Go Phish: How the ATF and CISA Got Hooked — And How Mark Gough Spotted the Bait
![]() |
| By Dawn Pennington |
“They got to me!”
Just a few days ago, Mark Gough wrote to you about how the “Trezor Data Breach Raises Serious Security Concerns.”
Now, Trezor scammers have just hit his inbox.
Mark said this was a very good attempt. And he’s thrilled we put Weiss Crypto Daily readers on high alert beforehand.
But wait, you may say. That is a real support address … and looks like a real email from a real company!
That’s why it was such a good attempt.
Trezor’s newest statement confirmed that phishing emails had gone out from its official domain.
Unfortunately, that’s the digital world we live in now.
As we get smarter about spotting a scam, hackers have cleaned up their acts … and their spelling and grammar.
This ongoing problem serves as a good reminder to us all that there are weak links in the crypto ecosystem. Even though blockchains themselves are largely secure.
It isn’t just crypto companies that take a hit.
Sometimes it’s entire governments.
And, just like Trezor users are experiencing, multiple hits are becoming more common.
The ATF Just Got Hacked
The U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives just quietly filed a notice with Congress.
That was after what federal law calls a "major incident." A cyberattack serious enough to trigger mandatory disclosure to lawmakers within a week of discovery.1
The ransomware gang Qilin claimed responsibility on its leak site.
Qilin hasn't yet produced sample data or any other verified breach evidence.
What we do know, via an ATF spokesperson, is this …
The compromised system held live law enforcement intelligence about targets of active ATF investigations.2
We also know this wasn’t the first time cyber criminals came within inches of stealing sensitive government data.
The ATF now joins the U.S. Marshals Service, which reported a major incident in 2023.
There was also an FBI system breach earlier this year that exposed phone numbers tied to active surveillance targets.3
Anyone With Data to Protect … Has a Target on Their Back
Perhaps you don’t have classified data on your phone or laptop.
Or maybe you use a different crypto wallet than Trezor.
But what you do have is still valuable to a cyber thief.
If an agency with a three-letter name, a badge and a mandate to hunt down criminals can get hit …
How does anyone with a Social Security number and something to lose stand a chance?
Especially when the ATF breach isn't even the most notable cybersecurity story out of Washington.
This Would Be Ironic if it Weren’t So Terrifying
That distinction arguably belongs to the Cybersecurity and Infrastructure Security Agency.
In case you didn’t know, CISA is the very agency tasked with defending the nation's networks.
It experienced a major incident not once but twice in recent memory.
Major Incident No. 1
In January 2024, CISA's own Chemical Security Assessment Tool was breached by a malicious actor.
By CISA's own account, the intruder installed an advanced webshell on its Ivanti Connect Secure device.
It was capable of executing commands and writing files to the underlying system.
Now, the agency found no confirmed evidence that data was exfiltrated.
But the intrusion may have exposed security plans and user accounts tied to the Chemical Facility Anti-Terrorism Standards program.
The scale of the breach met the legal threshold for a "major incident."
That’s the same classification triggered by the ATF breach4 we talked about earlier.
Major Incident No. 2
This past May, CISA opened another internal incident response.
This was after a journalist asked about its cloud credentials sitting exposed on GitHub.
A security researcher's firm — one that continuously scans public repos for leaked secrets — found roughly 844 megabytes of sensitive CISA-related data sitting in the open on GitHub.
It took about 26 hours to get that data taken down once flagged.5
To its credit, CISA didn't bury this story, either.
On July 9, the agency published a public postmortem, co-authored by its acting chief information officer and chief information security officer.
The notice called incidents like this "not a matter of 'if,' but 'when.'"
Nothing illustrates the need to take this seriously quite like watching the top of the pyramid get hit twice.
Nobody's Off-Limits — Including Us
We know this firsthand, after a bad actor posed as one of our crypto team members.
Fortunately, our readers are savvy.
They found the Online Fraud center on the Weiss Ratings website.
And they reported the scam immediately.
That’s how we beat the bad guys. By being aware and ready to question whether communications are truly legitimate.
We here at Weiss welcome the opportunity to verify whether a communication was real.
Especially as technology takes a literal quantum leap … which may temporarily break even some of the most trusted systems.
The instinct to treat cybersecurity as someone else's problem —banks, crypto companies and exchanges, brokers, the government — is exactly the instinct that gets people burned.
The ATF and CISA had presumably serious infrastructure and a mandate around it.
And look what happened to them.
Your Five-Step Cyber Checkup
For crypto holders specifically, the Trezor incident is a useful prompt to run through the basics.
Not because they're novel. But because most people know them and still don't do them.
Find some time this week to run a cyber checkup where you …
- Get real custody clarity.
If you don't hold your keys, you don't fully control the asset — you're trusting someone else's security posture.
As the ATF and CISA proved, even well-resourced institutions get breached.
That doesn't mean self-custody is right for everyone. But it means knowing the trade-off you're actually making.
- Cold storage for anything you're not actively trading.
A hardware wallet, kept offline, is still one of the highest-return, lowest-effort security moves available.
If your holdings sit in a hot wallet or on an exchange out of convenience, that convenience has a price tag attached — you just haven't paid it yet.
- Multi-signature setups for anything significant.
Requiring more than one key to move funds turns a single point of failure into a harder problem for an attacker to solve.
- Phishing-resistant authentication.
Hardware security keys over SMS-based two-factor, always.
Why? Because SIM-swapping remains one of the most common ways crypto holders get cleaned out.
And it routes directly around a text-message code.
- Assume the breach, plan the response.
Every institution above assumed it were secure enough.
Don’t make the same mistake.
Have a plan for what you do in the first hour if you suspect a compromise — which accounts to freeze, who to call, how to move remaining assets fast.
What Comes After the Basics
Wallet hygiene solves today's threat model. It's worth asking what could solve tomorrow's.
On the federal level, the White House signed an executive order in June on this very topic.
This EO mandates that federal agencies transition their highest-value systems to ones that meet updated security guidelines.
NIST, the National Security Agency and CISA are jointly responsible for guiding agencies through these upgrades over the next four years.
Meanwhile, private industry isn't waiting on Washington. Cloudflare, Google and Microsoft have all recently moved up their own updated security targets to 2029.6
For crypto specifically, this matters more than it does for most industries.
A meaningful share of blockchain security rests on cryptographic signatures that, in theory, follow the same vulnerability path as the systems the federal government is racing to replace.
The migration timeline gives the industry runway — but the clock on protecting high-value holdings may already be running.
To your health and wealth,
Dawn
P.S. Speaking of federal reforms, those have recently opened the door to the secret world of private deals.
Including one very special private deal opening to Weiss members just days from now.
The U.S. government is very interested in accelerating the transition to post-quantum cryptography.
This upcoming deal is in the immensely lucrative quantum computing sector. Which has outperformed even many AI stocks like Nvidia over the past year.
If you’re interested in digital security and getting “in the room” before even some of the biggest-money players get their shot, you really take a few moments to watch this video now.
1Zack Whittaker, "ATF declares major incident as ransomware gang claims hack," TechCrunch, August 27, 2026. https://techcrunch.com/2026/08/27/atf-declares-major-incident-as-ransomware-gang-claims-hack/
2Cybersecurity and Infrastructure Security Agency, "Chemical Security Assessment Tool (CSAT) — Ivanti Notification."https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/chemical-security/assessment-tool-csat-ivanti-notification
3Cybersecurity and Infrastructure Security Agency, "Lessons from CISA's Cyber Incident," July 9, 2026.https://www.cisa.gov/news-events/news/lessons-cisas-cyber-incident
4Cybersecurity and Infrastructure Security Agency, "Chemical Security Assessment Tool (CSAT) — Ivanti Notification." https://www.cisa.gov/topics/critical-infrastructure-security-and-resilience/chemical-security/assessment-tool-csat-ivanti-notification
5Cybersecurity and Infrastructure Security Agency, "Lessons from CISA's Cyber Incident," July 9, 2026. https://www.cisa.gov/news-events/news/lessons-cisas-cyber-incident
6Cloudflare, "The White House's post-quantum executive order is an important milestone. It's time to get to work," June 2026. https://blog.cloudflare.com/post-quantum-eo-2026/

