CSIDB logo
Incident

Department of Homeland Security

Incident posture

Attack window
May 2026
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-26 23:14

Linked entities

Victim
Department of Homeland Security
Threat actors
1 actor
Sources
3 sources

Timeline

Occurred
May 2026
Discovered
Undetermined
Disclosed
Jul 2026
Resolved
Pending

Summary

The Department of Homeland Security is investigating a breach of its Homeland Security Information Network that potentially exposed information shared across federal, state, and local agencies. The breach, discovered recently, has prompted scrutiny of government cybersecurity defenses and prompted a senator to note that the HSIN platform supports the World Cup games. Separately, CISA ordered federal agencies including the department to patch a critical VPN vulnerability exploited by the ransomware group Qilin.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Department of Homeland Security is investigating a breach of its Homeland Security Information Network (HSIN) that occurred during late May and early June 2026. HSIN is a platform used by federal, state, and local governments and law enforcement agencies to share intelligence, plan and coordinate responses to major events, and exchange information during emergencies. According to an unnamed DHS spokesperson, the department became aware of a recent cyber incident involving a specific, unclassified legacy information sharing environment. The investigation is ongoing and it remains unclear what data, if any, was exfiltrated or the volume of information potentially exposed. Senator Mark Warner noted that HSIN has been used to support the World Cup games and was employed the previous year to manage the response to a mid‑air collision. The identity of the attackers has not been disclosed, and the breach is described as the latest security lapse affecting federal government systems.

Separately, the Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent directive on June 9 and June 10 2026 requiring all civilian federal agencies to remediate a critical vulnerability in Check Point software by the end of day June 11. Check Point confirmed that the flaw affects remote access tools, firewalls, and VPN systems that serve as digital gateways protecting networks from unauthorized access. The company stated that a ransomware group known as Qilin is actively exploiting this vulnerability, with hacking attempts beginning on May 7 and activity surging sharply the week preceding the directive. Qilin has reportedly attacked dozens of organizations worldwide that rely on the affected security tools. CISA cited Operational Directive BOD 22‑01 as the basis for ordering agencies to address the issue due to the heightened risk to federal government networks. The directive explicitly named the Department of Homeland Security, the Department of State, and the Treasury among the agencies required to apply patches or other mitigations.

In response to these developments, DHS officials acknowledged the HSIN breach and continued their investigation into the unauthorized access to its servers. Simultaneously, the agency was instructed by CISA to locate and remediate any instances of the vulnerable Check Point products within its infrastructure before the June 11 deadline. No further details about the specific actions taken by DHS to address either incident have been disclosed in the available sources. The combined events underscore the ongoing challenges faced by federal agencies in defending their information technology environments against evolving cyber threats.

Sources

Sources available to members: 3 sources.

CSIDB