Particle.news
Download on the App Store

DHS Confirms Breach of HSIN Information-Sharing Network

Officials say they have isolated affected systems and opened a forensic probe with the scope of any data loss and the attackers' identity still unknown.

Overview

  • DHS acknowledged a cyber incident that hit the Homeland Security Information Network, an unclassified platform used by federal, state, local, tribal and private partners for real-time alerts and operational planning, after an intrusion believed to have occurred between late May and early June.
  • The department says it isolated the affected systems, mitigated the vulnerability, and launched a comprehensive forensic investigation while its Office of Intelligence and Analysis completed an initial damage assessment and found no sign that classified networks were impacted.
  • Multiple reports say the attackers targeted HSIN servers and a SharePoint collaboration system, but DHS has not publicly attributed the attack to any actor and has not confirmed whether files were stolen.
  • Senator Mark R. Warner warned that HSIN holds highly sensitive but unclassified operational and personnel information and called for DHS and DOJ to identify who accessed the system and to notify partners so they can mitigate risks to event security and public safety.
  • The incident follows a 2023 HSIN exposure caused by a contractor misconfiguration and is likely to deepen scrutiny of DHS cybersecurity, prompt oversight demands, and pressure to modernize the decades-old platform that many local and state agencies rely on.