The U.S. Department of Homeland Security said it is investigating a breach of the Homeland Security Information Network (HSIN), an information-sharing platform used by government agencies, international partners, and private-sector organizations to exchange sensitive but unclassified data. Reporting cited by DHS indicates the intrusion likely occurred in late May or early June 2026 and affected HSIN servers as well as a SharePoint system tied to the environment. DHS said it isolated the impacted systems, remediated the issue, and began a comprehensive investigation, adding that no classified networks were compromised and that HSIN remains operational.
The incident has raised concern because HSIN supports coordination and information exchange across public- and private-sector entities, meaning exposed data could include operational planning or interagency communications even if the affected environment was described as legacy and unclassified. DHS has not confirmed that any specific information was stolen, and no threat actor has been publicly identified or linked to a known hacking group.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
After discovering the HSIN incident, the U.S. Department of Homeland Security said it isolated the affected systems, remediated the issue, and launched a comprehensive investigation. DHS also stated that the platform remains operational and that no classified networks were compromised.
According to reporting cited in the article, attackers likely compromised Homeland Security Information Network servers and a SharePoint system in late May or early June 2026. The affected environment was described as a legacy unclassified information-sharing platform, and no classified networks were said to be impacted.
Discord previously acknowledged an incident involving its support environment, while disputing attacker claims about the scale of stolen data. The article links the case to the same likely access vector discussed for Crunchyroll: compromised outsourced support-agent accounts connected to Zendesk.
Crunchyroll confirmed a breach in March 2026 involving exposure of customer data. The article says Have I Been Pwned listed 1,195,684 email addresses tied to the incident and describes the likely access vector as compromise of outsourced support-agent accounts connected to Zendesk rather than a Zendesk zero-day.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.