The U.S. Department of Homeland Security confirmed a cyber intrusion into the Homeland Security Information Network (HSIN), an unclassified but sensitive platform used to share information with federal, state, local, tribal, territorial, international, and private-sector partners. The breach reportedly occurred between late May and early June and targeted HSIN servers along with an associated SharePoint collaboration system. DHS said it isolated the affected systems, mitigated the vulnerability, and opened a forensic investigation, while the platform remains operational and there is no indication that classified networks were affected.
Officials have not attributed the intrusion to a specific threat actor or foreign government, and it remains unclear whether documents or other sensitive data were stolen. DHS's Office of Intelligence and Analysis has completed a damage assessment as concerns persist over possible exposure of operational and security-planning information used for incident response, interagency coordination, and major event security, including preparations tied to the World Cup in the United States. The incident also renewed scrutiny of HSIN after a separate 2023 permissions error exposed restricted data to unauthorized internal users because of a contractor coding mistake.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
CISA added CVE-2026-45659, a Microsoft SharePoint Server remote code execution vulnerability, to its Known Exploited Vulnerabilities catalog. Reporting cited in the reference noted the flaw as a possible but unconfirmed avenue related to the HSIN intrusion.
After discovering the intrusion, DHS isolated the affected systems, mitigated the vulnerability, and launched a forensic investigation. The department also said HSIN remained operational and there was no indication that classified networks were impacted.
DHS's Office of Intelligence and Analysis conducted a damage assessment of the HSIN incident to evaluate potential exposure and impact. Reporting said the compromise raised concerns about possible exposure of operational and security-planning information.
DHS said attackers compromised the Homeland Security Information Network and targeted HSIN servers and an associated SharePoint collaboration system. The intrusion was reported to have occurred between late May and early June, but no threat actor had been identified and it remained unclear whether documents were stolen.
7 references tracked. Mallory keeps watching after this page renders.
thecybersecguru.com
Open sourcescworld.com
Open sourcecybersecuritynews.com
Open sourcetechcrunch.com
Open sourceteiss.co.uk
Open sourcebleepingcomputer.com
Open sourcenextgov.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.