The Government Accountability Office is auditing three security incidents affecting the Department of Homeland Security’s Homeland Security Information Network between 2023 and 2026. The latest incident involved an outside malicious actor whose affiliation remains unknown. DHS analysts twice dismissed suspicious activity, allowing attackers to remain inside the network for weeks before personnel confirmed the breach on June 4. The attackers installed hidden access points and stole authentication credential data; the extent of any additional data theft remains unclear.
The other two incidents involved employee or contractor errors that exposed restricted information to unauthorized users. The audit may examine whether DHS promptly notified Congress, while some information-sharing partners remain uncertain whether attackers accessed their files. DHS previously said it isolated affected systems, addressed the vulnerability and began a forensic investigation. The incidents raise concerns about intrusion triage, credential security and timely notification to organizations sharing sensitive information through the network.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
A similar security incident exposed restricted HSIN information to unauthorized users. The source attributed the two earlier incidents to employee or contractor errors.
A contractor’s coding error allowed Homeland Security Information Network users to access restricted information they were not authorized to view, according to an internal memo.
The Government Accountability Office began reviewing three known HSIN security incidents spanning 2023–2026 in response to a directive in the fiscal 2025 defense policy package. The audit may examine whether DHS promptly notified Congress about the incidents.
DHS acknowledged a cyber incident affecting a specific unclassified legacy information-sharing environment. It said it isolated affected systems, addressed the vulnerability and began a forensic investigation.
By June 4, attackers had installed hidden access points and stolen authentication credential data; personnel declared an active breach after identifying those actions. The attacker’s affiliation and the extent of any additional information theft remained unknown.
An internal incident readout documented suspicious activity beginning in mid-May. DHS analysts twice dismissed activity as harmless, allowing an outside malicious actor to remain in HSIN for weeks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.