← Blog

DHS HSIN Breach: Homeland Security Network Hit During World Cup

Share on X

June 30, 2026: The Department of Homeland Security confirmed it is investigating a cyber incident involving the Homeland Security Information Network (HSIN)—the department's primary platform for sharing sensitive but unclassified threat intelligence among federal, state, local, tribal, international, and private-sector partners. The intrusion occurred between late May and early June 2026, overlapping with U.S. security planning for the 2026 FIFA World Cup.

What happened

According to an exclusive Nextgov/FCW report, an unknown threat actor accessed HSIN servers and a SharePoint collaboration system used for interagency coordination. DHS investigators are probing the intrusion; the actor's affiliation and whether documents were exfiltrated remain unclear.

The department's Office of Intelligence and Analysis conducted a damage assessment. After the story published, a DHS spokesperson said the department isolated affected systems, mitigated the vulnerability, and launched a forensic investigation. DHS stated there is no indication classified networks were impacted and that HSIN remains operational for authorized partners.

What is HSIN?

HSIN is DHS's official system for trusted sharing of sensitive but unclassified (SBU) information. Approved users rely on it to:

  • Exchange requests and coordinate with partner agencies
  • Manage operations and respond to incidents
  • Coordinate safety and security for planned events
  • Share information about persons of interest and emerging threats
  • Conduct real-time communication, document sharing, alerts, and web conferencing

During major events such as the World Cup, HSIN is a critical coordination layer connecting federal agencies, host cities, and industry partners responsible for physical security and threat response.

What data was at risk?

HSIN carries unclassified but sensitive information—not Secret or Top Secret material, but data that can include threat assessments, event security plans, interagency coordination documents, and persons-of-interest information. Nextgov reported that the extent of any data theft is still unknown.

DHS has not published a victim count or detailed data-inventory at initial disclosure. BreachHistory indexes the incident with attested scope pending further DHS or CISA updates.

World Cup timing

The intrusion comes as the United States hosts World Cup matches across multiple cities—a period of heightened federal, state, and local security coordination. A compromise of HSIN raises questions about whether adversaries could gain insight into security planning, interagency coordination, or response procedures surrounding one of the highest-profile international events on U.S. soil.

Prior HSIN security issues

This is not HSIN's first security challenge. In 2023, a contractor coding error caused restricted HSIN data—including sensitive U.S. person information—to be exposed to unapproved users inside the platform, as reported by Wired and Nextgov/FCW.

Who is at risk?

HSIN does not hold consumer account data in the way a retailer breach would. Risk concentrates on:

  • Government and industry HSIN partners whose shared documents or coordination threads may have been accessed
  • Event-security personnel if planning materials were exposed
  • Anyone targeted by spear-phishing referencing World Cup security themes or HSIN access

Action items

  1. HSIN authorized users: Follow DHS partner communications; rotate credentials if directed; report anomalous HSIN activity through official channels.
  2. State/local fusion centers and private partners: Treat unsolicited requests for HSIN credentials or event-security documents as suspicious.
  3. Do not trust leak-site claims about HSIN data until independently verified by DHS or CISA.
  4. Monitor CISA and DHS advisories for follow-up guidance as the forensic investigation continues.

Canonical record: DHS HSIN intrusion 2026 on BreachHistory.

Sources: Nextgov/FCW (June 30, 2026), DHS — HSIN, Wired (2023 HSIN misconfiguration)