2026 DHS — Homeland Security Information Network (HSIN) intrusion; World Cup security coordination platform accessed
Data compromised
Unclassified but sensitive information exchanged on HSIN among federal, state, local, territorial, tribal, international, and private-sector partners—including event security coordination, threat intelligence, persons-of-interest data, and mission-critical documents; extent of exfiltration unclear; DHS states classified networks were not impacted
Technical writeup
Verified incident — reported June 30–July 1, 2026. Nextgov/FCW and BleepingComputer reported that an unknown threat actor accessed the Department of Homeland Security's Homeland Security Information Network (HSIN) in recent weeks, potentially exposing sensitive but unclassified data shared among federal, state, local, and industry partners. DHS investigators are probing the intrusion; the actor's affiliation and whether documents were exfiltrated remain unclear. The Office of Intelligence and Analysis conducted a damage assessment; the intrusion is believed to have occurred between late May and early June 2026, targeting HSIN servers and a SharePoint system used for collaboration. HSIN supports real-time communication, document sharing, alerts, web conferencing, and incident management for event security coordination—including during major events such as the 2026 FIFA World Cup hosted across the United States. DHS confirmed to BleepingComputer July 1, 2026 that it is aware of a cyber incident involving a specific unclassified legacy information-sharing environment, isolated affected systems, mitigated vulnerabilities, and launched a forensic investigation, with no indication classified networks were impacted and HSIN remaining operational for partners. Distinct from dhs2026 (March hacktivist ICE contract leak). BreachHistory indexes recordsAffected 0 pending attested scope.
Root cause
Unknown threat actor accessed HSIN servers and a SharePoint collaboration system between late May and early June 2026; DHS Office of Intelligence and Analysis damage assessment underway
References
- https://www.bleepingcomputer.com/news/security/dhs-confirms-hackers-breached-hsin-info-sharing-platform/
- https://www.nextgov.com/cybersecurity/2026/06/hackers-breached-dhs-information-sharing-network-people-familiar-say/414534/
- https://www.dhs.gov/homeland-security-information-network-hsin
- https://x.com/ddimolfetta/status/2071976919541666104
- https://www.wired.com/story/a-dhs-data-hub-exposed-sensitive-intel-to-thousands-of-unauthorized-users/