DHS Confirms Hackers Breached HSIN Intelligence-Sharing Platform

The Department of Homeland Security is investigating a cyberattack that hit the Homeland Security Information Network (HSIN) — a platform used by federal, state, local, and private-sector partners to share sensitive intel.

Unknown attackers breached the system between late May and early June, according to sources who spoke with Nextgov. DHS hasn’t attributed the attack to anyone yet. It’s also not clear if documents were stolen.

HSIN is used for real-time alerts, incident management, and sharing info about persons of interest and threats. With the World Cup happening across the US right now, the timing is rough. Nextgov flagged concerns about exposed security planning and response procedures.

A DHS spokesperson confirmed the breach to BleepingComputer. Classified systems weren’t affected, they said. The department isolated the affected systems and launched a forensic investigation.

This isn’t HSIN’s first security problem. In 2023, a contractor’s coding error set access permissions to everyone instead of a limited group, exposing sensitive data including US person info.

DHS says the system is still operational for partners. But questions remain — who got in, what they took, and how long they were there.

References