D

DHS Acknowledges Cyberattack on Homeland Security Information Network

The information-sharing system designed to enable secure communication among U.S. federal agencies has itself fallen prey to a cyber intrusion.

The Department of Homeland Security (DHS) has officially acknowledged that attackers infiltrated the Homeland Security Information Network (HSIN) and remained inside the system for weeks without detection. Officials noted that investigators are still working to identify those responsible for the breach and determine what data may have been compromised.

This event shifts the spotlight away from the government’s classified networks and onto the everyday platforms that keep agencies interconnected.

As reported by Nextgov, the timing has also sparked concern due to the hacked platform’s involvement in security coordination for the World Cup and the rising frequency of cybersecurity incidents affecting U.S. government agencies in recent years.

Details of the incident

The breach became public after individuals with knowledge of the situation informed Nextgov that attackers had gained access to HSIN servers and SharePoint systems. Together, these two platforms enable the storage and exchange of sensitive but unclassified information across government agencies and critical infrastructure partners.

The sources indicated that the intrusion took place sometime between late May and early June, though it is still unknown exactly when the DHS first learned of the incident.

The Department later acknowledged in a statement cited by BleepingComputer that it was “aware of a recent cyber incident involving a specific, unclassified legacy information sharing environment.” According to the department, the affected systems were isolated, the vulnerability was patched, and a forensic investigation has begun.

The DHS did not disclose the method used by the attackers to gain entry. However, the mention of mitigating a vulnerability suggests that the intruders may have exploited a flaw in HSIN or Microsoft’s SharePoint, a commonly used attack vector.

Must-read security coverage

Sensitive information raises concerns

Although the DHS has stated that classified systems were not impacted, the results of the Department’s investigation will clarify whether the breach involved mere unauthorized access or the actual theft of information shared across the environment.

Nonetheless, even without classified data being compromised, sensitive material within the system could include operational and situational reports from law enforcement, security, and emergency response teams. This is why Nextgov is troubled by the timing of the incident, given the DHS’s role in the FIFA World Cups across the U.S. and other activities it oversees.

Advertisement

Repeated security incidents involving US government agencies

While private enterprises account for many of the cybersecurity incidents making headlines, U.S. government agencies have also experienced numerous security failures involving sensitive information.

In 2023, an HSIN misconfiguration allowed thousands of unauthorized users to view sensitive intelligence reports. Another incident occurred in March, when more than 6,600 ICE records were exposed.


David Hall

David Hall

David is the senior editor at TheCyberMag. He has a background in journalism and has worked with various media outlets, covering topics ranging from threat intelligence and data privacy to cybercrime and cloud security. When he is not writing, David enjoys reading, hiking, photography, and exploring new coffee shops.