A self-described hacktivist group calling itself “Department of Peace” claimed it breached U.S. Department of Homeland Security (DHS) systems and exfiltrated internal records tied to Immigration and Customs Enforcement (ICE) contracting. The group published the material via the transparency collective Distributed Denial of Secrets (DDoSecrets), and reporting indicates the dataset contains 6,600+ contractor-related records listing thousands of companies associated with federal immigration enforcement contracts, including major vendors such as Microsoft, Oracle, Palantir, Raytheon, and Anduril.
The alleged source of the leaked records was described as DHS’s Office of Industry Partnership, a unit involved in procuring technology from the private sector. As of the reporting cited, DHS had not publicly confirmed the intrusion or validated the authenticity and provenance of the released data, leaving the breach claim unverified while the documents circulate publicly via the DDoSecrets-hosted release.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Security researcher Micah Lee created a GitHub-backed page to organize and make the leaked DHS contractor records searchable, including sorting by contract amount. The site highlighted major contracts and made the dataset easier to review.
Hacktivist group "Department of Peace" claimed it compromised U.S. Department of Homeland Security systems and released data allegedly taken from DHS's Office of Industry Partnership. The leak, published on DDoSecrets, reportedly included records tied to DHS and ICE contracts involving more than 6,000 companies and exposed contractor contact details and identifiers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcetechrepublic.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.