logo

DHS network intrusion was twice ruled a false positive before breach confirmed

ID: 42e4c460-4947-53db-be98-2cff6be51894

STIX ID: report--42e4c460-4947-53db-be98-2cff6be51894

Feed Name: Nextgov Cybersecurity

Threat Score
75/100

Date Published: 2026-07-13

Date Updated: 2026-07-15

Author: David DiMolfetta

...
...

The DHS Homeland Security Information Network (HSIN) was infiltrated in May–June; attackers altered files, used a legitimate web server to run malicious code, deleted logs, installed hidden backdoors, and stole credential files while initial alerts were misclassified as benign, allowing weeks of undetected access. DHS has isolated affected systems and initiated a forensic investigation, reporting no indication of classified network compromise but acknowledging potential exposure of sensitive unclassified information shared with partner organizations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.