Watchdog to examine summertime hack of DHS information network, other incidents

Heather Diehl/Getty Images
The Government Accountability Office is expected to flag that DHS delayed in notifying Congress of the incidents, according to a person familiar with the review.
A forthcoming audit of a key Department of Homeland Security information-sharing network will examine three known security incidents that occurred on agency networks, including an intrusion by outside hackers that Nextgov/FCW first reported this summer, according to two people with knowledge of the matter.
The review concerns the Homeland Security Information Network, or HSIN, which allows government agencies, law enforcement and other approved partners to exchange sensitive but unclassified information. Its users rely on the platform to share threat reporting, coordinate security for major events and respond to emergencies.
The Government Accountability Office review is expected to document the incidents that occurred between 2023 and 2026 and potentially scrutinize DHS for failing to promptly notify Congress about those security problems, the first person said.
The audit is being conducted in response to a directive in the fiscal 2025 defense policy package, the second person said. Both people spoke on the condition of anonymity to discuss details of the review. It’s not clear when the final report will be released.
The previously unreported scope of the audit places this summer’s intrusion within a longer history of security problems on the platform. It also raises questions about whether DHS has given Congress and HSIN stakeholder organizations enough detail to understand what may have been exposed.
GAO has identified two incidents stemming from employee and contractor errors, while the most recent involved a malicious actor whose affiliation remains unknown, the first person said.
In 2023, a contractor’s coding error allowed HSIN users to access restricted information they were not authorized to see, according to a memo previously obtained by Nextgov/FCW. Another similar incident occurred in 2025, the first person said.
Having an HSIN account does not automatically give a user access to everything on the platform. Information is organized into restricted groups, called communities of interest, focused on particular threats, regions or missions. A police official in a border state seeking information about cartel activity, for example, could request admission to a relevant group, with an administrator deciding whether to grant access.
The security incidents have also strained partners’ confidence in the network, according to the first person. Staff at some fusion centers — state and local hubs that bring together law enforcement and other partners to analyze and share threat information — do not know whether their files were accessed without authorization during the various incidents, the person said.
Sen. Mark Warner, D-Va., the Senate Intelligence Committee’s vice chairman, previously said HSIN supported security coordination for this summer’s World Cup and America250 events and that the network’s exposure “risks national security.”
During the most recent intrusion, DHS analysts twice dismissed suspicious activity as harmless, allowing hackers to remain inside for weeks, Nextgov/FCW reported in July. An internal incident readout showed suspicious activity beginning in mid-May. By June 4, the intruders had installed hidden access points and stolen credential data used to authenticate access to accounts or systems, prompting personnel to declare an active breach.
It remains unclear what data, if any, was pilfered from the network.
A DHS spokesperson did not immediately respond to a request for comment. In an earlier statement, the department said it was “aware of a recent cyber incident involving a specific, unclassified legacy information sharing environment” and had isolated affected systems, addressed the vulnerability and begun a forensic investigation.
David DiMolfetta can be reached on Signal via username djd.99
NEXT STORY: FBI seizes websites supporting Chinese contractor’s hacking operations




