never collected in the first place.” Gun owners are now being asked to trust that the database holding a record of nearly every firearm ever sold by a defunct dealer is walled off any better than the system Qilin just walked into.
A Registry Built on Trust ATF Hasn’t Earned
Congress has tried to head this off for decades. The Firearms Owners’ Protection Act (FOPA) bars any new rule that would create a “system of registration of firearms, firearms owners, or firearms transactions.” A separate appropriations rider, renewed every year since 1978 and made permanent in 2012, bars ATF from spending a dime to “consolidate or centralize” dealer records. And a third rider specifically forbids ATF from retrieving out-of-business records “by name or personal identification code.”
ATF’s defense has always been the same: the records aren’t searchable by name, so it isn’t a registry. The Congressional Research Service repeats that position, describing the digitized records as images that optical character recognition can’t read and that can be pulled only to complete a firearm trace. But that describes how ATF says it uses the system, not what the system can do. The FOIA production obtained under request 2020-0802 tells a more complicated story. ATF’s scanning and content-management software for building OBRIS comes from IBML and OpenText, as documented in ATF’s own vendor manuals and work instructions. Those commercial platforms include optical character recognition, intelligent handwriting recognition, and full-text search. The documents don’t settle one question: whether ATF’s licensed installation includes those features, or whether they were left out or stripped away. ATF has never publicly answered it. The record does show that name search is turned off in the interface. Nothing in ATF’s own paperwork shows the capability was ever removed at the database level, or that it was never there to begin with. Gun owners are being asked to accept that uncertainty on faith. A policy is not a wall. A policy is a setting, and settings can be changed.
Caught Red-Handed — Twice
This isn’t speculation. GAO’s 2016 report, titled bluntly “ATF Did Not Always Comply with the Appropriations Act Restriction,” found that ATF had spent sixteen years, from 2000 to 2016, pooling out-of-business dealer records from its Access 2000 program onto a single server at the National Tracing Center, in direct violation of the anti-consolidation law. ATF’s own Chief Counsel had separately determined in 2009 that a program called the “Southwest Border Weapons of Choice” initiative illegally collected non-investigative dealer inventory data for two years running. It took ATF until March 2016, six and a half years after its own lawyers flagged the violation, to actually delete the data.
GAO went further: because ATF had no lawful appropriation to do any of this, the violation also triggered the Antideficiency Act, a law that requires an agency head to report the violation immediately to the President, Congress, and the Comptroller General. GAO found no evidence that the report was ever filed. Nobody was held accountable. The data just sat there until an audit forced its hand.
A Bug That Let Agents See What Policy Said They Couldn’t
Perhaps the most alarming finding in the 2016 report has nothing to do with policy at all; it’s a straightforward technical failure. ATF’s Firearm Recovery Notification Program is supposed to shield purchaser and dealer identities from agents who don’t need them. But when the eTrace 4.0 system rolled out in 2009, it shipped with a global print function that let any agent with basic access print up to 500 full purchaser records in a single batch — names included. ATF knew about the defect before the system ever went live. By the time GAO published its report seven years later, it still hadn’t been fixed, and ATF admitted it kept no audit logs showing whether, or how many times, agents used that loophole to pull data they were never supposed to see.
To ATF’s credit, it has since closed that hole. The print defect has been fixed, and the system now keeps an audit log of who accesses what.
But notice what the fix doesn’t do. An audit log only records what happens after it is switched on. For the years the loophole sat open, there is no record, and there never will be. ATF cannot tell anyone whether that gap was ever exploited, by whom, or how many purchaser names walked out the door. The agency shipped a privacy safeguard broken, knew it was broken, left it broken for years, and fixed it only after an outside auditor put it in writing. That is the pattern this report keeps finding: ATF fixes problems after they are exposed, rather than preventing them.
Paper Records Stacked to the Ceiling
It isn’t just the software. As of 2016, roughly 8,060 boxes of unscanned paper dealer records were piled up at the National Tracing Center in Martinsburg, West Virginia, nearing a 10,000-box limit that GSA itself warned could put the building’s floor at risk of structural failure. Overflow records ended up stored in outdoor shipping containers.
The digital side has improved, but only halfway. Records are now encrypted once they are inside ATF’s system. Getting them there is another story. Dealers can still email their records to ATF, and ATF still accepts them unencrypted. There is no requirement to encrypt the file and no secure upload portal. A closing dealer’s entire customer history, with names, addresses, and Social Security numbers, can still cross the open internet like a grocery list, and be protected only after it arrives.
That gap is ATF’s to close. Federal law requires dealers who go out of business to turn their records over to ATF. If the government is going to require dealers to hand over a lifetime of customer data, it must give them a secure way to do it. That means an encrypted upload system built for the job, with unencrypted email no longer accepted. Encrypting records after they arrive does nothing to protect them on the way in, and the way in is where they are most exposed.
The Mission Keeps Creeping
Even the boundary of what counts as an “out-of-business” record has proven elastic. Gun Owners of America’s May 2022 report, built substantially on the same FOIA release, documents that ATF has, through internal rulings and standing orders rather than any actual rulemaking, “strongly recommended” that active, still-operating dealers voluntarily ship records older than 20 years into the same Out-of-Business Records Repository, years before those dealers ever close their doors.
Fifty-two members of Congress raised nearly the exact same concern with the ATF in November 2021, citing the 2016 GAO report by name. ATF’s written answer brushed it off as old news about “a discrete situation.”
History suggests otherwise: an unreviewed data-collection program, run by internal memo instead of law, is precisely the pattern that produced ATF’s last two confirmed violations.
Not Just ATF: A Justice Department Pattern
ATF is not an outlier. Over the past four years, the DEA, the U.S. Marshals Service, and the FBI have all had sensitive systems breached. Each of them, like ATF, answers to the Department of Justice, and the details read like a dress rehearsal for what just happened to ATF.
DEA, 2022.
In May 2022, intruders used a local police officer’s stolen credentials to enter the DEA’s EPIC System Portal. EPIC is a DEA-led, multi-agency intelligence center, and ATF is part of it: a 2017 DOJ inspector general report documented ATF analysts working in its Firearms and Explosives Intelligence Unit and recorded 1,609 ATF queries of EPIC’s Law Enforcement Inquiries and Alerts system in fiscal 2015, most commonly for firearms investigations. At the time of that review, LEIA searched 18 law enforcement databases, including DOJ systems. The criminal complaint says Sagar Singh entered the portal with a stolen username and password and shared them with Nicholas Ceraolo; it also says some linked databases required separate credentials they did not have. KrebsOnSecurity reported that screenshots showed options to look up firearms and other property, and that a source said the login prompted for no second authentication factor. The public record does not establish that the intruders retrieved firearm-ownership records. What it does establish is troubling enough: criminals entered an intelligence portal used by an ATF-staffed center and exploited information from it to threaten victims. Both men later pleaded guilty and were sentenced to prison.
U.S. Marshals Service, 2023.
In February 2023, the Marshals Service discovered a “ransomware and data exfiltration event” that affected a “stand-alone” system. According to the agency, the affected system held law enforcement sensitive information, including returns from legal process, administrative information, and personal data on subjects of Marshals investigations, third parties, and certain employees. The hacked network belonged to a secretive unit called the Technical Operations Group, which provides surveillance capabilities to track fugitives. Officials determined that it constituted a major incident. The stolen files didn’t stay put: the data was put up for sale in March 2023 on a Russian-speaking hacking forum, and it resurfaced on the Hunters International ransomware gang’s leak site in 2024. It wasn’t the agency’s first failure, either. In a December 2019 incident, the Marshals accidentally exposed the details of over 387,000 former and current inmates, including names, dates of birth, home addresses, and Social Security numbers.
A “stand-alone” system. Surveillance data. A “major incident.” Three years before ATF, the Marshals Service used nearly the same words, and the data still ended up for sale on a Russian forum.
FBI wiretap network, 2026.
This year the FBI itself was hit, in one of its most sensitive systems. An inquiry into abnormal activity on the network the bureau uses to manage wiretaps and other surveillance work opened on February 17. The affected system contains data from electronic surveillance and personal identification information on subjects of bureau investigations, and senior Justice Department officials determined on March 23 that the intrusion was a “major incident”. The attackers got in through a vendor ISP connected to the FBI’s network, and the Wall Street Journal reported that investigators suspect Chinese government-affiliated hackers.
FBI personnel data, September 2026.
Only last week, the extortion group ShinyHunters claimed it had breached the FBI’s online jobs portal and stolen information on almost all FBI agents and job applicants. The FBI confirmed on September 26 that it is dealing with a “cybersecurity incident.” Journalists who reviewed a sample of 5,000 records found names, home addresses, phone numbers, dates of birth, and Social Security numbers, with some records including spouse and emergency contact details. The group’s price isn’t even money. ShinyHunters says it is holding the data while demanding the FBI withdraw a statement the bureau issued about the group in May.
The CALEA Thread
Look closely, and a common target emerges: surveillance infrastructure. ATF’s breached system was its CALEA intercept system. The FBI’s breached network manages wiretaps. And in 2024, China’s Salt Typhoon campaign compromised the networks of at least nine major U.S. telecommunications carriers and reportedly accessed the lawful intercept systems used by U.S. law enforcement. The systems Washington built to watch suspects have become the doorway foreign hackers and criminal gangs use to watch Washington.
The lesson for gun owners is straightforward. “Standalone” is not a guarantee, and a “major incident” designation comes after the damage, not before it. If the FBI, the nation’s lead cyber agency, cannot keep its own wiretap network and personnel files out of hostile hands, there is no reason to trust ATF’s over-a-billion-record, out-of-business repository as any safer.
The door that’s open right now. The threat isn’t just in the past. This past weekend, Citrix confirmed that two critical NetScaler remote code execution vulnerabilities are being exploited in attacks. NetScaler appliances are the gateways many organizations use for VPN access, load balancing, and user authentication, which makes them the front door to a network. Attackers exploited these flaws as zero-days before any fix existed. The first one lets an unauthenticated attacker run any command they want on the appliance, and it affects every NetScaler ADC and Gateway deployment, including those running the default configuration.
The warning signs came before the fix. Starting September 26, suppliers and security teams told NetScaler administrators to shut down their appliances after a private warning from the Dutch National Cyber Security Center. NetScaler is common enough across the federal government that CISA ordered every federal civilian agency to secure its vulnerable appliances by September 30. CISA also warned agencies that suspect a compromise to preserve forensic evidence before patching, because updating can erase the traces an attacker left behind. In other words, patching closes the door but doesn’t tell you whether someone already walked through it.
It isn’t a one-off, either. This is at least the third actively exploited NetScaler flaw since August. In late August, CISA gave federal agencies three days to fix another NetScaler vulnerability that attackers were already exploiting to plant web shells. Shadowserver counts more than 23,000 NetScaler instances exposed to the internet.
But the point stands. The same commercial gateway products sit at the edge of agency after agency, and every newly exploited flaw is a race between federal IT staff and attackers. Every system holding firearm-owner data sits behind a gateway like this one. How fast those gateways get patched, and whether anyone checks for intruders before patching, can decide whether a billion records stay walled off or end up on a Russian-language leak site.
DOJ’s Job, Not Just ATF’s
Every public statement about the Qilin breach so far has come from one office: ATF’s Chief of Public Affairs. That’s worth pausing on, because ATF doesn’t actually own its cybersecurity. Under the Federal Information Security Modernization Act (44 U.S.C. Chapter 35), the legal duty to protect an agency’s information systems sits with the head of the parent department, not the component bureau. ATF is a component of the Department of Justice. For information security policy, system authorization, and incident response, ATF answers up to DOJ’s Justice Management Division and the Office of the Chief Information Officer housed inside it, the office that is supposed to set the rules ATF’s IT staff follow and certify whether a system like the one Qilin broke into was secure enough to be plugged in at all.
That chain of responsibility matters for a second reason: “major incident” isn’t editorial color; it’s a legal trigger. Under OMB Memorandum M-25-04 and 44 U.S.C. § 3554(b)(7)(C)(iii)(III), an agency that designates a breach a major incident has seven days to notify the authorizing and appropriations committees of both chambers of Congress, plus, where personal data is involved, the House Committees on Oversight, Homeland Security, and Science, and the Senate Committees on Homeland Security and Governmental Affairs, Commerce, and Judiciary, and to loop in its own Inspector General. That clock is a department-level obligation. Coverage of the breach describes ATF as coordinating with DOJ on the response, but none of it quotes an independent DOJ statement, only ATF’s public affairs office speaking for both.
There’s a reason to wonder whether DOJ is the reassuring voice gun owners should want here. A 2024 DOJ Inspector General audit of JMD’s own information security program, the same office chartered to set the security bar for ATF and every other component, found weaknesses in four of the nine FISMA domain areas it tested, plus a gap tied to a congressional letter on telework security vulnerabilities. That’s the department’s central cybersecurity apparatus failing its own checkup, years before Qilin got near ATF’s servers. Meanwhile, the public list of OIG reports on ATF runs to 121 and counting, heavy on firearms-trace management, dealer inspections, and recordkeeping, but nothing in that list resembles a dedicated audit of the bureau’s network security or FISMA compliance. ATF’s paper trail has been picked for over thirty years. Whether its digital perimeter has ever been tested with the same rigor is, on the public record, an open question.
There’s a reason to wonder whether DOJ is the reassuring voice gun owners should want here. The DOJ Inspector General’s most recent audit of JMD’s own information security program covered fiscal 2024. JMD is the office chartered to set the security bar for ATF and every other component, and the audit found weaknesses in two of the nine FISMA domain areas it tested, plus a vulnerability left unresolved from the year before. That’s the department’s central cybersecurity apparatus falling short on its own checkup, two years before Qilin got near ATF’s servers. Meanwhile, the public list of OIG reports on ATF runs to 121 and counting, heavy on firearms-trace management, dealer inspections, and recordkeeping, but nothing in that list resembles a dedicated audit of the bureau’s network security or FISMA compliance. ATF’s paper trail has been picked apart for over thirty years. Whether its digital perimeter has ever been tested with the same rigor is, on the public record, an open question.
What Needs to Happen Now
Until late August, none of the sources reviewed for this report documented a proven external hack of ATF’s firearms database, and this piece still won’t claim that OBRIS itself has been breached. But the Qilin incident proves the underlying fear isn’t hypothetical. ATF’s systems can be broken into. The agency’s first instinct is to insist the damage is contained to a walled-off corner. And the public is left to take that on faith until a leak site forces a fuller accounting. The same pattern has now played out at the FBI, the U.S. Marshals Service, and the DEA. This is not one agency’s bad luck. It is a Justice Department problem.
ATF deserves credit where it has earned it. When GAO auditors came in, the agency accepted the findings rather than fighting them, and it has addressed several concerns honestly. The eTrace print loophole has been closed, and the system now logs who accesses purchaser records. Dealer records are encrypted once they reach ATF’s system. ATF deleted the illegally consolidated Access 2000 data and the Southwest Border inventory data. The current ATF has also been open with AmmoLand News, answering questions directly instead of hiding behind boilerplate.
So let’s be clear about what this report is and isn’t saying. Today’s ATF is not the problem. The problem is the ATF that comes after it. Administrations change, and directors change with them. A future president hostile to gun owners would inherit everything described in this report. That includes a repository with over a billion records, built on software with full-text and handwriting search already installed. Name-search is blocked by a setting, not by the architecture. Record intake has expanded by internal memo rather than by rulemaking. The whole system rests on the agency’s promise that it will never be used as a registry. Those safeguards can be undone by the people in charge. A hostile ATF wouldn’t need to build a registry. It would only need to switch one on.
To be fair, ATF didn’t invent this repository on its own. Federal law, 18 U.S.C. § 923(g)(4), requires a dealer who goes out of business to turn their records over to the government, and ATF is the agency that has to receive them. That’s exactly why this can’t be left to ATF alone. The agency can make the system more secure, but only Congress can decide whether a billion records need to sit in one federal building at all. Technical and legal fixes have to happen together.
That’s why the time to act is now, while the agency is cooperative and the fixes can be made in good faith rather than forced in a fight. Protections that depend on who holds office aren’t protections. They must be built into the system and written into law, so no future administration can quietly reverse them, and no outside hacker can exploit them. Congress should demand answers on seven fronts:
-
- Full disclosure of the Qilin breach. ATF and DOJ should say exactly what Qilin obtained, and whether any technical pathway ever connected the compromised CALEA system to OBRIS, A2K, or eTrace. “Standalone” should be demonstrated, not asserted
- An independent technical audit of name-search. Someone outside ATF should confirm that name-search is disabled at the database level, not just switched off in a menu. A setting that can be turned off can be turned back on.
- A secure, encrypted upload system for dealer records. If the law requires dealers to surrender a lifetime of customer records, ATF must give them a secure way to do it. It should stop accepting unencrypted emailed records, so dealer data is protected in transit and not only after it arrives.
- A public accounting of access. ATF should disclose who has access to a database now with more than a billion records, and what background standard they had to meet to get it.
- A hard stop on records expansion outside rulemaking. ATF should stop quietly expanding what records it accepts, including its push for active dealers to send in records older than 20 years, outside the rulemaking process the law actually requires.
- A department-wide security review. The DOJ Inspector General should conduct a dedicated FISMA audit of ATF’s own network, and a broader review of why DOJ components keep losing sensitive data from systems described as “standalone.” That review should cover the Marshals in 2023, the FBI’s wiretap network and personnel data in 2026, and now ATF.
- Revisit the law that created the repository. Congress wrote the out-of-business records requirement, and Congress can change it. At minimum, it should decide whether decades-old records with no connection to any trace need to be kept forever, or whether they can be purged after a set period. It should also weigh whether records have to be centralized in a single federal repository at all. Tracing can work without the government holding a permanent, near-complete archive of who bought what. Every record that isn’t collected is a record no future administration can misuse, and no hacker can steal.
Thirty years of audits have produced the same conclusion every time: ATF says the records aren’t a registry, and then an outside auditor finds a program, a server, or a software bug that says otherwise. Today’s ATF has accepted those findings, fixed a number of them, and been more transparent than many of its predecessors. But that is exactly why this is the moment to finish the job. A database of more than a billion records will outlast any director and any president. The question isn’t whether gun owners can trust this ATF. It’s whether they can trust every ATF that comes after it, under every administration yet to be elected. The only safe answer is a system that doesn’t require that trust at all, one that can’t be switched on as a registry and can’t be broken into by the next Qilin. Congress has a cooperative agency and a narrow window. It should use both.
About John Crump
Mr. Crump is an NRA instructor and constitutional activist with more than 26 years of experience in networking and cybersecurity for major Fortune 100 companies. John has written about firearms, the Constitution, and cybersecurity, and has interviewed people from all walks of life. John lives in Northern Virginia with his wife and sons. Follow him on X at @right2bear, or at www.crumpy.com.
