HomeSecurityDHS: HSIN breach – hackers targeted servers and SharePoint

DHS: HSIN breach – hackers targeted servers and SharePoint

The U.S. Department of Homeland Security (DHS) is investigating a cyber incident that, according to reports, led to unauthorized access to the Homeland Security Information Network (HSIN).

DHS HSIN

According to Nextgov, the incident is believed to have occurred between late May and early June. It is unclear who was behind the attack or whether any documents/data were extracted.

Cybercriminals managed to gain access to HSIN servers, as well as a SharePoint platform used for collaboration and information sharing between various government agencies. Following the incident, the Office of Intelligence and Analysis at the Department of Homeland Security (DHS) began a process to assess the scope of the breach and its potential impact.

Why the HSIN breach is important

The HSIN is DHS's central platform for the secure exchange of sensitive, but unclassified, information between federal agencies, local authorities, international partners, and private sector organizations. This system facilitates issues public safety and crisis management.

See also: Phantom Squatting: Hackers exploit AI hallucinations for phishing

Authorized users have the ability to access operational data, exchange information with other services, organize security actions, coordinate the protection of major events, and manage emergency incidents. In addition, the platform is used to exchange information on suspicious persons and potential threats, while offering real-time communication, alerting, and operation management capabilities.

The timing of the attack is particularly concerning, as the United States is responsible for security at the World Cup being hosted in the country. Nextgov notes that since the attackers gained access to critical data, there is a possibility that information related to security planning, coordination between relevant agencies, or incident response protocols may have been exposed.

The Department of Homeland Security confirmed the cyberattack in a statement to BleepingComputer, clarifying that the incident was limited to an older, unclassified information-sharing environment and did not affect classified networks.

See also: Azure CLI Password Spray: 78 accounts compromised

DHS: HSIN breach – hackers targeted servers and SharePoint

How did DHS react?

A DHS spokesperson said that the relevant teams responded immediately, isolating the affected systems, addressing the vulnerability exploited in the attack, and launching a full forensic investigation. At the same time, he emphasized that the platform continues to operate for authorized partners, while more information cannot be released while the investigation is ongoing.

This is not the first time HSIN has been at the center of a security incident. In 2023, an incorrect access rights setting, attributed to a code error by an external contractor, resulted in the exposure of restricted data hosted on HSIN-Intel, the platform's information division.

See also: New data breach at Aflac – Attack on Japanese subsidiary

According to an internal DHS memo leaked to Wired, the technical error changed access settings from a specific group of authorized users to the general “everyone” option, allowing all network users to see information that would normally be strictly restricted. The data exposed included personally identifiable information and sensitive information about U.S. citizens.

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS