Hackers breached the U.S. Department of Homeland Security’s Homeland Security Information Network (HSIN), a platform used to share sensitive but unclassified information with federal, state, local, tribal, territorial, international, and private-sector partners. Internal incident details indicate suspicious activity was detected between mid-May and early June on HSIN and an associated SharePoint environment, including altered files on test and production servers, use of a legitimate web-server program to run malicious code, and deletion of logs. DHS said it isolated affected systems, mitigated the underlying vulnerability, opened a forensic investigation, and maintained that classified networks were not affected and HSIN remained operational.
The attackers reportedly remained in the environment for weeks after DHS personnel twice dismissed the activity as false positives. On June 4, the intruders were said to have installed hidden backdoors and stolen credential files before the breach was confirmed. Investigators had not publicly attributed the intrusion, and it remained unclear whether data was exfiltrated, but potentially exposed information may have included event security plans, suspicious activity reports, alerts, persons-of-interest data, and shared operational dashboards. The compromise has raised national security concerns because access to HSIN could support broader intelligence collection, impersonation of trusted partners, targeted spear-phishing, and exposure of emergency and major-event security planning.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
After additional suspicious activity was detected in the HSIN environment, analysts again dismissed the alerts as benign. This second misclassification extended attacker dwell time in the network for weeks.
FEMA analysts observed suspicious activity in the DHS Homeland Security Information Network environment, including altered files, malicious code execution via a legitimate web-server program, and deleted logs. Internal responders ruled these signs a false positive, allowing the intrusion to continue.
Following confirmation of the intrusion, DHS said it isolated affected HSIN servers and an associated SharePoint environment, mitigated the underlying vulnerability, and opened a forensic investigation. The department stated that classified networks were not impacted and HSIN remained operational.
On June 4, intruders installed hidden backdoors in the HSIN environment and stole credential files. DHS personnel then confirmed that the network had been actively breached.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcenextgov.com
Open sourcecyberveille.ch
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.