DHS's Info-Sharing Network Just Got Hacked — Twice

The Department of Homeland Security just confirmed that hackers broke into HSIN — the Homeland Security Information Network — a platform that connects federal, state, local, and private-sector partners to share sensitive-but-unclassified intelligence. The breach, first reported by Nextgov and confirmed by DHS in a statement to BleepingComputer, hit sometime between late May and early June. The attackers targeted HSIN servers and a SharePoint collaboration system, but so far nobody knows who they are, what they got, or whether anything actually left the building. DHS says classified systems were untouched and HSIN remains operational, but it's an unclassified legacy environment — which is government-speak for "we've been patching this thing with duct tape and hope."

What makes this worth paying attention to is the pattern. HSIN had its own breach in 2023 when a contractor's coding error set HSIN-Intel's access permissions to "everyone" instead of a limited group, exposing restricted intelligence from the FBI, the National Counterterrorism Center, and dozens of state and local agencies to tens of thousands of unauthorized users — including foreign nationals. That was a misconfiguration. This time, actual threat actors got in. The timing is especially awkward: the U.S. is currently hosting World Cup matches, and HSIN handles real-time incident coordination, threat alerts, and security planning for events. A breach during a tournament with massive interagency coordination could mean the difference between a quiet embarrassment and a full security review.

Source article image
Source image 1

There's something almost predictable about how government information-sharing networks age. You build them with the best intentions — connect all the agencies, share threat data, coordinate response — and then you forget to lock the doors. The DHS has now had two incidents in roughly three years: one where a single line of code opened the front door, and one where someone walked through it. The question isn't whether HSIN will be patched. It's whether the thousands of agencies that plug in

Source article image
Source image 2
to it actually trust the data flowing through it anymore. If a state emergency manager in Florida or a local fusion center in Arizona pulls intel from HSIN during the World Cup, how do they know it's still reliable? The DHS says the system is operational. The real test will be whether the partners who depend on it believe that.

Sources

Comments

Popular posts from this blog

AI Is Starting to Feel Less Like a Gadget and More Like Infrastructure

When Two AI Bots Finally Learned to Talk in Discord

A CISA Contractor's GitHub Repo Held 844 MB of Secrets — and No One Closed the Door