
The Department of Homeland Security is investigating a cyberattack that compromised the Homeland Security Information Network (HSIN), an information-sharing platform used by federal, state, local and private-sector partners to exchange sensitive but unclassified data.
The intrusion is believed to have occurred sometime between late May and early June, according to two people familiar with the matter who spoke on condition of anonymity. The identity and affiliation of the attackers remain unknown, and whether any documents were removed from the system is also unclear.
According to one of the people familiar with the matter, the attackers targeted HSIN servers along with a SharePoint system used for collaboration. DHS’s Office of Intelligence and Analysis has since conducted a damage assessment of the intrusion.
HSIN allows approved users to securely access data, coordinate operations, respond to incidents, exchange requests with partner agencies and share information tied to persons of interest and potential threats. The platform supports real-time communication, alerts, document sharing, web conferencing and incident management, and is relied on to help agencies maintain situational awareness during emergencies and major events.
The breach comes as the United States oversees security for World Cup games being held across the country, intensifying scrutiny of the systems federal, state and local officials use to coordinate large-scale events. A compromise of the platform could raise questions about whether the intruders gained visibility into security planning, interagency coordination or response procedures tied to the tournament.
DHS confirmed the incident in a statement. "The Department of Homeland Security is aware of a recent cyber incident involving a specific, unclassified legacy information sharing environment," a department spokesperson said. "We immediately took action to isolate the affected systems, mitigate the vulnerability, and launch a comprehensive forensic investigation. There is no indication that classified networks were impacted, and the system remains operational for our partners. As this is an ongoing investigation, we cannot provide further operational details at this time."
This is not the first time HSIN has faced a security lapse. In 2023, a coding error linked to a contractor caused an access misconfiguration that set permissions to allow all HSIN users, rather than a restricted group, to view sensitive information, including U.S. person data and other personally identifiable material tied to the platform’s intelligence section. The full impact of that earlier incident remains unclear, according to a person familiar with the matter.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543