Ignore a legitimate cybersecurity breach warning once? Shame on the hacker. Ignore a legitimate warning a second time? There might be a deeper, structural flaw at play.
Last month, Nextgov/FCW revealed that, according to unnamed sources, a hacker of currently unknown identity and affiliation had infiltrated the Homeland Security Information Network—a database designed for federal, state, and local law enforcement agencies to exchange security intelligence with each other and with private-sector partners.
The intrusion occurred, according to Nextgov/FCW, “as the U.S. [was] overseeing security for World Cup games across the country, placing added scrutiny on the systems federal, state and local officials use to coordinate major events.”
Based on a new story from the same outlet, citing anonymous sources, analysts at the Federal Emergency Management Agency (FEMA, an arm of DHS) detected indicators that the attackers had been altering files and hiding their tracks from mid- to late May, according to Federal Computer Week. Comparable suspicious activity was then observed from late May into early June, yet on both occasions the incident was written off as a false positive.
It was not until June 4 that staff observed the intruders had “installed hidden backdoors and [stolen] credential data,” prompting an official alert to be raised.
DHS provided a statement to Nextgov/FCW, but the publication notes it is “the same statement it provided earlier this month that confirmed the hack”:
“The Department of Homeland Security is aware of a recent cyber incident involving a specific, unclassified legacy information sharing environment […] We immediately took action to isolate the affected systems, mitigate the vulnerability, and launch a comprehensive forensic investigation. There is no indication that classified networks were impacted, and the system remains operational for our partners. As this is an ongoing investigation, we cannot provide further operational details at this time.”



