DHS network intrusion was twice ruled a false positive before breach confirmed
ID: 42e4c460-4947-53db-be98-2cff6be51894
STIX ID: report--42e4c460-4947-53db-be98-2cff6be51894
Feed Name: Nextgov Cybersecurity
The DHS Homeland Security Information Network (HSIN) was infiltrated in May–June; attackers altered files, used a legitimate web server to run malicious code, deleted logs, installed hidden backdoors, and stole credential files while initial alerts were misclassified as benign, allowing weeks of undetected access. DHS has isolated affected systems and initiated a forensic investigation, reporting no indication of classified network compromise but acknowledging potential exposure of sensitive unclassified information shared with partner organizations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
